Downadup

Photo of a virusThere is some deja vu in this story.  I talked about Conficker back in January when Conficker.B made it’s way around the Internet.  Now, Conficker.C is said to be released on Wednesday April 1st.

And, again, the solution to protecting yourself is the same and just as simple.  So, is the removal if you have it.



Preventing Conficker from getting into your system

Here is the key.  You should already be protected.  Yep!  If you listen to the show and actually do the things we suggest, you really will have prevented most of the problems your computer will experience.  There are two problems that can cause your computer to get infected.  The common cold, and YOU!

Well, maybe not the common cold.

But, if you enjoy listening to the show every week and don’t DO what we recommend almost every week, then your computer is partially or fully vulnerable to a lot of malicious infections.

Here are 3 tips that will help you prevent almost all threats from infecting your computer.  This includes Conficker.

1.  Make sure that you have your Windows Operating System up to date.  There are a lot of people who disable automatic updates because it bugs them or because someone told them it’s better to turn it off.

Microsoft issues updates regularly to patch new security issues.  You MUST turn automatic updates on.

Also, Microsoft patched the issue that allows the Conficker worm to infect your computer way back in October.  Yet, at least 12 million computers have been infected.  Go figure.

You can ensure that you have this particular patch by going to http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx.  Scroll down and click on the version of Windows you have installed on your computer to download the patch.  Make sure it is installed.

2.  Next, you need to make sure that you have good active protection.  Active means that it is always running, keeping an eye on activity on your computer.

This active protection I am talking about is your anti-virus program.  You NEED to have a modern version of a good anti-virus and make sure automatic updates for it are turned on and it is updated.

By modern I mean that your version of Norton, McAfee, AVG, Avast, NOD32, Trend, Bit Defender, and all of the rest of the big named products should be the most current version. No more than a year old.

How much money do you spend changing the oil in your car every year?  The purchase of a new copy of a good anti-virus is far cheaper.  Or, you can can install one of the good free products like Avast, which I recommend and is available for download by clicking the Downloads link in the menu at the top of the blog, or AVG 8 for new machines.

At least download and install the trial version of a good anti-virus.  This will give you at least 30 days of free protection.

3.  Finally, avoid the Conficker.C virus.  Don’t do searches with the word Conficker or Downadup.  The bad guys know you will be looking for information and many sites could be infected.

Stay away from websites that you are not familiar with.  Don’t fall for the removal tool tricks.  Many of them are fake and will infect you computer. 

Don’t use Torrent sites to download music, movies, or files.

Don’t click on attachments in email if you were not expecting them.  Especially this week, verify that your sister sent you those pictures.

This worm can be spread using a USB thumb drive or external drive as well as over your
home or business network. If your protection is correct, it should catch it.

Practice safe surf.

If you follow these three methods to protect your computer, the chances are you will not become infected by Conficker or any other virus.  Unless you click on something you should not.

How to remove Conficker/Downadup if you are infected.

You know if you are infected if you open any browser and try to go to one of the security companies like Symantec (Norton), McAfee, F-Secure, or any of them and you get an error something like “Page Can Not Load”.

If you need to remove Conficker, download one of the several programs in the links I have listed below and follow the instructions after  you install it.

You should do a complete clean up and tune up of your computer after you remove Conficker.  There will be other malware on it if Conficker was on it.

Removal Tools (Use any one of them)

I have not used all of these products.  They were obtained from their
respective manufacturer sites.

If you are on a network, home or business, unplug your computer from the Internet after you download the tool and before you run it.

Bit Defender Removal Tool
Bit Defender For Computers On A Network Removal Tool
F-Secure Removal Tool
McAfee Removal Tool
Microsoft Removal Tool
Norton Removal Tool

Photo of a virus Back in October, Microsoft released a patch, MS08-067 , that would block the Conficker.A worm in a special update.

Over the last couple of weeks, a new variant of this worm has been affecting customers. Microsoft detected it as Worm:Win32/Conficker.B. In addition to exploiting MS08-067 (the patch from October), this variant also uses other propagation methods; it tries to copy itself to network shares by guessing their passwords. If the password is weak, it may succeed. It also tries to spread via removable media like thumb or jump drives.

In the last few days, including January 15, 16, and 17. It has infected more than 3.5 million computers worldwide. And, it is spreading rapidly.

  • Shared computers with weak passwords may get infected by the worm
  • External hard disks and USB sticks may get infected by the worm
  • Computers without the latest patches and updates may get infected by the worm

It is important that you update all of the computers on your business or home network that are running the any version of the Windows operating system immediately, including Windows XP, Vista, and Server Operating systems. The update will block Conficker.B from infecting your computers if it has not already!

If you have been infected by Conficker, I have a link below that will allow you to download the Microsoft Malicious Software Removal Tool directly from Savemybutt to get rid of it.

However, because the warm blocks not only the Microsoft site, but also, most major security sites, including Norton, McAfee, Trend Micro, AVG, and Avast. You will have to download the removal tool from my site on the infected machine (because it is not blocked) or onto a clean machine that is not on your network, and then install it on all machines in your network. This MUST be run, and all computers on your network, because it spreads over your network to other machines.

Click here to download the Microsoft Malicious Software Removal Tool directly from this site.  Savemybutt is not be blocked  by the worm. Run it on EVERY computer on your network!

Also known as by different security companies:

TA08-297A (other)

CVE-2008-4250 (other)

VU827267 (other)

Win32/Conficker.A (Computer Associates)

Mal/Conficker-A (Sophos)

Trojan.Win32.Agent.bccs (Kaspersky)

W32.Downadup.B (Symantec)

List of word, character strings, websites, and domains that are blocked (that we know of).

virus
spyware
malware
rootkit
defender
microsoft
symantec
norton
mcafee
trendmicro
sophos
panda
etrust
networkassociates
computerassociates
f-secure
kaspersky
jotti
f-prot
nod32
eset
grisoft
drweb
centralcommand
ahnlab
esafe
avast
avira
quickheal
comodo
clamav
ewido
fortinet
gdata
hacksoft
hauri
ikarus
k7computing
norman
pctools
prevx
rising
securecomputing
sunbelt
emsisoft
arcabit
cpsecure
spamhaus
castlecops
threatexpert
wilderssecurity
windowsupdate