Downadup
Downadup, also known as W32.Downadup, Conficker, and Kido, is a worm that spreads accross networks by exploiting the Microsoft MS08-067 vulnerability. Once infected with Downadup worm, it prevents access to several security websites, denies access to admin shares, congested network, turns off Windows Update's Automatic Update and disables Windows Error Reporting Services, Windows Defender and Background Intelligent Transfer Service (BITS).
It is advised to run the latest Windows updates from the Microsoft Download Center and perform a system scan with an anti-virus or anti-malware software to identify and clean your computer from Downadup.
Aliases
WORM_DOWNAD.AP (Trend)
Conficker.A (Panda Software)
Win32/Conficker.A (Computer Associates)
Net-Worm.Win32.Kido.bt (Kaspersky)
File System Modifications
- The following files were created in the system:
# File Name 1 %All Users Application Data%\[RANDOM FILE NAME].dll 2 %Program Files%\Internet Explorer\[RANDOM FILE NAME].dll 3 %Program Files%\Movie Maker\[RANDOM FILE NAME].dll 4 %System%\[RANDOM FILE NAME].dll 5 %System%\[Random].tmp 6 %Temp%\[RANDOM FILE NAME].dll 7 %Temp%\[Random].tmp
Registry Modifications
- The following newly produced Registry Values are:
HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, netsvcs = %Previous data% and %Random%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHO WALLCheckedValue = dword:00000000HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netsvcs\Parameters\"ServiceDll" = "[PATH OF WORM EXECUTABLE]"
Use SpyHunter to Detect and Remove PC Threats
If you are concerned that malware or PC threats similar to Downadup may have infected your computer, we recommend you start an in-depth system scan with SpyHunter. SpyHunter is an advanced malware protection and remediation application that offers subscribers a comprehensive method for protecting PCs from malware, in addition to providing one-on-one technical support service.
* See Free Trial offer below. EULA and Privacy/Cookie Policy.
Why can't I open any program including SpyHunter? You may have a malware file running in memory that kills any programs that you try to launch on your PC. Tip: Download SpyHunter from a clean computer, copy it to a USB thumb drive, DVD or CD, then install it on the infected PC and run SpyHunter's malware scanner.
Leave a Reply
Please note that we are not able to assist with billing and support issues regarding SpyHunter or other products. If you're having issues with SpyHunter, please get in touch with SpyHunter customer support through your SpyHunter . If you have SpyHunter billing questions, we recommend you check the Billing FAQ. For general suggestions or feedback, contact us.