Home Malware Programs Worms Downadup

Downadup

Posted: January 27, 2009

Downadup, also known as W32.Downadup, Conficker, and Kido, is a worm that spreads accross networks by exploiting the Microsoft MS08-067 vulnerability. Once infected with Downadup worm, it prevents access to several security websites, denies access to admin shares, congested network, turns off Windows Update's Automatic Update and disables Windows Error Reporting Services, Windows Defender and Background Intelligent Transfer Service (BITS).

It is advised to run the latest Windows updates from the Microsoft Download Center and perform a system scan with an anti-virus or anti-malware software to identify and clean your computer from Downadup.

Aliases

W32/Downadup.A (F-Secure)
WORM_DOWNAD.AP (Trend)
Conficker.A (Panda Software)
Win32/Conficker.A (Computer Associates)
Net-Worm.Win32.Kido.bt (Kaspersky)

File System Modifications

  • The following files were created in the system:
    # File Name
    1 %All Users Application Data%\[RANDOM FILE NAME].dll
    2 %Program Files%\Internet Explorer\[RANDOM FILE NAME].dll
    3 %Program Files%\Movie Maker\[RANDOM FILE NAME].dll
    4 %System%\[RANDOM FILE NAME].dll
    5 %System%\[Random].tmp
    6 %Temp%\[RANDOM FILE NAME].dll
    7 %Temp%\[Random].tmp

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{Subkeys}HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SvcHost, netsvcs = %Previous data% and %Random%HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer\Advanced\Folder\Hidden\SHO WALLCheckedValue = dword:00000000HKEY..\..\..\..{RegistryKeys}HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\netsvcs\Parameters\"ServiceDll" = "[PATH OF WORM EXECUTABLE]"

Related Posts

Loading...