How to remove the virus CONFICKER / DOWNADUP / KIDO?

It is important to know how to remove the conficker or the downadup or the kido from an infected computer. Viruses and worms such as the conficker, also known as the downadup, or the kido, pose a grave security risk to all computers. A computer infected with the conficker is vulnerable to attack and all data including personal information is compromised. Disinfect the conficker affected computer by removing it from the network and running FlashDiskinfector software. Install the Windows patch to plug the entry point of the virus in the Windows operating system. It is a time consuming job to remove the conficker and it is best to take precautions to avoid infection by the conficker in the future.

How to remove the virus CONFICKER / DOWNADUP / KIDO




What is the Conficker?


Conficker (also known under the names of Downup, Downandup and Kido) is a worm that first appeared in October 2008. It has infected millions of computers, especially in companies or institutions such as the French Navy, hospitals or the British Royal Navy. This threat is taken seriously, Microsoft has even promised a reward of $250,000 to anyone who gives information to stop the author of this worm.

When it is installed in a computer, Conficker disables the Windows updates and some security software. It then connects to a server, allowing an attacker to gain complete control to retrieve personal information, install other malicious software or conduct illegal acts.


How to avoid being infected by Conficker


This infection uses a Windows vulnerability to propagate. A patch correcting this vulnerability was published on October 15 by Microsoft, but many users have not installed it. If you have disabled automatic updates and have not yet installed this patch, you can download it here:
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

Conficker can also spread through removable drives (USB keys, external hard drives etc.) and within an open network or one protected by weak passwords. Use FlashDisinfector to vaccinate your removable disks, and secure your networks using strong passwords.


Disinfect a computer affected by Conficker

Preliminary


Take precautions to prevent the virus from spreading and to prevent reinfecting the computer again after disinfection.
  • Temporarily disconnect your computer from the network.
  • Stop the server temporarily:
    • In the Start Menu click Run and type "services.msc"
    • Click OK
    • Right-click on the "Server" and select Properties
    • Click "Stop", set Startup type to "Disabled" and click OK.
  • Disinfect and vaccinate all removable drives (USB keys, external hard drives, mp3 players etc.) with FlashDisinfector.


- Download the Microsoft patch to fix the vulnerability exploited by Conficker:
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx

It is likely that you will not be able to do it from your computer. If this is the case, take it from another and upload the patch on a vaccinated removable disk (see above).

Remove infection


You can now start disinfecting the computer.
  • First try to scan the computer with your antivirus, or MalwareBytes Anti-Malware for example
  • Microsoft also provides a tool for removing malicious software (MSRT), which can help with the disinfection process. More information is available on Microsoft's website.
  • F-Secure (which works with Microsoft on Conficker) offers a removal tool targeting this infection:

http://www.f-secure.com/v-descs/worm_w32_downadup_gen.shtml
  • However, Conficker is quite difficult to remove, because it creates files that are associated with legitimate Windows process, such as Svchost. It is therefore possible that all previous recommendations are not enough. In this case, feel free to post a message on the forum Viruses / security.
Published by jak58 - Last update on February 6, 2012 07:19 PM by Paul Berentzen
This document entitled « How to remove the virus CONFICKER / DOWNADUP / KIDO? » from Kioskea.net (en.kioskea.net) is made available under the Creative Commons license. You can copy, modify copies of this page, under the conditions stipulated by the licence, as this note appears clearly.
Suggestions
  •  How to remove the virus CONFICKER / DOWNADUP / KIDO?
  •  How to remove shortcut virus (Solved) » Best answer: Hello, If you did not format your flash drive, then check whether the files are not in hidden mode. Follow the following steps. Step 1: Click on the below link and download the file "AutorunExterminator" http://en.kioskea.net/download/downloa
  •  How to remove recycler virus (Solved) » Best answer: There is a much simple way to remove the Autorun.inf file. Genreally when you refresh the windows explorer view a bounded virus process recreates this file. This file is attached to many events of windows explorer including OPEN, REFRESH, etc
  •  How to remove recycler virus from my Drive (Solved) » Best answer: Hello, Try this 1. Check whether the files are not in hidden mode. Follow the following steps. Step 1: Click on the below link and download the file "AutorunExterminator" http://en.kioskea.net/download/download-11613-autorun-exterminator Extr
  •  Pendrive all shortcuts (Solved) » Best answer: Hello, Try this 1. Check whether the files are not in hidden mode. Follow the following steps. Step 1: Click on the below link and download the file "AutorunExterminator" http://en.kioskea.net/download/download-11613-autorun-exterminator Extr
  •  Files on flash drive changed to shortcuts » Tips : A virus infected flash drive can definitely create trouble. It is possible a virus in the flash drive could alters the names of the files to shortcuts. In this condition it becomes difficult to view files even after the virus is eradicated. This...
Delete the virus ''Christina Aguilera''
Online scanning using F-secure