1. This forum is in read-only mode.

Conficker/Downadup Virus

Discussion in 'Technical Help' started by Sbf93, May 1, 2009.

Thread Status:
Not open for further replies.
  1. Sbf93

    Sbf93 Well-Known Member

    My problem is simple:
    For some days, my avira free gives me a virus warning when i put in a usb-stick from a friend. Something from that stick creates a infected .dll file in my system32 folder.
    From this time I cant see my hidden folders anymore. When I tryed to change the option for it, it always switches back after a part of a second. I searched trough the internet and found some registry-entries i have to change -> Problem solved.
    2 days later i cant see hidden folders again and I decided to download a full internet security suite. I choose Norton Internet Security 2009, because there was a unlimited trial crack for it. (Whenever I restart my PC Ive got a new 90 days license)
    First I cant visit the symantec website, something was blocking it. I downloaded the Suite over a Proxi and instaled it. I cant connect to the Update Server and run a complete scan with a older Virus-Database. It found some infections and from this moment i can make Updates, see all folders and so on.
    After updating I make a second full scan. It found a lot more than at the first time. One of the Viruses: W32.Downadup.B

    Nice, i have the Conficker!!!
    Norton says: Virus is removed and my question:
    Do I have to download a special Conficker Removal Tool like this one: http://www.symantec.com/security_response/writeup.jsp?docid=2009-011316-0247-99 or is my PC clean right now?
  2. Loonylion

    Loonylion Administrator Staff Member

    yes you have to. Also don't trust norton, its detection and cleaning rates are abysmal.
  3. pugmalion1

    pugmalion1 Well-Known Member

  4. Sbf93

    Sbf93 Well-Known Member

    You relly think, norton is as bad as you say? It becomes good to very good rates from all PC-Magazines and websites is know.
    But back to topic: Ive downloaded a removal tool and let it work. After 2 hours it says, that my PC is clean and no conficker is detected. And I also realized, that the Worm disable my Windows Update! Why the hell no antivirus software can detect problems like this?!? I have to activate manually all services like safetycenter and windowsupdate myself.
  5. Seph

    Seph Administrator Staff Member

    AVG would have caught it. :)

    The problem is that you got it from a USB stick, they work differently than internet sources and are, apparently, harder to block.
    The usual procedure for getting rid of these things is to boot into safe mode and then run your anti virus / specialized tools. After that you'll want to delete any system restore points as well as those might be infected too.
  6. Sbf93

    Sbf93 Well-Known Member

    I dont like AVG, its blocking some hacks, cracks, trainers... and i cant set up a folder in this prog, where it doesnt scan.

    To the restore points: I never use them, thats why the disc space is set to only 1 GB for them, but how can I deleate restore points?
  7. Loonylion

    Loonylion Administrator Staff Member

    Disabling system restore will delete them.
  8. Sbf93

    Sbf93 Well-Known Member

    Thank you guys. Its looking my sytem is clear now, only think founded: Tracking Cookie.

    Is that from the Conficker, or is that something else?
  9. Loonylion

    Loonylion Administrator Staff Member

    tracking cookies are harmless and are used to control how often webpages (such as romulation) show ads.
  10. mds64

    mds64 Well-Known Member

    AVG free is good, if constantly updated that is-they only time it stops me is when an actual virus comes thru!

    It won't work correctly if there already is a virus, as my mother just found out thank to me :(
  11. Sbf93

    Sbf93 Well-Known Member

    I havent anythink against the safety or whatever of AVG, its just a problem for me, that i cant set it up to ignor specific files/folders on my harddrive.
    I think I will going with Norton Internet security 2009 and the unlimited Trial Hack, it deleates the conficker completely and it also detects the W32.Downadup.B-autorun! file on the USB Stick from my friend.
    By the way: AVG and Avira only detect the created .dll in System32 and not the source-virus on the stick. I know it from both programs, because this little fucking stick dont only infects my and his PC. There were also 3 other guys, which used the stick and one of them used AVG.
    Tomorrow we will clean their PCs, while we making a LAN. Im the only of us, who can play games all the time :p
  12. vhiznu

    vhiznu Well-Known Member

    conficker is usually infect with an autorun files...(like autorun.inf from your flashdisk)
    the virus itself is hidden....as long as the source is not deleted...the autorun will always reproduce...
    do not open file with autorun menu...or just disable the autorun...
    scan with your avira first! i'm an avira free user too ;)
Thread Status:
Not open for further replies.