Author Topic: Downadup Removal Tool  (Read 2726 times)

Offline faith_michele

  • Anti - Phishing Staff
  • Gold Member
  • Posts: 1947
    • A Beacon of Light
Downadup Removal Tool
« on: March 13, 2009, 02:45:49 AM »
What do you all think of this tool?  The Downadup Removal Tool is here.

BitDefender's Press Release

BitDefender is the first to offer a free tool which disinfects all versions of Downadup

Wednesday, March 11, 2009

On Saturday, March 7, BitDefender detected a new and more aggressive version of the Downadup virus. It spreads using a Windows RPC Server Service vulnerability and is called Win32.Worm.Downadup.C.

The new version is more resistant to disinfection. Once the system is compromised, the worm disables Windows Update and blocks access to most anti-virus websites in order to hinder the user to disinfect the machine.

BitDefender is the first to offer a free tool which disinfects all versions of Downadup and is available for all infected users at This domain is the first to serve a removal tool without being blocked by the e-threat.

The worm itself is not new, it made its first appearance in late November 2008, known under the names Conficker or Kido. The worm is also known for exploiting the vulnerability described in the Microsoft security bulletin MS08-067. After successful exploitation it used to install rogue security software on the infected machine.

“BitDefender Labs has been seeing an increase in worms, like Downadup, that have a built-in mathematical algorithm, generating strings based on the current date,” said Vlad Valceanu, BitDefender’s senior malware analyst. “The worms then produce a fixed number of domain names on a daily basis and check them for updates. This makes it easy for malware writers and cybercriminals to upgrade a worm or give it a new payload as they only have to register one of the domains and then upload the files."

Microsoft Consumer Security MVP, July 2007-June 2010

"Fight your fights, find the grace in all the things that you can't change and help somebody, if you can." Van Zant

A Beacon of Light

Offline Bugbatter

  • Microsoft® MVP
  • Administrator
  • Diamond Member
  • Posts: 9567
Re: Downadup Removal Tool
« Reply #1 on: March 13, 2009, 09:58:58 AM »
We use it. It disinfects and produces a log that can be analyzed along with other information available to our helpers on the forums.

Microsoft MVP - Consumer Security
“Tell me and I forget, teach me and I may remember, involve me and I learn.” ~ Benjamin Franklin