Eng
  1. Skip to navigation
  2. Skip to content
  3. Skip to sidebar


Worm:W32/Downadup.gen


Aliases:


Worm:W32/Downadup.gen
Net-Worm.Win32.Kido
Win32.Worm.Downadup.Gen, Win32.Worm.DownadupINF.Gen
Worm:W32/Downadup.gen, Worm:W32/Downadup.gen!A

Malware
Worm
W32

Summary

Worm:W32/Downadup.gen is a Generic Detection of Worm:W32/Downadup.



Disinfection & Removal


Automatic Disinfection

Allow F-Secure Anti-Virus to disinfect the relevant files.

Note

Downadup makes use of random extension names in order to avoid detection. During disinfection, Scanning Options should be set to:

  • Scan all files

For more general information on disinfection, please see Removal Instructions.


REMOVAL TOOLS

Some variants of the Downadup worm attempt to block execution of F-Secure malware removal tools. If the downloaded tool does not work, please rename the file. Example: from "f-downadup.exe" to "file.exe" or "explorer.exe". Then try running the tool again.


F-Downadup

Specific tool with heuristics for Downadup worm variants:

This is a command line tool. Please read the text file included in the ZIP for additional details.


Microsoft Help and Support

Knowledge Base Article 962007 provides numerous details for manual disinfection of Conficker.B (alias Downadup):



Technical Details

For technical details of Downadup's installation and propagation mechanisms, see the following descriptions:


Propagation

Downadup uses a variety of methods and vectors to spread itself:

  • Exploits a Windows vulnerability; patched by security update 958644 (read our Vulnerability Report, SA32326: Microsoft Windows Server Service Vulnerability).
  • Use of network shares; weak passwords.
  • It uses Windows AutoRun functionality; autorun.inf files are copied to USB drives and other removable media.

Certain Downadup variants have additional rooutines:


About Generic Detections

Unlike more traditional detections (also known as signatures or single-file detections) a Generic Detection does not identify a unique or individual malicious program. Instead, a Generic Detection looks for broadly applicable code or behavior characteristics that indicate a file as potentially malicious, so that a single Generic Detection can efficiently identify dozens, or even hundreds of malware.

For more information about Generic Detections, see the Generic Detection description.





Description Created: 2009-01-09 11:53:48.0
Description Last Modified: 2010-09-29 09:40:20.0



Submit a sample




Wondering if a file or URL is malicious? Submit a sample to our Lab for analysis via the Sample Analysis System (SAS)

Give And Get Advice




Give advice. Get advice. Share the knowledge on our free discussion forum.