Problems with Conficker or Downadup?

Or How to Disable Autoruns

– to Stop This Particular Infection Route

This is a brief summary of what to do…
  1. Make sure you have a proper anti-virus program running
    • NOD32 is a good one!
    • AVG is too
    • Kaspersky, Trend, CA are also good brands
  2. Make sure your anti-virus is current and updated.  Check like so:
    • Somewhere on your program will be it’s last update
    • For NOD32, hover your mouse cursor over the little icon next to the taskbar clock (bottom right in XP)
    • As well as version numbers, the last update shows in reverse date format – 6 Feb 2009 is 20090206
    • Other programs are very similar and the last update is usually pretty obvious so you don’t need to fiddle with settiings etc.
  3. Disable autoruns as this is a good way for the virus/malware/trojan to get you
    • This is the best and easiest way to do this:
Copy This Text:

REGEDIT4
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\IniFileMapping\Autorun.inf]
@=”@SYS:DoesNotExist”

Open Notepad:

start -> run -> type ‘notepad’ (without quotes) and hit Enter on the keyboard

Paste Into Notepad:

Now paste the copied text into Notepad

Now Save the File:

Call the file a handy name like “StopAutoRun” but make sure it has a ‘reg’ extension!

So your file should be called something like StopAutoRun.reg

Now Run The Reg File You’ve Just Made:

Double-click the file – your registry will pick up the change and the handy autorun feature will be disabled!

Of course, you may be used to using this “handy feature”.  If you want to keep it, don’t do any of the above but be very, very, very careful about any USB stick you insert into your computer, any CD you insert or play, any video you watch on DVD, and any network you map or connect to…

What About if I’m Already Infected?

How to Clear and Eliminate Conficker or Downadup?

  1. Connect to the internet with a “good”, clean computer.  You may need to borrow one or visit a friend’s house..
  2. Download a clean up program – the NOD32 version is here: http://download.eset.com/special/EConfickerRemover.exe Other Anti-virus makers have similar ones.
  3. Copy the tool you’ve just downloaded to your own PC and run it.   It may take a while and you’ll definately need a reboot afterwards.
  4. Install and/or Update a good Antivirus program (see above at top)

Further Reading and Information Sources

Comments

Leave a Reply

Copyright ©1976

All Rights Reserved by Strangely Perfect

Occasional Tweets here @crawlingchaosuk