Security [CENTRAL] Forum - SCforum.info
31. July 2010., 07:23:01 *
Welcome, Guest. Please login or register.

Login with username, password and session length

SCforum.info - Security [CENTRAL] Forum

↑ Grab this Headline Animator

Custom Search
News: # Win 3 licenses of BitDefender Total Security 2010 ! ! !
 
  Home   Forum   Help Chess Links Login Register   *

SCforum.info




SCF Recent Posts
[30. July 2010., 21:34:58]

[30. July 2010., 04:46:02]

[29. July 2010., 18:08:07]

[29. July 2010., 10:48:03]

[29. July 2010., 06:49:07]

[28. July 2010., 18:43:20]

[28. July 2010., 09:39:19]

[28. July 2010., 08:25:57]

[27. July 2010., 20:10:00]

[26. July 2010., 09:48:23]
SCF Translate


Members
Total Members: 4608
Latest: bufuNk
Stats
Total Posts: 10662
Total Topics: 3314
Online Today: 957
Online Ever: 51419
(01. January 2010., 12:27:49)
Users Online
Users: 13
Guests: 1103
Total: 1116

@MEMBER OF PROJECT HONEY POT
Spam Harvester Protection Network
provided by Unspam

Friend of WOT

Creative Commons License

SCF Feedburner

SCF Facebook

SCF Twitter

Welcome to SCforum.info - Security [CENTRAL] Forum, a home of the SCF Community devoted to provide Computer related News, Alerts, Downloads and FREE Help in such a way that even the novice computer user can understand.

Getting started using our community is extremely easy, check the two steps below:

Step 1: Create an account by clicking here. It's completely free with no hidden strings attached.

Step 2: If you have a computer problem and need some help, or just want to take part in opened discussions, simply visit scForum. Once you *Register an account, you can quickly post your questions and comments.

(*Registered Members get: free support, also, they can communicate privately with other members via PM, removal of this message, see fewer ads and much more...)






Pages: 1
  Print  
Author Topic: Microsoft Removal Tool (delete, clean, fix, remove: Conficker, Kido, Downadup)  (Read 34469 times)
0 Members and 7 Guests are viewing this topic.
Samker
SCF Administrator
*****

KARMA: 49
Gender: Male
Age: 32
Location: Europe
Posts: 3620


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« on: 18. January 2009., 10:10:32 »



The Microsoft Windows Malicious Software Removal Tool checks computers running Windows Vista, Windows XP, Windows 2000, and Windows Server 2003 for infections by specific, prevalent malicious software—including Blaster, Sasser, and Mydoom—and helps remove any infection found. When the detection and removal process is complete, the tool displays a report describing the outcome, including which, if any, malicious software was detected and removed.

Microsoft releases an updated version of this tool on the second Tuesday of each month, and as needed to respond to security incidents. The tool is available from Microsoft Update, Windows Update and the Microsoft Download Center.

Note: The version of the tool delivered by Microsoft Update and Windows Update runs in the background and then reports if an infection is found. If you would like to run this tool more than once a month, use the version on this Web page or install the version that is available in the Download Center.

Because computers can appear to function normally when infected, Microsoft advises you to run this tool even if your computer seems to be fine. You should also use up-to-date antivirus software to help protect your computer from other malicious software.

Here is a list of every major virus and worm family added since the tool was first released on January 11, 2005.:

  • Alcan
    Alemod
    Allaple
    Alureon
    Antinny
    Atak
    Badtrans
    Bagle
    Bagz
    Bancos
    Banker
    Banload
    Beenut
    Berbew
    Blaster
    Bobax
    Bofra
    Brontok
    Bropia
    Bugbear
    Busky
    Captiya
    Ceekat
    Chir
    Codbot
    Conficker (Kido, Downadup)
    Conhook
    Corripio
    Cissi
    Cutwail
    DoomJuice
    Dumaru
    Esbot
    Evaman
    Eyeveg
    FakeSecSen
    FakeXPA
    F4IRootkit
    Fizzer
    Fotomoto
    Frethog
    Funner
    Gael
    Ganda
    Gaobot
    Gibe
    Gimmiv
    Goweh
    Hacker Defender
    Hacty
    Harnig
    Haxdoor
    Horst
    Hupigon
    IRCBot
    Ispro
    Jeefo
    Kelvir
    Korgo
    Ldpinch
    Locksky
    Lolyda
    Lovgate
    Mabutu
    Magistr
    Maslan
    Matcash
    Mimail
    Mitglieder
    Mydoom
    Mytob
    Mywife
    Nachi
    Netsky
    Newacc
    Nsag
    Nuwar
    Oderoor
    Opaserv
    Optix
    Optixpro
    Parite
    Passalert
    Plexus
    Purstiu
    Randex
    Rbot
    Reatle
    Renos
    Rjump
    Rustock
    Ryknos
    Sasser
    Sdbot
    Sinowal
    Slenfbot
    Sober
    Sobig
    Spybot
    Spyboter
    Storark
    Stration
    Swen
    Taterf
    Tibs
    Tilcun
    Torvil
    Valla
    Virtumonde
    Virut
    Vundo
    Wootbot
    Wukill
    Yaha
    Yektel
    Zafi
    Zindos
    Zlob
    Zonebac
    Zotob
    Zuten

Download: http://www.microsoft.com/downloads/details.aspx?FamilyId=AD724AE0-E72D-4F54-9AB3-75B8EB148356&displaylang=en

Logged

Security [CENTRAL] Forum - SCforum.info
« on: 18. January 2009., 10:10:32 »



 Logged
siteriver
SCF Newbie
*

KARMA: 0
Posts: 1


« Reply #1 on: 25. January 2009., 18:24:19 »

Once you HAVE the virus, you can no longer download updates from Microsoft and most antivirus software vendors. One thing the virus does is block requests from you computer to these web sites. Following the steps from a site I found - edit - removed link until we check this site - downloading a free removal tool, disabling AutoPlay, and repairing the registry - you can remove this virus and protect from infection.  The cleaning tools can still be reached by IP address.

Logged
Samker
SCF Administrator
*****

KARMA: 49
Gender: Male
Age: 32
Location: Europe
Posts: 3620


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #2 on: 25. January 2009., 18:37:21 »

Hi siteriver and welcome to SCF Community.

Thank you for your reply and useful information about infection. As you notice I was remove your posted link until we check this site.

Until that, I'll suggest our Topic with recommended protection for this worm: http://scforum.info/index.php/topic,2280.0.html

Regards,

Samker
Logged

LeeH
Guest
« Reply #3 on: 26. January 2009., 16:36:34 »

Hi there,

In desperate need of help.  I have Conficker / Kido.CJ on my NT 4.0 File Server and would really appreciate a Step By Step 'Dummy's' Guide (or link to same) to remove it manually.

As soon as I get rid of this damn thing I'll upgrade, but until then any help would be appreciated.

Thanks in advance
Logged
Samker
SCF Administrator
*****

KARMA: 49
Gender: Male
Age: 32
Location: Europe
Posts: 3620


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #4 on: 26. January 2009., 20:48:10 »

Hi LeeH and Welcome to SCF Portal.

For immediately help, related to any kind of PC problems, please visit our "PC Help Center": http://scforum.info/index.php/board,16.0.html

Read this topic "New Visitor? Read This First: Online AntiMalware Scanners" and after that open your own (help request)Topic.

It's also good idea to finish your registration to SCF Portal because you will also enable few additional forum functions like Private Messages etc.

Regards,

Samker
Logged

Samker
SCF Administrator
*****

KARMA: 49
Gender: Male
Age: 32
Location: Europe
Posts: 3620


Whatever doesn't kill us makes us stronger.

Google Talk
WWW
« Reply #5 on: 04. April 2009., 09:18:29 »


Latest update info. related to Conficker infections: http://scforum.info/index.php/topic,2577.0.html



Logged

stations
SCF Member
**

KARMA: 1
Posts: 26


« Reply #6 on: 16. May 2009., 08:48:49 »

i'm use removal from eset. EConfickerRemover
Logged
saradhi
SCF Member
**

KARMA: 1
Posts: 10


« Reply #7 on: 19. May 2009., 11:39:01 »

Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008.[1] The worm uses a combination of advanced malware techniques which has made it difficult to counter, and has since spread rapidly into what is now believed to be the largest computer worm infection.

The origin of the name Conficker is thought to be a portmanteau of the term "configure" with German word Ficker, which means "fucker."[3][4] On the other hand, Microsoft analyst Joshua Phillips described the name as a rearrangement of portions of the domain name trafficconverter.biz,[5] which was used by early versions to download updates.

Discovery:

The first variant of Conficker, discovered in early November 2008, propagated through the Internet by exploiting a vulnerability in a network service (MS08-067) on Windows 2000, Windows XP, Windows Vista, Windows Server 2003, Windows Server 2008, and Windows Server 2008 R2 Beta. While Windows 7 may have been affected by this vulnerability, the Windows 7 Beta was not publicly available until January 2009. Although Microsoft released an emergency out-of-band patch on October 23, 2008 to close the vulnerability, a large number of Windows PCs (estimated at 30%) remained unpatched as late as January 2009. A second variant of the worm, discovered in December 2008, added the ability to propagate over LANs through removable media and network shares. Researchers believe that these were decisive factors in allowing the worm to propagate quickly: by January 2009, the estimated number of infected computers ranged from almost 9 million to 15 million. Antivirus software vendor Panda Security reported that of the 2 million computers analyzed through ActiveScan, around 115,000 (6%) were infected with Conficker.

Recent estimates of the number of infected computers have been more notably difficult because of changes in the propagation and update strategy of recent variants of the worm.

TRY macafee antivirus for the detection of w32.downadup.b.




Logged
Pages: 1
  Print  
 
Jump to:  

Enter your email address to receive daily email with 'SCforum.info - Security CENTRAL Forum' newest content:

Terms of Use | Privacy Policy
Powered by MySQL Powered by PHP Powered by SMF 1.1.11 | SMF © 2006-2009, Simple Machines LLC
TinyPortal v0.9.8 © Bloc
Valid XHTML 1.0! Valid CSS!


Google visited last this page 31. July 2010., 02:01:24