Conficker.D or W32.Downadup.c is a worm that spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability (BID 31874). It also attempts to spread to network shares protected by weak passwords and block access to security-related Web sites.
It checks the system date and depending on it, it will try to connect to a certain website in order to download and run another type of malware in the affected computer.
It reduces considerably the protection level of the computer, as it prevents the user and the computer from connecting to many websites related to antivirus companies.
Conficker.D spreads by exploiting the vulnerability MS08-067. In order to do so, it sends malformed RPC requests to other computers in which it attempts to enter a copy of itself. Additionally, it spreads through mapped, shared and removable drives.
How to Remove Conficker.D or Conficker.c using the W32.Downadup Removal Tool
1.Symantec Security Response has developed a removal tool to clean the infections of W32.Downadup. Use this removal tool first, as it is the easiest way to remove this threat.
2.Download the Microsoft released patch (MS08-067) to fix the vulnerability
3.using Malwarebytes’Anti-Malware to Remove other spyware ,here is :Malwarebytes’ Anti-Malware Download Link
4.download Registry Easyfor other Registry repairing, cleaning errors and problems to optimize your PC. It is an amazing program that I use!
good luck!
Manual Removal:
The following instructions pertain to all current and recent Symantec antivirus products, including the Symantec AntiVirus and Norton AntiVirus product lines.
- Disable System Restore (Windows Me/XP).
- Update the virus definitions.
- Find and stop the service.
- Find and remove unrecognised scheduled tasks, if necessary.
- Run a full system scan.
- Delete any values added to the registry.
For specific details on each of these steps, read the following the instructions.



March 30, 2009 IP:213.31.172.5
Hi,
Good article. Sophos’ Conficker removal tool can detect and remove all variants of the worm/virus.
As long as people run these tools it should stop any serious outbreak.
James
Reply