W32.Downadup.B How to prevent from it???
Created: 16 Mar 2010 | Updated: 19 Sep 2010 | 4 comments
Hi All,
w32.Downadup.B is coming in whole network. How i can do prevention from this virus. Please share it with me. i download its removal tool also but i dont think so it can be a right way.. or work.???
Discussion Filed Under:
Comments 4 Comments • Jump to latest comment
W32.Downadup is a worm that spreads by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability. So applying the Microsoft patches is mandatory
http://www.microsoft.com/technet/security/Bulletin/MS08-067.mspx
http://www.microsoft.com/technet/security/bulletin/ms08-078.mspx
http://support.microsoft.com/kb/953252
Disabling the Computer Browser and Server service on the affected systems will help protect systems from remote attempts to exploit this vulnerability.
Disabling the "Task Scheduler" will help protect systems from local attempts to use scheduled tasks to copy infected files all over the network.
Worms and threats that spread across networks by network shares have become more common in recent years.--Like Downadup/Conficker
Best Practice for Downadup.B and Additional information on the same.
The 5 Steps of Virus Troubleshooting
Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind
Apart from the guidelines given above, make sure you change the local administrator passwords on the computers. Also make sure that no other administrator accounts, or really any user account with privileges to log into many computers, have weak passwords.
If you have password problems, you will not be safe, even with all the patching and everything else.
First off, identify the source using the risk log in SEPM. if you select a line and hit Details, it should show you the source. Once you find the machine, get it off the network and into safe mode and run a full scan. You can also run the Conficker removal tool and apply the patch. From there, change the password of the user that Conficker is using to spread itself across the network. Then you should be good.
I'm dealing with this as we speak.
SEP Knowledge Base
Endpoint SWAT
Would you like to reply?
Login or Register to post your comment.