Learn How to Remove Conficker Virus / Downadup Virus without any Anti-Virus

May 14, 2009

WindowsSecurity

Conficker, also known as Downup, Downadup and Kido, is a computer worm targeting the Microsoft Windows operating system that was first detected in November 2008. The worm uses a combination of advanced malware techniques which has made it difficult to counter, and has since spread rapidly into what is now believed to be the largest computer worm infection since the 2003 SQL Slammer.

To start itself at system boot, the worm saves a copy of its DLL form to a random filename in the Windows system folder, then adds registry keys to have svchost.exe invoke that DLL as an invisible network service.

Once infected, it disables Windows Automatic Update, Windows Security Center, Windows Defender, Windows Error Reporting and installs more malware in your computer. It also collects personal information and attach to several processes like svchost.exe, explorer.exe and services.exe.

So, How to Remove this Virus?
1.) Right-click the Explorer.exe process and choose the option “Properties”.
2.) Click on the “Threads” Tab, locate and highlight the Conficker DLL files listed below.
3.) To kill Conficker DLL files, click the “Kill” button.
4.) Kill the following Conficker DLL files: %System%\[RANDOM FILE NAME].dll
5.) Open Regedit
6.) Find and Delete HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\Parameters\”ServiceDll” = “[PATH OF WORM]”
7.) HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\{random}\”ImagePath” = %SystemRoot%\system32\svchost.exe -k netsvcs

[Thanks to Wikipedia for information about Conficker Virus!]

Click here to scan your PC for common system errors

About the Author:

Rajesh Patel is a M.B.B.S student and a professional blogger from India. Here he has written Articles based on SEO, Wordpress, Webmaster tips and much more. If you have any Query regarding anything, then you can contact him from Contact Page. You can also follow Rajesh Patel on twitter, Follow Rajesh on Twitter.

Bookmark and Share