is also known as Downadup
| Type: Worms
W32.Downadup.B is a worm that infects computers by exploiting the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability. This virus was detected in December 2008 and since then it is spreading all over the world. Various sources have said that somewhere between 3million and 10million systems have been infected already.
W32.Downadup.B monitors DNS requests to certain domains and blocks access to them causing network request timed out notification to show up. Typically, users gets a Windows alert saying that there is no network provider. However users still can ping the computer name or IP Address. W32.Downadup.B also creates autorun.inf file on all mapped drives and automatically executes it when the drive is accessed. Then the virus monitors for other computers that are connected to the infected computer. W32.Downadup.B creates autorun.inf as soon as other computer becomes accessible.
Most of the anti-spywares are worthless against this virus. Manual removal instructions will not work too, because registry permissions have to be restored, before registry keys are removed. The most effective way to avoid W32.Downadup.B is to use the registry to block Autorun of external media and to use a strong administrator password.
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background
Automatic W32.Downadup.B removal:
It might be that we are affiliated with any of our recommended products. Full disclosure can be found in
our Agreement of Use.
We are testing STOPzilla's efficiency at removing W32.Downadup.B
We are testing SpyHunter's efficiency at removing W32.Downadup.B
Malwarebytes Anti Malware
We are testing Malwarebytes Anti Malware's efficiency at removing W32.Downadup.B
We are testing XoftSpySE Anti Spyware's efficiency at removing W32.Downadup.B
Virus Removal Phone Support
Geolocation of W32.Downadup.B
This map reveals the prevalence
of W32.Downadup.B. Countries and regions that have been affected the most
are: China, India, Japan and United States.
QR code for W32.Downadup.B removal instructions
QR is short for Quick Response. They can be read quickly by the mobile phones. QR codes can store more data than
standard barcodes, including url links, geo coordinates, and text.
The reason we add QR code to the
website is that parasites like W32.Downadup.B are really hard to remove on infected computer.
you can quicly scan the QR code with your mobile device and have manual removal instructions to
uninstall W32.Downadup.B right in your pocket.
Simply use the QR scanner and read removal instructions from mobile device.
Information added: 2009-02-17 00:53
Information updated: 2009-03-18 01:03
Attention: If you know know a reputable website reated to security threats, please add a link here: add url