Knowledge Base

Support

Cleaning WORM_DOWNAD, WORM_DOWNAD.AD, and WORM_DOWNAD.KK malware - for Enterprise Business

Solution IDLast Updated
1038611Date : 2012/01/17 Time: 9:53 PM (PST)


Product/VersionPlatform
OfficeScan - 10.0, 10.5, 8.0; ServerProtect for Microsoft Windows/Novell Netware - 5.7
Windows - 2000 Advanced Server, 2000 Server, 2003 Enterprise Server, 2003 Standard Server Edition, 7 32-bit, 7 64-bit, Vista 32-bit, XP Professional

Problem Description

WORM_DOWNAD causes the following unauthorized behavior:
  • Connects to various time servers to determine the current date and time
  • Registers itself as a system service to ensure auto execution every startup
  • Deletes a registry key to prevent system startup in safe mode
  • Terminates security-related processes (i.e. procexp, regmon, autoruns, gmer etc.)
  • Blocks access to security and antivirus websites
  • Generates 50,000 malicious URLs and attempts to connect to around 500 random generated URLs at a time
  • Disables services, such as Windows Automatic Update Service (wuauserv)
  • Causes high traffic on affected system's port 445 upon successful exploitation
  • Creates [random filename].dll and autorun.inf in all mapped drives
  • Creates [random filename].dll and autorun.inf on Internet Explorer and movie maker folder under the program files directory
  • Hides hidden files in Folder Options
  • Attempts to connect to several URLs to download a file that indicates the location of the affected system
  • Users cannot login using their windows credentials because it is locked out

Solution

Please do the following:
 
OfficeScan 8.0 and 10/10.5
  1. Apply Microsoft Security Patch MS08-67.
  2. Update now to ensure that you have the latest components.
  3. Once all the update components are up-to-date, perform a scan now from the OfficeScan server.
  4. Machines that are infected with WORM_DOWNAD require reboot to be completely cleaned.
OfficeScan 7.x
  1. Apply Microsoft Security Patch MS08-67.
  2. Once all the update components are up-to-date, perform a scan now from the OfficeScan server.
  3. Machines that are infected with WORM_DOWNAD require reboot to be completely cleaned.
ServerProtect for Windows (SPNT) 5.x
  1. Apply Microsoft Security Patch MS08-67.
  2. Update now to ensure you have the latest components:
    1. latest pattern file (lpt$vpn)
    2. Scan engine (VSAPI) 8.9113
  3. Use the Sysclean tool to clean WORM_DOWNAD. Please contact Trend Micro Technical Support for this package.
  4. Machines that are infected with WORM_DOWNAD require reboot to be completely cleaned.
For more information, click on the following links:
You can also refer to the following file:


Rate this Solution
Did this article help you?  
 
Please provide your comments to help us improve this solution.

 
  *This form is an automated system. General questions, technical, sales and product-related issues submitted through this form will not be answered.
 
 

Connect with us on