<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>DAMN TROJAN &#187; Conficker C</title>
	<atom:link href="http://www.damntrojan.com/tag/conficker-c/feed" rel="self" type="application/rss+xml" />
	<link>http://www.damntrojan.com</link>
	<description>We make it go away</description>
	<lastBuildDate>Thu, 22 Jul 2010 23:26:11 +0000</lastBuildDate>
	<generator>http://wordpress.org/?v=2.8.5</generator>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
			<item>
		<title>How I removed W32.Downadup.B/Conficker</title>
		<link>http://www.damntrojan.com/how-i-removed-w32downadupb</link>
		<comments>http://www.damntrojan.com/how-i-removed-w32downadupb#comments</comments>
		<pubDate>Fri, 30 Jan 2009 21:45:14 +0000</pubDate>
		<dc:creator>Grabate</dc:creator>
				<category><![CDATA[Damn Headline]]></category>
		<category><![CDATA[Worms]]></category>
		<category><![CDATA[Conficker]]></category>
		<category><![CDATA[Conficker B++]]></category>
		<category><![CDATA[Conficker C]]></category>
		<category><![CDATA[Micorsoft]]></category>
		<category><![CDATA[RECYCLER]]></category>
		<category><![CDATA[RECYCLER\S]]></category>
		<category><![CDATA[remove]]></category>
		<category><![CDATA[Trojan]]></category>
		<category><![CDATA[W32.Downadup.B]]></category>
		<category><![CDATA[Windows XP]]></category>

		<guid isPermaLink="false">http://www.damntrojan.com/?p=2392</guid>
		<description><![CDATA[I have just been infected by W32.Downadup.B - AKA Conficker and have spent all night removing it, so now I am going to share the quick way to remove W32.Downadup.B.

First make sure you are infected with W32.Downadup.B/Conficker.  The biggest sign is going into <strong>My Computer</strong> and double clicking your hard drive.  If you get an error message about "RECYCLER\S" then you are infected.  

There are alot of sites out there showing you how to manually remove W32.Downadup.B/Conficker. Most of these files have the word [Random] in it meaning it could be anything. Don’t bother trying to manually remove it, it’s time consuming and you could do more harm than good.]]></description>
			<content:encoded><![CDATA[<p>I have just been infected by W32.Downadup.B &#8211; AKA Conficker and have spent all night removing it, so now I am going to share the quick way to remove W32.Downadup.B.</p>
<p>First make sure you are infected with W32.Downadup.B/Conficker.  The biggest sign is going into <strong>My Computer</strong> and double clicking your hard drive.  If you get an error message about &#8220;RECYCLER\S&#8221; then you are infected.  </p>
<p>Be on the lookout for the &#8220;RECYCLER&#8221; folder as W32.Downadup.B/Conficker puts this on any drive on your computer.  It is launched when autorun runs and is responsible for installing the infection.  If your computer is infected with W32.Downadup.B/Conficker, you cant remove the RECYCLER folder as it is just put straight back on.  RECYCLER is in the main directory &#8220;[YourDriveLetter]:\RECYCLER&#8221; so it is easy to find.</p>
<p>There are alot of sites out there showing you how to manually remove W32.Downadup.B/Conficker.  Most of these files have the word [Random] in it meaning it could be anything.  Don&#8217;t bother trying to manually remove it, it&#8217;s time consuming and you could do more harm than good.</p>
<p>To get rid of W32.Downadup.B/Conficker you have to use an antivirus/anti-spyware program, I just don&#8217;t see any other way around it.  Microsoft recommends using their <a href="http://www.microsoft.com/security/malwareremove/default.mspx">Malicious Software Removal tool</a>.  If you can&#8217;t access that link, it&#8217;s because W32.Downadup.B/Conficker is blocking it.  Even if you were able to download it, W32.Downadup.B/Conficker stops the Malicious Software Removal tool from being executed.</p>
<p>I did have some limited success using <a href="http://support.microsoft.com/kb/962007">Microsoft&#8217;s Conficker manual removal instructions.</a>. Surprisingly W32.Downadup.B/Conficker allowed me to view the page however it didn&#8217;t allow me to download or even install the patches.</p>
<p>Although I used <a href="http://www.dpbolvw.net/click-3194029-10539715">Spyware Doctor to remove W32.Downadup.B/Conficker</a>, this post applies to all antivirus/anti-spyware programs.  Even if you are able to download and purchase an antivirus/anti-spyware program, it is next to useless as Conficker will prevent it from downloading the necessary updates.  Beceause of this, get whatever antivirus/anti-spyware program you want from an uninfected friends computer.  When you have the program, manually download the updates from a website.  Most antivirus/anti-spyware programs allow you to do this.</p>
<p>Now <strong>BURN THE ANTIVIRUS/ANTI-SPYWARE TO A CD.</strong>  I cannot stress this enough.  <strong>DO NOT USE A PENDRIVE/USB DEVICE.</strong>  It will be infected as soon as you plug it into your computer.  This is how I was infected in the first place.</p>
<p>Once on a CD/DVD, install the program onto your computer, put in your registation details and install the manual updates you downloaded.  Now let it do a full scan and say goodbye to W32.Downadup.B/Conficker.</p>
<p>After you have removed W32.Downadup.B/Conficker, be sure to install <a href="http://www.microsoft.com/downloads/details.aspx?familyid=0D5F9B6E-9265-44B9-A376-2067B73D6A03&#038;displaylang=en">this Microsoft patch.</a>  It prevents hackers from taking over your system using W32.Downadup.B/Conficker.  Those of you are uninfected will want to install it anyway for safety.</p>
<p>Good luck.</p>
<p>UPDATE: Conficker B++ &#038; Conficker C has recently been released.  This is just Conficker that has been modified with different ways to communicate with hackers.  It&#8217;s impact on your computer is the same as it&#8217;s twin brother.  As before don&#8217;t bother trying to manually remove it but use <a href="http://www.dpbolvw.net/click-3194029-10539715">Spyware Doctor to remove Conficker B++ and Conficker C  instead.</a></p>
<p>Conficker is scheduled to start doing something on April 1st.  No one is exactly sure what it will do the general consensus is that it will connect to a server and get further instructions like download a Trojan.  </p>
<img src="http://www.damntrojan.com/?ak_action=api_record_view&id=2392&type=feed" alt="" />]]></content:encoded>
			<wfw:commentRss>http://www.damntrojan.com/how-i-removed-w32downadupb/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>
