By Graham

How to Remove W32.Downadup.B/Conficker

Updated Jun 12, 2009

I’ve just been infected by W32.Downadup.B — AKA Downadup or Conficker — and have spent all night removing it, so now I’m going to share the quick way to remove W32.Downadup.B.

Do You Have Downadup?

First, make sure you’re really infected with W32.Downadup. The surest sign is to go into My Computer and double-click your hard drive. If you get an error message about “RECYCLER\S,” then you’re infected with W32.Downadup.

How Did I Get W32.Downadup.B?

I’m a computer repair dude in New Zealand; I actually caught W32.Downadup.B from a dirty USB drive. Be careful what you plug into your system; you can get Conficker from other removable devices and network shares. Other ways to get Downadup include a vulnerability in the Microsoft Server service (if you don’t already have the October patch, download the Conficker patch).

How I Got Rid of W32.Downadup.B

There are a lot of sites out there showing you how to manually remove W32.Downadup/Conficker files. Most of the files listed have the word “[Random]” in them, meaning these W32.Downadup/Conficker files could be named anything. Don’t bother trying to manually remove W32.Downadup.B with those instructions; you can waste a lot of time, and do more harm than good to your system.

To get rid of W32.Downadup.B, you have to use an antivirus/anti-spyware program; I just don’t see any other way around it. Microsoft recommends using their Malicious Software Removal Tool (if you can’t access that link, it’s because W32.Downadup.B/Conficker is blocking it). Even if you were able to download Microsoft’s removal tool, W32.Downadup.B blocks the Malicious Software Removal Tool from being executed.

Although I used Spyware Doctor to remove W32.Downadup.B/Conficker, you can use my instructions with any antivirus/anti-spyware program. Even if you’re able to download and purchase an antivirus program on your PC right now, it’s next to useless as Conficker will prevent it from downloading the necessary updates. Because of this, get whatever antivirus program you want from an uninfected friend’s computer. While still on your friend’s PC, manually download the program’s updates from a website. Most antivirus programs allow you to do this.

Now BURN THE ANTIVIRUS SOFTWARE TO A CD. I cannot stress this enough. DO NOT USE A PEN DRIVE/USB DEVICE. It will be infected as soon as you plug it into your computer. This is how I was infected with W32.Downadup.B in the first place.

Once you have your updated antivirus program on a CD or DVD, install the program onto your computer, enter in your registration details, and install the manual updates you downloaded. Now let the program run a full scan, and say goodbye to W32.Downadup.B.

Good luck.

If you’ve got any suggestions, questions, or stories about how you got rid of W32.Downadup.B/Conficker, leave a comment.