You are welcome to subscribe to "New articles in Knowledge base" mailing list.

You are visiting our Support Website and we thank you in advance for your participation in this poll and your feedbacks.

Please vote honestly, we will analyze the results and will do our best to improve our service as soon as possible.

 Consumer Support Website Usability Survey:
Navigation quality*
Technical articles efficiency*
Relevance of the article(s) turned out by your query*
Ease of access to relevant information*
Comments

Read the same in:    English  Francais  Deutsch  Dutch  日本語  Polski  Русский  Español  
Home / Home products /  Home supported products /  Troubleshooting

 
Search :  
Search tips Article ID # :   
 

Kaspersky Anti-Virus 7.0 MP1 (build 7.0.1.325)

 
How to remove network worm Net-Worm.Win32.Kido (aka Conficker, Downadup) [KK.exe version 3.4.13]
 ID Article: 1956    Other languages:  Francais  Deutsch  Dutch  日本語  Polski  Русский  Español      Views for 7 days 8 240    Last modified on 2009 Oct 27 18:50 Printable version

Concerning to:
  • Kaspersky Internet Security 6.0/7.0/2009
  • Kaspersky Anti-Virus 6.0/7.0/2009
  • Kaspersky Anti-Virus 6.0 for Windows Workstations (all versions)
  • Kaspersky Anti-Virus 6.0 for Windows Servers (all versions)
  • Kaspersky Administration Kit 6.0 MP1/MP2
  • Technical Support Service would like to inform Kaspersky Lab clients that there is an increase in incoming calls concerning infection of Windows based workstations and servers with network worm Net-Worm.Win32.Kido (aka Conficker, Downadup).

    Symptoms of network infection.

    1. Network traffic volume increases if there are infected PCs in the network, because network attack starts from these PCs.

    2. Anti-Virus product with enabled Intrusion Detection System informs of the attack Intrusion.Win.NETAPI.buffer-overflow.exploit

    3. It is impossible to access websites of the majority of anti-virus companies, e.g. avira, avast, esafe, drweb, eset, nod32, f-secure, panda, kaspersky, etc.

    4. An attempt to activate Kaspersky Anti-Virus or Kaspersky Internet Security with an activation code at a computer infected with the Net-Worm.Win32.Kido network worm may result in abnormal termination and give one of the following errors:

    • Activation procedure completed with system error 2.
    • Activation error: Server name cannot be resolved.
    • Activation error. Unable to connect to server.

     

    Short description of the Net-Worm.Win32.Kido family.

    1. It creates files autorun.inf and RECYCLED\{SID<....>}\RANDOM_NAME.vmx on removable drives (sometimes on public network shares)

    2. It stores itself in the system as a DLL-file with a random name, for example, c:\windows\system32\zorizr.dll

    3. It registers itself in system services with a random name, for example, knqdgsm.

    4. It tries to attack network computers via 445 or 139 TCP port, using MS Windows vulnerability MS08-067.

    5. It tries to connect to the following sites in order to learn the external IP address of the infected computer (we recommend configuring a rule to monitor connection attempts to these sites it network firewall):

     

    Methods of disinfection.

    A special utility KK.exe should be used to remove this worm. MS Windows 95/MS Windows 98/MS Windows ME operating systems can’t be infected with this network worm.

    Warning To prevent all workstations and file servers from being infected with the worm, you are recommended to do the following: 

      • Install the patch from Microsoft that covers the vulnerability MS08-067, MS08-068, MS09-001 (on these pages you will have to select which operating system is installed on the infected PC, download corresponding patch and install it). 

     

      • Make sure the password of the local administrator account is not obvious and cannot be hacked easily – the password should contain 6 letters minimum; use a mixture of uppercase and lowercase, numbers and non-alphanumeric characters such as punctuation marks. 

     

      • Disable autorun of executable files from removable drives by launching the KK.exe utility with -a switch.

        For Windows XP/Server OS: Start – Run – type kk.exe –a – click OK
        For Windows Vista OS: Start – All Programs – Accessories – Run – type kk.exe –a – click OK

      • Block access to TCP ports number 445 and 139 using a network screen.

        You need to block these ports only while you perform the disinfection. As soon as you have the entire red disinfected, feel free to unblock the ports.

    The utility KK.exe can be run locally on the infected PC, or remotely with the help of Kaspersky Administration Kit.

     

    Running the utility via command line. In the table below you can view the list of all switches that can be used with the utility.

    • To start command line:
      • Windows Vista: Start > All Programs > Accessories > Command Prompt > type in cmd and press Enter
      • Windows XP/Server: Start > Run > type in cmd and press Enter
    • To start the utility KK.exe:
      • Save the utility KK.exe on disk C, for example.
      • You have to specify location of the utility KK.exe in order to start it. For example, if you have saved the utility on disk C, you have to type the command "С:\KK.exe" and press Enter.

     

    To remove the virus locally:

    1. Download the archive KK.zip (current version of utility is version 3.4.13) and extract the contents into a folder on the infected PC.

    2. If you have one of the following Kaspersky Lab applications installed on the infected PC:

    - Kaspersky Internet Security 2009;
    - Kaspersky Anti-Virus 2009;
    - Kaspersky Internet Security 7.0;
    - Kaspersky Anti-Virus 7.0;
    - Kaspersky Internet Security 6.0;
    - Kaspersky Anti-Virus 6.0; 
    - Kaspersky Anti-Virus 6.0 for Windows Workstations;
    - Kaspersky Anti-Virus 6.0 SOS;
    - Kaspersky Anti-Virus 6.0 for Windows Servers.

    Warningplease disable the component File Anti-Virus of the Kaspersky Anti-Virus for run time of the utility.
    Run the file KK.exe
    .

    3. Run file KK.exe

    If you run the KK.exe file without any switches, the utility will put a stop to active infection (kill threads and remove hooks), perform a memory scan and a scan of critical areas vulnerable to infection, clean up the registry, and scan flash drives.

    Information When the scan is over an active window of the command prompt may be displayed on your computer monitor, in order to minimize the window press any button. For the window of the command prompt to close automatically it is recommended to run the utility KK.exe with the the parameter –y.

    4. Wait till the scanning is complete.

    Warning If Agnitum Outpost Firewall is installed on the computer where the utility KK.exe is launched, in this case it is obligatory to restart your PC once the work of the utility is over.

     

    5. Perform a full scan of your computer with Kaspersky Anti-Virus.

    To remove the virus via Administration Kit:

    1. Download the archive with the utility KK.zip (current version of utility is version 3.4.13) and extract contents into a folder.

    2. In Administration console create installation package for application KK.exe. In the installation package settings on the Application step select the variant Make installation package for specified executable file.

    Information In the field Executable file command line (optional) define the parameter –y to close the console window automatically once the utility work is over.

     

     

    3. Use this package to create a group or global application deployment task for all infected or suspicious networked computers.

    Information You can start the utility KK.exe on all computers in your corporate network.

     

    4. Please disable the component File Anti-Virus of the Kaspersky Anti-Virus on client PCs for run time of the utility.

    5. Start the task.

    InformationIf you run the utility via Administration Kit it will be started with SYSTEM user permissions making all network drives and shared folders inaccessible to it. If administrator wants the utility to write reports to a network drive or shared resource, the utility must be run using the ‘run as’ command.

    6. Once the utility work is over, scan each computer in the network using your Kaspersky Anti-Virus.

    Warning If Agnitum Outpost Firewall is installed on the computer where the utility KK.exe is launched, in this case it is obligatory to restart your PC once the work of the utility is over.

    To get additional information about the utility, run KK.exe with an additional parameter –help.

    InformationIn a domain network it is important to disinfect in the first place domains and computers with logged users from the groups "Administrators" and "Domain Admins" in the domain. Otherwise disinfection will be pointless – all PCs within the domain will keep getting infected every 15 minutes.

     

    Switches to run the utility KK.exe from the command prompt


    Switch

    Description

    -p <scan path>

    Scan a defined folder.

    -f

    Scan hard disks.

    -n

    Scan network disks.

    -r

    Scan flash drives, scan removable hard disks connected via USB and Fire Wire.

    -y

    End program without pressing any key.

    -s

    Silent mode (without a black window)

    -l <file name>

    Write info into a log.

    -v

    Extended log maintenance (the switch -v works only if the -l switch is entered in the command prompt).

    -z

    Restore the following services:

    • Background Intelligent Transfer Service (BITS),
    • Windows Automatic Update Service (wuauserv),
    • Error Reporting Service (ERSvc/WerSvc),
    • Windows Defender (WinDefend),
    • Windows Security Center Service (wscsvc).

    Restore display of hidden system files.

    -a

    Disable auto start from all drives.

    -m

    Monitoring mode to protect the system from getting infected.

    -t

    Registry clean up from the services that remain after removing the network worm using our products.

    -j

     

    Restore the registry branch SafeBoot (if the registry branch is deleted, computer cannot boot in Safe Mode).

    -help

    Show additional information about the utility.

     

    For example, in order to scan a flash-drive and to generate and write a detailed report into a file report.txt (which will be created in the setup folder of the utility KK.exe), use the following command:

    KK.exe -r -y -l report.txt -v

    Starting with the version 3.4.6 the KK.exe utility includes following return codes (%errorlevel%):

    3 - Malicious threads were found and killed (worm was active).
    2 - Malicious files were found and deleted (worm was inactive).
    1 - Malicious scheduler jobs or function hooks were detected (this PC is not infected but the network might contain infected PCs – administrator should address this issue).
    0 - Nothing found.


     Did the provided info help you?

                           

     Give your detailed feedback.

     

    Kaspersky Lab

    Copyright © 1997 - 2009 Kaspersky Lab
    Site map  |   Contact us  |   International Support Service  |  Send us a suspected virus
    Login Your Personal Cabinet  |   Register  |   FAQ for Personal Cabinet