Hello.. We need to do a few steps.
Free removal tools available to download and use...
Sophos Conficker Clean-up Toolor
F-Secure Downadup Removal ToolThe
Conficker/Downadup Worm targets
unpatched systems so be sure to read
Conflicker Worm - More Potent MS08-067 attacks to unpatched systems. Just in case you are not dealing with Conficker and to remove anything else you should also download and scan with MBAM (MalwareBytes):
NOTE: Before saving MBAM please rename it to zztoy.exe....now save it to your desktop.Please download
Malwarebytes Anti-Malware and save it to your desktop.
alternate download link 2MBAM may "make changes to your registry" as part of its disinfection routine. If using other security programs that detect registry changes (ie Spybot's Teatimer), they may interfere or alert you. Temporarily disable such programs or permit them to allow the changes.- Make sure you are connected to the Internet.
- Double-click on mbam-setup.exe to install the application.
- When the installation begins, follow the prompts and do not make any changes to default settings.
- When installation has finished, make sure you leave both of these checked:
- Update Malwarebytes' Anti-Malware
- Launch Malwarebytes' Anti-Malware
- Then click Finish.
MBAM will automatically start and you will be asked to update the program before performing a scan.
- If an update is found, the program will automatically update itself. Press the OK button to close that box and continue.
- If you encounter any problems while downloading the definition updates, manually download them from here and just double-click on mbam-rules.exe to install.
On the Scanner tab:
- Make sure the "Perform Quick Scan" option is selected.
- Then click on the Scan button.
- If asked to select the drives to scan, leave all the drives selected and click on the Start Scan button.
- The scan will begin and "Scan in progress" will show at the top. It may take some time to complete so please be patient.
- When the scan is finished, a message box will say "The scan completed successfully. Click 'Show Results' to display all objects found".
- Click OK to close the message box and continue with the removal process.
Back at the main Scanner screen:
- Click on the Show Results button to see a list of any malware that was found.
- Make sure that everything is checked, and click Remove Selected.
- When removal is completed, a log report will open in Notepad.
- The log is automatically saved and can be viewed by clicking the Logs tab in MBAM.
- Copy and paste the contents of that report in your next reply. Be sure to post the complete log to include the top portion which shows MBAM's database version and your operating system.
- Exit MBAM when done.
Note: If MBAM encounters a file that is difficult to remove, you will be asked to reboot your computer so MBAM can proceed with the disinfection process. If asked to restart the computer, please do so immediately. Failure to reboot normally (not into safe mode) will prevent MBAM from removing all the malware. Keeping Autorun enabled on USB (pen, thumb, jump) and other removable drives
has become a significant security risk due to the increasing number of malware variants that can infect them and transfer the infection to your computer. To learn more about this risk, please read:
•What security risks are associated with USB drives?.
•USB-Based Malware Attacks.
•When is AUTORUN.INF really an AUTORUN.INF?.Many security experts recommend you
disable Autorun asap as a method of prevention.
Microsoft recommends doing the same.
...Disabling Autorun functionality can help protect customers from attack vectors that involve the execution of arbitrary code by Autorun when inserting a CD-ROM device, USB device, network shares, or other media containing a file system with an Autorun.inf file...
Microsoft Security Advisory (967940): Update for Windows AutorunDownload and Run FlashDisinfectorYou have a flash drive infection. These worms travel through your portable drives. If they have been connected to other machines, they may now be infected.
Please download
Flash_Disinfector.exe by sUBs and save it to your desktop.
Double-click
Flash_Disinfector.exe to run it and follow any prompts that may appear.
The utility may ask you to insert your flash drive and/or other removable drives including your mobile phone. Please do so and allow the utility to clean up those drives as well.
Wait until it has finished scanning and then exit the program.
Reboot your computer when done.
Note: Flash_Disinfector will create a hidden folder named autorun.inf in each partition and every USB drive plugged in when you ran it. Don't delete this folder. It will help protect your drives from future infection.Running FD On a clean Computer
You would need to run sub's flash disinfector on the clean computer first and hold down the shift key before connecting the external drive.