Conficker, Downadup, Net-Worm.Win32.KidoSymptoms of network infection from Kaspersky site
1. Network traffic volume increases if there are infected PCs in the network, because network attack starts from these PCs.
2. Anti-Virus product with enabled Intrusion Detection System informs of the attack Intrusion.Win.NETAPI.buffer-overflow.exploit
3. It is impossible to access websites of the majority of anti-virus companies, e.g. avira, avast, esafe, drweb, eset, nod32, f-secure, panda, kaspersky, etc.
4. An attempt to activate Kaspersky Anti-Virus or Kaspersky Internet Security with an activation code at a computer infected with the Net-Worm.Win32.Kido network worm may result in abnormal termination and give one of the following errors:
Activation procedure completed with system error 2.
Activation error: Server name cannot be resolved.
Activation error. Unable to connect to server.
KidoKiller should be used to remove this worm.
Download the archive
kk.zip and extract the contents into a folder on the infected PC.
Disable autorun of executable files from removable drives by launching the file kk.exe with -a switch.
For Windows XP/Server OS: Start - Run - type kk.exe -a - click OK
For Windows Vista OS: Start - All Programs - Accessories - Run - type kk.exe -a - click OK
Block access to TCP ports number 445 and 139 using a network screen.
You need to block these ports only while you perform the disinfection. As soon as you have the entire red disinfected, feel free to unblock the ports.
Start the task.
Install the patch from Microsoft that covers the vulnerability
MS08-067,
MS08-068,
MS09-001 (on these pages you will have to select which operating system is installed on the infected PC, download corresponding patch and install it).
Kaspersky support