How to remove Conficker.E

Thursday, April 9th, 2009 at 5:17 am
Home » Backdoor, Worm » Conficker.E

Conficker.E description

Conficker-E is the latest version of the notorious Conficker worm. It seems that creators of this malware are not ready to give up yet.

Learn more about Conficker.C and April 1, 2009.

Not only Conficker.E infects new machines, but it also “updates” computers infected with previous versions of the worm. The malware spreads via MS08-067 exploit; keep your Windows OS updated in order to prevent the infection.

Conficker.E functions in pretty much the same way as its forerunners. The worm joins compromised machines into a botnet. The computer then might be used for DDoS attacks and spam attacks. Conficker a.k.a. Downadup also establishes hidden remote access to the PC.

Conficker-E comes with two additional features. First of all, it downloads W32.Waledac trojan as if Conficker wasn’t problem enough (click here to remove Waledac trojan). It may also download rogue security tool Spyware Protect 2009. Click here to remove Spyware Protect 2009.

How to manually remove Conficker.E

To remove Conficker.E spyware you must block Conficker.E sites, stop and remove processes, unregister DLL files, search and delete all other Conficker.E files and registry utility. Follow the Conficker.E detection and removal instructions below.

The most typical software removal method is to remove Conficker.E by using "Add or Remove Programs" service. However there may be hidden Conficker.E files, running processes and registries in your computer, so Conficker.E may recreate all other files after reboot.

Conficker.E manual removal instructions

Locate and delete Conficker.E registry entries:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\"[RANDOM CHARACTERS]" = "rundll32.exe "[RANDOM DLL FILE NAME]", [RANDOM PARAMETER STRING]"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[RANDOM CHARACTERS]\"ImagePath" = %System%\svchost.exe -k netsvcs
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[RANDOM CHARACTERS]\Parameters\"ServiceDll" = "[PATH TO SECURITY RISK]"
Read more how to delete Conficker.E registry entries
Download RegistryBooster 2010 to scan errors caused by Conficker.E

We strongly recommend you to use spyware remover to track Conficker.E and automaticaly remove Conficker.E processes, registries and files as well as other spyware threats.

Download does not start? Try a mirror download here

Tags: , , , ,

13 Responses to

Conficker.E

  1. Berit

    GOt spyware protect 2009 on my PC; impossible to get rid off.

    Reply

    Luciana Reply:

    Feel free to use Spyware Protect 2009 manual removal guide.

    Reply

  2. John

    i got it last night. tryed a system restore and no go. giving this removal tool a try. hope it works.

    Reply

  3. Brett

    Got it just now. Spyware doctor doesnt work. Nothing is picking it up.

    Reply

    Luciana Reply:

    Boot your computer in a safe mode and then run the anti-spyware scan.

    Reply

  4. Jennifer

    Spyware Protect 2009 is totally messing up my web browser. It won’t let me on any site; I’m so upset. I’m hoping that this will help, I’m downloading the removal system right now. I’m glad I didn’t buy it; I’m super protective about my computer, so I was worried that I really had been infected. UGH stuff like this pisses me off!!!!!!

    Reply

  5. Doug R.

    I downloaded the removal tool. There is no free version I saw despite claims that there are. I am satisfied however since it did remove this nasty little bugger as well as 157 others that “Spybot search and destroy” missed. I have no trouble getting into sites or email with the exception that auto-log-ins are wiped out so I have to re-log in. No biggie to me. Make sure your browser is current as well as your OS updates.
    Thanks for the removal tool!
    Doug

    Reply

  6. sky

    i got it and it wont let me open anything except internet and theres a stupid thing that pops up every 30 sec saying _____file is infected

    Reply

  7. Maddie

    Can’t even access this site on my other computer, can’t acess Add/Delete programs or even Run.. desperate for help.

    Reply

    Luciana Reply:

    That is tough but it’s not hopeless. Star the computer in a safe mode and them proceed with the manual removal guide.

    Reply

Trackbacks

Leave a Reply

Download does not start? Try a mirror download here