1. Download the FixDownadup.exe file from here 2. Save the file to a convenient location, such as your Windows desktop.
NOTE : If you are on a network or if you have a full-time connection to the Internet, disconnect the computer to the network or to the Internet connection.
3. Close all the running programs. 4. Turn off System Restore (this feature is not available in Windows 2000):
NOTE : Disabling System Restore will remove all your restore points. You can enable System Restore again after this procedure and create a new restore point. - on Windows XP: right-click on My computer -> choose Properties -> go to System restore tab and check "Turn off System restore…" - on Windows Vista: right-click on My computer and select Properties -> click on System protection then on the System protection tab -> uncheck all drives under "Available disks" -> press "Turn system restore off" when dialog appears
5. Locate the file that you just downloaded. 6. Double-click the FixDownadup.exe file to start the removal tool. 7. Click Start to begin the process, and then allow the tool to run.
NOTE: If you have any problems when you run the tool, or it does nor appear to remove the threat, restart the computer in Safe mode and run the tool again.
8. Restart the computer. 9. Run the removal tool again to ensure that the system is clean. 10. Reenable System Restore. 11. Install patch for the Microsoft Windows Server Service RPC Handling Remote Code Execution Vulnerability by choosing your operating system. 12. Ensure that user accounts have strong passwords that are not in the list used by the worm. 13. If you are on a network or if you have a full-time connection to the Internet, reconnect the computer to the network or to the Internet connection.