Threat level 1
The Internet threat alert status is currently normal. At present, no major epidemics or other serious incidents have been recorded by Kaspersky Lab’s monitoring service.
Threat level 2
The Internet threat alert status is currently raised. At present, a malicious mass mailing or malware sample with previously unknown functionality has been detected.
Threat level 3
The Internet threat alert status is currently high. At present, there is a significant rise in reports of malware that exploits a critical vulnerability in the Windows operating system.
Threat level 4
The Internet threat alert status is currently critical. At present, malware levels are extremely high. Internet usage may be severely disrupted as the epidemic spreads.
01.13.09 16:12 GMT
Status : moderate risk
Net-Worm.Win32.Kido exploits a critical vulnerability (MS08-067) in Microsoft Windows to spread via local networks and removable storage media.
The worm disables system restore, blocks access to security websites, and downloads additional malware to infected machines.
Users are strongly recommended to ensure their antivirus databases are up to date. A patch for the vulnerability is available from Microsoft.
Detailed descriptions of Net-Worm.Win32.Kido.bt, Net-Worm.Win32.Kido.dv and Net-Worm.Win32.Kido.fx are available in the Virus Encyclopaedia. A dedicated removal tool is available here.
Analysis
Weblog