Kidala_e details

  • Description

    Kidala.e is an Internet worm that propagates through instant messages, via file sharing networks, by e-mail with the help of messages with malicious attachments, through weakly protected network shares, and by exploiting known system and software vulnerabilities. Once executed, the parasite secretly installs itself to the system and runs a spreading routine. Kidala.e sends copies of itself to contacts in the Windows Address Book and addresses gathered from files of several types. It also generates some e-mail addresses. The worm searches for opened instant messages and sends replies containing malicious links. It uses LimeWire, Warez P2P, eDonkey, Kazaa, iMesh and Morpheus programs to share infected files that have meaningful names with users of popular peer-to-peer applications. Furthermore, the worm spreads through weakly protected network shares by picking common user names and passwords. The parasite’s payload is comprised of several harmful functions. Kidala.e opens a back door providing the attacker with unauthorized remote access to the compromised computer. It allows the intruder to download and execute arbitrary files, perform denial of service (DoS) attacks, uninstall or update the worm. Kidala.e also terminates running antiviruses, firewalls and other security-related programs. The worm runs on every Windows startup.