What is Kido/Conficker/Downadup?
Kido (Net-Worm.Win32.Kido), also known as Conficker and Downadup, is a malicious program which spreads on Windows networks. The first generation of Kido programs were obfuscated worms with Trojan-Downloader functionality. The latest variants of Kido do not propagate and work as Trojan-Downloaders. Kido has created a powerful botnet of infected machines and uses quite sophisticated technologies to prevent removal. It attempts to download updates to itself from a huge list of constantly changing domain names; it uses P2P channels as an additional control mechanism; it also uses strong encryption to protect against interference by third parties; and finally it prevents security solutions from updating over the Internet. The latest generation of this malicious program also generates a dramatically increased number of unique domain names which it can contact to download daily updates: 50,000 in contrast to the 250 generated and contacted by previous versions.