Discovered: December 23, 2008
Updated: December 23, 2008 1:34:08 PM
Also Known As: TROJ_GENETIK.TI [Trend], Email-Worm:W32/Waledac.A [F-Secure], Troj/Waled-C [Sophos], WORM_WALEDAC.C [Trend], WORM_WALEDAC.AB [Trend], WORM_WALEDAC.AS [Trend], Iksmas.A.worm [Panda Software], WORM_WALEDAC.AI [Trend], W32/Waled-Q [Sophos], W32/Waled-R [Sophos], Trojan:W32/Waledac.A [F-Secure], Troj/Waled-U [Sophos], W32/Waled-Z [Sophos], Troj/Waled-AB [Sophos], W32/Waled-AF [Sophos], Win32/Waledac.AJ [Computer Associates], Mal/WaledPak-B [Sophos], WORM_WALEDAC.BK [Trend], W32/Waled-AW [Sophos], Win32/Waledac.Z [Computer Associates], Mal/WaledPak-D [Sophos], WORM_WALEDAC.CRV [Trend], WORM_WALEDAC.ED [Trend], W32/Waledac.AX [Panda Software], WORM_WALEDAC.DU [Trend]
Type: Worm
Infection Length: 386,560 bytes
Systems Affected: Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows Server 2003, Windows Vista, Windows XP
W32.Waledac is a worm that spreads by sending email containing links to copies of itself. It also opens a back door on the compromised computer.
For more information, please read the following:Protection
-
Initial Rapid Release version December 23, 2008 revision 002
-
Latest Rapid Release version November 19, 2009 revision 009
-
Initial Daily Certified version December 23, 2008 revision 007
-
Latest Daily Certified version November 19, 2009 revision 024
-
Initial Weekly Certified release date December 24, 2008
Click for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
-
Wild Level: Low
-
Number of Infections: 50 - 999
-
Number of Sites: 0 - 2
-
Geographical Distribution: Medium
-
Threat Containment: Easy
-
Removal: Easy
Damage
-
Damage Level: Medium
-
Payload: Opens a back door on the compromised computer.
-
Large Scale E-mailing: May send spam email.
-
Releases Confidential Info: Attempts to steal information.
Distribution
-
Distribution Level: Low
-
Target of Infection: Spreads by sending links to copies of itself via email.
Writeup By: Liam O'Murchu