- Discovered:
- August 1, 2005
- Updated:
- August 1, 2005 3:37:20 PM
- Type:
- Worm
- Infection Length:
- 46080 Bytes
- Systems Affected:
- Windows 2000, Windows 95, Windows 98, Windows Me, Windows NT, Windows XP
W32.Reatle.D@mm is a mass-mailing worm that opens a back door and attempts to spread by exploiting the Microsoft Windows LSASS Buffer Overrun Vulnerability (BID 10108).
Antivirus Protection Dates
- Initial Rapid Release version August 1, 2005
- Latest Rapid Release version September 28, 2010 revision 054
- Initial Daily Certified version August 1, 2005
- Latest Daily Certified version September 28, 2010 revision 036
- Initial Weekly Certified release date August 3, 2005
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Threat Assessment
Wild
- Wild Level: Low
- Number of Infections: 0 - 49
- Number of Sites: 0 - 2
- Geographical Distribution: Low
- Threat Containment: Easy
- Removal: Easy
Damage
- Damage Level: Medium
- Payload: Opens a back door
- Large Scale E-mailing: Sends itself as an attachment to emails
- Compromises Security Settings: Blocks access to several security related Web sites.
Distribution
- Distribution Level: High
- Subject of Email: Varies
- Name of Attachment: Varies
- Size of Attachment: Varies
- Ports: TCP ports 3351 and 8190
- Target of Infection: Computers vulnerable to the Microsoft Windows LSASS Buffer Overrun Vulnerability (BID 10108)
Writeup By: Jeong Mun







