W32.Waledac

Risk Level 2: Low

Printer Friendly Page

Discovered: December 23, 2008
Updated: December 23, 2008 1:34:08 PM
Also Known As: TROJ_GENETIK.TI [Trend], Email-Worm:W32/Waledac.A [F-Secure], Troj/Waled-C [Sophos], WORM_WALEDAC.C [Trend], WORM_WALEDAC.AB [Trend], WORM_WALEDAC.AS [Trend], Iksmas.A.worm [Panda Software], WORM_WALEDAC.AI [Trend], W32/Waled-Q [Sophos], W32/Waled-R [Sophos], Trojan:W32/Waledac.A [F-Secure], Troj/Waled-U [Sophos], W32/Waled-Z [Sophos], Troj/Waled-AB [Sophos], W32/Waled-AF [Sophos], Win32/Waledac.AJ [Computer Associates], Mal/WaledPak-B [Sophos], WORM_WALEDAC.BK [Trend], W32/Waled-AW [Sophos], Win32/Waledac.Z [Computer Associates], Mal/WaledPak-D [Sophos], WORM_WALEDAC.CRV [Trend], WORM_WALEDAC.ED [Trend], W32/Waledac.AX [Panda Software], WORM_WALEDAC.DU [Trend]
Type: Worm
Infection Length: 386,560 bytes
Systems Affected: Windows 98, Windows 95, Windows XP, Windows Me, Windows Vista, Windows NT, Windows Server 2003, Windows 2000

W32.Waledac is a worm that spreads by sending email containing links to copies of itself. It also opens a back door on the compromised computer.

For more information, please read the following:

Protection

  • Initial Rapid Release version December 23, 2008 revision 002
  • Latest Rapid Release version November 22, 2009 revision 038
  • Initial Daily Certified version December 23, 2008 revision 007
  • Latest Daily Certified version November 19, 2009 revision 024
  • Initial Weekly Certified release date December 24, 2008

Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.

Threat Assessment

Wild

  • Wild Level: Low
  • Number of Infections: 50 - 999
  • Number of Sites: 0 - 2
  • Geographical Distribution: Medium
  • Threat Containment: Easy
  • Removal: Easy

Damage

  • Damage Level: Medium
  • Payload: Opens a back door on the compromised computer.
  • Large Scale E-mailing: May send spam email.
  • Releases Confidential Info: Attempts to steal information.

Distribution

  • Distribution Level: Low
  • Target of Infection: Spreads by sending links to copies of itself via email.

Writeup By: Liam O'Murchu
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security