Threat Search: 

ThreatExpert's Statistics for Mal/WaledPak-A [Sophos]:

Mal/WaledPak-A [Sophos] is also known as:
Threat AliasNumber of Incidents
W32.Waledac [Symantec]65
Trojan Horse [Symantec]44
W32/Waledac.gen.h [McAfee]37
W32/Waledac.gen.e [McAfee]31
Spam-Mailbot.m [McAfee]29
Trojan:Win32/Waledac.gen!A [Microsoft]28
TrojanDownloader:Win32/Bredolab.B [Microsoft]27
Packed.Win32.Krap.m [Kaspersky Lab]26
Infostealer.Banker.C [Symantec]25
Trojan.Win32.Waledac [Ikarus]23
PWS:Win32/Zbot.J [Microsoft]22
Email-Worm.Win32.Iksmas.all [Kaspersky Lab]20
Email-Worm.Win32.Iksmas [Ikarus]19
W32/Waledac.gen.j [McAfee]19
Packed.Generic.221 [Symantec]18
Email-Worm.Win32.Iksmas.gen [Kaspersky Lab]17
Spammer:Win32/Tedroo.I [Microsoft]17
W32/Waledac.gen.b [McAfee]17
Trojan.Waledac [Ikarus]15
HeurEngine.Waledac [PC Tools]13
W32/Waledac.gen.d [McAfee]12
Packed.Win32.Krap [Ikarus]11
PWS.Win32 [Ikarus]11
Email-Worm.Win32.Joleee [Ikarus]9
TrojanSpy:Win32/Bebloh.A [Microsoft]9
WORM_WALEDAC.SR [Trend Micro]8
Trojan-Spy.Win32.Bebloh [Ikarus]7
WORM_WALEDAC.RUI [Trend Micro]7
Backdoor.Trojan [Symantec]6
Infostealer [Symantec]6
Net-Worm.Waledac [PC Tools]6
PWS:Win32/Zbot.gen!R [Microsoft]6
PWS:Win32/Zbot.UO [Microsoft]6
Spammer [Ikarus]6
Trojan.Crypt [Ikarus]6
Trojan-Downloader.Win32.Bredolab [Ikarus]6
Trojan-Downloader.Win32.Small [Ikarus]6
Trojan-Downloader.Win32.Small.jgw [Kaspersky Lab]6
Trojan-Dropper.Agent [Ikarus]6
Trojan-Spy.Banker!sd6 [PC Tools]6
Trojan-Spy.Win32.Zbot.mlk [Kaspersky Lab]6
Email-Worm.Iksmas [PC Tools]5
Generic PWS.y [McAfee]5
Generic.dx [McAfee]5
Packed.Generic.210 [Symantec]5
Trojan.Win32.Agent [Ikarus]5
Downloader [Symantec]4
Email-Worm.Iksmas!sd6 [PC Tools]4
Email-Worm.Win32.Iksmas.cu [Kaspersky Lab]4
PWS:Win32/Zbot.PI [Microsoft]4
Spammer:Win32/Tedroo.A [Microsoft]4
Spy-Agent.bw [McAfee]4
Trojan-Downloader.Small!sd6 [PC Tools]4
TrojanDownloader:WinNT/Nupylos.A [Microsoft]4
Trojan-Spy.Win32.Zbot.tem [Kaspersky Lab]4
TSPY_BEBLOH.KO [Trend Micro]4
Win-Trojan/Horst.58368.F [AhnLab]4
Win-Trojan/Krap.77312.C [AhnLab]4
Win-Trojan/Zbot.76288.D [AhnLab]4
Win-Trojan/Zbot.79360 [AhnLab]4
Spammer:Win32/Tedroo.gen!A [Microsoft]3
Trojan.Agent!sd6 [PC Tools]3
Trojan.Win32.Agent2 [Ikarus]3
Trojan:Win32/Waledac [Microsoft]3
Trojan-Dropper.Win32.Cutwail [Ikarus]3
TrojanDropper:Win32/Cutwail.AN [Microsoft]3
Trojan-Spy.Win32.Zbot [Ikarus]3
W32/Waledac.gen.a [McAfee]3
Win32.SuspectCrc [Ikarus]3
Backdoor.Zdoogu!sd6 [PC Tools]2
Backdoor:Win32/Momibot.gen!B [Microsoft]2
Backdoor:Win32/Poebot.gen [Microsoft]2
Email-Worm.Win32.Small.ah [Kaspersky Lab]2
Generic Downloader.x [McAfee]2
Mal/WaledPak-A, Mal/TibsPk-D [Sophos]2
New Malware.bx [McAfee]2
New Malware.ix [McAfee]2
not-a-virus:FraudTool.Win32.AntivirusAgent.b [Kaspersky Lab]2
Packed.Generic.230 [Symantec]2
PWS:Win32/Zbot.FAQ [Microsoft]2
Spam-Mailbot.h.gen.b [McAfee]2
Trojan.Dropper [Symantec]2
Trojan:Win32/Waledac.A [Microsoft]2
Trojan-Banker.Win32.Bancos [Ikarus]2
TrojanDropper:Win32/Agent.UM [Microsoft]2
Trojan-Spy.Win32.Zbot.neo [Kaspersky Lab]2
Trojan-Spy.Win32.Zbot.qtb [Kaspersky Lab]2
W32.IRCBot [Symantec]2
W32/Waledac.gen.m [McAfee]2
Win32/Joleee.worm.46592.B [AhnLab]2
Win-Trojan/Agent.23040.LI [AhnLab]2
Win-Trojan/Krap.28672.B [AhnLab]2
Win-Trojan/Waledac.395776.B [AhnLab]2
Win-Trojan/Waledac.410624.G [AhnLab]2
Win-Trojan/Xema.129536.C [AhnLab]2
Win-Trojan/Xema.variant [AhnLab]2
Win-Trojan/Zbot.75264.B [AhnLab]2
Win-Trojan/Zpack.76288 [AhnLab]2
WORM_WALEDAC.KW [Trend Micro]2
Backdoor.Agent!sd6 [PC Tools]1

Mal/WaledPak-A [Sophos] has the following possible country of origin:
OriginNumber of Incidents
Russian Federation125

Mal/WaledPak-A [Sophos] is known to be created as:
%System%\digeste.dll
%System%\digiwet.dll
%System%\mcenspc.dll
%System%\ntos.exe
%System%\reader_s.exe
%System%\sdra64.exe
%System%\servises.exe
%System%\spooisv.exe
%System%\svchost.exe:ext.exe
%System%\twex.exe
%System%\wbem\grpconv.exe
%System%\wbem\proquota.exe
%System%\winiogon.exe
%Temp%\0.exe
%Temp%\fuck3.exe
%Temp%\kafan virlist 2009.03.08\090308-4-4.exe
%Temp%\kafan virlist 2009.03.23\090323-6-4.exe
%Temp%\kafan virlist 2009.03.31\090330-1-7.exe
%Temp%\kafan virlist 2009.04.07\090407-3-4.exe
%Temp%\kafan virlist 2009.04.13\090413-1-1.exe
%Temp%\out.exe
%Temp%\p_virus\vru.exe
%UserProfile%\reader_s.exe
%Windir%\msauc.exe
%Windir%\services.exe
%Windir%\winlogon.exe
Notes:
  • %System% is a variable that refers to the System folder. By default, this is C:\Windows\System (Windows 95/98/Me), C:\Winnt\System32 (Windows NT/2000), or C:\Windows\System32 (Windows XP).
  • %Temp% is a variable that refers to the temporary folder in the short path form. By default, this is C:\Documents and Settings\[UserName]\Local Settings\Temp\ (Windows NT/2000/XP).
  • %UserProfile% is a variable that specifies the current user's profile folder. By default, this is C:\Documents and Settings\[UserName] (Windows NT/2000/XP).
  • %Windir% is a variable that refers to the Windows installation folder. By default, this is C:\Windows or C:\Winnt.