Threat Database Worms W32.Waledac.D

W32.Waledac.D

By ZulaZuza in Worms

Threat Scorecard

Popularity Rank: 12,253
Threat Level: 10 % (Normal)
Infected Computers: 4,174
First Seen: April 4, 2012
Last Seen: March 2, 2026
OS(es) Affected: Windows

W32.Waledac.D is a malicious worm that circulates by sending emails that carry links of its copies. W32.Waledac.D also opens a back door on the targeted PC. Once executed, W32.Waledac.D may create the particular files. W32.Waledac.D will create the certain registry entry so that it can launch automatically every time you boot up Windows. W32.Waledac.D will also modify the Windows registry by creating more registry entries and a registry subkey. W32.Waledac.D opens a back door on TCP port 80 and UDP port 53 and awaits further commands from a remote IT criminal, which may incorporate downloading and running files, sending email and stealing information from the corrupted PC. W32.Waledac.D may try to steal sensitive details from network traffic that include FTP user name, FTP password and Bitcoin wallets. Uninstall W32.Waledac.D as early as possible.

SpyHunter Detects & Remove W32.Waledac.D

File System Details

W32.Waledac.D may create the following file(s):
# File Name Detections
1. %System%\Packet.dll
2. %Windir%\Temp\temp68.exe
3. %System%\drivers\npf.sys
4. %Windir%\Temp\_ex-68.exe
5. %UserProfile%\[FOUR TO SEVEN RANDOM CHARACTERS].exe
6. %System%\wpcap.dll
7. %Windir%\Temp\_ex-08.exe
8. %UserProfile%\start1.exe
9. %SystemDrive%\Documents and Settings\Default User\Application Data\Bitcoin\wallet.dat
10. %Temp%\sdtInfo.dat
11. %UserProfile%\Application Data\Bitcoin\wallet.dat
12. %Temp%\[HEXADECIMAL VALUE].dmp
13. %UserProfile%\Local Settings\Application Data\Bitcoin\wallet.dat

Registry Details

W32.Waledac.D may create the following registry entry or registry entries:
HKEY_CURRENT_USER\Software\Intel\"DATAID" = "[HEXADECIMAL VALUE]"
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\NPF
HKEY_CURRENT_USER\Software\Intel\"DATA3" = "[HEXADECIMAL VALUE]"
HKEY_CURRENT_USER\Software\Intel\"DATA2" = "[HEXADECIMAL VALUE]"
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\"intelagent" = "%Windir%\Temp\temp68.exe"
HKEY_CURRENT_USER\Software\Intel\"DATA" = "[HEXADECIMAL VALUE]"

Directories

W32.Waledac.D may create the following directory or directories:

%localappdata%\YixSpeedup
%programfiles%\YixSpeedUp

Analysis Report

General information

Family Name: PUP.YixSpeedUp
Signature status: Root Not Trusted

Known Samples

MD5: 65c01eeb43992feb9f63f61aa47ea61f
SHA1: 5808dc5a7f6ad62dcdf2c21135ad68e1310bd82c
SHA256: 079EFD114BDE65DE9FA634CDDB264C99E8A403FC2713861E3D5464FE9938A6DA
File Size: 426.70 KB, 426704 bytes

Windows Portable Executable Attributes

  • File doesn't have "Rich" header
  • File doesn't have debug information
  • File has exports table
  • File is 32-bit executable
  • File is either console or GUI application
  • File is GUI application (IMAGE_SUBSYSTEM_WINDOWS_GUI)
  • File is Native application (NOT .NET application)
  • File is not packed
  • IMAGE_FILE_DLL is not set inside PE header (Executable)
  • IMAGE_FILE_EXECUTABLE_IMAGE is set inside PE header (Executable Image)

Windows PE Version Information

Name Value
Company Name YixSpeedup Soft
File Description driverhelper
File Version 1.0.0.1
Internal Name ddr.dll
Legal Copyright (c) YixSpeedup Soft 2020
Original Filename ddr.dll
Product Name driverhelper
Product Version 1.0.0.1

Digital Signatures

Signer Root Status
YixSpeedupSoft YixSpeedupSoft Root Not Trusted

Block Information

Total Blocks: 594
Potentially Malicious Blocks: 1
Whitelisted Blocks: 555
Unknown Blocks: 38

Visual Map

0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 ? ? ? ? ? ? ? ? ? ? ? x ? ? ? ? ? ? ? ? 0 0 0 ? ? ? ? ? ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 0 0 0 ? 0 0 0 0 0 ? 0 ? ? ? ? 0 ? ? 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 2 3 0 0 0 0 0 0 0 0 0 0 1 0 1 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 2 2 1 0 0 0 0 0 1 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 2 1 1 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 1 0 0 0 1 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 0 1 0 0 1 1 0 0
0 - Probable Safe Block
? - Unknown Block
x - Potentially Malicious Block

Windows API Usage

Category API
Syscall Use
  • ntdll.dll!NtAlpcSendWaitReceivePort
  • ntdll.dll!NtClose
  • ntdll.dll!NtCreateFile
  • ntdll.dll!NtCreateSection
  • ntdll.dll!NtFreeVirtualMemory
  • ntdll.dll!NtMapViewOfSection
  • ntdll.dll!NtOpenFile
  • ntdll.dll!NtOpenKey
  • ntdll.dll!NtOpenProcessToken
  • ntdll.dll!NtQueryAttributesFile
Show More
  • ntdll.dll!NtQueryDebugFilterState
  • ntdll.dll!NtQueryInformationProcess
  • ntdll.dll!NtQueryInformationToken
  • ntdll.dll!NtQuerySystemInformationEx
  • ntdll.dll!NtQueryValueKey
  • ntdll.dll!NtQueryVirtualMemory
  • ntdll.dll!NtQueryVolumeInformationFile
  • ntdll.dll!NtReadFile
  • ntdll.dll!NtSetEvent
  • ntdll.dll!NtSetInformationFile
  • ntdll.dll!NtSetInformationProcess
  • ntdll.dll!NtSetInformationVirtualMemory
  • ntdll.dll!NtSetInformationWorkerFactory
  • ntdll.dll!NtTestAlert
  • ntdll.dll!NtTraceControl
  • ntdll.dll!NtUnmapViewOfSection
  • ntdll.dll!NtWaitForSingleObject
  • ntdll.dll!NtWriteFile
Process Manipulation Evasion
  • NtUnmapViewOfSection
Process Shell Execute
  • CreateProcess
Anti Debug
  • NtQuerySystemInformation

Shell Command Execution

C:\WINDOWS\SysWOW64\rundll32.exe C:\WINDOWS\system32\rundll32.exe c:\users\user\downloads\5808dc5a7f6ad62dcdf2c21135ad68e1310bd82c_0000426704.,LiQMAxHB

Trending

Most Viewed

Loading...