Home Malware Programs Backdoors Wollf

Wollf

Posted: March 28, 2006

Wollf is a dangerous backdoor that gives the attacker unauthorized remote access to a compromised PC. It allows the intruder to manage the file computer, download and upload files, install and run arbitrary potentially harmful software, terminate running processes, disable certain computer functions, steal user sensitive information, show messages, shutdown or restart a PC. Wollf can also log user keystrokes, capture network traffic, run hiden proxy, FTP or Telnet servers. The backdoor automatically runs as a service on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 mshms.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}00000008HKEY_LOCAL_MACHINESYSTEMCurrentControlSetControlServiceCurrent(default)=00000008HKEY_LOCAL_MACHINESYSTEMCurrentControlSetEnumRootLEGACY_HARDWARE_MONITORHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesadobe3mHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceshardwaremonitor
Loading...