Wollf (d)

(Backdoor.Win32.Wollf.d)

by Wollf

Telnet Server

Written in C++, compressed with UPX

Released in 2002

Made in China

more versions


dropped file:
c:\WINDOWS\system32\wrm.exe 
size: 62,464 bytes 

port: 7614 TCP

added to registry:
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Enum\Root\LEGACY_WRM 
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\WRM 
HKEY_LOCAL_MACHINE\SYSTEM\ControlSet002\C 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_WRM 
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\WRM 


tested on Windows XP
January 13, 2006

MegaSecurity