Wollf.16

Discussion in 'Malware Help (A Specialist Will Reply)' started by eyemind, Aug 31, 2010.

  1. eyemind

    eyemind Private E-2

    Hello everyone. New poster, semi-old lurker here. I'd been having some issues and running all the necessary defense software and coming up dry. I knew (know) I was infected but I didn't (don't) want to do a re-install. I downloaded Assassin and sure enough, it found the Wollf.16 Trojan immediately.

    It's a sneaky little devil and it bounces around as a mis-spelled windows process ("wininit.exe" and/or "winnit.exe").

    I chased this thing around in Assassin for a while and watched as it attached itself to various open processes each time I tried to delete it within Assassin.

    Setting my options to "show all dates" and making my way through the forum malware removal section, I came across 2 threads linking to wollf.16.

    Following Tim's step-by-step instructions I attempted to download GTools in an effort to get it to reveal it's true location.

    When I first clicked the download link for GTools, I got an error message from Firefox stating "Cannot download to this directory, try another directory" (?) then subsequently, every attempt thereafter, the "page could not be found" over and over again. The link was correct.

    I do know that the file, once downloaded should be renamed as to avoid being detected when run, but when *being* downloaded? Any thoughts? Suggestions? Help!

    Thanks ever so kindly.
     
  2. eyemind

    eyemind Private E-2

    I'm sorry - I mean *M*GTools.
     
  3. eyemind

    eyemind Private E-2

    :-o... and the Firefox error message is:

    "Firefox can't find the file at http://forums.majorgeeks.com/chaslang/files/MGtools.exe."

    Apologies.
     
  4. eyemind

    eyemind Private E-2

    I Seriously Need Help With This One:Creating Restoration DVDs With a Trojan Installed

    Well, http://windows7news.com/forum/Smileys/default/sad.gif the subject line pretty much sums it up. I just got my shiny new computer that has Windows 7 on it (I know, I'm late), and 2 days later I'm hit with the wollf.16 trojan which sets up my system as a client and allows the server to have complete control over my system.

    Does anyone know if I can make my new restoration dvd's while this trojan exists on my system? Will the factory restore be affected?

    It's an HP desktop, fwiw. I'm pretty leary about it, and am really stuck at this point with absolutely no alternative as I have no image disk to restore from. As I said, the system is brand spanking new.

    Thanks for any help anyone can provide.

    Delores
     
  5. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Refrain from following fixes given to other users even if they are having the same problems as you!

    You need to complete all of the below, and if you can't use Firefox to download, use another browser. Failing that, transfer all of the tools onto flashdrive or disk and then get them onto the sick PC.

    Welcome to Major Geeks!

    Please read ALL of this message including the notes before doing anything.

    Pleases follow the instructions in the below link:

    READ & RUN ME FIRST. Malware Removal Guide


    and attach the requested logs when you finish these instructions.
    • **** If something does not run, write down the info to explain to us later but keep on going. ****
    • Do not assume that because one step does not work that they all will not. MGtools will frequently run even when all other tools will not.

    • After completing the READ & RUN ME and attaching your logs, make sure that you tell us what problems still remain ( if any still do )!
    Helpful Notes:

    1. If you run into problems trying to run the READ & RUN ME or any of the scans in normal boot mode, you can run the steps in safe boot mode but make sure you tell us what you did later when you post logs. See the below if you do not know how to boot in safe mode:
    2. If you have problems downloading on the problem PC, download the tools and the manual updates for SUPERAntiSpyware and Malwarebytes ( links are given in the READ & RUN ME) onto another PC and then burn to a CD. Then copy them to the problem PC. You will have to skip getting updates if (and only if) your internet connection does not work. Yes you could use a flash drive too but flash drives are writeable and infections can spread to them.
    3. If you cannot seem to login to an infected user account, try using a different user account (if you have one) in either normal or safe boot mode and running only SUPERAntiSpyware and Malwarebytes while logged into this other user account. Then reboot and see if you can log into the problem user account. If you can then run SUPERAntiSpyware, Malwarebytes, ComboFix and MGtools on the infected account as requested in the instructions.
    4. To avoid additional delay in getting a response, it is strongly advised that after completing the READ & RUN ME you also read this sticky:
    Any additional post is a bump which will add more delay. Once you attach the logs, your thread will be in the work queue and as stated our system works the oldest threads FIRST.
     
  6. eyemind

    eyemind Private E-2

    Kestrel13!,

    I give. I'm unable to download the tools. All of my machines are on the same network thus all are clients of the trojan server. I'm going to re-install on my 2 Vista machines but I don't know in the case of my Windows 7 system that I just purchased. I did not get the opportunity to create my restoration DVDs in time and am incredibly frightened, to be quite honest.

    I posted as much on an MS list, but haven't heard anything back yet.

    Thank you for your response.
     
  7. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you not download the tools with another computer and transfer them onto the sick PC'(s) to run?
     
  8. eyemind

    eyemind Private E-2

    Well, they are both infected because it is a client/server trojan and it saw both clients on the network and had a freaking party. Here is the initial message I get upon download attempt number one:

    " C:\Users\Delores\Downloads\MGtools.exe could not be saved, because you cannot change the contents of that folder.

    Change the folder properties and try again, or try saving in a different location. "

    Which has never happened to me before, I clicked "save", and I have been able to download to my download directory all day long (programs and regular files).

    Right after this happens, I immediately get sent to an error page that says the file cannot be found.
     
  9. eyemind

    eyemind Private E-2

    I should note, that I did set up an alternate directory, and the same thing happened.

    I do know that the file, once downloaded should be renamed as to avoid being detected when run, but when *being* downloaded? Now that's some serious kung-foo and I want to know how to eradicate that kind of technique *big* time.
     
  10. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    Can you not download the tools with another NON Infected computer and transfer them onto the sick PC'(s) to run?
     
  11. eyemind

    eyemind Private E-2

    Yes, but it will take me some time to get access to one. I'll get everything together and be back with the results. In the meantime, thanks for hanging in there with me.
     
  12. Kestrel13!

    Kestrel13! Super Malware Fighter - Major Dilemma Staff Member

    No problem. I will be here floating about somewhere. :)
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds