<?xml version="1.0" encoding="UTF-8"?>
<rss version="2.0"
	xmlns:content="http://purl.org/rss/1.0/modules/content/"
	xmlns:wfw="http://wellformedweb.org/CommentAPI/"
	xmlns:dc="http://purl.org/dc/elements/1.1/"
	xmlns:atom="http://www.w3.org/2005/Atom"
	xmlns:sy="http://purl.org/rss/1.0/modules/syndication/"
	xmlns:slash="http://purl.org/rss/1.0/modules/slash/"
	>

<channel>
	<title>Corporate Zombie &#187; sdfix</title>
	<atom:link href="http://faolain.net/corporate_zombie/tag/sdfix/feed" rel="self" type="application/rss+xml" />
	<link>http://faolain.net/corporate_zombie</link>
	<description>Welcome to the world of Beige!</description>
	<lastBuildDate>Thu, 08 Dec 2011 17:31:54 +0000</lastBuildDate>
	<language>en</language>
	<sy:updatePeriod>hourly</sy:updatePeriod>
	<sy:updateFrequency>1</sy:updateFrequency>
	<generator>http://wordpress.org/?v=3.1.3</generator>
		<item>
		<title>wlctrl32 &#8211; nasty little bugger of a rootkit virus</title>
		<link>http://faolain.net/corporate_zombie/2008/05/01/wlctrl32-nasty-little-bugger-of-a-rootkit-virus</link>
		<comments>http://faolain.net/corporate_zombie/2008/05/01/wlctrl32-nasty-little-bugger-of-a-rootkit-virus#comments</comments>
		<pubDate>Thu, 01 May 2008 15:42:33 +0000</pubDate>
		<dc:creator>admin</dc:creator>
				<category><![CDATA[Uncategorized]]></category>
		<category><![CDATA[Work]]></category>
		<category><![CDATA[antivirus]]></category>
		<category><![CDATA[comparfix]]></category>
		<category><![CDATA[prevx]]></category>
		<category><![CDATA[rootkit]]></category>
		<category><![CDATA[sdfix]]></category>
		<category><![CDATA[symantec]]></category>
		<category><![CDATA[virus]]></category>
		<category><![CDATA[wlctrl32]]></category>

		<guid isPermaLink="false">http://faolain.net/corporate_zombie/?p=28</guid>
		<description><![CDATA[I had a nasty encounter with wlctrl32 in aq clients office. First, Symantec Corporate would not detect the virus. I had to install the trial of PrevX to detect the malware. once that was done the issue of removal came up. Luckily someone has had the issue before me, Experts Exchange The two main applications [...]]]></description>
			<content:encoded><![CDATA[<p>I had a nasty encounter with wlctrl32 in aq clients office.</p>
<p>First, Symantec Corporate would not detect the virus. I had to install the trial of <a href="http://www.prevx.com/">PrevX</a> to detect the malware.</p>
<p>once that was done the issue of removal came up.</p>
<p>Luckily someone has had the issue before me, <a href="http://www.experts-exchange.com/Software/Internet_Email/Spy_Ad_Blockers/Q_23210830.html">Experts Exchange </a></p>
<p>The two main applications that helped with this issue were ComboFix and SDFix</p>
<p>In addition to their main download locations (<a rel="nofollow" href="http://download.bleepingcomputer.com/sUBs/ComboFix.exe" target="_blank">http://download.bleepingcomputer.com/sUBs/ComboFix.exe</a>, <a rel="nofollow" href="http://downloads.andymanchesta.com/RemovalTools/SDFix.exe" target="_blank">http://downloads.andymanchesta.com/RemovalTools/SDFix.exe</a>) i have added them here: <a href="http://www.faolain.net/applications/ComboFix.exe">ComboFix </a>and <a href="http://www.faolain.net/applications/SDFix.exe">SDFix</a></p>
<p>To use these, disable System Restore first.</p>
<p>I am not in anyway supporting these tools, however</p>
<p><strong>SDFix:</strong></p>
<p>Double click on SDFix.exe. It should automatically extract a folder called SDFix to your system drive (usually C:\). Please reboot your computer in Safe Mode by doing the following :</p>
<ul>
<li>Open the SDFix folder and double click on RunThis.bat to start the script.</li>
<li>Type Y and press Enter to begin the script.</li>
<li>It will start cleaning your PC and then prompt you to press any key to Reboot.</li>
<li>Press any key to restart the PC.</li>
</ul>
<p>Your system will take longer than normal to restart as the fixtool will be removing files.</p>
<ul>
<li>When the desktop loads the Fixtool will complete the removal and display Finished.</li>
<li>Press any key to end the script and to load your desktop icons.</li>
</ul>
<p>A text file should automatically open.</p>
<p>On ExpertsExchange the expert used this log file to create a script of files and drivers for Combo Fix to remove. I have not yet figured out where they pulled the content from, but here is what they suggest they put into a file called CFScript.txt. This file is then dragged over onto the ComboFix exe. It will try and remove them</p>
<blockquote><p>
<em>File::<br />
C:\WINDOWS\system32\Drivers\Jnp57.sy</em></p>
<div id="EchoTopic" class="answerBody quoted"><em>s<br />
C:\WINDOWS\system32\WLCtrl32.dll<br />
C:\WINDOWS\system32\drivers\nkv2.sys</em><em></p>
<p>Driver::<br />
Jnp57<br />
USB2_04</p>
<p>Registry::<br />
[-HKEY_LOCAL_MACHINE\software\micros</em><em>oft\window</em><em>s nt\currentversion\winlogon\notify\WL</em><em>Ctrl32]</em></div>
</blockquote>
<p><strong>Combo Fix</strong>: Disable your AntiVirus and any real-time Anti-spyware monitors that are running.</p>
<div id="EchoTopic" class="answerBody quoted">Then double click Combofix.exe &amp; follow the prompts.<br />
When finished, it will produce a log for you.</p>
<p>Note 1: Do not mouseclick combofix&#8217;s window while it&#8217;s running. That may cause it to stall.<br />
Note 2: Remember to re-enable your <a class="tfTextLink" style="border-bottom: 1px solid #f78200; color: #f78200; text-decoration: underline; display: inline; padding-bottom: 1px;" href="javascript:void(0)">Anti-virus</a> and Anti-spyware.</div>
<div class="answerBody quoted">
</div>
<div class="answerBody quoted">There is a recommended cleanup method as well after this has been run</div>
<blockquote>
<div class="answerBody quoted">Click START then Run&#8230;<br />
Now type Combofix /u in the runbox  and click OK.  Note the space between the X and the U, it needs to be there.</p>
<p>The above procedure will:</p>
<p>Delete the following:<br />
ComboFix and its associated files and folders.<br />
VundoFix backups, if present<br />
The C:\Deckard folder, if present<br />
The C:_OtMoveIt folder, if present</p>
<p>Reset the clock settings.<br />
Hide file extensions, if required.<br />
Hide System/Hidden files, if required.<br />
Reset System Restore.</p></div>
</blockquote>
<p><em><strong>This worked first time for me. No issue at all.</strong></em></p>
]]></content:encoded>
			<wfw:commentRss>http://faolain.net/corporate_zombie/2008/05/01/wlctrl32-nasty-little-bugger-of-a-rootkit-virus/feed</wfw:commentRss>
		<slash:comments>0</slash:comments>
		</item>
	</channel>
</rss>

