Thread: wauclt.exe
View Single Post
Old 02-14-2007, 08:20 PM   #2 (permalink)
DylanO
Registered User
 
DylanO's Avatar
 
Join Date: Feb 2007
Location: 127.0.0.1:1000
Posts: 89
OS: Windows XP Professional

My System

Send a message via ICQ to DylanO Send a message via AIM to DylanO Send a message via MSN to DylanO Send a message via Yahoo to DylanO Send a message via Skype™ to DylanO
okay, well the wauclt.exe was in a Microsoft Video Capture Controls for a worm called " Win32/Slinbot.ALJ ".

Win32/Slinbot.ALJ is IRC controlled backdoor that can be used to gain unauthorized access to a victim's machine. It can also spread by exploiting weak passwords on administrative shares, by exploiting several vulnerabilities, and by using backdoors created by other malware, so bad maxx when this Win32/Slinbot.ALJ is executed this variant copies itself to the %System% directory as WAUCLT.EXE and makes the following modifications to the registry to ensure that this file is executed at each Windows system start:

HKCU\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Video Capture Controls = "wauclt.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Microsoft Video Capture Controls = "wauclt.exe"
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\Microsoft Video Capture Controls = "wauclt.exe".

But anyways this process is most likely a virus or trojan, and runs as a .ajd worm.

But I'm sure you know this already, XD.

So as of what you're doing please do so to upload the HJT log, and sure a TSF security member will guide you through.

P.S. sorry, I didn't provide really decent information, just pretty much gave you more info on it.
__________________
- Dylan O.
DylanO is offline