possibly could be a virus
http://www.symantec.com/avcenter/ven...kdoor.clt.html Quote:
When Backdoor.Clt is executed, it performs the following actions:
Copies itself as %System%\WUAUCLT.EXE.
Adds the value:
"Microsoft auto update"="%System%\wuauclt.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run
so that the Trojan runs when you start Windows.
Connects to an IRC server to receive commands. By default, the Trojan will connect to irc.icq.com on port 6667 and join a specific channel. |
the link also includes removal information
here is a link for a free online scan
http://housecall.trendmicro.com/ Quote:
FILENAME: Wuauclt.exe.
PROGRAM NAME: Windows Update AutoUpdate client.
DESCRIPTION: Retrieves updates from Windows Update server.
RECOMMENDED ACTION: Always permit. But be warned: According to Microsoft, updates may invoke DRM restrictions, preventing you from playing multimedia content already on your system. Read the details of each update before applying it.
|
http://www.pcmag.com/article2/0,4149,640479,00.asp