Windows Update trojan?

AndrewR

Lifer
Oct 9, 1999
11,157
0
0
I recently rebuilt my laptop Windows XP Pro from scratch. After a few weeks, the system became unstable after every login and reached a point where I couldn't start any programs, including the Task Manager. I had to do a hard reset to recover.

I started Task Manager as soon as I logged in, and I noticed that a file named wuauclt.exe was running immediately. Concurrent with that, a svchost.exe file would grow exponentially. I did some digging and found out that the wu* file is Windows Update so I shut automatic updates off. The file still loaded.

I could shut the process down, but it restarts every time I log in. I finally deleted the file in the System32 folder, but it keeps coming back and running again. When I looked online at some sites, it seems that my copy of the program is smaller than others report (mine is about 50K, several people mentioned theirs is over 100K).

I did a Registry search, but there are no mentions of the file in there, which is odd. One of the sites I looked at mentioned the possibility of a trojan or a virus of some sort, but I've run AVG Free and A-Squared with no negative results. I also ran an online scanner from someone else with nothing found.

Does anyone have a clue what's happening with this laptop? Any ideas on how to get rid of this without reinstalling again? Thanks in advance.
 

Nothinman

Elite Member
Sep 14, 2001
30,672
0
0
I did some digging and found out that the wu* file is Windows Update so I shut automatic updates off. The file still loaded.

But did you disable the service? It's possible that it still runs but just does nothing if you only turn them off.

I finally deleted the file in the System32 folder, but it keeps coming back and running again.

No big surprise there, welcome to Windows File Protection.
 

AndrewR

Lifer
Oct 9, 1999
11,157
0
0
Originally posted by: Nothinman
I did some digging and found out that the wu* file is Windows Update so I shut automatic updates off. The file still loaded.

But did you disable the service? It's possible that it still runs but just does nothing if you only turn them off.

I finally deleted the file in the System32 folder, but it keeps coming back and running again.

No big surprise there, welcome to Windows File Protection.

Yes, I did disable the service. I first tried just stopping automatic updates, but I have since shut the whole thing down completely. I actually had the same problem on this desktop, but when I ran Microsoft Update (not Windows Update), the problem went away on the desktop. Same thing didn't work on the laptop.

Didn't know that about the File Protection. Thanks.

Can anyone confirm that wuauclt.exe is running on their WinXP machine without Windows Update turned on?
 

montag451

Diamond Member
Dec 17, 2004
4,587
0
0
Not on mine.
No wuauclt.exe = no update service.

did you access the services in admin account?
 

AndrewR

Lifer
Oct 9, 1999
11,157
0
0
Originally posted by: montag451
Not on mine.
No wuauclt.exe = no update service.

did you access the services in admin account?

I run as an admin, but I'll check with logging in as Administrator.