Antivirus Protection
 
Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
User Name:
Password:
Remember me
Go Back   Dev Shed ForumsSystem AdministrationAntivirus Protection

Reply
Add This Thread To:
  Del.icio.us   Digg   Google   Spurl   Blink   Furl   Simpy   Y! MyWeb 
Thread Tools Search this Thread Rate Thread Display Modes
 
Unread Dev Shed Forums Sponsor:
Stay one step ahead of the competition. Evaluate and give feedback on some of the hottest web development tools on the market today. Make your opinion heard! Click Here
  #1  
Old August 26th, 2004, 06:14 PM
Matthew Doucette Matthew Doucette is offline
matthewdoucette.com
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2002
Posts: 635 Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level)Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 9 h 59 m 37 sec
Reputation Power: 6
What is wuaudt.exe?

What is wuaudt.exe?

[EDIT]

To cut to the chase, wuaudt.exe is wuauclt.exe, and I have an up-to-date documentation of what that process is here:

"wuauclt.exe & wuaudt.exe?"
http://xona.com/2004/08/26.html

[CUT description of running process...]

Last edited by Matthew Doucette : November 9th, 2005 at 08:58 AM.

Reply With Quote
  #2  
Old August 31st, 2004, 12:34 AM
dcr19700 dcr19700 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 3 dcr19700 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
wuaudt.exe or wuauclt.exe?

Since the font size in Task Manager is small you might be confusing wuaudt.exe with wuauclt.exe. If you take a close look at your screen you can see that the 'c' and the 'l' are very close together and might look like a 'd'.

Here's an explanation of wuauclt.exe:

http://computercops.biz/postp282658.html

Reply With Quote
  #3  
Old August 31st, 2004, 08:50 AM
Matthew Doucette Matthew Doucette is offline
matthewdoucette.com
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2002
Posts: 635 Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level)Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 9 h 59 m 37 sec
Reputation Power: 6
I think you are correct. I have anti-aliasing enabled, which blurs the letters together an extra bit more. I just created my own application called wuauclt.exe to see what it looks like is Task Manager and it does look like wuaudt.exe! Not only that, but I found five results for wuauclt.exe on my computer (and none for wuaudt.exe). Thanks for solving this "bug"!

Here is the process information on non-virus wuauclt.exe:
- http://www.liutilities.com/products...ibrary/wuauclt/
- says it is a Windows ME Windows update process

Here is more information on the trojan:
- http://www.sophos.com/virusinfo/analyses/trojcultb.html
- http://securityresponse.symantec.co...ckdoor.clt.html

Norton Anti-virus does not detect my files as viruses.

Also, if I delete them all, Windows immediately asks me for my Windows XP Service Pack 2 CD (which I don't have as I installed it off the Internet.) Same as the second poster in this thread: http://www.windowsbbs.com/showthread.php?t=34098

So, maybe liutilities.com is out-of-date, and these files are now update processes for Windows XP too???

Last edited by Doucette : August 31st, 2004 at 09:43 AM.

Reply With Quote
  #4  
Old September 1st, 2004, 04:13 PM
Matthew Doucette Matthew Doucette is offline
matthewdoucette.com
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2002
Posts: 635 Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level)Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 9 h 59 m 37 sec
Reputation Power: 6
From studying the nature of the process (when it runs, etc.), I determined that the process is a legitimate process for Windows XP users. This means that this website is out-of-date (as it only mentions the process as a Windows ME process):

http://www.liutilities.com/products...ibrary/wuauclt/

I wrote up my research information here, for those interested:

"wuauclt.exe & wuaudt.exe?"
http://xona.com/2004/08/26.html

Last edited by Matthew Doucette : November 9th, 2005 at 09:00 AM. Reason: url update

Reply With Quote
  #5  
Old September 2nd, 2004, 12:02 AM
dcr19700 dcr19700 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 3 dcr19700 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Try this

Start/Run/services.msc

Disable Automatic Updates. I have mine turned off in System Properties, but wuauclt.exe still ran on start up. When I disabled the Automatic Updates service itself, wuauclt.exe no longer ran on start up. However, when I perform a manual Windows Update I cannot do it without enabling the Automatic Updates service. This leads me to believe that wuauclt.exe is a valid process, or at least on my system it is. Trend Micro Internet Security does not detect it as a virus either. Also, try opening a command prompt and typing 'netstat' this will show you TCP/IP connections.

Reply With Quote
  #6  
Old September 2nd, 2004, 12:05 AM
dcr19700 dcr19700 is offline
Registered User
Dev Shed Newbie (0 - 499 posts)
 
Join Date: Aug 2004
Posts: 3 dcr19700 User rank is Just a Lowly Private (1 - 20 Reputation Level) 
Time spent in forums: < 1 sec
Reputation Power: 0
Here's more about Windows Update and XP:

http://www.dslreports.com/forum/remark,11199217~mode=flat

Reply With Quote
  #7  
Old September 2nd, 2004, 07:15 AM
Matthew Doucette Matthew Doucette is offline
matthewdoucette.com
Dev Shed Novice (500 - 999 posts)
 
Join Date: May 2002
Posts: 635 Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level)Matthew Doucette User rank is Private First Class (20 - 50 Reputation Level) 
Time spent in forums: 9 h 59 m 37 sec
Reputation Power: 6
Quote:
Originally Posted by dcr19700
Start/Run/services.msc

Disable Automatic Updates. I have mine turned off in System Properties, but wuauclt.exe still ran on start up. When I disabled the Automatic Updates service itself, wuauclt.exe no longer ran on start up. However, when I perform a manual Windows Update I cannot do it without enabling the Automatic Updates service. This leads me to believe that wuauclt.exe is a valid process, or at least on my system it is. Trend Micro Internet Security does not detect it as a virus either. Also, try opening a command prompt and typing 'netstat' this will show you TCP/IP connections.
Good Point. The process is a known trojan, so it could be a trojan... but the method you described is the perfect way to figure out if you have a trojan or if you have a legitmate Windows process. If you disable Automatic Updates using services.msc, and then the process still shows up, then you know something is fishy. However, if the process reacts precisely the way it is suppose to react (i.e. not showing up with Automatic Updates turned off in services.msn, showing up upon start-up with Automatic Updates enabled, showing up when you visit Windows Update website, etc.), then you know the process is legitmate.

Another point, is that disabling Automatic Updates in Control Panel does not shut down the process, according to this thread (page 4) below.
Instead, you must use services.msc to 'actually' shut it down
- http://www.windowsbbs.com/showthread.php?t=34098

......

Also, I wrote up my research information here, for those interested:

"wuauclt.exe & wuaudt.exe?"
http://xona.com/2004/08/26.html

Last edited by Matthew Doucette : November 9th, 2005 at 09:02 AM. Reason: url update

Reply With Quote
Reply

Viewing: Dev Shed ForumsSystem AdministrationAntivirus Protection > What is wuaudt.exe?


Thread Tools  Search this Thread 
Search this Thread:

Advanced Search
Display Modes  Rate This Thread 
Rate This Thread:


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
View Your Warnings | New Posts | Latest News | Latest Threads | Shoutbox
Forum Jump

 Free IT White Papers!
 
Accelerating Trading Partner Performance
One in five. That's how many partner transactions have at least one error. That is an amazing statistic, particularly given the extraordinary leaps in innovation across the global supply chain during the past two decades. Download this white paper to learn more.

 
Competing on Analytics
This Tech Analysis is designed to help identify characteristics shared by analytics competitors, and includes information about 32 organizations that have made a commitment to quantitative, fact-based analysis.

 
Cost Effective Scaling with Virtualization and Coyote Point Systems
An overview of the industry trend toward virtualization, how server consolidation has increased the importance of application uptime and the steps being taken to integrate load balancing technology with virtualized servers.

 
Five Checkpoints to Implementing IP Telephony
Implementation planning for IP PBX software and IP telephony has become vital as businesses replace discontinued legacy PBX phone systems. This informative whitepaper outlines five "checkpoints" for any implementation plan that will help make IP communications a successful proposition.

 
Hosted Email Security: Staying Ahead of New Threats
In the last two years, email has become a fierce battleground between the nefarious forces of spam and malware, and the heroes of messaging protection. The spam volumes increased alarmingly every month, bringing clever new forms of phishing and virus propagation attacks.

 

Forums: » Register « |  User CP |  Games |  Calendar |  Members |  FAQs |  Sitemap |  Support | 
  
 





© 2003-2008 by Developer Shed. All rights reserved. DS Cluster 2 hosted by Hostway