When Backdoor.Clt is executed, it performs the following actions:
1. Copies itself as %System%\WUAUCLT.EXE.
2. Adds the value:
"Microsoft auto update"="%System%\wuauclt.exe"
to the registry key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
so that the Trojan runs when you start Windows.
3. Connects to an IRC server to receive commands. By default, the Trojan will connect to irc.icq.com on port 6667 and join a specific channel.