So CWP support was awsome.
they identified where the file was coming from.
the file was found in /usr/local/cwpsrv/htdocs/resources/admin/tpl/new_account_tpl/
once removed all is back to normal.
i ran all securety tools and nothing came up.
i changed root pwd just to be safe
thanks for your help
love
BaD