Meron
asked on
A virus remnants
Hi all,
Lately a pc here had an infected usb flash drive infect it - each usb that was inserted to it would only show a shortcut inside it & its content would disappear.
While trying to clean the pc I've found a file named obupnitujr.exe under C:\Users\username\AppData\ Roaming with a shortcut to it at C:\Users\username\AppData\ Roaming\Mi crosoft\Wi ndows\Star t Menu\Programs\Startup.
The file is about 70 Mb & we would be very happy to get to the bottom of this & understand what it was exactly doing.
Is there a way for us to analyze the file? (notepad would show random characters)
Thanks in advance!
Lately a pc here had an infected usb flash drive infect it - each usb that was inserted to it would only show a shortcut inside it & its content would disappear.
While trying to clean the pc I've found a file named obupnitujr.exe under C:\Users\username\AppData\
The file is about 70 Mb & we would be very happy to get to the bottom of this & understand what it was exactly doing.
Is there a way for us to analyze the file? (notepad would show random characters)
Thanks in advance!
ASKER
The thing is - non of the AVs I've used to scan this specific file show it as a virus :s
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
I would delete it then, or at least rename the file extension to something non-executable to avoid accidentally running it.
http://housecall.trendmicro.com/
But if you're having doubts and don't know what it's for, simply deleting the program would be the safe thing to do. I would also do a fully system scan to be safe, and let your users know not to download random files or follow links in emails.