Should I delete au_.exe?įor the most part, deleting the au_.exe process is completely unnecessary as your operating system should automatically remove it once it decides to clean up the temp folder. If you want extra help in installing configuring your security scanner to specifically look for treats of this type, follow our in-depth article on installing and scanning with Malwarebytes ( here). For the best results, we recommend either Malwarebytes or Microsoft’s Security Scanner. If the analysis is inconclusive, you can put the matter to rest by scanning your system with a powerful malware remove. Next, copy the au_.exe process and upload it to VirusTotalin order to be analyzed for any malicious activity. If it is, open Task Manager, right-click on the au_.exe process and choose Open File Location. Start by rebooting your system and promptly check to see if the au_.exe process is still there. However, if you see that the au_.exe process persists in Task Manager (Ctrl + Shift + Esc) long after the installation or uninstallation of a certain program is complete, aditional investigations should be made. If you are able to locate the au_.exe process in the ~nsu.tmp folder, you can rest easy as you’re not dealing with a security threat. Navigate to C: / Users / *YourUserName* / AppData / Local/Temp / ~nsu.tmp and see whether you’re able to locate the au_.exe executable. Since au_.exe is dynamically used by installers and uninstallers, the process will automatically be created and stored in a temporary folder ( nsu.tmp). Now that you know the purpose of AU_.exe, let’s make sure that the process is indeed genuine. Because the antivirus suites have very few means of figuring out if the script ran by AU_.exe is legitimate or not, a common practice is to flag every occurrence. Au_.exe is extremely common in adware installers, security suite developers often choose to take no chances. The excessive amounts of false positives related to the AU_.exe process can be traced to the rise of adware installers and the likes. Note: Manually stopping the process from Task Manager will likely force-stop the installation / uninstallation process. Because of this, the user ends up seeing the AU_.exe process inside Task Manager while this process is occurring. In essence, what the AU_.exe does is packing a particular script into a SFX file that auto starts the script engine. Here’s a shortlist of popular Windows-based programs and games that are using Au_.exe during installation or uninstallation: In fact, the majority of applications that have been released during the past few years are using AutoIt either during the installation or uninstallation. What is au_.exe?Īu_.exe is a scripting engine that is often included inside of AutoIt executables. However, in most cases, these cases turned to be nothing more than false positives.Īlthough the executable is most likely not malicious, additional investigations should be made if you see that the AU_.exe process remains active (with high resource usage) even when the system is not installing/uninstalling a software. The au_.exe is often reported to get flagged by security suites such as Avast, McAfee, and Avira. Users typically report a high resource usage caused by the au_.exe process when the system is busy either installing or uninstalling a particular software. A lot of users are suspecting the au_.exe process of being malicious after seeing the amount of system resources that it consumes in Task Manager.
0 Comments
Leave a Reply. |
AuthorWrite something about yourself. No need to be fancy, just an overview. ArchivesCategories |