Au_.exe

(Note, the name of the file is not always 'AU_.exe'; the NullSoft NSIS uninstaller changes the original name while copying it to the temporary directory.) This NSIS uninstallation utility is designed to provide removal capabilities of the accompanied program. This is the uninstaller utility registered in the Windows Control Panel for the program rFactor (remove only).
MD5:
88da92f17a3da3f9e03d0b395370a6a8

SHA-1:
02a52e5bf91a9f6c0c23f70fc36084ca7fa6c5c6

SHA-256:
486004f14dc16e0abce2855ba813f3161d5fd9ec99453f923aad82d84d47ae34

Scanner detections:
1 / 68

Status:
Clean  (1 probable false positive detection)

Explanation:
This is mosty likely a false positive detection, the file is probably clean.

Analysis date:
5/11/2025 7:18:45 PM UTC  (today)

Scan engine
Detection
Engine version

Comodo Security
Heur.Packed.Unknown
17425

File size:
80.5 KB (82,403 bytes)

File type:
Executable application (Win32 EXE)

Installer:
Nullsoft Scriptable Install System

Common path:
C:\users\{user}\appdata\local\temp\{random}.tmp\au_.exe

File PE Metadata
Compilation timestamp:
12/24/2007 10:04:20 PM

OS version:
4.0

OS bitness:
Win32

Subsystem:
Windows GUI

Linker version:
6.0

CTPH (ssdeep):
1536:kDV6awBrdbLkrude7mnflp4tmJn2JW6LbfcIBd5i+I2g3uwXCk1BUm5iXnA/U/g:kDV6dAruRdWmJWhbfcILHI27vk1GmMQd

Entry address:
0x30BE

Entry point:
81, EC, 80, 01, 00, 00, 53, 55, 56, 33, DB, 57, 89, 5C, 24, 18, C7, 44, 24, 10, C0, 91, 40, 00, 33, F6, C6, 44, 24, 14, 20, FF, 15, 30, 70, 40, 00, 68, 01, 80, 00, 00, FF, 15, B0, 70, 40, 00, 53, FF, 15, 7C, 72, 40, 00, 6A, 08, A3, 98, 3F, 42, 00, E8, E1, 2A, 00, 00, A3, E4, 3E, 42, 00, 53, 8D, 44, 24, 34, 68, 60, 01, 00, 00, 50, 53, 68, 90, F4, 41, 00, FF, 15, 58, 71, 40, 00, 68, B4, 91, 40, 00, 68, E0, 36, 42, 00, E8, 98, 27, 00, 00, FF, 15, AC, 70, 40, 00, BF, 00, 90, 42, 00, 50, 57, E8, 86, 27, 00, 00...
 
[+]

Code size:
22 KB (22,528 bytes)

Program Uninstaller
Program name:
rFactor (remove only)

Uninstall string:
"C:\Program Files (x86)\rFactor\Uninstall.exe"


The file Au_.exe has been discovered within the following program.

F1RFT 2012 V2  by F1RFT
maszosz.hu
About 8% of users remove it
 
Powered by Should I Remove It?

Scan Au_.exe - Powered by Reason Core Security