Weird file extension

BO Terry

Active Member
Reaction score
112
Location
NC
Hi,

I have a client computer that pops up on every reboot asking how to open a certain file. I've never seen what appears to be the file extension and can't find anything on Google searches. The first image is what pops up
on reboot. Initially, it would freeze the computer preventing anything else to work. You had to manually power it off. After some cleanup, I can work with it but not make it go away. You can click "more apps" and choose options or close it down. I tried opening the file from a USB drive on an offline test computer with no success.

The last image shows the file path. I tried removing the 29b11 folder from within Roaming but then it prompts for the missing file on reboot.

Next I tried removing the file from the 29b11 folder and receive the message: Windows cannot find 'C:\appdata\roaming\2911b\e7acb.15b899'.



sw2.PNG

SW file.PNG

sw3.PNG
 

Attachments

  • sw2.PNG
    sw2.PNG
    190 KB · Views: 4
For sure it's some kind of infection, malware or PUP. You didn't mention looking in the startup items or task scheduler. That's where you should find what's making it pop up. It's possible the actual program is gone and this file is the remains of it. What scans have you run on it?
 
Look at the file header with a hex editor not the file extension this will help you figure it out.

Sent from my SM-G870W using Tapatalk
 
I agree with the others. Probably a remnant of some app, good, bad or ugly. From what I've seen it might be legit malware or something else that got removed and the removal left references in the registry.
 
Thanks all. I ran some additional scans, including some cleanup tools in Windows Repair Toolbox and (fingers crossed) It seems to be gone. I’ve reboot 6-8 times with no pop up.
 
Back
Top