Two places to look for definitive proof of the filename:
Open the registry (Start-Run-Regedit):
HKEY_CLASSES_ROOT\exefile\shell\open\command
The default value should be "%1" %*, if not, the file before it will show the path/filename of the infecting file.
Otherwise, if you can, post everything...
This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
By continuing to use this site, you are consenting to our use of cookies.