syswin7u8.exe -- on w700p anyone know of it?

exscentric
exscentric Member Posts: 78 Troubleshooter

Picked up malware few days ago, malwarebytes took care of some objects. Tonight cpu was running hot and hard, found this file was doing it(syswin7u8.exe). Googled and only one page about malware came up. Found two directories that didn't belong so deleted them. One was syswin.

Would like to be sure all is gone. Did full malwarebytes scan and all is well.

Any other info would be appreciated.

Best Answer

  • exscentric
    exscentric Member Posts: 78 Troubleshooter
    Answer ✓


    I am posting this in case others try to find info on this beast.

    I got the malware from a user of cloudfilers.pw.  It asked to install adobe flash player.  I downloaded and ran it, got error message so forgot about looking at them.  Next night I noticed the cpu running hard.  Opened taskmanager and it was
    syswin7u8.exe.  I found it and deleted it then found a directory of that name and another directory that did not belong so deleted them.

    I searched for the file online and found this link and very little else.  http://camas.comodo.com/cgi-bin/submit?
    file=bbfb2c368179b603d49701c9a206faf2d12bff0d8721583df3c5c8a0be9f776d

    I searched through it and deleted all that it referenced (mostly in temp directories) and found no registry entries that it
    mentioned on my rig.

    I am assuming I am safe after clean malwarebytes and windows defender scans.  This is on a windows 8 tablet so if it returns nothing serious will be lost.

    I noticed on the comodo listing "documents and settings" which was back a few versions of windows I think so that may be why it did not do me any harm -- don't know.

    Thanks for the help offered.

     

    [edited to comply with guidelines]

Answers

  • ptrkhh
    ptrkhh Member Posts: 72 Troubleshooter

    It is very likely to be a malware, I would recommend to remove it.

    First open the location of the file using the task manager (right click > open file location). After the folder opens, go back to Task Manager and end the task/process. Then you can move the file to other folder in case my suspicion was false.

  • exscentric
    exscentric Member Posts: 78 Troubleshooter

    I had done that, had found a directory by the same name, deleted it and another directory that did not belong, deleted it.  I think it is okay now but ??? who knows with the creeps out there and what they do to people :-)  I know where it came from, going to search that site a little on google and see what else I can find.

     

    Thanks for your comment.

  • exscentric
    exscentric Member Posts: 78 Troubleshooter
    Answer ✓


    I am posting this in case others try to find info on this beast.

    I got the malware from a user of cloudfilers.pw.  It asked to install adobe flash player.  I downloaded and ran it, got error message so forgot about looking at them.  Next night I noticed the cpu running hard.  Opened taskmanager and it was
    syswin7u8.exe.  I found it and deleted it then found a directory of that name and another directory that did not belong so deleted them.

    I searched for the file online and found this link and very little else.  http://camas.comodo.com/cgi-bin/submit?
    file=bbfb2c368179b603d49701c9a206faf2d12bff0d8721583df3c5c8a0be9f776d

    I searched through it and deleted all that it referenced (mostly in temp directories) and found no registry entries that it
    mentioned on my rig.

    I am assuming I am safe after clean malwarebytes and windows defender scans.  This is on a windows 8 tablet so if it returns nothing serious will be lost.

    I noticed on the comodo listing "documents and settings" which was back a few versions of windows I think so that may be why it did not do me any harm -- don't know.

    Thanks for the help offered.

     

    [edited to comply with guidelines]

This discussion has been closed.