syswin7u8.exe -- anyone know of it?

exscentric

New Member
Member
Messages
201
Picked up malware few days ago, malwarebytes took care of some objects. Tonight cpu was running hot and hard, found this file was doing it(syswin7u8.exe). Googled and only one page about malware came up. Found two directories that didn't belong so deleted them. One was syswin.

Would like to be sure all is gone. Did full malwarebytes scan and all is well.

Any other info would be appreciated.
 

My Computer

System One

  • OS
    win 8
Hi,question, do you have any steam games or software installed, if so that could be the program/s causing the problem. Not really sure, albeit some of the search sites suggest that could be the problem. . .good luck.:)
 

My Computer

System One

  • OS
    Win 8, (VM win7, XP, Vista)
    Computer type
    PC/Desktop
    System Manufacturer/Model
    HP Pavilion p1423w
    CPU
    Intel Core i5 3330 Ivy Bridge
    Motherboard
    Foxconn - 2ADA Ivy Brige
    Memory
    16 GB 1066MHz DDR3
    Graphics Card(s)
    ATI Radeon HD 5450
    Sound Card
    HD Realteck (Onboard)
    Monitor(s) Displays
    Mitsubishi LED TV/Montior HD, Dell 23 HD, Hanspree 25" HD
    Screen Resolution
    Mit. 1980-1080, Dell 2048-115, Hanspree 1920-10802
    Hard Drives
    1 SanDisk 240Gig SSD, 2 Samsung 512Gig SSDs
    Case
    Tower
    Cooling
    Original (Fans)
    Keyboard
    Microsoft Keyboard 2000
    Mouse
    Microsoft Optical Mouse 5000
    Internet Speed
    1.3 (350 to 1024 if lucky)
    Browser
    Firefox 19.1
    Antivirus
    MSE-Defender
Ouch. Because of that install flash player reference, this could be a Cryptolocker install method.

Comodo Instant Malware Analysis

I really would 0 out the drive with Killdisk, then install Windows from scratch.

That's the proper and professional way to fix this.
 

My Computer

System One

  • OS
    7601.18247.x86fre.win7sp1
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Self-built Intel based
    CPU
    Pentium D 925 3.0 GHz socket 775, Presler @ ~ 3.2 GHz
    Motherboard
    Intel DQ965MT
    Memory
    Hyundai 2 GB DDR2 @ 333 MHz
    Graphics Card(s)
    ASUS DirectCU II HD7790-DC2OC-2GD5 Radeon HD 7790 2GB 128-Bit GDDR5
    Sound Card
    MOTU Traveler firewire interface
    Hard Drives
    1 Seagate Barracuda SATA II system/boot drive 80 GB, 2 Western Digital hdds - 1 is SATA II Caviar Black 1 TB attached to card (assorted media, page, temp), other is SATA I 420 GB (games, media, downloads)
    PSU
    Thermaltake 450W
    Cooling
    stock Gateway cooling, extra large fan in rear of case
    Keyboard
    Alienware/Microsoft Internet kb
    Mouse
    Logitech M510
    Internet Speed
    Optimum Online, fast for US
    Browser
    Pale Moon
    Antivirus
    Kaspersky integrated into ZoneAlarm+Antivirus
The original malware I picked up going to look at some pictures and the site asked to install an adobe program -- had not heard of it but stupid me I okeyed it. it did not load so got worried and ran a scan, it found some stuff, got rid of it and all was fine till tonight. I had run a full scan after getting rid of the bad items.

No steam games or software.

Will dig some more tomorrow and probably redo a drive.

Thanks!
 

My Computer

System One

  • OS
    win 8
I am posting this in case others try to find info on this beast.

I got the malware from a user of WebJobHost. It asked to install adobe flash player. I downloaded and ran it, got error
message so forgot about looking at them. Next night I noticed the cpu running hard. Opened taskmanager and it was
syswin7u8.exe. I found it and deleted it then found a directory of that name and another directory that did not belong so
deleted them.

I searched for the file online and found this link and very little else. Comodo Instant Malware Analysis
file=bbfb2c368179b603d49701c9a206faf2d12bff0d8721583df3c5c8a0be9f776d

I searched through it and deleted all that it referenced (mostly in temp directories) and found no registry entries that it
mentioned on my rig.

I am assuming I am safe after clean malwarebytes and windows defender scans. This is on a windows 8 tablet so if it returns
nothing serious will be lost.

I noticed on the comodo listing "documents and settings" which was back a few versions of windows I think so that may be why it
did not do me any harm -- don't know.

Thanks for the help offered.
 

My Computer

System One

  • OS
    win 8
You may not be worried about losing the data on the machine, but if you do anything with the machine that you'd want to have privacy about or do things like enter credit card numbers to purchase items, it sill is best to 0 the drive so you are guaranteed security as much as possible.

Also, any network (other machines on it) that you connect to can be compromised through your machine. That means that it can potentially harm (software-wise) other machines. Will it? Probably not but that's only odds. Definitely possible.

Other than that, best of luck with it, regardless...and enjoy.
 

My Computer

System One

  • OS
    7601.18247.x86fre.win7sp1
    Computer type
    PC/Desktop
    System Manufacturer/Model
    Self-built Intel based
    CPU
    Pentium D 925 3.0 GHz socket 775, Presler @ ~ 3.2 GHz
    Motherboard
    Intel DQ965MT
    Memory
    Hyundai 2 GB DDR2 @ 333 MHz
    Graphics Card(s)
    ASUS DirectCU II HD7790-DC2OC-2GD5 Radeon HD 7790 2GB 128-Bit GDDR5
    Sound Card
    MOTU Traveler firewire interface
    Hard Drives
    1 Seagate Barracuda SATA II system/boot drive 80 GB, 2 Western Digital hdds - 1 is SATA II Caviar Black 1 TB attached to card (assorted media, page, temp), other is SATA I 420 GB (games, media, downloads)
    PSU
    Thermaltake 450W
    Cooling
    stock Gateway cooling, extra large fan in rear of case
    Keyboard
    Alienware/Microsoft Internet kb
    Mouse
    Logitech M510
    Internet Speed
    Optimum Online, fast for US
    Browser
    Pale Moon
    Antivirus
    Kaspersky integrated into ZoneAlarm+Antivirus
Back
Top