SysWoW64 Infection

FlyDwen

New Member
Thread author
Sep 27, 2018
7
Hello,
Seeing my reset's logs contain some "Warning: Overlap: Directory \??\C:\Windows\SysWOW64\sv-SE\ is owned twice or has its security set twice", I have search how to correct it (I know my computer was infected after I downloaded "Cheat Engine". So I have reset my computer and, after checking the logs and seeing the message, I have restart my computer in "Command Prompt" mode.
I have did the analysis and get the FRST.txt.

Thanks for your help.
P.S. Sorry for my bad English. I am French.
 
  • Like
Reactions: oldschool

FlyDwen

New Member
Thread author
Sep 27, 2018
7
Here are Addition.txt and FRST.txt generated on normal boot.
 

Attachments

  • Addition.txt
    27.8 KB · Views: 47
  • FRST.txt
    95.1 KB · Views: 48

FlyDwen

New Member
Thread author
Sep 27, 2018
7
And my ''setupper.log" file contains the next informations (with errors) (attachment)
After resetting my computer, I just had a "Windows.Old" file in C: while I didn't choose to keep my personal files. So I just started my computer in "Command Prompt" mode to delete it (it contains some dll files in three folders).
 

Attachments

  • setuperr.log
    6.2 KB · Views: 46
Last edited:

FlyDwen

New Member
Thread author
Sep 27, 2018
7
But, after the installation of CheatEngine, I have rebot my computer and, on restart, I have saw in Process Hacker two programs which were instances of "Syswow64". I didn't see them before.
 

FlyDwen

New Member
Thread author
Sep 27, 2018
7
I got that CheatEngine on official website, and saw after it is detected like trojan on virustotal by more than 10 antivirus.
It was Wednesday, more than one week ago.
On restart, like I have said, I have saw some SysWoW64's processus on Process Hacker.
And actually, I can see two processus : "Memory Compression" and "Registry" which have no description and no file location (error when I click on Open File Location).
 

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top