• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

SysWOW64 directory and Virus

CptTrips

Weaksauce
Joined
Jan 14, 2005
Messages
121
Microsoft Security Essentials keeps popping up telling me I have various file infected in my temporary internet files. I cleaned it, cleared all my temp files, then reran the scan. MORE files in my temp internet files! I just cleared them and haven't connected to the net at all!

I then looked at the directory:
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5

That is not the normal directory for the temp internet files. WTF directory is this? Clearing the cache does nothing to this directory, and I've tried clearing from both 64bit and 32bit IE.

My settings say it's this directory:
C:\Users\username\AppData\Local\Microsoft\Windows\Temporary Internet Files

Any idea how this directory is getting used?
 
That is definitely not a legit path, notice the Micro (space) soft? That is one common thing I've seen malware do is have odd names with spaces or random letters. I would run a combofix scan as well as a malwarebytes (actually do the mbam first, then see if that fixes it, then try combofix). Also what OS are you running?
 
It's the space between Micro and soft that worries me. That shouldn't be there. Especially if MSE is pointing to it and calling foul.
 
that path is indeed a legit path for a legit profile, but not your profile. This profile is for the SYSTEM user. The space that is there is most likely a typeo or c/p erorr by the op. As to what has run internet explorer as system (or a program that uses IE inside of itself, like steam used to), no clue.
 
Back
Top