Jump to content

Search the Community

Showing results for tags 'pgq.exe'.

  • Search By Tags

    Type tags separated by commas.
  • Search By Author

Content Type


Forums

  • Announcements
    • Malwarebytes News
    • Beta Testing Program
  • Malware Removal Help
    • Windows Malware Removal Help & Support
    • Mac Malware Removal Help & Support
    • Mobile Malware Removal Help & Support
    • Malware Removal Self-Help Guides
  • Malwarebytes for Home Support
    • Malwarebytes for Windows Support Forum
    • Malwarebytes for Mac Support Forum
    • Malwarebytes for Android Support Forum
    • Malwarebytes for iOS Support
    • Malwarebytes Privacy
    • Malwarebytes Browser Guard
    • False Positives
    • Comments and Suggestions
  • Malwarebytes for Business Support
    • Malwarebytes Endpoint Protection
    • Malwarebytes Incident Response (includes Breach Remediation)
    • Malwarebytes Endpoint Security
    • Malwarebytes Business Products Comments and Suggestions
  • Malwarebytes Tools and Other Products
    • Malwarebytes AdwCleaner
    • Malwarebytes Junkware Removal Tool Support
    • Malwarebytes Anti-Rootkit BETA Support
    • Malwarebytes Techbench USB (Legacy)
    • Malwarebytes Secure Backup discontinued
    • Other Tools
    • Malwarebytes Tools Comments and Suggestions
  • General Computer Help and Security Updates
    • BSOD, Crashes, Kernel Debugging
    • General Windows PC Help
  • Research Center
    • Newest Rogue-Ransomware Threats
    • Newest Malware Threats
    • Newest Mobile Threats
    • Newest IP or URL Threats
    • Newest Mac Threats
    • Report Scam Phone Numbers
  • General
    • General Chat
    • Forums Announcements & Feedback

Find results in...

Find results that contain...


Date Created

  • Start

    End


Last Updated

  • Start

    End


Filter by number of...

Joined

  • Start

    End


Group


AIM


MSN


Website URL


ICQ


Yahoo


Jabber


Location


Interests

Found 1 result

  1. Good afternoon, A co-worker has been experiencing some strange behavior and sluggish performance on our shared work PC for the past two weeks. When he showed me the problem, I observed strange behavior: IE8 windows would close before ever loading the page, and twice, the browser was redirected to AOL Mail, where I watched as it created an account and signed in in a matter of seconds before closing on its own. When this happened, a program titled xkadf.exe had over 80% CPU usage according to the task manager. I ran a full Malwarebytes scan and found three instances: Trojan.Ransom.REL, Backdoor.Bot, and Trojan.FakeAlert. All three were in the same folder as xkadf.exe, along with two other large, suspicious .exe files over 40mb each, which I deleted. Here is the log: I rebooted the computer and noticed immediately that it was running sluggishly. Also, a window kept popping up for a split-second before closing again; it had a distorted image and was titled "nachwinterlicher." Eventually the CPU usage was so high that the window stopped responding, after which Windows told me that "Ausströmt has stopped responding." The task manager showed that two dozen randomly-titled .exes were taking up all of my processing power. I rebooted the PC, and since then, none of these symptoms have re-occurred. However, I ran another Malwarebytes scan, and each one of them was discovered in a temp folder. I cleaned the infection, but here is the log: I have not seen any other symptoms of this attack, but I'm concerned that this PC may have been permanently compromised. Google searches have left me without any answers, so I was wondering if anybody was familiar with any of this and could give me some advice. I don't want to reformat the drive if I don't have to. Here is the dds.txt: Thank you in advance for any help you can offer -- I really appreciate it. Regards, John
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.