Inactive Trojan Process pwdgcabsvc exe in system 32, Win 7

Status
Not open for further replies.

SteveTraverse

Posts: 22   +0
Can't find any information about this process: pwdgcabsvc.exe
It's wasting 19,956 k of my memory and it won't let me close it.

Malwarebytes and Rkill do not find it. It claims to be published by microsoft, but there is no record of it to be found online.

There is on my desktop, so I want to be very careful. Any idea on how to remove it? The program exists in System32 folder, but cannot be closed or deleted.

taskmanager.jpg

Malwarebytes live protection gave me a message saying it stopped pwdgcabsvc from opening a malicious site, but did not recognize the process itself to be malicious. It is definitely bad news, and should go.

Claims it was created on the exact same time and date I downloaded Firefox 70 last year. Then says last modified June 6, 2020. The only odd behavior I have noticed is that when closing firefox regularly, it does not remember my tabs when I reopen, and instead opens another site, which I have not seen, an adult site. If I kill process firefox, so that it ends suddenly, the tabs load correctly.

In AnVir taskmng, it says Toshiba corporation, lists the affected memory at 29,000 k instead of 19,000 ish. You can set it to quarantine, but it won't actually do it, nor can you kill the process. This tool lists a number of info about this process which may be useful:

Anvir has a feature where you can scan a file with 30 virus engines on virustotal.com, but I cannot locate pwdgcabsvc when trying to find the file.
It appears in normal task manager when I click open file location, and the file appears normally in my explorer.

Anvir1.jpg
 

Attachments

  • Anvir1.jpg
    Anvir1.jpg
    274.8 KB · Views: 7
Last edited:
Please, complete all steps listed here: http://www.techspot.com/vb/topic58138.html
Make sure, you PASTE all logs. If some log exceeds 50,000 characters post limit, split it between couple of replies.
Attached logs won't be reviewed.

Please, observe following rules:
  • Read all of my instructions very carefully. Your mistakes during cleaning process may have very serious consequences, like unbootable computer.
  • If you're stuck, or you're not sure about certain step, always ask before doing anything else.
  • Please refrain from running any tools, fixes or applying any changes to your computer other than those I suggest.
  • Never run more than one scan at a time.
  • Keep updating me regarding your computer behavior, good, or bad.
  • The cleaning process, once started, has to be completed. Even if your computer appears to act better, it may still be infected. Once the computer is totally clean, I'll certainly let you know.
  • If you leave the topic without explanation in the middle of a cleaning process, you may not be eligible to receive any more help in malware removal forum.
  • I close my topics if you have not replied in 5 days. If you need more time, simply let me know. If I closed your topic and you need it to be reopened, simply PM me.
 
Status
Not open for further replies.
Back