GDHW ? What on EArf?

Discussion in 'Malware Help (A Specialist Will Reply)' started by kOOmoO, Jul 12, 2005.

  1. kOOmoO

    kOOmoO Private E-2

    hi this is my first post so go easy on me :D

    Alright Problem : CPU usage hitting 100%
    What was going on during Problem : Nothing only about 3 programs open Trillian, Winamp, and McaFee Security Center.
    When does Problem Occur: Randomly, somedays does not happen somedays does.
    How to get rid of problem : REstarting computer

    so yeah basically i get 100% cpu usage, my comps gets really laggy and i have to restart. it really bugs me when something is wrong with my computer, i have to fix it right away or i will be mad and sad for a long time.

    well whenever i restart it tells me "END TASK GDHW" and im like W T F mate?
    then when i end task boom restarts real fast.

    so if u guys know what is this "GDHW" then help me! please

    i followed everything on the scanning and removing trojans, spyware and virus

    it went away for a week (or didint come out to destroy me) like i said it happens randomly

    HELP!!! please!!!
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

  3. kOOmoO

    kOOmoO Private E-2

    fo sho fo sho i did all that trojan scanning in safe mode n stuff

    my Specs

    Windows XP Professional
    AMD Athlon 2700+
    80 GB HDD Western Digital
    2x 512 pc3200 Kingston RAM
    Asus a7n8x-x mobo
    Geforce FX-5200 256mb Asylum Series

    yes im a GAMER but this happens when im not playing games, as to think of it, it never happens when im playing games.

    i think GDHW is a virus or something.. any info on what it is please help.
    Task manager does not even show it in the process.
    i run Hijackthis and everything there i recognize.

    sorry for not posting my OS earlier
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Let's do a few things.


    Download and run AutoStart Viewer save a log from it and post as an attachment.

    Also follow the below steps exactly:

    - Download HijackThis 1.99.1

    - Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    - Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the downloaded ZIP file.

    - Before running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    - Run HijackThis and save your log file.

    - Post your log as an ATTACHMENT to your next message. (Do NOT copy/paste the log into your post).
     
  5. kOOmoO

    kOOmoO Private E-2

    here are my logs
     

    Attached Files:

  6. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Well other than the fact that you did not follow my directions for installing and using HJT and the fact that it does not look like you ran all of the READ ME FIRST, your logs are clean. It does not look to me like you are having a malware problem. It may be that the problem is something related to your game installation or some other problem on your PC.

    Perhaps you should check over in the Gaming Forum.
     
  7. kOOmoO

    kOOmoO Private E-2

    but i did do what u did, i downloaded Hijackthis and made a folder HJT in program files extracted the .exe from it into the HJT i really did.

    i did do that, and i did do the readme first thing.


    What makes u think that i didnt?

    I sometimes do believe it is a game that.... but it happens when im not even playing games.

    You telling me what i did or did not do when i did do the correct way has really offended me :confused:
    I guess im here for help so might as well let you guys help me\\

    Also i would like to add,
    my computer is not HOT, and yet it Restarts sometimes i get about 2 random restarts (when im not playing games) each day. can this be related to Spyware? Virus? it mostly occures when i click on something. Like i right click on desktop to refresh, once i click the refresh button it restarts.

    so i just wanna know is it related to spyware or virus.
    thanks!
     
  8. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No! You are running it from the ZIP file using Winrar as shown in your log:

    C:\Program Files\WinRAR\WinRAR.exe
    C:\DOCUME~1\Nhan\LOCALS~1\Temp\Rar$EX00.812\HijackThis.exe

    Also you did not exit browsers: C:\Program Files\Mozilla Firefox\firefox.exe



    There are online scanners in the READ ME FIRST that are supposed to be run. They were Trend Micro and Symantec and yesterday they were changed to BitDefender and RavAntivirus. If they were run they would show in your HJT log in the O16 section.

    If I do not see them, that means they were not run. If you had problems running them, your should have said something.


    I'm not sure why your PC is restarting. Try the all the online scans including the ones in the Alternative scans section of the READ ME FIRST to see if any problems are detected. If you cannot do them in safe mode, do them in normal boot mode.
     
  9. kOOmoO

    kOOmoO Private E-2

    i tried them online scans iono why wont work

    and i swear i did run it from HJT maybe i got the wrong Hijackthis list?
    because i ran 1 from zip, than i read the forum again and i saw that it saids DO NOT, so i extracted it and ran it again hijackthis.exe and i guess i got the wrong log..
    When i ran those trendmicro and online scans it was about 2 weeks ago nothing showed up, only trendmicro works i dont know why wont the others work\\

    have u ever heard of this GDHW?
     
  10. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You did not ask for help two weeks ago and that is a long time to go in the malware world. When you said you ran the READ ME FIRST you should have run ALL the steps NOW. Not two weeks ago.

    What do you mean the won't work? You said nothing about that when you posted for help. Also you said was
    Run the online scans below now:

    do an online scan at Bitdefender <-- agree to the license and then select Scan
    do an online scan at RavAntivirus <-- select Auto Clean then click Scan My PC
    <LI>Trend Micro's Free Online Virus Scan
     
  11. kOOmoO

    kOOmoO Private E-2

    bitdefender was teh only one that found something it was this

    C:\WINDOWS\tqp.exe=>(NSIS o)=>bzip2_nsis0001

    couldnt clean it though
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Did you run it in normal or safe boot mode?

    Is there a C:\WINDOWS\tqp.exe file on your PC? If so, try booting in safe mode and deleting
    it.

    Have you tried searching your PC for anything named GDHW? Make sure Windows search is configured properly as below:

    Click Search and the Select "All files and folders"
    Enter the filename in the "All or part of the file name:" box
    Now select "More advanced options"
    Make sure the following check boxes are checked:
    - Search system folders
    - Search hidden files and folders
    - Search subfolders
    Then click the Search button.


    Also have you tried search your registry for any hits on GDHW?
     
  13. kOOmoO

    kOOmoO Private E-2

    u want me to run the search in safe mode too?

    i havent tried searching GDHW in regiestry i dont know how to

    yes i have tried a system search

    i did this while in normal mode
    should i do it in safe mode?
     
  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    It is not necessary to search in safe mode. Did you configure the options as I gave before doing search? They are not the defaults. Windows will not look in all folders unless you configure it properly.

    You could use the built in Registry Editor called regedit to search your registry but let's try the below because it is usually faster.

    Download the Registry Search Tool from here:

    http://www.billsway.com/vbspage/vbsfiles/RegSrch.zip

    Unzip to your Desktop and double click on regsrch.vbs
    (if you have script protection, please allow this to run)

    In the dialog that opens enter the following:

    GDHW

    Press 'OK'

    The search will run for a while then alert you when it is finished.

    Press 'OK' and copy the contents of the WordPad window and post in this thread.
     
  15. kOOmoO

    kOOmoO Private E-2

    REGEDIT4
    ; RegSrch.vbs © Bill James

    ; Registry search results for string "GDHW" 7/15/2005 10:44:27 AM

    ; NOTE: This file will be deleted when you close WordPad.
    ; You must manually save this file to a new location if you want to refer to it again later.
    ; (If you save the file with a .reg extension, you can use it to restore any Registry changes you make to these values.)


    [HKEY_USERS\S-1-5-21-484763869-1580818891-725345543-1003\Software\Microsoft\Search Assistant\ACMru\5603]
    "000"="GDHW"


    thats what i got....... so what now?
     
  16. kOOmoO

    kOOmoO Private E-2

    the file didnt delete i ran the search again and its still there
     
  17. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    What file did not delete? I did give any recent directions to delete anything. Are you talking about the registry key found by RegSrch? That's not a file. It is information stored in your registry. And RegSrch just looks for information in your registry. It does not do anything else. And for this particular item, it is not a problem. MRU = Most Recently Used. All it is telling you is that your had run a search to look for GDHW.

    As far as I can tell there are no malware related issues on you PC. You may need to look into software, driver, or hardware problems. Maybe even heat problems. But those discussions belong in other forums.

    Did you ever try to manually delete the C:\WINDOWS\tqp.exe file as I requested in message # 12?
     
    Last edited: Jul 15, 2005
  18. kOOmoO

    kOOmoO Private E-2

    yeah i deleted the tqp.exe manually.

    alright than Thanks a lot. i posted this thread here because i thought it had something to do with spyware or mal ware.

    i have no idea what GDHW is...

    Thanks again! :D
     
  19. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    From what I can tell, it does not look like any visible form of malware. But it could have to do with some application on your computer. Possibly even a game.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds