Advertisement
If you have a new account but are having problems posting or verifying your account, please email us on hello@boards.ie for help. Thanks :)
Hello all! Please ensure that you are posting a new thread or question in the appropriate forum. The Feedback forum is overwhelmed with questions that are having to be moved elsewhere. If you need help to verify your account contact hello@boards.ie
Hi there,
There is an issue with role permissions that is being worked on at the moment.
If you are having trouble with access or permissions on regional forums please post here to get access: https://www.boards.ie/discussion/2058365403/you-do-not-have-permission-for-that#latest

Cdghsy

  • 29-01-2005 11:18pm
    #1
    Closed Accounts Posts: 14,013 ✭✭✭✭


    I pressed ctrl-alt-dlt today and found a process called cdghsy.exe running and taking up over 20mb of memory. I'd never seen it before so ended it and restarted my computer and it hasn't been in processes since (edit: just restarted and it is now). I googled and no results came up for it. Only a few minutes ago I went to startups in msconfig and it was listed as a startup from my SYSTEM32 folder. I went and looked in that folder and there's a load of xml files starting with cdghsy (eg. cdghsyk1.xml) aswell as the .exe file. Does anyone have a clue what this could be as I can't find it google?

    Cheers.

    edit - another startup item is wxahkt.exe in my windows folder.


Comments

  • Registered Users, Registered Users 2 Posts: 3,357 ✭✭✭snappieT


    That is Odd. Not a single reference to either processes in any search engine. That means it hasn't even ever been discused on any (indexed) boards.

    Clueless. Will be checking back to this post often to see how it spans out.

    Are you sure you've spelled them right?


  • Registered Users, Registered Users 2 Posts: 1,569 ✭✭✭maxheadroom


    That is Odd. Not a single reference to either processes in any search engine. That means it hasn't even ever been discused on any (indexed) boards.

    Clueless. Will be checking back to this post often to see how it spans out.

    Are you sure you've spelled them right?

    Have you run an AV scan recently? Some viruses use random process names. If not, download stinger and run it.


  • Closed Accounts Posts: 14,013 ✭✭✭✭eirebhoy


    Are you sure you've spelled them right?
    http://members.boards.ie/eirebhoy/cdghsy.jpg :)


  • Registered Users, Registered Users 2 Posts: 4,287 ✭✭✭NotMe


    Yeah sounds like a randomly name virus. Have you done all the checks?


  • Closed Accounts Posts: 14,013 ✭✭✭✭eirebhoy


    I've done a scan with Stinger (from the link maxheadroom provided), that found an IRC/Flood.bi trojan but nothing more. I got a message from Norton that there is a trojan in the Windows folder called msnbc.com but that can't be deleted. I'll do a few more scans.


  • Advertisement
  • Registered Users, Registered Users 2 Posts: 4,287 ✭✭✭NotMe




  • Closed Accounts Posts: 154 ✭✭smorton


    it could be spyware. some spyware generates a random filename which is why it doesn't show up in google. i'd assume some viruses would do the same. the trick is to start in safe mode so the exe doesn't automatically start and then delete it. Probably problem solved


  • Registered Users, Registered Users 2 Posts: 1,569 ✭✭✭maxheadroom


    smorton wrote:
    it could be spyware. some spyware generates a random filename which is why it doesn't show up in google. i'd assume some viruses would do the same. the trick is to start in safe mode so the exe doesn't automatically start and then delete it. Probably problem solved

    Actually, this sounds a bit like a coolwebsearch variant. Try CWShredder and see what it finds. Have you noticed any problems with IE, extra popup windows for example?


  • Closed Accounts Posts: 14,013 ✭✭✭✭eirebhoy


    Yeah, I only use IE when I have to (hotmail, etc.) and when I was using it last week I got a good few popups and still get them from dealhelper. I posted a log file on another site but still got no reply:
    http://www.spywarewarrior.com/viewtopic.php?t=9788

    I've tried every anti-Spyware program under the sun without any luck.


  • Registered Users, Registered Users 2 Posts: 8,225 ✭✭✭Ciaran500


    Did you look for the offiicial uninstaller from dealhelper? There normally is one.



    EDIT: http://sarc.com/avcenter/venc/data/pf/adware.dealhelper.html


  • Advertisement
  • Closed Accounts Posts: 14,013 ✭✭✭✭eirebhoy


    Ciaran500 wrote:
    Did you look for the offiicial uninstaller from dealhelper? There normally is one.



    EDIT: http://sarc.com/avcenter/venc/data/pf/adware.dealhelper.html
    I did everything that says in the link. When I did the full scan with Norton it got rid of that msnbc.com thing I mentioned earlier but nothing else. None of the registry keys were found and I deleted dealhelper from add/remove last week.

    I've just noticed that wxahkt.exe is gone from the Windows folder and no loger in Startups. I've attached the icon for the other file.


Advertisement