• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

GPU-Z v2.57.0 trojan alert

GD83

New Member
Joined
Jan 25, 2024
Messages
3 (0.03/day)
Hello, I am French, forgive me for the poor writing of my post, it is probably not serious but the latest version of GPU-Z causes problems with Windows 11.

It's in French but experts will understand the Windows protection history screens.

It is not possible to install GPU-Z without removing the threat, I don't know why my Windows detects this and not others, otherwise there would be many messages here.

Simple reporting of the problem.




Capture d'écran 2024-01-25 010339.png


What it says in summary:

Serious threat blocked, malicious act/malware, removed and quarantined (another related alert indicates quarantine).
 
Joined
Feb 10, 2023
Messages
158 (0.35/day)
Location
Lake Superior
What's the MD5 of the exe you have on your computer? It should be DB28131D2F25B980553974A6399E639D.

You can calculate it by opening powershell and running
Get-FileHash .\Downloads\GPU-Z.2.57.0.exe -Algorithm MD5

where the part in bold is the location of your GPU-Z executable


Edit: Disregard this. You're using an installer? Not sure what the checksum should be for that.
Download the exe from the TechPowerUp main page and verify it doesn't have the same detection.
 
Last edited:

GD83

New Member
Joined
Jan 25, 2024
Messages
3 (0.03/day)
Basic installation of the GPU-Z .exe available here, as usual.

There's definitely nothing dangerous here, I don't know why windows gets angry o_O

Downloading the same .exe (already taken from the main page) gives the same result.
 
Joined
Jun 13, 2012
Messages
1,333 (0.31/day)
Processor i7-13700k
Motherboard Asus Tuf Gaming z790-plus
Cooling Coolermaster Hyper 212 RGB
Memory Corsair Vengeance RGB 32GB DDR5 7000mhz
Video Card(s) Asus Dual Geforce RTX 4070 Super ( 2800mhz @ 1.0volt, ~60mhz overlock -.1volts)
Storage 1x Samsung 980 Pro PCIe4 NVme, 2x Samsung 1tb 850evo SSD, 3x WD drives, 2 seagate
Display(s) Acer Predator XB273u 27inch IPS G-Sync 165hz
Power Supply Corsair RMx Series RM850x (OCZ Z series PSU retired after 13 years of service)
Mouse Logitech G502 hero
Keyboard Logitech G710+
where did you download it from if it was somewhere other then this site they might infected it
 
Joined
Mar 28, 2018
Messages
1,795 (0.80/day)
Location
Arizona
System Name Space Heater MKIV
Processor AMD Ryzen 7 5800X
Motherboard ASRock B550 Taichi
Cooling Noctua NH-U14S, 3x Noctua NF-A14s
Memory 2x32GB Teamgroup T-Force Vulcan Z DDR4-3600 C18 1.35V
Video Card(s) PowerColor RX 6800 XT Red Devil (2150MHz, 240W PL)
Storage 2TB WD SN850X, 4x1TB Crucial MX500 (striped array), LG WH16NS40 BD-RE
Display(s) Dell S3422DWG (34" 3440x1440 144Hz)
Case Phanteks Enthoo Pro M
Audio Device(s) Edifier R1700BT, Samson SR850
Power Supply Corsair RM850x, CyberPower CST135XLU
Mouse Logitech MX Master 3
Keyboard Glorious GMMK 2 96%
Software Windows 10 LTSC 2021, Linux Mint
Went ahead and ran the installer (downloaded from TPU) to get the hash. SHA256 is cff3be1e0f885dab1998e00d041abbaf8d9a521b818bcd73ea4c38a858638bc6

I've attached the file in question. It appears in <boot drive>\Users\<username>\AppData\Local\Temp when you install GPU-Z.

Interestingly, on VT


Twelve detections, including Windows Security detecting as Trojan:Win32/AgentTesla!ml (though my AV doesn't detect it). The detection was different before I refreshed VT.

I trust TPU, so I'm assuming it's a false positive/heuristic match.

EDIT: I went ahead and checked an older version of GPU-Z (2.55.0). Looks like it used a different installer program

SHA256: 6cdfac9a6fd83d7a0b652bd8d5a971a753704302e697c3129dcaa5f2de465a44


I've attached that one too, but I renamed it to differentiate them.

EDIT 2: 2.57.0 uses Inno Setup 6.1.0 while 2.55.0 uses 6.0.0

gpu-z-installer-compare.png
 

Attachments

  • gpuz_installer.exe
    1.6 MB · Views: 30
  • gpuz_installer-2550.exe
    1.4 MB · Views: 32
Last edited:
Joined
Dec 25, 2020
Messages
4,758 (3.86/day)
Location
São Paulo, Brazil
System Name Project Kairi Mk. IV "Eternal Thunder"
Processor 13th Gen Intel Core i9-13900KS Special Edition
Motherboard MSI MEG Z690 ACE (MS-7D27) BIOS 1G
Cooling Noctua NH-D15S + NF-F12 industrialPPC-3000 w/ Thermalright BCF and NT-H1
Memory G.SKILL Trident Z5 RGB 32GB DDR5-6800 F5-6800J3445G16GX2-TZ5RK @ 6400 MT/s 30-38-38-38-70-2
Video Card(s) ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition
Storage 1x WD Black SN750 500 GB NVMe + 4x WD VelociRaptor HLFS 300 GB HDDs
Display(s) 55-inch LG G3 OLED
Case Cooler Master MasterFrame 700
Audio Device(s) EVGA Nu Audio (classic) + Sony MDR-V7 cans
Power Supply EVGA 1300 G2 1.3kW 80+ Gold
Mouse Razer DeathAdder Essential Mercury White
Keyboard Redragon Shiva Lunar White
Software Windows 10 Enterprise 22H2
Benchmark Scores "Speed isn't life, it just makes it go faster."
It's probably a false positive, probably a good idea to let @W1zzard know though

Cheers
 
Joined
Aug 29, 2005
Messages
7,098 (1.04/day)
Location
Asked my ISP.... 0.0
System Name Lynni PS \ Lenowo TwinkPad L14 G2
Processor AMD Ryzen 7 7700 Raphael \ i5-1135G7 Tiger Lake-U
Motherboard ASRock B650M PG Riptide Bios v. 2.02 AMD AGESA 1.1.0.0 \ Lenowo BDPLANAR Bios 1.68
Cooling Noctua NH-D15 Chromax.Black (Only middle fan) \ Lenowo C-267C-2
Memory G.Skill Flare X5 2x16GB DDR5 6000MHZ CL36-36-36-96 AMD EXPO \ Willk Elektronik 2x16GB 2666MHZ CL17
Video Card(s) Asus GeForce RTX™ 4070 Dual OC GPU: 2325-2355 MEM: 1462| Intel® Iris® Xe Graphics
Storage Gigabyte M30 1TB|Sabrent Rocket 2TB| HDD: 10TB|1TB \ WD RED SN700 1TB
Display(s) LG UltraGear 27GP850-B 1440p@165Hz | LG 48CX OLED 4K HDR | Innolux 14" 1080p
Case Asus Prime AP201 White Mesh | Lenowo L14 G2 chassis
Audio Device(s) Steelseries Arctis Pro Wireless
Power Supply Be Quiet! Pure Power 12 M 750W Goldie | 65W
Mouse Logitech G305 Lightspeedy Wireless | Lenowo TouchPad & Logitech G305
Keyboard Akko 3108 DS Horizon V2 Cream Yellow | L14 G2 UK Lumi
Software Win11 Pro 23H2 UK
Benchmark Scores 3DMARK: https://www.3dmark.com/3dm/89434432? GPU-Z: https://www.techpowerup.com/gpuz/details/v3zbr
It's probably a false positive, probably a good idea to let @W1zzard know though

Cheers

Hmm I am wondering if OP has updated his Windows 11 and defender because my server is on Windows 11 Pro 22H2 Build 22621.3007 and mine doesn't find anything with the installer I just downloaded.

W11Pro.GPUZ.png


Windows Defender scanning GPUZ-.exe, unins000.dat and unins000.exe nothing found:
GPUZ.MD.png
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
You are right, for some reason the installer gets a lot of detections now

I'm using regular Innosetup.. not sure why this is happening

Edit: next version of GPU-Z will use an installer that's digitally signed with our EV signature. Seems this helps a little bit

 
Last edited:

8up

New Member
Joined
Jan 25, 2024
Messages
1 (0.01/day)
Downloaded GPU-Z-2.56.0 from techpowerup on Jan 19. Ran it again on Jan 22 and got an update notification. Clicked through to get the update, as I figured there was no reason to worry since I got the app from the horse's mouth.

1706219560595.png


Google searched within the past month for gpuz and a few malware keywords and came up with:

https://www.reddit.com/r/techsupport/comments/19d79ck
and


Going back farther in the archives, there seem to have been many such reports of malware coming via Techpowerup's GPUz, as well as CPUID's CPUz. What could be in GPUz and CPUz that looks so much like either of these keylogger and/or RAT malwares? Something to do with the required low level hardware access? Also, what are the odds of the latest version being flagged for 3 different keylogger/RAT malwares?

edit:

Just looked at the Virustotal results above (as I didn't think to click them earlier). Should have asked the odds of the latest version getting flagged for 3 or more different keylogger/RAT malwares.

Sure these COULD all be false positives, but even the most likely possibility it is not a certainty. I don't feel like putting any more thought into this. Mine is a brand new PC -- the first I've assembled in over a decade and it's only been used over the past couple weeks. The simplest and most effective solution for me, which coincidentally is also the only guaranty of no positives at all, is to repartition the hard drive and reinstall Winblows like it's 1998, avoiding the install of anything questionable until a proper backup has been made. I didn't like how the SSD was partitioned anyhow.
 
Last edited:
Joined
Aug 20, 2007
Messages
20,815 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64 / Windows 11
Sure these COULD all be false positives,
They are certainly false positives. Techpowerup is a identifiable business with a US HQ that would be gone pretty quick if peddling malware.

If it bothers you though, you can wait for the next release that w1zzard will sign with his business code signing cert, that will certainly clear it up.

FYI some of my original mods I do for ksp get multiple flags so this is not unheard of, just overeager AV at work.
 
Joined
Mar 28, 2018
Messages
1,795 (0.80/day)
Location
Arizona
System Name Space Heater MKIV
Processor AMD Ryzen 7 5800X
Motherboard ASRock B550 Taichi
Cooling Noctua NH-U14S, 3x Noctua NF-A14s
Memory 2x32GB Teamgroup T-Force Vulcan Z DDR4-3600 C18 1.35V
Video Card(s) PowerColor RX 6800 XT Red Devil (2150MHz, 240W PL)
Storage 2TB WD SN850X, 4x1TB Crucial MX500 (striped array), LG WH16NS40 BD-RE
Display(s) Dell S3422DWG (34" 3440x1440 144Hz)
Case Phanteks Enthoo Pro M
Audio Device(s) Edifier R1700BT, Samson SR850
Power Supply Corsair RM850x, CyberPower CST135XLU
Mouse Logitech MX Master 3
Keyboard Glorious GMMK 2 96%
Software Windows 10 LTSC 2021, Linux Mint
I wonder if antivirus engines just don't like Inno Setup installers.

I've made installers in Inno Setup before, so out of curiosity, I submitted one of mine to VT.


Five AV engines detected it.

For those who are curious, it's the setup executable from a repack I made of Skyrim for personal use. I wanted to back the game up to DVDs, and I also wanted to learn how installers work.

my-setup-file.png


All this setup file does is ask for an install location and ask you to select what is installed. Then, it simply unpacks an archive into the target location and then offers to install DirectX and VC runtimes.

It just uses standard LZMA2 compression for the files.

I even still have the source file for this installer. I don't really want to share it as text, but I'll show a screenshot.

my-setup-file-source.png
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
I wonder if antivirus engines just don't like Inno Setup installers.
that, and the lower quality AV engines are way too sensitive and will flag virtually everything.

If you create an empty program that does nothing it will get flagged by those, too.

Sure these COULD all be false positives, but even the most likely possibility it is not a certainty
It is a certainty, look at Virustotal, reputable antivirus engines. These don't flag GPU-Z

What could be in GPUz and CPUz that looks so much like either of these keylogger and/or RAT malwares? Something to do with the required low level hardware access?
Correct, a .sys driver gets extracted to %TEMP% and loaded, requires admin privileges to run, accesses hardware in various ways

Five AV engines detected it.
Yeah.. it's always the same guys .. CrowdStrike, SecureAge, MaxSecure etc
 

Teddy1983

New Member
Joined
Jan 25, 2024
Messages
17 (0.16/day)
I also have a problem, regardless of which server I download from.
 

Attachments

  • Zrzut ekranu 2024-01-26 091835.png
    Zrzut ekranu 2024-01-26 091835.png
    75.7 KB · Views: 39

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
I also have a problem, regardless of which server I download from.
Yeah, this is not a server issue on our end, but an antivirus false positive. Running GPU-Z without installation works fine though, right?

You can submit it here for analysis, to help improve Defender:
 
Last edited:
Joined
Jan 14, 2019
Messages
9,970 (5.13/day)
Location
Midlands, UK
System Name Nebulon-B Mk. 4
Processor AMD Ryzen 7 7800X3D
Motherboard MSi PRO B650M-A WiFi
Cooling be quiet! Dark Rock 4
Memory 2x 24 GB Corsair Vengeance EXPO DDR5-6000
Video Card(s) Sapphire Pulse Radeon RX 7800 XT
Storage 2 TB Corsair MP600 GS, 2 TB Corsair MP600 R2, 4 + 8 TB Seagate Barracuda 3.5"
Display(s) Dell S3422DWG, 7" Waveshare touchscreen
Case Kolink Citadel Mesh black
Power Supply Seasonic Prime GX-750
Mouse Logitech MX Master 2S
Keyboard Logitech G413 SE
Software Windows 10 Pro
Benchmark Scores Cinebench R23 single-core: 1,800, multi-core: 18,000. Superposition 1080p Extreme: 9,900.
Wait a minute... "gpuz_installer.exe"? Shouldn't it be called "GPU-Z.2.57.0.exe"? Are you sure you downloaded it from this site, and not a fake one that looks like it, but isn't? :wtf:
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
Wait a minute... "gpuz_installer.exe"? Shouldn't it be called "GPU-Z.2.57.0.exe"? Are you sure you downloaded it from this site, and not a fake one that looks like it, but isn't? :wtf:
He downloaded GPU-Z.2.57.0.exe correctly. When you click on "start installer" within GPU-Z, it will extract "gpuz_installer.exe" to %TEMP% and run it
 
Joined
Jan 14, 2019
Messages
9,970 (5.13/day)
Location
Midlands, UK
System Name Nebulon-B Mk. 4
Processor AMD Ryzen 7 7800X3D
Motherboard MSi PRO B650M-A WiFi
Cooling be quiet! Dark Rock 4
Memory 2x 24 GB Corsair Vengeance EXPO DDR5-6000
Video Card(s) Sapphire Pulse Radeon RX 7800 XT
Storage 2 TB Corsair MP600 GS, 2 TB Corsair MP600 R2, 4 + 8 TB Seagate Barracuda 3.5"
Display(s) Dell S3422DWG, 7" Waveshare touchscreen
Case Kolink Citadel Mesh black
Power Supply Seasonic Prime GX-750
Mouse Logitech MX Master 2S
Keyboard Logitech G413 SE
Software Windows 10 Pro
Benchmark Scores Cinebench R23 single-core: 1,800, multi-core: 18,000. Superposition 1080p Extreme: 9,900.
He downloaded GPU-Z.2.57.0.exe correctly. When you click on "start installer" within GPU-Z, it will extract "gpuz_installer.exe" to %TEMP% and run it
Ah, I see! :ohwell:

By the way, I've just downloaded and updated to the latest version without any issues. It did ask for a system restart, though, which it hasn't before. I'm on Windows 10, using only Defender as AV.
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
By the way, I've just downloaded and updated to the latest version without any issues. It did ask for a system restart, though, which it hasn't before. I'm on Windows 10, using only Defender as AV.
Interesting .. so maybe the definitions have already been updated
 
Joined
Jan 14, 2019
Messages
9,970 (5.13/day)
Location
Midlands, UK
System Name Nebulon-B Mk. 4
Processor AMD Ryzen 7 7800X3D
Motherboard MSi PRO B650M-A WiFi
Cooling be quiet! Dark Rock 4
Memory 2x 24 GB Corsair Vengeance EXPO DDR5-6000
Video Card(s) Sapphire Pulse Radeon RX 7800 XT
Storage 2 TB Corsair MP600 GS, 2 TB Corsair MP600 R2, 4 + 8 TB Seagate Barracuda 3.5"
Display(s) Dell S3422DWG, 7" Waveshare touchscreen
Case Kolink Citadel Mesh black
Power Supply Seasonic Prime GX-750
Mouse Logitech MX Master 2S
Keyboard Logitech G413 SE
Software Windows 10 Pro
Benchmark Scores Cinebench R23 single-core: 1,800, multi-core: 18,000. Superposition 1080p Extreme: 9,900.
Interesting .. so maybe the definitions have already been updated
Maybe. Or maybe the definitions on my PC are out of date. :ohwell: :D
 
Joined
Nov 15, 2021
Messages
2,731 (3.01/day)
Location
Knoxville, TN, USA
System Name Work Computer | Unfinished Computer
Processor Core i7-6700 | Ryzen 5 5600X
Motherboard Dell Q170 | Gigabyte Aorus Elite Wi-Fi
Cooling A fan? | Truly Custom Loop
Memory 4x4GB Crucial 2133 C17 | 4x8GB Corsair Vengeance RGB 3600 C26
Video Card(s) Dell Radeon R7 450 | RTX 2080 Ti FE
Storage Crucial BX500 2TB | TBD
Display(s) 3x LG QHD 32" GSM5B96 | TBD
Case Dell | Heavily Modified Phanteks P400
Power Supply Dell TFX Non-standard | EVGA BQ 650W
Mouse Monster No-Name $7 Gaming Mouse| TBD
I had downloaded it yesterday, and installed it today. Defender, SentinelOne, and ESET all gave it a pass.
 
Joined
Feb 18, 2005
Messages
5,302 (0.76/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Logitech G613
Software Windows 10 Professional x64
Downloaded GPU-Z-2.56.0 from techpowerup on Jan 19. Ran it again on Jan 22 and got an update notification. Clicked through to get the update, as I figured there was no reason to worry since I got the app from the horse's mouth.

View attachment 331443

Google searched within the past month for gpuz and a few malware keywords and came up with:

https://www.reddit.com/r/techsupport/comments/19d79ck
and


Going back farther in the archives, there seem to have been many such reports of malware coming via Techpowerup's GPUz, as well as CPUID's CPUz. What could be in GPUz and CPUz that looks so much like either of these keylogger and/or RAT malwares? Something to do with the required low level hardware access? Also, what are the odds of the latest version being flagged for 3 different keylogger/RAT malwares?

edit:

Just looked at the Virustotal results above (as I didn't think to click them earlier). Should have asked the odds of the latest version getting flagged for 3 or more different keylogger/RAT malwares.

Sure these COULD all be false positives, but even the most likely possibility it is not a certainty. I don't feel like putting any more thought into this. Mine is a brand new PC -- the first I've assembled in over a decade and it's only been used over the past couple weeks. The simplest and most effective solution for me, which coincidentally is also the only guaranty of no positives at all, is to repartition the hard drive and reinstall Winblows like it's 1998, avoiding the install of anything questionable until a proper backup has been made. I didn't like how the SSD was partitioned anyhow.
You should educate yourself before making such uninformed and alarmist posts.
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
You should educate yourself before making such uninformed and alarmist posts.
He has every right to come here and be worried. Actually I appreciate learning about this, so I can do something about it (vs not knowing about it in the first place)
 

W1zzard

Administrator
Staff member
Joined
May 14, 2004
Messages
27,070 (3.71/day)
Processor Ryzen 7 5700X
Memory 48 GB
Video Card(s) RTX 4080
Storage 2x HDD RAID 1, 3x M.2 NVMe
Display(s) 30" 2560x1600 + 19" 1280x1024
Software Windows 10 64-bit
1706271100103.png


So it's just a question of getting the signatures updated now.

Their internal tool did confirm the detection when I submitted it
1706271154807.png
 
Top