Register a SA Forums Account here!
JOINING THE SA FORUMS WILL REMOVE THIS BIG AD, THE ANNOYING UNDERLINED ADS, AND STUPID INTERSTITIAL ADS!!!

You can: log in, read the tech support FAQ, or request your lost password. This dumb message (and those ads) will appear on every screen until you register! Get rid of this crap by registering your own SA Forums Account and joining roughly 150,000 Goons, for the one-time price of $9.95! We charge money because it costs us money per month for bills, and since we don't believe in showing ads to our users, we try to make the money back through forum registrations.
 
  • Locked thread
Maha
Dec 29, 2006
sapere aude
So I ran FRST on my (Windows 7, 64-bit) PC and found this:

==================== Alternate Data Streams (Whitelisted) =========

(If an entry is included in the fixlist, only the ADS will be removed.)

AlternateDataStreams: C:\Windows\System32:5CD8EBDA_Abn.gbp
AlternateDataStreams: C:\Windows\TEMP:temp


From googling a bit, it seems like this 5CD8EBDA_Abn.gbp might be part of this beyond-shady "security suite" called G-Buster Browser Defense (aka GbPlugin, aka Warsaw) that some Brazilian banks require so you can do online banking through them. This sprawling, self-reinstalling piece of poo poo malware was installed to my computer a few months ago, and I spent a long time piecing together instructions to get rid of it. I think I got it all, with the possible exception of this. So how do I get rid of an ADS? Thanks in advance.

Adbot
ADBOT LOVES YOU

Gromit
Aug 15, 2000

I am an oppressed White Male, Asian women wont serve me! Save me Campbell Newman!!!!!!!
I'm sure there are tools to do it specifically, but ADS is only supported on NTFS so you could just copy the file to, say, a FAT filesystem disk and then copy it back. The file will lose its ADS attachment in the process.

Maha
Dec 29, 2006
sapere aude
I got it using FRST itself, thanks.

  • Locked thread