Wikiposts
Search
Computer/Internet Issues & Troubleshooting Anyone with questions about the terribly complex world of computers or the internet should try here. NOT FOR REPORTING ISSUES WITH PPRuNe FORUMS! Please use the subforum "PPRuNe Problems or Queries."

Adspy/gdown

Thread Tools
 
Search this Thread
 
Old 9th Oct 2009, 19:59
  #1 (permalink)  
Thread Starter
 
Join Date: Mar 2007
Location: Here and there
Posts: 2,781
Likes: 0
Received 1 Like on 1 Post
Adspy/gdown

The anti-vrus (AVG) caught this on a friends laptop and then shortly afterwards the laptop owner could not get into the control panel,or get any of the system tools to run or even get on the internet.Can anybody offer any help please?
tubby linton is offline  
Old 9th Oct 2009, 20:40
  #2 (permalink)  
More bang for your buck
 
Join Date: Nov 2005
Location: land of the clanger
Age: 82
Posts: 3,512
Likes: 0
Received 0 Likes on 0 Posts
Cant find a lot but try reading:

BleepingComputer.com > ADSPY/Gdown - Help
green granite is offline  
Old 9th Oct 2009, 21:12
  #3 (permalink)  
Thread Starter
 
Join Date: Mar 2007
Location: Here and there
Posts: 2,781
Likes: 0
Received 1 Like on 1 Post
Thank you for the link I but I had already found that one! The problem is that shortly after this bug was discovered on the computer,the owner could no longer get many of the computer functions to work,such as firefox,system restore ,control panel etc.
tubby linton is offline  
Old 9th Oct 2009, 22:23
  #4 (permalink)  
 
Join Date: Jan 2008
Location: Bracknell, Berks, UK
Age: 52
Posts: 1,133
Likes: 0
Received 0 Likes on 0 Posts
Boot into safe mode with command prompt, and try executing things like Malwarebytes from there....as these new rootkit viruses seem to hook into windows Explorer, and the command prompt variant of safe mode appears not to let these processes execute immediately. Hence you need to be fairly savvy with your DOS commands (not too difficult for someone in the business with a memory), but as long as you stick to these instead of trying to use the windowed versions, you should be able to successfully initiate a MBAM scan. However, you'll need to update MBAM first though.
Mike-Bracknell is offline  
Old 10th Oct 2009, 09:48
  #5 (permalink)  
Thread Starter
 
Join Date: Mar 2007
Location: Here and there
Posts: 2,781
Likes: 0
Received 1 Like on 1 Post
Thank you for the advice.I have managed to remove this nasty bug,but it took a very long time!
tubby linton is offline  
Old 10th Oct 2009, 11:48
  #6 (permalink)  
Recidivist
 
Join Date: Jun 2005
Location: Essex, UK
Posts: 1,239
Likes: 0
Received 0 Likes on 0 Posts
Am I being naive in thinking that AVG should have stopped it in the first place?
frostbite is offline  
Old 10th Oct 2009, 12:40
  #7 (permalink)  
Thread Starter
 
Join Date: Mar 2007
Location: Here and there
Posts: 2,781
Likes: 0
Received 1 Like on 1 Post
Avg did find it ,but I do not know what the owner did after it was discovered.I would suspect that the owner may have ignored the warning or the virus started to do damage as soon as it had been downloaded.
tubby linton is offline  
Old 11th Oct 2009, 05:35
  #8 (permalink)  
 
Join Date: Dec 2005
Location: Wellington,NZ
Age: 66
Posts: 1,678
Received 10 Likes on 4 Posts
If you have time, what did you have to do to kill/remove it?
Tarq57 is offline  
Old 11th Oct 2009, 08:32
  #9 (permalink)  
Thread Starter
 
Join Date: Mar 2007
Location: Here and there
Posts: 2,781
Likes: 0
Received 1 Like on 1 Post
The big problem was trying to get the machine to respond. I knew from the avira log that the bug had been found on the 3rd so I tried to do a system restore to a date before that.By booting into safe mode I managed to get it back to a system checkpoint before the infection and then I had avira rescan the whole system.It found the bug again and removed it.I downloaded tools onto a stick from another computer and then installed them on the machine I also used another anti malware tool to scan it again.I scannned it in safe mode and again when I rebooted it in normal mode.
If you ever have this problem there are a number of topics to read if you search for "cannot access control panel or system restore".I am not an it professional so I was just following the advice from the various websites to remove this virus.
There is not a lot of info about the actual bug but I think that it was a rootkit.Some of them are getting very nasty and stop you even running the anti malware tools.
tubby linton is offline  
Old 11th Oct 2009, 08:51
  #10 (permalink)  
 
Join Date: Dec 2005
Location: Wellington,NZ
Age: 66
Posts: 1,678
Received 10 Likes on 4 Posts
Thanks for that, tubby. Well done. You're a bit lucky system restore worked.

Just out of interest, read an article that said there's been a 585% increase in rogues in the first 6 months of this year.
I was involved (peripherally) on another forum with helping someone to try and remove pretty much a "zero-day" rogue antimalware. Poor bu@@er hasn't got access to the control panel, any system tools, can't boot into safe, no .exe will run, with a message saying "..has been disabled by the administrator..." and nothing he had detected it before it went belly up. His AV has now been disabled. I think he's either looking at a BART cd, or a format/reinstall.

This sort of thing just reinforces the idea that it is a very good idea to disable (or prompt) for scripts to be allowed to run in any browser.
Among other GOP's.
Tarq57 is offline  
Old 11th Oct 2009, 20:54
  #11 (permalink)  
Thread Starter
 
Join Date: Mar 2007
Location: Here and there
Posts: 2,781
Likes: 0
Received 1 Like on 1 Post
For the record the file was:
GTDownDE_87.ocx

Having surfed the net a number of sites have reports of problems with this file.
This site probably offers the best advice:
Bleeping Computer - Computer Help and Discussion
tubby linton is offline  

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off



Contact Us - Archive - Advertising - Cookie Policy - Privacy Statement - Terms of Service

Copyright © 2024 MH Sub I, LLC dba Internet Brands. All rights reserved. Use of this site indicates your consent to the Terms of Use.