none
GBuster makes IE Slow, Can't Delete

    General discussion

  • I spent oodles of hours on this and finally got it.  I tried replying to other's questions but could not find a way to replay (tells you about my technical prowess.)  Here's the answer I found:

    GBuster or gbplugin is a horrible program that is heavily defended by the Brazilian banking developers.  It is purposely designed to avoid removal numerous ways, uses files in program files/gbplugin and a system32/driver, my version was called gbpkm.sys, I'm on XP Home.

    I tried all the canned reponses, no virus checker or malware program stood a chance.  Restoring from before live existed on earth didn't work, upgrading the OS didn't work, using Avenger to weed out root-kits and bad stuff long before windows starts was the best shot but it didn't work and the Brazilian banks have successfully wiped out specialized programs designed to kill it.  (of course reformatting your harddrive and starting with a blank disk would work.)  Arg.

    I have fixed it though.  Much to my displeasure, I used a free Linux based too found here, and followed directions to a T, creating a Linux boot CD and using Linus based commands to navigate to the offending files, then rebooting in Windows, then editing the Registr to remove the doze or so entries:

    http://trinityhome.org/Home/index.php?pid=1&wpid=5&p_node=1&edit_pid=5&front_id=12

    For my Brazilian bank, Caixi Economica, the bad files are:
    c:\Program Files\GbPlugin\cef.gpc
    c:\Program Files\GbPlugin\gbidh.gmd
    c:\Program Files\GbPlugin\gbiehCef.dll
    c:\Program Files\GbPlugin\gbpdist.dll
    c:\Program Files\GbPlugin\gbpsv.exe
    c:\Windows\System32\drivers\gbpkm.sys

    I found registry keys by searching for "gbplugin" and removing ones closely named too, for my pc:
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\GblehObjClass
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\GbPluginCef
    HKLM\Software\Classes\CLSID\{C41A1C0E-EA6C-11D4-B1B8-444553540003}
    HKLM\Software\Classes\CLSID\{DB6BF2CD-4F59-4F1C-AA9C-D08C0B61A931}
    HKLM\Software\Classes\CLSID\{E37CB5F0-51F5-4395-A808-5FA49E399003}
    HKLM\Software\Classes\CLSID\{E37CB5F0-51F5-4395-A808-5FA49E399003}
    HKLM\Software\Classes\GbiehCef.GbPluginObj
    HKLM\Software\Classes\GbiehCef.GbPluginObj.1
    HKLM\Software\Classes\GbiehCef.GbIehObj
    HKLM\Software\Classes\GbiehCef.GbIehObj.1
    HKLM\Software\Classes\GbpDist.GbpDistObj
    HKLM\Software\Classes\GbpDist.GbpDistObj.1
    HKLM\Software\Classes\TypeLib\{6B71634C-5867-4D85-BFFE-DF1C322F8B96}
    HKLM\Software\Classes\TypeLib\{C41A1C01-EA6C-11D4-B1B8-444553540003}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\{E37CB5F0-51F5-4395-A808-5FA49E399003}
    HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
    HKLM\Software\Microsoft\Windows\CurrentVersion\ShellExtensions\Approved\{E37CB5F0-51F5-4395-A808-5FA49E399003}
    HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ GbPluginCef
    HKLM\SYSTEM\ControlSet001\Servces\GbpKm
    HKLM\SYSTEM\ControlSet001\Servces\GbpSv
    HKLM\SYSTEM\ControlSet002\Servces\GbpKm
    HKLM\SYSTEM\ControlSet002\Servces\GbpSv

    Saturday, January 22, 2011 6:08 PM

All replies

  • Hi rgillie9,

     

    Thanks for the sharing here. It can be beneficial to other community members who have the similar questions, the effort you give is very appreciated!

     

    Best Regards,

    Miya


    This posting is provided "AS IS" with no warranties, and confers no rights. | Please remember to click "Mark as Answer" on the post that helps you, and to click "Unmark as Answer" if a marked post does not actually answer your question. This can be beneficial to other community members reading the thread.
    Monday, January 24, 2011 3:37 AM
    Moderator
  • Well, at least it is not virus. the problem of those GPB Busters is that they turn on sometimes and keep using 50% of the CPU in a constant way.

    Some small forms laptops like HP 2540 if using in a high processing for a long time, becomes extremely hot.

    So in a way to override this, i restarted under safe mode, renamed the original folder (Usualy Program Files (x86)\GpbPlugin) and also renamed the executable.

    It seems that it didnt load in the next boot, and didnt ask any user action.

    Now user will have to test if his internet banking works or not without this program.

     

    Thursday, January 19, 2012 12:02 PM
  • Felipe, I struggled with this for a long time. Followed your suggestion and simply changed name and that solved the problem. I do not care if the Banco do Brasil internet banking works I just want to get rid of it so Explorer is not so slow. THANK YOU so much for your suggestion.
    Saturday, March 29, 2014 4:04 PM
  • Hello rgillie9

    I am very frustated with this Gbplugin...

    I just download the iso but don't know how to boot from it. I have Windows Vista. Please help me with the instructions and the command after that. I can follow it pretty good if you help a little.

    Thanks so much.

    Brienza

    Monday, March 31, 2014 8:08 PM