Go Back   IceInSpace > Equipment > Software and Computers
Register FAQ Calendar Today's Posts Search

Reply
 
Thread Tools Rate Thread
  #1  
Old 26-10-2008, 07:34 PM
John K's Avatar
John K
Registered User

John K is offline
 
Join Date: Sep 2005
Location: Melbourne
Posts: 1,468
Pop up window virus on my PC

Hi everyone,

I seem to have picked up a pop up virus in the form of an application on my PC that is trying to get me download some free anti virus software from it's site.

I think it's a eibtm.exe type of virus.

It cannot be detected with my anti virus software and it cannot be deleted with my program manager or any other software - it lives in my program files -> applications area. Have tried to end it working by cnt alt del but it keeps working so cannot be deleted.

Attached are some images of the software and what it's doing. It also keeps making itself my internet home page. Very annoying!!!

Any suggestions how I can get rid of this thing?

Really thought that my anti virus software would kill it.

Thanks in advance for any help.

John.

p.s. I tried re-naming one of the files to the name virus so I could delete it, still not good.
Attached Thumbnails
Click for full-size image (LaptopVirus1.jpg)
153.8 KB52 views
Click for full-size image (LaptopVirus2.jpg)
186.1 KB55 views
Click for full-size image (LaptopVirus3.jpg)
177.3 KB52 views
Click for full-size image (LaptopVirus4.jpg)
105.6 KB37 views
Click for full-size image (LaptopVirus6.jpg)
127.0 KB33 views
Click for full-size image (LaptopVirus5.jpg)
186.4 KB38 views

Last edited by John K; 26-10-2008 at 08:08 PM.
Reply With Quote
  #2  
Old 26-10-2008, 08:33 PM
Dooghan's Avatar
Dooghan (Dooghan)
Registered User

Dooghan is offline
 
Join Date: Jun 2007
Location: Rockhampton
Posts: 62
If it is a virus then your computer is toast. They dig themselves in so well now days that it's next to impossible to rid of every file, etc out of the system. I would just get out the install disks and backups and do a full reinstall. If it was my system I could never ever trust that system again with my private data until I did the full reinstall.
Reply With Quote
  #3  
Old 26-10-2008, 08:39 PM
Bob
Registered User

Bob is offline
 
Join Date: Mar 2007
Location: Keilor East
Posts: 27
Hi John

Go to Tucows,download Malaware and install,run Malaware, that should get rid of your problem.

Regards Bob
Reply With Quote
  #4  
Old 26-10-2008, 09:03 PM
monoxide's Avatar
monoxide
Registered User

monoxide is offline
 
Join Date: Oct 2006
Location: Adelaide
Posts: 658
these ones are the worst of the lot, the 'anti virus' company infects your pc and it will constantly download more viruses until you pay their $50 or whatever to remove the problem they caused in the first place..
i dont know how its not illegal, its extortion.

whenever i get a virus (very very rarely) i format as its the only way to be sure its completely gone, too many experiences with AV software 'cleaning' system files which are needed for the pc to boot.

try AdAware and Spybot Search & Destroy (these are the best tools for removing malware)
Reply With Quote
  #5  
Old 26-10-2008, 09:07 PM
John K's Avatar
John K
Registered User

John K is offline
 
Join Date: Sep 2005
Location: Melbourne
Posts: 1,468
Thanks guys.

Quote:
Originally Posted by Bob View Post
Hi John

Go to Tucows,download Malaware and install,run Malaware, that should get rid of your problem.

Regards Bob
Hi Bob,

have now done that and giving that a go, so lets see what happens.
Reply With Quote
  #6  
Old 26-10-2008, 09:26 PM
Jeff's Avatar
Jeff
Starry Eyed

Jeff is offline
 
Join Date: Dec 2007
Location: Wonga Park
Posts: 692
Also, run "msconfig" and look for rogue programs loaded at boot time in the "startup" section. This low tech approach is still used for some malware. You can remove check marks and reboot to test to see if the messages stop. Also check for / disable unwanted browser plug ins.

Good luck!
Reply With Quote
  #7  
Old 26-10-2008, 10:25 PM
John K's Avatar
John K
Registered User

John K is offline
 
Join Date: Sep 2005
Location: Melbourne
Posts: 1,468
Quote:
Originally Posted by Jeff View Post
Also, run "msconfig" and look for rogue programs loaded at boot time in the "startup" section. This low tech approach is still used for some malware. You can remove check marks and reboot to test to see if the messages stop. Also check for / disable unwanted browser plug ins.

Good luck!
Thanks, yep tried that. It's pretty smart, as quickly as you un tick and re-ticks the box so it's always running!
Reply With Quote
  #8  
Old 26-10-2008, 10:28 PM
monoxide's Avatar
monoxide
Registered User

monoxide is offline
 
Join Date: Oct 2006
Location: Adelaide
Posts: 658
restart and go into safe mode, you should be able to get rid of it with AdAware or Spybot S&D:

http://www.lavasoft.com/
http://www.safer-networking.org/en/index.html
Reply With Quote
  #9  
Old 26-10-2008, 10:37 PM
Bob
Registered User

Bob is offline
 
Join Date: Mar 2007
Location: Keilor East
Posts: 27
This program, Malwarebytes' Anti-Malware.
Solved the same problem on a friends computer.
Reply With Quote
  #10  
Old 26-10-2008, 11:02 PM
John K's Avatar
John K
Registered User

John K is offline
 
Join Date: Sep 2005
Location: Melbourne
Posts: 1,468
Quote:
Originally Posted by Bob View Post
This program, Malwarebytes' Anti-Malware.
Solved the same problem on a friends computer.
Malware is an absolute winner. Cannot believe how much stuff it cleaned out. All fixed.

thanks very much everyone.

john k.
Reply With Quote
  #11  
Old 27-10-2008, 08:20 AM
wasyoungonce's Avatar
wasyoungonce (Brendan)
Certified Village Idiot

wasyoungonce is offline
 
Join Date: Jul 2006
Location: Mexico city (Melb), Australia
Posts: 2,338
Quote:
Originally Posted by Bob View Post
This program, Malwarebytes' Anti-Malware.
Solved the same problem on a friends computer.

2nd that.

This program is "the only one" that has removed multiple Trojans and virus's from the one computer and cleaned it completely, for me.

Trojan's have a habit of opening your computer to other worms and malware so they can be difficult to clean. Get the Malwarebytes' Anti-Malware from the source and update it before running:

http://www.malwarebytes.org/
Reply With Quote
  #12  
Old 27-10-2008, 08:52 AM
jjjnettie's Avatar
jjjnettie (Jeanette)
Registered User

jjjnettie is offline
 
Join Date: Feb 2005
Location: Monto
Posts: 16,738
Glad you solved the problem.
I wonder how many people out there have paid the extortion fee, then have to keep on paying?
Reply With Quote
  #13  
Old 27-10-2008, 09:41 AM
GrampianStars's Avatar
GrampianStars (Rob)
Black Sky Zone

GrampianStars is offline
 
Join Date: Apr 2005
Location: Western Victoria
Posts: 776
I got this once used "Avast" anti virus and it shows the file name it resides in memory as well so I re-boot in safe mode then delete before std. start
"its Gone"
Reply With Quote
Reply

Bookmarks


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump


All times are GMT +10. The time is now 03:25 AM.

Powered by vBulletin Version 3.8.7 | Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
Advertisement
Testar
Advertisement
Bintel
Advertisement