Welcome guest. Before posting on our computer help forum, you must register. Click here it's easy and free.

Author Topic: TROJAN IN MY ITUNES..  (Read 7123 times)

0 Members and 1 Guest are viewing this topic.

dj_dvs

    Topic Starter


    Greenhorn

    TROJAN IN MY ITUNES..
    « on: July 24, 2009, 05:55:59 PM »
    HEY GUYS ....I WENT TO START UP ITUNES,THEN I GOT WINDOW SAYING THREAT DETECTED"A BUNCH OF TROJANS IN ITUNES.".I RAN A SCAN WITH ANTIMAKLWARE:SAID ::UNABLE TO HEAL FILES...
    I UNINSTALLED ITUNES THEN REINSTALLED IT..BUT WHEN IT WAS AT LIKE 90 %...SAME WINDOW CAME UP WITH:THREATS DETECTED...NOW I CANT EVEN INSTALL IT...PLEASE HELP ME

    Quantos



      Guru
    • Veni, Vidi, Vici
    • Thanked: 170
      • Yes
      • Yes
    • Computer: Specs
    • Experience: Guru
    • OS: Linux variant
    Re: TROJAN IN MY ITUNES..
    « Reply #1 on: July 24, 2009, 05:58:01 PM »
    Don't shout.

    Go here and follow the directions.  A specialist will be with you.
    Evil is an exact science.

    dj_dvs

      Topic Starter


      Greenhorn

      Re: TROJAN IN MY ITUNES..
      « Reply #2 on: July 24, 2009, 05:59:24 PM »
      thanx man...sorry about the caps...lol

      Teeman



        Beginner

        Re: TROJAN IN MY ITUNES..
        « Reply #3 on: July 24, 2009, 06:15:32 PM »
        I just found it too. But It seems my AVG says



        Can some one please help? :-[

        Yes This is my first time this has happen to me.  :o

        dj_dvs

          Topic Starter


          Greenhorn

          Re: TROJAN IN MY ITUNES..
          « Reply #4 on: July 24, 2009, 07:03:53 PM »
          thats exactly what i got...

          Teeman



            Beginner

            Re: TROJAN IN MY ITUNES..
            « Reply #5 on: July 24, 2009, 07:08:19 PM »
            Did the Help work for you?

            Quantos



              Guru
            • Veni, Vidi, Vici
            • Thanked: 170
              • Yes
              • Yes
            • Computer: Specs
            • Experience: Guru
            • OS: Linux variant
            Re: TROJAN IN MY ITUNES..
            « Reply #6 on: July 24, 2009, 07:10:17 PM »
            Teeman, please start your own thread.  That will insure that you get the best help for your situation.

            Do not hijack other support threads.
            Evil is an exact science.

            dj_dvs

              Topic Starter


              Greenhorn

              Re: TROJAN IN MY ITUNES..
              « Reply #7 on: July 24, 2009, 07:14:10 PM »
              i d/l all the required programs and heres my log file..


              Logfile of Trend Micro HijackThis v2.0.2
              Scan saved at 9:12:03 PM, on 7/24/2009
              Platform: Windows Vista SP1 (WinNT 6.00.1905)
              MSIE: Internet Explorer v8.00 (8.00.6001.18702)
              Boot mode: Normal

              Running processes:
              C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
              C:\Program Files (x86)\Digital Line Detect\DLG.exe
              C:\Program Files (x86)\Kiwee Toolbar\2.8.167\kwtbaim.exe
              C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe
              C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe
              C:\Program Files (x86)\Java\jre6\bin\jusched.exe
              C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
              C:\Program Files (x86)\AVG\AVG8\avgtray.exe
              C:\Program Files (x86)\Common Files\Logishrd\LQCVFX\COCIManager.exe
              C:\Program Files (x86)\Internet Explorer\iexplore.exe
              C:\Program Files (x86)\Internet Explorer\iexplore.exe
              C:\Program Files (x86)\Windows Live\Toolbar\wltuser.exe
              C:\Program Files (x86)\Trend Micro\sniper.exe\HijackThis.exe

              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
              R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
              R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
              R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
              R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
              R3 - URLSearchHook: AGSearchHook Class - {0BC6E3FA-78EF-4886-842C-5A1258C4455A} - C:\Program Files (x86)\AGI\common\agcutils.dll
              O1 - Hosts: ::1 localhost
              O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - c:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
              O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG8\avgssie.dll
              O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
              O2 - BHO: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files (x86)\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
              O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program Files (x86)\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dll
              O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
              O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files (x86)\Google\GoogleToolbarNotifier\5.1.1309.3572\swg.dll
              O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - C:\Program Files (x86)\Dell\BAE\BAE.dll
              O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
              O2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
              O3 - Toolbar: Kiwee Toolbar - {6638A9DE-0745-4292-8A2E-AE530E7B9B3F} - C:\Program Files (x86)\Kiwee Toolbar\2.8.167\KiweeIEToolbar.dll
              O3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program Files (x86)\Windows Live\Toolbar\wltcore.dll
              O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files (x86)\Adobe\Reader 9.0\Reader\Reader_sl.exe"
              O4 - HKLM\..\Run: [KiweeHook] "C:\Program Files (x86)\Kiwee Toolbar\2.8.167\kwtbaim.exe"
              O4 - HKLM\..\Run: [LogitechCommunicationsManager] "C:\Program Files (x86)\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"
              O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "C:\Program Files (x86)\Logitech\QuickCam\Quickcam.exe" /hide
              O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre6\bin\jusched.exe"
              O4 - HKLM\..\Run: [SweetIM] C:\Program Files (x86)\SweetIM\Messenger\SweetIM.exe
              O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~2\AVG\AVG8\avgtray.exe
              O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
              O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
              O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
              O4 - HKCU\..\Run: [EPSON NX100 Series] C:\Windows\system32\spool\DRIVERS\x64\3\E_IATIEDA.EXE /FU "C:\Windows\TEMP\E_SF02C.tmp" /EF "HKCU"
              O4 - HKCU\..\Run: [msnmsgr] ~"C:\Program Files (x86)\Windows Live\Messenger\msnmsgr.exe" /background
              O4 - HKCU\..\Run: [SUPERAntiSpyware] C:\Program Files (x86)\SUPERAntiSpyware\SUPERAntiSpyware.exe
              O4 - HKCU\..\RunOnce: [Shockwave Updater] C:\Windows\SysWOW64\Adobe\Shockwave 11\SwHelper_1150595.exe -Update -1150595 -"Mozilla/4.0 (compatible; MSIE 7.0; Windows NT 6.0; WOW64; GTB6; SLCC1; .NET CLR 2.0.50727; Media Center PC 5.0; .NET CLR 3.5.30729; .NET CLR 3.0.30618)" -"http://www.cyberjuegos.com/pool/Default.aspx?&RoomID=aaa_02&GameID=pool"
              O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
              O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
              O4 - Global Startup: Digital Line Detect.lnk = C:\Program Files (x86)\Digital Line Detect\DLG.exe
              O13 - Gopher Prefix:
              O16 - DPF: CabBuilder - http://kiw.imgag.com/imgag/kiw/toolbar/download/InstallerControl.cab
              O16 - DPF: Justin.tv Publisher - http://www.justin.tv/plugins/justintv_publisher.CAB
              O16 - DPF: {0CCA191D-13A6-4E29-B746-314DEE697D83} (Facebook Photo Uploader 5 Control) - http://upload.facebook.com/controls/2008.10.10_v5.5.8/FacebookPhotoUploader5.cab
              O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/ES-US/a-UNO1/GAME_UNO1.cab
              O16 - DPF: {9C23D886-43CB-43DE-B2DB-112A68D7E10A} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader2.cab
              O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
              O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/flashplayer/current/swflash.cab
              O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files (x86)\AVG\AVG8\avgpp.dll
              O20 - Winlogon Notify: !SASWinLogon - C:\Program Files (x86)\SUPERAntiSpyware\SASWINLO.dll
              O23 - Service: Andrea RT Filters Service (AERTFilters) - Unknown owner - C:\Windows\system32\AERTSr64.exe (file missing)
              O23 - Service: AG Windows Service (AGWinService) - Unknown owner - C:\Program Files (x86)\AGI\common\win32\PythonService.exe
              O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
              O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
              O23 - Service: AVG Free8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgemc.exe
              O23 - Service: AVG Free8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~2\AVG\AVG8\avgwdsvc.exe
              O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
              O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
              O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files (x86)\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
              O23 - Service: Google Update Service (gupdate1c9958021140855) (gupdate1c9958021140855) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
              O23 - Service: Google Software Updater (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
              O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
              O23 - Service: LVCOMSer - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVCOMSER\LVCSer64.exe
              O23 - Service: Process Monitor (LVPrcS64) - Logitech Inc. - C:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exe
              O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
              O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
              O23 - Service: PremierOpinion - Unknown owner - C:\Program Files (x86)\PremierOpinion\pmservice.exe (file missing)
              O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
              O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
              O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
              O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
              O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
              O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
              O23 - Service: stllssvr - MicroVision Development, Inc. - C:\Program Files (x86)\Common Files\SureThing Shared\stllssvr.exe
              O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
              O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
              O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
              O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
              O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)
              O23 - Service: XAudioService - Unknown owner - C:\Windows\system32\DRIVERS\xaudio64.exe (file missing)

              --
              End of file - 10667 bytes

              Teeman



                Beginner

                Re: TROJAN IN MY ITUNES..
                « Reply #8 on: July 24, 2009, 07:15:28 PM »
                thats exactly what i got...

                Sorry I thought it might be the same thing. Sorry for Hijacking.

                I just disbelieve in making threads of the same. Sorry again.

                Quantos



                  Guru
                • Veni, Vidi, Vici
                • Thanked: 170
                  • Yes
                  • Yes
                • Computer: Specs
                • Experience: Guru
                • OS: Linux variant
                Re: TROJAN IN MY ITUNES..
                « Reply #9 on: July 24, 2009, 07:16:56 PM »
                Sorry I thought it might be the same thing. Sorry for Hijacking.

                I just disbelieve in making threads of the same. Sorry again.

                It gets very confusing trying to help more than one user in the same thread.
                Evil is an exact science.

                Teeman



                  Beginner

                  Re: TROJAN IN MY ITUNES..
                  « Reply #10 on: July 24, 2009, 07:24:28 PM »
                  Understand Quantos and thank you. I'll give you a thanks.  ;) But does the info of dj_dvs post help?


                  Mulreay

                  • Guest
                  Re: TROJAN IN MY ITUNES..
                  « Reply #11 on: July 24, 2009, 11:20:25 PM »
                  Understand Quantos and thank you. I'll give you a thanks.  ;) But does the info of dj_dvs post help?

                  re-post in
                  http://www.computerhope.com/forum/index.php/board,7.0.html
                  as Quantos said.

                  Posting on here will get you no joy.

                  SuperDave

                  • Malware Removal Specialist
                  • Moderator


                  • Genius
                  • Thanked: 1020
                  • Certifications: List
                  • Experience: Expert
                  • OS: Windows 10
                  Re: TROJAN IN MY ITUNES..
                  « Reply #12 on: July 29, 2009, 06:36:18 PM »
                  Dj, did you run HJT as administrator?
                  Windows 8 and Windows 10 dual boot with two SSD's

                  dj_dvs

                    Topic Starter


                    Greenhorn

                    Re: TROJAN IN MY ITUNES..
                    « Reply #13 on: July 30, 2009, 11:27:32 PM »
                    yes,super dave

                    SuperDave

                    • Malware Removal Specialist
                    • Moderator


                    • Genius
                    • Thanked: 1020
                    • Certifications: List
                    • Experience: Expert
                    • OS: Windows 10
                    Re: TROJAN IN MY ITUNES..
                    « Reply #14 on: July 31, 2009, 05:59:54 PM »
                    Hi dj. There is a problem running HJT on a 64 bit computer
                    Quote
                    Your computer has a 64-bit processor which is not 100% compatible with HijackThis and can cause improper errors in the log.

                    I'm not very familiar with 64 bit systems so I can't give you a lot of information about how to get around this problem. I found a link here that explains what's happening with your system. I checked the HJT site and there's no information about whether or HJT is designed to run on 64 bit. In my research, I also discovered that a lot of Anti-virus programs do not function correctly on 64 bit systems. I checked out AVG and there's no information about this. Perhaps the resident expert (Evil or someone else) can provide more information about this problem. Good luck.  ;)
                    Windows 8 and Windows 10 dual boot with two SSD's