Welcome to Tech Support Forum home to more then 136,000 problems solved. Issues have included: Spyware, Malware, Virus Issues, Windows, Microsoft, Linux, Networking, Security, Hardware, and Gaming Getting your problem solved is as easy as:
1. Registering for a free account
2. Asking your question
3. Receiving an answer

Registered members:
* Get free support
* Communicate privately with other members (PM).
* Removal of this message
* See fewer ads.
* And much more..

 



Want to know how to post a question? click here Having problems with spyware and pop-ups? First Steps
Go Back   Tech Support Forum > Security Center > General Computer Security
User Name
Password
Site Map Register Donate Rules Blogs Mark Forums Read


General Computer Security Get Help With System Security - This forum is not for malware removal assistance. For malware removal assistance, read the sticky topic at the top of the Virus/Trojan/Spyware Help forum, or the "First Steps" link at the top right of each page.

Reply
 
LinkBack Thread Tools
Old 01-23-2007, 08:51 AM   #1 (permalink)
Registered User
 
Join Date: Jan 2007
Posts: 2
OS: windows XP


Mistake itunes.exe hell - I surrender

The other day my computer was running a bit slow so i went in to the startup msconfig menu and started cleaning out all the nonsense. I did this, restarted, went back in, and noticed that itunes.exe was still checked, and after a closer look saw that it was sitting in my system32 folder. Not a great sign, so I went on over to a start-up list database, searched itunes.exe, and sure enough itunes.exe in the system32 folder is the result of all kinds of viruses and evilware.

I scanned my PC up and down using probably a dozen anti-virus/spyware scanners, and the most that ever came up were a few tracking cookies. (I always keep my A/V definitions up to date, and have my firewall set pretty tightly).

All I know is that the file doesn't belong there, and it is doing something (it shows up as a running process always using 2-10% of my processor power), although god only knows what. I'm sure it isn't good.

Ok well here's where it gets fun, not for me though. When I try to end the process itunes.exe, it shuts my computer down. Very violently too I might add, no other programs have a chance to do anything or close themselves out.

The file is listed as hidden, system, read-only, and it does let me delete it. Then it shuts my computer down, when i restart it my computer shuts down before windows can even finish loading. I restore itunes.exe, and it's fine again. Same thing happens when I tried to quarantine the file. If that wasn't bad enough, when I try to boot into safe mode...computer shuts down.

I searched my registry looking for something, anything, that was calling or even referring to itunes.exe...nothing. Which leaves me to think that another program tries to load the itunes.exe and when it can't, it throws a temper tantrum and shuts me down.

So after hours of repeatedly playing around with this thing it finally occured to me that if something was forcing a shut down, it had to be creating a system event saying what program was doing it. So I killed itunes.exe, restarted, went into event handler, opened the last entry and it read: "The event logging service has been started." The entry right before it, a minute or so earlier when i had killed itunes.exe read: "The event logging service has been stopped."

At which point I collapsed into a heap sobbing and admitted that this thing is simply smarter than I am, it wins. I don't even know where to start here, but any help would be greatly appreciated.
ohnoohno is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Important Information
Join the #1 Tech Support Forum Today - It's Totally Free!

TechSupportForum.com is a leading support website for your computer needs. We offer free, friendly and personalized computer support. Why pay to have your computer fixed when you can do it for free.

Join TechSupportforum.com Today - Click Here

Old 01-23-2007, 09:30 AM   #2 (permalink)
Moderator, Home Support
 
Basementgeek's Avatar
 
Join Date: Feb 2005
Location: Central Ohio, USA
Posts: 1,505
OS: XP Pro SP2/Vista Ultimate SP2


Blog Entries: 3
Hi ohnoohno :

Your are probably correct, you got a "nasty"- Could be WIN32.RBOT WORM

Here is the place to start on it. Please follow all the directions:

http://www.techsupportforum.com/secu...kthis-log.html

Please do not post your HJT logs here! They are to be posted in the HijackThis Log Help forum

BG
__________________
Donating to the forum keeps TSF free for all.


Proud member of ASAP
Basementgeek is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 01-23-2007, 10:03 AM   #3 (permalink)
Registered User
 
Join Date: Jan 2007
Posts: 2
OS: windows XP


Quote:
Originally Posted by Basementgeek View Post
Hi ohnoohno :

Your are probably correct, you got a "nasty"- Could be WIN32.RBOT WORM

Here is the place to start on it. Please follow all the directions:

http://www.techsupportforum.com/secu...kthis-log.html

Please do not post your HJT logs here! They are to be posted in the HijackThis Log Help forum

BG
I'd taken care of those already, I wasn't exagerrating when I said I must've run a dozen anti-virus/spyware scanners. The one thing I was unable to do was run them in safe mode, since I can't currently boot into safe mode without the computer restarting.

I've been running hjt every step of the way and saving the logs, and am somewhat familiar with what should/shouldn't be on hjt logs...there isn't anything there calling up itunes.exe, and nothing terribly suspicious.

That's the worst thing about this little monster, I have a pretty good idea what I'm doing in terms of cleaning these things out normally, and it's like the damn thing is one step ahead of me no matter what I try.
ohnoohno is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Old 01-23-2007, 12:25 PM   #4 (permalink)
Moderator, Home Support
 
Basementgeek's Avatar
 
Join Date: Feb 2005
Location: Central Ohio, USA
Posts: 1,505
OS: XP Pro SP2/Vista Ultimate SP2


Blog Entries: 3
ohnoohno :

I still recommend that you follow my instructions.

This forum is for General Computer Security questions. Your question is for a specific fix and it is not done here.

I sure you will be helped, following the link I gave you.

BG
__________________
Donating to the forum keeps TSF free for all.


Proud member of ASAP
Basementgeek is offline  
Digg this Post!Add Post to del.icio.usBookmark Post in TechnoratiFurl this Post!Reddit!
Reply With Quote
Reply


Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are Off
Pingbacks are Off
Refbacks are Off




All times are GMT -7. The time now is 12:24 PM.



Copyright 2001 - 2009, Tech Support Forum
Home Tips Plus | Outdoor Basecamp | Automotive Support Forum

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85