Help - Search - Members - Calendar
Full Version: Perfc000, Not Sure Though..
BleepingComputer.com > Security > Am I infected? What do I do?
   
collon
Ok, on May 02, 2007 there was a folder created of the name perfc000.dat in my SYSTEM32 folder. It affected my computer Internet browser. At first the effects were not noticable. On May 8th i beleive is when my internet browser stopped working alltogether. It wouldnt load pages, only google. I could not figure out what was going on. My AVG wouldnt pick it up, and i was really mad because i couldnt use my computer. My freind sent me a direct download for Ad-Aware and i installed it and ran it. It found some tracking cookie/data miners. I quarintined and deleted. The problem still exsisted. My dad then took a IE .4 disc and downloaded that and re-downloaded IE .7. My internet worked and AVG picked up the virus. It didnt seem to bother me until about May 11th-12th when i decided to delete the file where it was located. I found it in C:\WINDOWS\SYSTEM32 as perfc000. Everytime i deleted it, it would just come back. So i googled it and found this site with some steps to take. People were talking about killing it on reboot. I didn't know how until i saw someone show killbox. So i downloaded it, killed perfc000 and my web browser seemed to be working again. I ran AVG and only find tacking cookies. Same with Ad-aware. But just recently i have been noticing its affect again. Its the affects of me not cleaning out my Internet cache. Pictures have red x's, Page wont load properly, Page wont load at all, and some other affects. I usually just reloaded the page and it was fine. But now, its taking several reloads and stuff to fix it. Also google isint working properly. Some links are, but not all. Like adware and ad viruses. But i killed perfc000. Please help, i would rather not reformat my computer. I am open to most suggetions and tips. If you need any info and its not to private ask away. Thank you!

P.S. I had to copy this because of the browser saying 'Page cannot be displayed'
buddy215
Use the smitfraudfix tool in the link below. Follow the instructions carefully.
http://siri.urz.free.fr/Fix/SmitfraudFix_En.php
--------------------------------------------------------------------------------


Install Super Antispyware. Run it in safe mode. Allow it to quarantine whatever it finds.
http://www.superantispyware.com/

Run the online scan for Bit Defender in normal mode. Allow it to quarantine whatever it finds.
http://www.bitdefender.com/scan8/ie.html

--------------------------------------------------------------------------------

Post a Hijack This log in the Hijack This Forum by following the directions in the link below if the programs above have not removed ALL malware. DO NOT post the log in this forum.
http://www.bleepingcomputer.com/forums/topic34773.html
--------------------------------------------------------------------------------

How To start Windows in Safe Mode
http://www.bleepingcomputer.com/tutorials/tutorial61.html
quietman7
The perfc000.dat file is loaded through the AppInit_DLLs Registry value & Winlogon Notify Subkeys which remains after the physical file is deleted. I'm also finding that file seems to be accompanied by other malware infections so you may be dealing with several issues. Your best course of action is to follow buddy215's instructions for posting a hijackthis log.
collon
I followed it, and posted a HJT log in the correct forum. The bit defender did not work though. Thanks for the help.
This is a "lo-fi" version of our main content. To view the full version with more information, formatting and images, please click here.
Invision Power Board © 2001-2008 Invision Power Services, Inc.