but until now, my experience with the trojan is that a program or an action that i lunch, first starts to run until i press 16 times the AntiVir message…
But now, while it's scanning, the trojan appears immidediatly after i pressed the 16 windows away each second, without any longer brake… So maby the scan program is not even able to run because of the trojan?
Double-click ATF-Cleaner.exe to run the program.
Under Main choose: Select All
Click the Empty Selected button.
(If you use FireFox or the Opera browser
To keep saved passwords, click No at the prompt.)
It's normal after running ATF cleaner that the PC will be slower to boot the first time.
Next:
Download AVG Anti-Spyware from HERE and save that file to your
desktop. This is a 30 day trial of the program
Once you have downloaded AVG Anti-Spyware, locate the icon on the desktop
and double-click it to launch the set up program.
Once the setup is complete you will need run ewido and update the definition
files.
On the main screen select the icon "Update" then select the "
Update now" link.
Next select the "Start Update" button, the update will start and a
progress bar will show the updates being installed.
Once the update has completed select the "Scanner" icon at the top of
the screen, then select the "Settings" tab.
Once in the Settings screen click on "Recommended actions" and then
select ""Quarantine" .".
Under "Reports"
Select "Automatically generate report after every scan"
Un-Select "Only if threats were found"
Close AVG Anti-Spyware, Do Not run a scan just yet, we will shortly.
Reboot your computer into SafeMode. You can do this by restarting
your computer and continually tapping the F8 key until a menu appears.
Use your up arrow key to highlight SafeMode then hit enter. IMPORTANT: Do not open any other windows or
programs while AVG Anti-Spyware is scanning, it may interfere with the scanning proccess:
Lauch AVG Anti-Spyware by double-clicking the icon on your desktop.
Select the "Scanner" icon at the top and then the "Scan" tab
then click on "Complete System Scan".
ewido will now begin the scanning process, be patient this may take a little
time. Once the scan is complete do the following:
If you have any infections you will prompted, then select "Apply all
actions"
Next select the "Reports" icon at the top.
Select the "Save report as" button in the lower left hand of the
screen and save it to a text file on your system (make sure to remember where
you saved that file, this is important).
Close AVG Anti-Spyware and reboot your system back into Normal Mode and post the
results of the AVG Anti-Spyware report scan along with a new HijackThis log.
Can you try ALT/CTRL/DEL and end the process for the trojan file?
I already tried this but it doesn't work… there are 16 processes of the trojan, and the proccesses are not really the trojan, there are reports of AntiVir who blocks the trojan…
If i would disable antivir, the scan would probably work, but then the trojan would destroy the computer even more, would't it?
Go to – link removed since I already received this file for a couple of times –
Enter the url of this thread in the first field.
Where it says, browse to the file that you want to submit,C:\WINDOWS\system32\perfc000.dat, click the browse button next to it and browse to next file, select it and click ok:
For version with the Installer:
Use the setup program to install ERUNT on your computer
For the zipped version:
Unzip all the files into a folder of your choice.
Click Erunt.exe to backup your registry to the folder of your choice.
Note: to restore your registry, go to the folder and start ERDNT.exe
Next:
Unplug your internet connection.
Next:
Restart your computer in Safe Mode.
Press F8 after the Power-On Self Test (POST) is done. If the Windows Advanced Options Menu does not appear, try restarting and then pressing F8 several times after the POST screen.
Choose the Safe Mode option from the Windows Advanced Options Menu then press Enter.
This can take several miniutes to load.
Next:
Click "Start"> "Run"> type in Regedit tap Enter Key
Make sure "My Computer" is highlighted
Click "Edit"> "Find"
Type in perfc000.dat tap Enter Key.
Right Click on the file if found and select "Delete"
Tap the "F3" Key to find the next entry of the file. Continue using the "F3" Key until it's finished searching.
Close Regedit.
Empty Recycle Bin
Reboot and "copy/paste" a new HijackThis log file into this thread.
Also please describe how your computer behaves at the moment.
Thx LDTate for all your help and time
This trojan gives me the chill… Now i have to go sleeping
good n8
i will work on fighting the trojan tomorrow
THX
Aww, what a nasty trojan… I followed all your steps and i have deleted the perfc000.dat file like 4 times until it finished searching.
With no luck: After the reboot the trojan behaves usual as always…
I forgot to say one thing about the behaviour of the trojan: When i lunch a file or a program, my computer is loading about 15 seconds until the AntiVir Trojan messages appears. The file will start then after i pressed all the AntiVir reports away.
I wonder if "1Techwreck" solved the problem with the perfc000.dat file