This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Trojan Found: Perfc000.dat

63 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I don't know if it's relating, i have just scanned the perfc000.dat at Virustotal.com:

Antivirus Version Update Result
AhnLab-V3 2007.5.4.0 05.04.2007 no virus found
AntiVir 7.4.0.15 05.05.2007 TR/Crypt.XPACK.Gen
Authentium 4.93.8 05.04.2007 no virus found
Avast 4.7.997.0 05.05.2007 no virus found
AVG 7.5.0.467 05.05.2007 no virus found
BitDefender 7.2 05.05.2007 no virus found
CAT-QuickHeal 9.00 05.05.2007 no virus found
ClamAV devel-20070416 05.05.2007 no virus found
DrWeb 4.33 05.05.2007 no virus found
eSafe 7.0.15.0 05.03.2007 Suspicious Trojan/Worm
eTrust-Vet 30.7.3615 05.05.2007 no virus found
Ewido 4.0 05.05.2007 no virus found
FileAdvisor 1 05.05.2007 no virus found
Fortinet 2.85.0.0 05.05.2007 suspicious
F-Prot 4.3.2.48 05.04.2007 no virus found
F-Secure 6.70.13030.0 05.05.2007 no virus found
Ikarus T3.1.1.7 05.05.2007 no virus found
Kaspersky 4.0.2.24 05.05.2007 no virus found
McAfee 5024 05.04.2007 no virus found
Microsoft 1.2503 05.05.2007 no virus found
NOD32v2 2243 05.05.2007 no virus found
Norman 5.80.02 05.04.2007 no virus found
Panda 9.0.0.4 05.05.2007 Suspicious file
Prevx1 V2 05.05.2007 no virus found
Sophos 4.17.0 05.05.2007 no virus found
Sunbelt 2.2.907.0 05.05.2007 no virus found
Symantec 10 05.05.2007 no virus found
TheHacker [removed] 04.15.2007 no virus found
VBA32 3.11.4 05.04.2007 no virus found
VirusBuster 4.3.7:9 05.05.2007 no virus found
Webwasher-Gateway 6.0.1 05.05.2007 Trojan.Crypt.XPACK.Gen


Aditional Information
File size: 6144 bytes
MD5: 4cf879e7ec03cb098b1ae77027dfd93c
SHA1: 7d97bbd60cf9002e682b0788172ea621c37a90bd
Yes, we know the file is bad but everytime you kill it, it comes back.
We need to try and find what is bring it back to life.

There are a couple more logs with that file and it looks like they are associated with a hidden file PhotoShow.

Did the look.bat run?
Sorry to jump in for a second… Zentor, do you have any idea where or how you got infected with this one? In your case, it looks like there is no random named exe present with "PhotoShow" in it. For example Nero PhotoShow Express.exe, Comcast PhotoShow Deluxe.exe.. with hidden attributes. In the other logs I've analysed where this Perfc000.dat appeared, similar ones with this PhotoShow file do appear. Not sure if they are related anyway though - could be installed through a malware bundle. Anyway, if you know how or where you got infected with this one, please let me know. If you know a link or whatever where you suspect you got infected, please send me the link via PM, do not post it here in the forum (since we don't want others getting infected with it) Thanks :)
I don't know how i get infected, it surely has been done by my brother… When i started the computer, AntVir already showed up the alerts after windows loaded… I don't know what my brother has done, but he isn't at home anyway now :wtf:
I don't know if this runs on 64bit but lets give it a try.

Download Silentrunners.zip from HERE to a new folder on your desktop.

Run the SilentRunners.vbs file. If your antivirus has a script blocker, you will get a warning asking if you want to allow SilentRunners.vbs to run. It might say something like "Malicious Script Warning". This script is not malicious so you are safe in allowing it to run.

Let it run, When it has finished it will produce a Startup Programs text file. Copy and paste that text file here in your next reply.
LDTate i will do this step now, but before i have the following idea:

Could it be that AntiVir just shows up the whole time false alarm ??
Maby the file isn't dangerous, but AntiVir detect it as a trojan?


Edit: Hmm, now when i think about it, it must be a trojan, because the file isn't removeable

LDTate i will do this step now, but before i have the following idea:

Could it be that AntiVir just shows up the whole time false alarm ??
Maby the file isn't dangerous, but AntiVir detect it as a trojan?

I don't think so. It shouldn't be in the 020 AppInit_DLLs for one thing.
http://ccollomb.free.fr/unlocker/


I am not sure but it might be worth trying. After installing the program, in Safe Mode, navigate to the file, right click on it, then click on unlocker. It gives you the options to delete, rename or move. Renaming it might also be an option. (System should be set to make system files visible of course.)
Renaming the file with unlocker also doesn't work, perfc000.dat is still there including with the renamed file… So there are 2 files when i rename perfc000.dat
It looks bad with this trojan… Maby formatting the harddisk is the last chance? 3 days ago my bro has already format the computer
Lets give this a go. Can't hurt anything. go to C:\windows\system32\wscript.exe <–Rename to wscript.old. Just remember to change the file name back to wscript.exe when we're finished. Now try silent runners again.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI