jathuerk Posted September 3, 2007 Report Share Posted September 3, 2007 (edited) Hi I recently connected my computer to a dorm network and I had 3 moth old definitions on my symantec antivirus. I got the trojan called perfcoo or perfc000.dat I do not know how I got it as I was not using my computer when the security alerts began appearing. The symptoms are that if I have symantec active protection on I get about 3 alerts per second about perfc000.dat until my computer locks up after about 10-15 minutes. I have followed the symmantec instructions to remove this trojan but it did not work, the trojan just appeared again immediatly after removal. Also the registry key modification instructions are not clear and detailed enough for me to follow. I have read around about this and it looks like a nasty one to remove. I have done updated ad aware, symantec antivirus and spy bot search and destroy scans while in safe mode and nothing has removed the trojanhere is my log file from hijak this, I hope someone can help, thanks in advance. Logfile of Trend Micro HijackThis v2.0.2Scan saved at 10:33:37 AM, on 9/3/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\RunDll32.exeC:\WINDOWS\system32\carpserv.exeC:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exeC:\Program Files\AIM\aim.exeC:\Program Files\Uniblue\ProcessLibrary\qaccess.exeC:\WINDOWS\system32\ctfmon.exeC:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exeC:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exeC:\WINDOWS\system32\HPZipm12.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\ZyXEL\G-302v2\tiwlnsvc.exeC:\WINDOWS\system32\wscntfy.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.wisc.edu/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - (no file)O2 - BHO: (no name) - AutorunsDisabled - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO4 - HKLM\..\Run: [Cmaudio] RunDll32 cmicnfg.cpl,CMICtrlWndO4 - HKLM\..\Run: [CARPService] carpserv.exeO4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\System32\NeroCheck.exeO4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exeO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKCU\..\Run: [AIM] C:\Program Files\AIM\aim.exe -cnetwait.odlO4 - HKCU\..\Run: [uniblue Quick Access] "C:\Program Files\Uniblue\ProcessLibrary\qaccess.exe" /startupO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Global Startup: AutorunsDisabledO4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - AutorunsDisabled - (no file)O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO16 - DPF: ActiveGS.cab - http://www.virtualapple.com/activegs.cabO16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan/as5free/asinst.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{8577AE3C-8681-44FC-BBC4-B365634F29F5}: NameServer = 194.54.90.226O17 - HKLM\System\CCS\Services\Tcpip\..\{A0243ACE-7216-4E05-896B-8064E0070CA5}: NameServer = 194.54.90.226O17 - HKLM\System\CCS\Services\Tcpip\..\{ABB638D0-1F64-455F-9C79-D7B7766C778E}: NameServer = 194.54.90.226O17 - HKLM\System\CS1\Services\Tcpip\..\{8577AE3C-8681-44FC-BBC4-B365634F29F5}: NameServer = 194.54.90.226O20 - AppInit_DLLs: C:\WINDOWS\system32\perfc000.datO21 - SSODL: bestreak - {874443fe-aa33-4ebf-a6ac-73208787e62d} - (no file)O22 - SharedTaskScheduler: {874443fe-aa33-4ebf-a6ac-73208787e62d} - bestreak - (no file)O23 - Service: DefWatch - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\DefWatch.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: Symantec AntiVirus Client (Norton AntiVirus Server) - Symantec Corporation - C:\PROGRA~1\SYMANT~1\SYMANT~1\Rtvscan.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: PC Tools Security Service (sdCoreService) - PC Tools - C:\Program Files\Spyware Doctor\swdsvc.exeO23 - Service: TI Wlan Service (tiwlnsvc) - Unknown owner - C:\Program Files\ZyXEL\G-302v2\tiwlnsvc.exeO23 - Service: Windows Media Connect Service (WMConnectCDS) - Unknown owner - C:\Program Files\Windows Media Connect 2\wmccds.exe (file missing)--End of file - 5256 bytes Edited September 3, 2007 by jathuerk Link to post Share on other sites
Shaba Posted September 6, 2007 Report Share Posted September 6, 2007 Hi jathuerkPlease download FixWareout from one of these sites:http://downloads.subratam.org/Fixwareout.exehttp://download.bleepingcomputer.com/lonny/Fixwareout.exeSave it to your desktop and run it. Click Next, then Install, make sure Run fixit is checked and click Finish.The fix will begin; follow the prompts.You will be asked to reboot your computer; please do so.Your system may take longer than usual to load; this is normal.Once the desktop loads, post the text that will open (report.txt) and a new Hijackthis log in the forum please.1. Download combofix from one of these links:Link1Link22. Double click combofix.exe & follow the prompts.3. When finished, it shall produce a log for you. Post that log in your next replyNote:Do not mouseclick combofix's window whilst it's running. That may cause it to stallPost:- a fresh HijackThis log- combofix report- fixwareout report Link to post Share on other sites
jathuerk Posted September 6, 2007 Author Report Share Posted September 6, 2007 Hello ShabaThank you for your response but I have posted my problem and started a fix from another forum. I hope I have not wasted much of your time and thank you agian for your effort. Link to post Share on other sites
Shaba Posted September 6, 2007 Report Share Posted September 6, 2007 HiOk, then this thread will get closed & archived. Link to post Share on other sites
Recommended Posts