How do I get rid of perfc000.dat ?

R

Russell

I am running Windows XP with Avast. I keep getting a warning message from
Avast saying "A Trojan Horse Was Found!" When I choose the "Delete" button
or "Move to chest", nothin happens, the message keep repeating. I can't seem
to get rid of the virus.
Here's the info:
File name: C:\WINDOWS\system32\perfc000.dat
Malware Name: Win32:Small-HNV [Trj]
Malware Type: Trojan Horse
VPS version: 000770-2, 09/01/2007
 
M

Malke

Russell wrote:
> I am running Windows XP with Avast. I keep getting a warning message from
> Avast saying "A Trojan Horse Was Found!" When I choose the "Delete" button
> or "Move to chest", nothin happens, the message keep repeating. I can't seem
> to get rid of the virus.
> Here's the info:
> File name: C:\WINDOWS\system32\perfc000.dat
> Malware Name: Win32:Small-HNV [Trj]
> Malware Type: Trojan Horse
> VPS version: 000770-2, 09/01/2007
>
>


A Google for "perfc000.dat" brings up a lot of links. Based on what I
found, I suggest you run HijackThis and post your log on one of the
following forums (listed in no particular order):

http://aumha.org/downloads/hijackthis.zip
http://www.aumha.org/a/hjttutor.htm - HijackThis tutorial by Merijn
http://www.bleepingcomputer.com/forums/index.php?showtutorial=42 -
another tutorial
http://aumha.net/ - Click on the HijackThis forum. Read the announcement
and the stickies *first*.
http://www.atribune.org/forums/index.php?showforum=9
http://aumha.net/viewforum.php?f=30
http://www.bleepingcomputer.com/forums/forum22.html
http://castlecops.com/forum67.html
http://www.dslreports.com/forum/cleanup
http://www.cybertechhelp.com/forums/forumdisplay.php?f=25
http://www.geekstogo.com/forum/Malware_Removal_HiJackThis_Logs_Go_Here-f37.html
http://gladiator-antivirus.com/forum/index.php?showforum=170
http://spywarewarrior.com/viewforum.php?f=5
http://forums.techguy.org/54-security/
http://forums.tomcoyote.org/

Please do not post HJT logs here in the MS newsgroups.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 
R

Russell

Thanks for trying to help. Can you please explain, I downloaded HijackThis
and ran and saved my log. What will happen when I post it?
 
M

Malke

Russell wrote:
> Thanks for trying to help. Can you please explain, I downloaded HijackThis
> and ran and saved my log. What will happen when I post it?
>
>


If you went to one of the forums and read their posting FAQ, you would
know this. Basically, you'll post according to the method they outline
and someone will help you.


Malke
--
Elephant Boy Computers
www.elephantboycomputers.com
"Don't Panic!"
MS-MVP Windows - Shell/User
 
B

BoaterDave

Hi Russell. See my post on microsoft.public.security.homeusers 'Cleaning
your computer'. It may well help you. :) Please let me know.

Dave

***********************************************************
"Russell" <fake@email.com> wrote in message
news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
>
>
 
U

Umpahx2

Hi Russell. There is a post on microsoft.public.security.homeusers
'Cleaning
your computer'. It may well help you.

"Russell" <fake@email.com> wrote in message
news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
>
>
 
P

Peter Foldes

DB You are unbelievable.

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"Umpahx2" <Umpahx2@home.here> wrote in message news:%23bVcVL87HHA.1204@TK2MSFTNGP03.phx.gbl...
> Hi Russell. There is a post on microsoft.public.security.homeusers
> 'Cleaning
> your computer'. It may well help you.
>
> "Russell" <fake@email.com> wrote in message
> news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
>>
>>

>
>
 
I

IamJohnDoe

You'd better believe it, Peter! <g>

************************************
"Peter Foldes" <okf22@hotmail.com> wrote in message
news:ePhGV497HHA.464@TK2MSFTNGP02.phx.gbl...
DB You are unbelievable.

--
Peter

Please Reply to Newsgroup for the benefit of others
Requests for assistance by email can not and will not be acknowledged.

"Umpahx2" <Umpahx2@home.here> wrote in message
news:%23bVcVL87HHA.1204@TK2MSFTNGP03.phx.gbl...
> Hi Russell. There is a post on microsoft.public.security.homeusers
> 'Cleaning
> your computer'. It may well help you.
>
> "Russell" <fake@email.com> wrote in message
> news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
>>
>>

>
>
 
P

Phil Weldon

'BoaterDave' wrote:
| Hi Russell. See my post on microsoft.public.security.homeusers
'Cleaning
| your computer'. It may well help you. :) Please let me know.
_____

You are rapidly approaching the status of, as you say, 'one of the bad guys'
by posting off topic, failing to quote ANY of the post to which you reply,
posting 'answers' even though you fail to understand the problem for which
help is requested, and frequent morphing of your sig. Reform, or become
known as even less useful than a stopped clock, and shunned as malicious.

Phil Weldon

"BoaterDave" <BoaterDave@nospam.invalid> wrote in message
news:%23Pb30B17HHA.5164@TK2MSFTNGP05.phx.gbl...
| Hi Russell. See my post on microsoft.public.security.homeusers
'Cleaning
| your computer'. It may well help you. :) Please let me know.
|
| Dave
|
| ***********************************************************
| "Russell" <fake@email.com> wrote in message
| news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
| >
| >
|
|
 
B

BoaterDave

Hi Phil.

The OP did not include a 'message body' in his original post. He asked,
simply, "How do I get rid of perfc000.dat ?"

My understanding is that CCleaner will remove '.dat' files. Do you disagree?

Dave

**************************************************************
"Phil Weldon" <not.disclosed@example.com> wrote in message
news:13du2cnb23kd24a@corp.supernews.com...
> 'BoaterDave' wrote:
> | Hi Russell. See my post on microsoft.public.security.homeusers
> 'Cleaning
> | your computer'. It may well help you. :) Please let me know.
> _____
>
> You are rapidly approaching the status of, as you say, 'one of the bad
> guys'
> by posting off topic, failing to quote ANY of the post to which you reply,
> posting 'answers' even though you fail to understand the problem for which
> help is requested, and frequent morphing of your sig. Reform, or become
> known as even less useful than a stopped clock, and shunned as malicious.
>
> Phil Weldon
>
> "BoaterDave" <BoaterDave@nospam.invalid> wrote in message
> news:%23Pb30B17HHA.5164@TK2MSFTNGP05.phx.gbl...
> | Hi Russell. See my post on microsoft.public.security.homeusers
> 'Cleaning
> | your computer'. It may well help you. :) Please let me know.
> |
> | Dave
> |
> | ***********************************************************
> | "Russell" <fake@email.com> wrote in message
> | news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
> | >
> | >
> |
> |
>
>
 
P

Phil Weldon

'BoaterDave' wrote:
| The OP did not include a 'message body' in his original post. He asked,
| simply, "How do I get rid of perfc000.dat ?"
|
| My understanding is that CCleaner will remove '.dat' files. Do you
disagree?
_____

A little knowledge is a dangerous thing. The proper reply would either to
answer as 'Malke' did, or to ask for a properly formatted post. Despite the
incorrect format, the original post DID give the file name, which is all a
knowledgeable person such as 'Malke' needs. Her post also gave information
that will help the original poster to research future problems.

You, on the other hand, ignored the specific information included in the
original post, and posted an irrelevant suggestion (and that by referring to
a post in another newsgroup, a post that was no longer than your redirecting
post in THIS newsgroup.)

CCleaner is irrelevant to the original poster's problem. "Remove '.dat'
files" is entirely irrelevant just check the number of '.dat' files in your
system and consider which you would wish to remove. The key question for
CCleaner would be WHICH '.dat' files and of course, most malware has
protection against removal and/or leaves other files and fingerprints on the
compromised system.

Phil Weldon

"BoaterDave" <BoaterDave@nospam.invalid> wrote in message
news:ekYDH$A8HHA.1208@TK2MSFTNGP05.phx.gbl...
| Hi Phil.
|
| The OP did not include a 'message body' in his original post. He asked,
| simply, "How do I get rid of perfc000.dat ?"
|
| My understanding is that CCleaner will remove '.dat' files. Do you
disagree?
|
| Dave
|
| **************************************************************
| "Phil Weldon" <not.disclosed@example.com> wrote in message
| news:13du2cnb23kd24a@corp.supernews.com...
| > 'BoaterDave' wrote:
| > | Hi Russell. See my post on microsoft.public.security.homeusers
| > 'Cleaning
| > | your computer'. It may well help you. :) Please let me know.
| > _____
| >
| > You are rapidly approaching the status of, as you say, 'one of the bad
| > guys'
| > by posting off topic, failing to quote ANY of the post to which you
reply,
| > posting 'answers' even though you fail to understand the problem for
which
| > help is requested, and frequent morphing of your sig. Reform, or become
| > known as even less useful than a stopped clock, and shunned as
malicious.
| >
| > Phil Weldon
| >
| > "BoaterDave" <BoaterDave@nospam.invalid> wrote in message
| > news:%23Pb30B17HHA.5164@TK2MSFTNGP05.phx.gbl...
| > | Hi Russell. See my post on microsoft.public.security.homeusers
| > 'Cleaning
| > | your computer'. It may well help you. :) Please let me know.
| > |
| > | Dave
| > |
| > | ***********************************************************
| > | "Russell" <fake@email.com> wrote in message
| > | news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
| > | >
| > | >
| > |
| > |
| >
| >
|
|
 
B

BoaterDave

You are right, of course, Phil - I know 'nozzink' <g>

The purpose of my post was designed to prompt reaction, not from you, but
from others here. I apologise to you personally.

Perhaps you could, though, answer a 'real' query for me. I currently have
set up on this machine (in OE6) two specific newsgroups. One is
'news.microsoft.com' and the other is 'msnews.microsoft.com'. Each *appears*
to contain the same posts. Is there a simple expanation/reason for these two
identical facilities? TIA

Dave

*************************************************************
"Phil Weldon" <not.disclosed@example.com> wrote in message
news:13dumkf3kr26j79@corp.supernews.com...
> 'BoaterDave' wrote:
> | The OP did not include a 'message body' in his original post. He asked,
> | simply, "How do I get rid of perfc000.dat ?"
> |
> | My understanding is that CCleaner will remove '.dat' files. Do you
> disagree?
> _____
>
> A little knowledge is a dangerous thing. The proper reply would either to
> answer as 'Malke' did, or to ask for a properly formatted post. Despite
> the
> incorrect format, the original post DID give the file name, which is all a
> knowledgeable person such as 'Malke' needs. Her post also gave
> information
> that will help the original poster to research future problems.
>
> You, on the other hand, ignored the specific information included in the
> original post, and posted an irrelevant suggestion (and that by referring
> to
> a post in another newsgroup, a post that was no longer than your
> redirecting
> post in THIS newsgroup.)
>
> CCleaner is irrelevant to the original poster's problem. "Remove '.dat'
> files" is entirely irrelevant just check the number of '.dat' files in
> your
> system and consider which you would wish to remove. The key question for
> CCleaner would be WHICH '.dat' files and of course, most malware has
> protection against removal and/or leaves other files and fingerprints on
> the
> compromised system.
>
> Phil Weldon
>
> "BoaterDave" <BoaterDave@nospam.invalid> wrote in message
> news:ekYDH$A8HHA.1208@TK2MSFTNGP05.phx.gbl...
> | Hi Phil.
> |
> | The OP did not include a 'message body' in his original post. He asked,
> | simply, "How do I get rid of perfc000.dat ?"
> |
> | My understanding is that CCleaner will remove '.dat' files. Do you
> disagree?
> |
> | Dave
> |
> | **************************************************************
> | "Phil Weldon" <not.disclosed@example.com> wrote in message
> | news:13du2cnb23kd24a@corp.supernews.com...
> | > 'BoaterDave' wrote:
> | > | Hi Russell. See my post on microsoft.public.security.homeusers
> | > 'Cleaning
> | > | your computer'. It may well help you. :) Please let me know.
> | > _____
> | >
> | > You are rapidly approaching the status of, as you say, 'one of the bad
> | > guys'
> | > by posting off topic, failing to quote ANY of the post to which you
> reply,
> | > posting 'answers' even though you fail to understand the problem for
> which
> | > help is requested, and frequent morphing of your sig. Reform, or
> become
> | > known as even less useful than a stopped clock, and shunned as
> malicious.
> | >
> | > Phil Weldon
> | >
> | > "BoaterDave" <BoaterDave@nospam.invalid> wrote in message
> | > news:%23Pb30B17HHA.5164@TK2MSFTNGP05.phx.gbl...
> | > | Hi Russell. See my post on microsoft.public.security.homeusers
> | > 'Cleaning
> | > | your computer'. It may well help you. :) Please let me know.
> | > |
> | > | Dave
> | > |
> | > | ***********************************************************
> | > | "Russell" <fake@email.com> wrote in message
> | > | news:T9adnVU9ve6s1kTbnZ2dnUVZ_u-unZ2d@ptd.net...
> | > | >
> | > | >
> | > |
> | > |
> | >
> | >
> |
> |
>
>
 
B

BoaterDave

"IamJohnDoe" wrote:

> You'd better believe it, Peter! <g>
>
> ************************************
> "Peter Foldes" <okf22@hotmail.com> wrote in message
> news:ePhGV497HHA.464@TK2MSFTNGP02.phx.gbl...
> DB You are unbelievable.

<snip>

This post didn't stay posted in my OE6 newsgroup - just wondering why.

BD
 
H

Heather

Ohferchrissakes!! Here you are morphing once again!! Take a hike, BD
or I will sick the Internet Police on you!!

It didn't stay on your OE6 because they are watching you and waiting to
pounce. You have been warned!! Mua ha ha ha.

"BoaterDave" <BoaterDave@discussions.microsoft.com> wrote in message
news:2957641D-2789-4D63-B85D-307A300249FC@microsoft.com...
>
>
> "IamJohnDoe" wrote:
>
>> You'd better believe it, Peter! <g>
>>
>> ************************************
>> "Peter Foldes" <okf22@hotmail.com> wrote in message
>> news:ePhGV497HHA.464@TK2MSFTNGP02.phx.gbl...
>> DB You are unbelievable.

> <snip>
>
> This post didn't stay posted in my OE6 newsgroup - just wondering why.
>
> BD
 
T

Tom [Pepper] Willett

Go away, you nutjob.

"BoaterDave" <BoaterDave@discussions.microsoft.com> wrote in message
news:2957641D-2789-4D63-B85D-307A300249FC@microsoft.com...
>
>
> "IamJohnDoe" wrote:
>
>> You'd better believe it, Peter! <g>
>>
>> ************************************
>> "Peter Foldes" <okf22@hotmail.com> wrote in message
>> news:ePhGV497HHA.464@TK2MSFTNGP02.phx.gbl...
>> DB You are unbelievable.

> <snip>
>
> This post didn't stay posted in my OE6 newsgroup - just wondering why.
>
> BD
 
M

Maurice N ~ MVP

Hello Russell,

If you happen to have posted at Aumha.net forum on Thursday 9-13, please respond back on the forum. I just posted a reply there Thursday evening.
--
Maurice N
MS-MVP (Windows Client) , Aumha.net VSOP , DTS-L
-----

"Russell" <fake@email.com> wrote in message news:OMKdnSBTZpEc5ETbnZ2dnUVZ_g-dnZ2d@ptd.net...
>I am running Windows XP with Avast. I keep getting a warning message from
> Avast saying "A Trojan Horse Was Found!" When I choose the "Delete" button
> or "Move to chest", nothin happens, the message keep repeating. I can't seem
> to get rid of the virus.
> Here's the info:
> File name: C:\WINDOWS\system32\perfc000.dat
> Malware Name: Win32:Small-HNV [Trj]
> Malware Type: Trojan Horse
> VPS version: 000770-2, 09/01/2007
>
>
 
Back
Top Bottom