Home > General > Perfc000.dat


Consistently helpful members with best answers are invited to staff. Start here -> Malware Removal Forum. Alternatively, visit the forum/contact the tech support department of your anitvirus application. In the Open box, type regedit and click OK.

All rights reserved. Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\corel\user assistant\12\recent work\wordperfect\last opened Description : list of recently opened documents in corel wordperfect MRU List Object Recognized! Click Yes in the Confirm Value Delete dialog box. Using your file explorer, browse to the file using the paths listed in Location of perfc000.dat and Associated Malware.

Please post (reply) with the reports from DSS and the Kaspersky log. Although the internet is still running at a crawling speed, it seems that it is still active. We recommend SecurityTaskManager for verifying your computer's security.

OriginalFilename : CTFMON.EXE #:36 [bttray.exe] FilePath : C:\Program Files\WIDCOMM\Bluetooth Software\ ProcessID : 2384 ThreadCreationTime : 5-27-2007 8:01:58 PM BasePriority : Normal FileVersion : 1.4.3 Build 4 ProductVersion : 1.4.3 Build 4 All rights reserved. Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\microsoft\direct3d\mostrecentapplication Description : most recent application to use microsoft direct3d MRU List Object Recognized! It detected 3 trojans and cleaned all of them successfully.

Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\microsoft\office\11.0\powerpoint\recentfolderlist Description : list of recent folders used by microsoft powerpoint MRU List Object Recognized! Kaspersky Lab Forum > English User Forum > Virus-related issues nelson 26.06.2007 05:21 Hi There, i got this virus which i can not delete, i have scanned my pc with spydoctor Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\microsoft\mediaplayer\player\settings Description : last open directory used in jasc paint shop pro MRU List Object Recognized! http://www.bleepingcomputer.com/startups/perfc000.dat-18512.html All rights reserved.

Back to top BC AdBot (Login to Remove) BleepingComputer.com Register to remove ads #2 DaveM59 DaveM59 Bleepin' Grandpa Members 1,355 posts OFFLINE Gender:Male Location:TN USA Local time:09:50 AM Posted OriginalFilename : svchost.exe #:7 [svchost.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 1148 ThreadCreationTime : 5-27-2007 8:01:45 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating Also when you use the computer to play games, watch movies or work, the computer may suddenly show you a blue screen then shut down itself. Type : IECache Entry Data : [email protected][2].txt TAC Rating : 3 Category : Data Miner Comment : Hits:6 Value : Cookie:[email protected]/ Expires : 5-15-2012 12:05:28 AM LastSync : Hits:6 UseCount :

After finishing installation,you need to do a full canning with SpyHunter to find out every threats in your computer.After that, you should select every detected threats and remove them all. Messenger - {E5D12C4E-7B4F-11D3-B5C9-0050045C3C96} - C:\Program Files\Yahoo!\Messenger\YahooMessenger.exe O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe O12 - Plugin FileDescription : Bluetooth Support Server InternalName : BTWDIns LegalCopyright : Copyright WIDCOMM, Inc. 2000-2004. The file will be deleted on restart.

Click the Save as Text button to save the file to your desktop so that you may post it in your next reply **Note for Internet Explorer 7 users: If at Known file sizes on Windows 10/8/7/XP are 6,144bytes (97% of all occurrences) or 3bytes. Search Startups Startup Database Navigation Startups Home Newest Entries Rootkit List Startup Database Forum How to use the Startup Database Submit a Startup RSS Feed Newsletter Sign Up

Follow Type : RegValue Data : TAC Rating : 10 Category : Monitoring Tool Comment : Rootkey : HKEY_LOCAL_MACHINE Object : software\microsoft\windows\currentversion\control panel\load Value : kyrpa Win32.TrojanSpy.BZub Object Recognized!

Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\adobe\adobe acrobat\6.0\avgeneral\crecentfiles Description : list of recently used files in adobe acrobat MRU List Object Recognized! Free Scan. Click here to Register a free account now! File Location %System% Startup Type This program starts from the following registry key:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs.It may be necessary to use a special file deletion utility, such as BlitzBlank, to delete these files.

Also was able to delete the perfc000.dat file. Required fields are marked * Name * Email * Website Comment You may use these HTML tags and attributes:

Download removal tool SpyHunter1) Click here or the icon below to download SpyHunter automatically. 2) Follow the instructions to install SpyHunter Step B.

O4 - Global Startup: Printkey2000.lnk = C:\Program Files\PrintKey2000\Printkey2000.exe O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000 O8 - Extra context menu item: Send To &Bluetooth - C:\Program

Your system as well as the saved data will be secure only when you immediately remove perfc000.dat from the PC. Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\microsoft\office\11.0\access\settings Description : list of recently opened documents in microsoft access MRU List Object Recognized! Name Filename perfc000.dat Command C:\Windows\System32\perfc000.dat Description Added by the Trojan.Perfcoo Trojan. Site Changelog Community Forum Software by IP.Board Sign In Use Facebook Use Twitter Need an account?

All rights reserved. In the Tasks Manager window, click the Processes tab. So, if you are not a computer savvy, I recommend you to solve this problem with removing perfc000.dat automatically with SpyHunter.Step 1: Download Spyhunter antivirus program by clicking the icon below: random.exeStep 3: Find and remove all corrupt files related to perfc000.dat virus: C:\program files%AllUsersProfile%\Application Data\%AllUsersProfile%\Step 4: Navigate to registry editor to clear all perfc000.dat virus registry entries as followings: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image

Manual Removal perfc000.dat Virus Step 1: Reboot your infected computer, when it reboots but before Windows launches, tap ‘F8′ key constantly. OriginalFilename : BTWDIns.EXE #:16 [defwatch.exe] FilePath : C:\Program Files\NavNT\ ProcessID : 1748 ThreadCreationTime : 5-27-2007 8:01:49 PM BasePriority : Normal FileVersion : ProductVersion : ProductName : Norton AntiVirus CompanyName Yesterday I accessed it for about 5 minutes (JUST FIVE MINUTES) and that was time enought for me to get a virus... Help other users!

Run SpyHunter to block perfc000.datRun SpyHunter and click ‘Malware Scan' button to scan your computer, after detect this unwanted program, clean up relevant files and entries completely. This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed Pressing CTRL+ALT+DEL identifies programs that are currently running - not necessarily at startup. Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\microsoft\terminal server client\default Description : list of recent systems connected to using remote desktop / terminal services MRU List Object Recognized!

Type : Regkey Data : TAC Rating : 10 Category : Malware Comment : Rootkey : HKEY_CLASSES_ROOT Object : clsid\{36dbc179-a19f-48f2-b16a-6a3e19b42a87} Win32.TrojanSpy.BZub Object Recognized! perfc000.dat virus attacked my computer and it slowed down the system performance obviously. OriginalFilename : services.exe #:5 [lsass.exe] FilePath : C:\WINDOWS\system32\ ProcessID : 908 ThreadCreationTime : 5-27-2007 8:01:44 PM BasePriority : Normal FileVersion : 5.1.2600.2180 (xpsp_sp2_rtm.040803-2158) ProductVersion : 5.1.2600.2180 ProductName : Microsoft® Windows® Operating This is NOT a list of tasks/processes taken from Task Manager or the Close Program window (CTRL+ALT+DEL) but a list of startup applications, although you will find some of them listed

Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\adobe\photoshop\7.0\visiteddirs Description : adobe photoshop 7 recent work folders MRU List Object Recognized! Location: : S-1-5-21-3760607338-1603120009-2945326695-1005\software\microsoft\windows\currentversion\explorer\comdlg32\opensavemru Description : list of recently saved files, stored according to file extension MRU List Object Recognized! The Registry Editor window opens.