Unsolved

This post is more than 5 years old

1429

May 6th, 2008 15:00

Syswow64 and andt.sys trojan

Hello

 

I keep getting pop-ups telling me I have a trojan  in the syswow64 folder and andt.sys.  I am afraid I really don't understand either of these references, although there are a few strange entries in the hijackthis log including perf.exe which when googled came up with some rather nasty descriptions.  I cannot fix this item nor find any other reference to it when I try a search.  Any help would be greatly appreciated.

 

My log as follows:

 

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17:20:49, on 06/05/2008
Platform: Windows Vista  (WinNT 6.00.1904)
MSIE: Internet Explorer v7.00 (7.00.6000.16643)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe
C:\Program Files (x86)\DAEMON Tools\daemon.exe
C:\Program Files (x86)\Azureus\Azureus.exe
C:\Program Files (x86)\Hotkey\Hotkey.exe
C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files (x86)\PowerISO\PWRISOVM.EXE
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exeA
C:\Program Files (x86)\SoftDisc\SoftDisc.exe
C:\Program Files (x86)\Winamp\winampa.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopIndex.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktopCrawl.exe
C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexStoreSvr.exe
C:\Program Files (x86)\Evidence Eliminator\Ee.exe
C:\Program Files (x86)\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exe
C:\PROGRA~2\MOZILL~1\FIREFOX.EXE

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.co.uk/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files (x86)\google\googletoolbar1.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files (x86)\google\googletoolbar1.dll
O4 - HKLM\..\Run: [Hotkey] "C:\Program Files (x86)\Hotkey\Hotkey.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [PWRISOVM.EXE] "C:\Program Files (x86)\PowerISO\PWRISOVM.EXE"
O4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files (x86)\Google\Google Desktop Search\GoogleDesktop.exe" /startup
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [SoftDisc] "C:\Program Files (x86)\SoftDisc\softdisc.exe" -hide
O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files (x86)\Winamp\winampa.exe"
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files (x86)\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files (x86)\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [swg] C:\Program Files (x86)\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKCU\..\Run: [BgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files (x86)\Common Files\Ahead\Lib\NMBgMonitor.exe"
O4 - HKCU\..\Run: [DAEMON Tools] "C:\Program Files (x86)\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKCU\..\Run: [Evidence Eliminator] C:\Program Files (x86)\Evidence Eliminator\ee.exe /m
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files (x86)\Windows Media Player\WMPNSCFG.exe
O4 - HKCU\..\Run: [updateMgr] "C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe" AcRdB7_0_9 -reboot 1
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: Azureus - Shortcut.lnk = C:\Program Files (x86)\Azureus\Azureus.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files (x86)\MagicDisc\MagicDisc.exe
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files (x86)\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files (x86)\Java\jre1.6.0_05\bin\ssv.dll
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O20 - AppInit_DLLs: C:\PROGRA~2\Google\GOOGLE~2\GOEC62~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files (x86)\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files (x86)\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files (x86)\Common Files\LightScribe\LSSrvc.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: NBService - Nero AG - C:\Program Files (x86)\Nero\Nero 7\Nero BackItUp\NBService.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NMIndexingService - Nero AG - C:\Program Files (x86)\Common Files\Ahead\Lib\NMIndexingService.exe
O23 - Service: perfmons Service (perfmons) - Unknown owner - C:\Windows\SysWOW64\perfs.exe
O23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files (x86)\Viewpoint\Common\ViewpointService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9519 bytes
 

10.4K Posts

May 7th, 2008 12:00

boston1021

1. Run an online virus scan called Kaspersky from HERE.
  • 1. Click on " Kaspersky Online Scanner"
    2. A new smaller window will pop up. Press on " Accept". After reading the contents.
    3. Now Kaspersky will update the anti-virus database. Let it run.
    4. Click on " Next"->>" Scan Settings", and make sure the database is set to " extended". And check both the scan options. Then click OK.
    5. Then click on " My Computer". And the scan will start.
    6. When the scan is complete Select "Save error report as"
    Then in the file name just type in kaspersky
    Under "save as type" select text .txt
    Save it to your Desktop.









Copy and post the results of the Kaspersky Online scan










Microsoft MVP Consumer-Security

 


"The world is what you make of it"




May 7th, 2008 17:00

Thanks for replying so quickly and being generous with your time; I appreciate it.

 

The scan revealed 3 viruses and 9 infected files, none of which came up on avast curiously.

 

Here is the scan:

 

C:\Program Files\Alwil Software\Avast4\DATA\aswResp.dat    Object is locked    skipped
C:\Program Files\Alwil Software\Avast4\DATA\Avast4.db    Object is locked    skipped
C:\Program Files\Alwil Software\Avast4\DATA\integ\avast.int    Object is locked    skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\AshWebSv.ws    Object is locked    skipped
C:\Program Files\Alwil Software\Avast4\DATA\log\nshield.log    Object is locked    skipped
C:\Program Files\Alwil Software\Avast4\DATA\report\Resident protection.txt    Object is locked    skipped
C:\Users\user\AppData\Local\Ahead\Nero Home\bl.db    Object is locked    skipped
C:\Users\user\AppData\Local\Ahead\Nero Home\is2.db    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbc2e.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbdam    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbdao    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbeam    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbeao    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbm    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbu2d.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbvm.cf1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\dbvmh.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\fii.cf1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\fiih.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\hp    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\hpt2i.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\rpm.cf1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\rpm1m.cf1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\rpm1mh.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Google\Google Desktop\24f8b3208101\rpmh.ht1    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Internet Explorer\MSIMGSIZ.DAT    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012008050720080508\index.dat    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG1    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat.LOG2    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat{18f76579-3192-11dc-a063-e2eae98f1300}.TM.blf    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat{18f76579-3192-11dc-a063-e2eae98f1300}.TMContainer00000000000000000001.regtrans-ms    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows\UsrClass.dat{18f76579-3192-11dc-a063-e2eae98f1300}.TMContainer00000000000000000002.regtrans-ms    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows Defender\FileTracker\{B1AEC161-4A70-4B3B-B85B-6415B3F7A93D}    Object is locked    skipped
C:\Users\user\AppData\Local\Microsoft\Windows Sidebar\Settings.ini    Object is locked    skipped
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\d4330m6m.default\Cache\_CACHE_001_    Object is locked    skipped
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\d4330m6m.default\Cache\_CACHE_002_    Object is locked    skipped
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\d4330m6m.default\Cache\_CACHE_003_    Object is locked    skipped
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\d4330m6m.default\Cache\_CACHE_MAP_    Object is locked    skipped
C:\Users\user\AppData\Local\Mozilla\Firefox\Profiles\d4330m6m.default\XUL.mfl    Object is locked    skipped
C:\Users\user\AppData\Local\Temp\hsperfdata_user\1636    Object is locked    skipped
C:\Users\user\AppData\Local\Temp\NERO13349\Toolbar.exe    Infected: not-a-virus:AdTool.Win32.MyWebSearch.bm    skipped
C:\Users\user\AppData\Local\Temp\Ultra$ISO\ultraiso.log    Object is locked    skipped
C:\Users\user\AppData\Local\Temp\~DF1D5E.tmp    Object is locked    skipped
C:\Users\user\AppData\Local\Temp\~DF3CF4.tmp    Object is locked    skipped
C:\Users\user\AppData\Local\Temp\~DFBC6.tmp    Object is locked    skipped
C:\Users\user\AppData\Local\Temp\~DFCE65.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\ipfilter.cache    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU100.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU101.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU94.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU95.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU96.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU97.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU98.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Azureus\tmp\AZU99.tmp    Object is locked    skipped
C:\Users\user\AppData\Roaming\Microsoft\Windows\Cookies\index.dat    Object is locked    skipped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\d4330m6m.default\cert8.db    Object is locked    skipped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\d4330m6m.default\history.dat    Object is locked    skipped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\d4330m6m.default\key3.db    Object is locked    skipped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\d4330m6m.default\parent.lock    Object is locked    skipped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\d4330m6m.default\search.sqlite    Object is locked    skipped
C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\d4330m6m.default\urlclassifier2.sqlite    Object is locked    skipped
C:\Users\user\NTUSER.DAT    Object is locked    skipped
C:\Users\user\ntuser.dat.LOG1    Object is locked    skipped
C:\Users\user\ntuser.dat.LOG2    Object is locked    skipped
C:\Users\user\NTUSER.DAT{1484be71-6a85-11db-b53d-88eb28f23ee5}.TM.blf    Object is locked    skipped
C:\Users\user\NTUSER.DAT{1484be71-6a85-11db-b53d-88eb28f23ee5}.TMContainer00000000000000000001.regtrans-ms    Object is locked    skipped
C:\Users\user\NTUSER.DAT{1484be71-6a85-11db-b53d-88eb28f23ee5}.TMContainer00000000000000000002.regtrans-ms    Object is locked    skipped
C:\Windows\Debug\PASSWD.LOG    Object is locked    skipped
C:\Windows\Debug\sam.log    Object is locked    skipped
C:\Windows\Debug\WIA\wiatrace.log    Object is locked    skipped
C:\Windows\Logs\CBS\CBS.log    Object is locked    skipped
C:\Windows\Logs\CBS\CBS.persist.log    Object is locked    skipped
C:\Windows\Logs\DPX\setupact.log    Object is locked    skipped
C:\Windows\Logs\DPX\setuperr.log    Object is locked    skipped
C:\Windows\Microsoft.NET\Framework\v3.0\Windows Communication Foundation\SMSvcHost.exe.config    Object is locked    skipped
C:\Windows\Microsoft.NET\Framework64\v3.0\Windows Communication Foundation\SMSvcHost.exe.config    Object is locked    skipped
C:\Windows\Panther\UnattendGC\diagerr.xml    Object is locked    skipped
C:\Windows\Panther\UnattendGC\diagwrn.xml    Object is locked    skipped
C:\Windows\Panther\UnattendGC\setupact.log    Object is locked    skipped
C:\Windows\Panther\UnattendGC\setuperr.log    Object is locked    skipped
C:\Windows\security\database\secedit.sdb    Object is locked    skipped
C:\Windows\SoftwareDistribution\EventCache\{063317DC-CFA8-4DE1-80E1-54FC61278692}.bin    Object is locked    skipped
C:\Windows\SoftwareDistribution\ReportingEvents.log    Object is locked    skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat    Object is locked    skipped
C:\Windows\System32\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat    Object is locked    skipped
C:\Windows\System32\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat    Object is locked    skipped
C:\Windows\System32\LogFiles\Scm\SCM.EVM    Object is locked    skipped
C:\Windows\System32\LogFiles\WUDF\WUDFTrace.etl    Object is locked    skipped
C:\Windows\System32\perfs.exe    Infected: Trojan-Downloader.Win32.Delf.grx    skipped
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat    Object is locked    skipped
C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat    Object is locked    skipped
C:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\Microsoft\Windows\Cookies\index.dat    Object is locked    skipped
C:\Windows\SysWOW64\perfs.exe    Infected: Trojan-Downloader.Win32.Delf.grx    skipped
C:\Windows\Tasks\SCHEDLGU.TXT    Object is locked    skipped
C:\Windows\Temp\_avast4_\Webshlock.txt    Object is locked    skipped
C:\Windows\WindowsUpdate.log    Object is locked    skipped
C:\Windows\winsxs\amd64_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_2b166a33f17217b5\dnary.xsd    Object is locked    skipped
C:\Windows\winsxs\x86_microsoft-windows-n..n_service_datastore_31bf3856ad364e35_6.0.6000.16386_none_cef7ceb03914a67f\dnary.xsd    Object is locked    skipped
 

10.4K Posts

May 7th, 2008 17:00

boston1021

Do not be too hard on Avast! One of the reasons we like to use online scans is that are updated quicker.

1. We need to be able to see hidden files and folders
  • Click Start (The Vista Icon)
    Control Panel ->> Folder Options
    After the new window appears select the View tab.
    Put a checkmark in the checkbox labeled Display the contents of system folders.
    Under the Hidden files and folders section select the radio button labeled Show hidden files and folders. Remove the checkmark from the checkbox labeled Hide file extensions for known file types.
    Remove the checkmark from the checkbox labeled Hide protected operating system files.
    Click Yes To confirm
    Press the Apply button and then the OK button.







2. Using Windows Explorer
  • Rt Click the Start Buttton (The Vista Icon) ->> Explore, and you will see the "tree' of file folders in the left side of the window.
    Click on the ">" next to any folder name to expand its contents

Locate and Delete the following files
  • C:\Windows\System32\perfs.exe
    C:\Windows\SysWOW64\perfs.exe

Note: Vista sometimes likes to hide the System32 folder so if you dont see it in the tree of folders on the left just copy and paste C:\Windows\System32 into the explorer browser bar
Note Also The file names in Vista are arranged in columns in the folders, so the file names will appear in one column and the file extension will be listed under the file type column.
Example
  • perfs will appear in the name column and .exe will appear in the type column

















Microsoft MVP Consumer-Security

 


"The world is what you make of it"




May 7th, 2008 20:00

Hi bamajim

 

Couldn't find perfs.exe in system32 but managed to delete it in SysWow64 in safe mode. Re-scanned on-line and it came up clean.

 

Thankyou so much and the tips will come in handy should I suffer similar problems in the future.

 

Bless you mate!

 

No Events found!

Top