Can't seem to get rid of this file

Discussion in 'Software' started by jak3y, Jun 26, 2005.

  1. jak3y

    jak3y Guest

    Ran everything including hijackthis (which im comfortable at this point).
    On my Aunts computer, she keeps having this Perflib_Perfdata_8c4.dat.
    Which no matter what number ending it ends in (in this case "8c4") it says that it is always being used by some program.
    This "Perflib"Perfdata" keeps reinventing itself and It always ends up in her TEMP file folder.
    C:\DOCUME~1\judi\LOCALS~1\Temp\Perflib_Perfdata_8c4.dat
    ad-aware, hijack, cwshredder, hsremove
    can't get rid of it.
    any clues as to what it is?
    help would be appreciated, thanks guys :)
     
  2. foot loose

    foot loose Private E-2

    Please observe our tried and trued method of removing malware via Chaslang, BJGarrick, Philliephan or myself before posting in this specific forum... Thanks :)
     
    Last edited by a moderator: Jun 27, 2005
  3. jak3y

    jak3y Guest

    in safe mode, the file doesn't show.
    hmmm :rolleyes:
     
  4. bjgarrick

    bjgarrick MajorGeeks Admin - Malware Expert

    Sounds like this could be related to Virtumundo!

    First, please follow ALL the steps in this Sticky thread READ ME FIRST BEFORE ASKING FOR SUPPORT: Basic Spyware, Trojan And Virus Removal

    After doing ALL of the above if you still have a problem:


    http://www.majorgeeks.com/images/grenade.gif Download HijackThis 1.99.1

    http://www.majorgeeks.com/images/grenade.gif Unzip the hijackthis.exe file to a folder you create named C:\Program Files\HJT

    http://www.majorgeeks.com/images/grenade.gif Do NOT run Hijack This from the Desktop, a temp folder, or a sub-folder of C:\Documents and Settings, or choose to run it directly from the ZIP file as your backups will not be safely stored.

    http://www.majorgeeks.com/images/grenade.gifBefore running HijackThis: You must close each of the following:your web browser, e-mail client, instant messenger, and programs like notepad, wordpad, MS Word etc. And any other unnecessary running programs.

    http://www.majorgeeks.com/images/grenade.gifRun HijackThis and save your log file.

    http://www.majorgeeks.com/images/grenade.gif Post your log as an ATTACHMENT to your next post. (Do NOT copy/paste the log into your post as it will be removed).

    http://www.majorgeeks.com/images/grenade.gifNeed help with HJT? See this thread: NO HIJACK THIS LOG FILES BEFORE READING THIS: HJT Tutorial & LOG File Posting
     
  5. jak3y

    jak3y Guest

    well big G (and anyone else)...i did the HJT and it found nothing
    so here's the attachment...good luck, cuz i tried all possible/viable ways of hunting this thing down.
    thanks. ;)
     

    Attached Files:

  6. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    albiet for w2k it will apply to XP

    http://support.microsoft.com/default.aspx?scid=kb;en-us;Q285798

    http://www.jsifaq.com/subG/TIP3300/rh3343.htm


    maybe not an easy task to locate whats creating that file at shutdown tho.... maybe run Process Explorer and see if anythings locking that file.

    as a last resort its quite likely that this can be disabled in GPEDIT or the Registry... depending on OS version.


    ------------------
    2nd Edit: just noticed your running 2 antivirus apps... remove one of them it could be the problem!
     
    Last edited: Jun 27, 2005
  7. jak3y

    jak3y Guest

    Halo, now all i gotta do is learn how to add a command logon script...lol
    wanna help me out here? lol
     
  8. jak3y

    jak3y Guest

    anyone...anyone...? ferris... :confused: lol
     
  9. jak3y

    jak3y Guest

    trying this one again...im assuming by non-response...it's a toughy :confused:
     
  10. jak3y

    jak3y Guest

    here's the HJT today...all done in safe mode, with ad-aware, spybot, cwshredder, about:buster, etc...etc...
     

    Attached Files:

  11. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Sorry jakey ..... completly forgot about I'd posted in this thread.. thought I was in software.... plus with all the new posts the Spyware forum wizzes by so quick...... also been way busy in work!

    dont think you have a spyware issue BUT Chas and BJ will soon correct me if I'm wrong,

    Do you still have 2 antivirus apps installed?

    Have you booted into Safe Mode and seen if it happens then?

    In a word yes its a toughy as tracing what software or hardware could be causing the perfdata file to be created is not easy as I not come across that often or at all, I have tho read and do know that you maybe able to edit the registry to stop the perfdat file from being created ( would need to read more about what it could affect tho ) but this depends on how happy you are to edit the registry?

    If I foregt do please PM me to basically remind me ;)

    ps...... WHO THE HELL IS FERRIS??
     
  12. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    You need to post a log from normal boot mode. The one you posted was from safe mode. However before doing that, uninstall one of the antivirus applications you have installed. You have both Avast and AVG. You should only use one antivirus application.
     
  13. jak3y

    jak3y Guest

    well...here it is...seems fine...but that preflip file is still showing up (whenever i right click an executable file on my usb key)
     

    Attached Files:

  14. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Your problems are not malware related. Perflib_Perfdata are valid files that windows creates.

    You may want to discuss this in the Software Forum. In fact, I will move this thread there with a redirect from the Spyware Forum (so you will still find it).
     
  15. jak3y

    jak3y Guest

    perfect thanks Chas'... :)
     
  16. Franklin

    Franklin Corporal

  17. jak3y

    jak3y Guest

    thanks Franklin will give the 2nd one a try first lol...looks more promising :mad: lol
     
  18. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Even when that app would delete perflib on reboot or shutdown it will be created again.. perflib is not a stubborn to remove file its a OS file that stubbornly creates itself because of somesuch error or issue, worth a try tho as stranger things have happened.

    now as you have just mentioned it happens when you use your USB key.. is that the only time it happens.. what if you remove the USB key software/driver does it still create its self?

    Have you checked for updated drivers for the USB key?

    How happy are you to edit the registry? ( we can try to add a registry key to block it from starting ) .. i'm still looking for a none registry answer.
     
  19. jak3y

    jak3y Guest

    well I DIDN'T really install software for the key, i actually just pop it in the usb and run it...(sometimes forget to remove it properly-using the lower right toolbar icon to "safely remove hardware" but...otherwise, i just use the drivers that winxp installs for it. it doesn't come with any software to begin with
    no i haven't...it only happens on my aunts computer, my computer and everyone elses it runs fine.

    im fine with it, but if it's not posing a threat or the file isn't as you said, maybe i should just leave it as is? lol?
    thanks halo
     
  20. DavidGP

    DavidGP MajorGeeks Forum Administrator - Grand Pooh-Bah Staff Member

    Ah ok, just curious if the USB key was a contibution to the file, dunno if this is part of XP Home or not as I dont have any machines at my disposal with XPH on, but I was told that if you goto > Control Panel > Add/Remove choose Add/Remove Windows Components and untick Managment and Monitoring Tools > Next it should uninstall the app that produces that perflib file on reboot.

    File wont pose a threat, more of any annoyance.
     
  21. jak3y

    jak3y Guest

    we're running on xppro and that very component was already unchecked...so...what now... :p lol
    this is a trivial issue, but now im just stubborn and the challenge is getting the better of me.lol
     
  22. bchivers

    bchivers Private First Class

    Have you tried gipo move on boot?Link
    Go to the bottom of the page where it says "Old Version (Freeware) "
     
  23. doug_hile

    doug_hile Private E-2

    :cryAUUUUGH~!~!~! too compicated for my apes brain to understand the secrets of the Krell......
    Isn't there simply a specific program that will get rid of/correct/remove/remedy this "thing"????
    Sounds like it is a basic flaw of Windows ---
    All the Windows updates, etc,,,, plus AVG, which I love, cannot fix this "thing"...
    I would do a complete system recovery,,, but it takes weeks to reconstruct everything and reload all the updates.
    Maybe I should just tote this Infernal Machine up to Best Buy and let the Geek Squad have at it?

    AUUUUUUUUUGHHHHHHHHH~~!~!~!~!~!~!~!


    ;-(
     
  24. hrlow2

    hrlow2 MajorGeek

    Welcome to Major Geeks, but what the ?????.
     
  25. doug_hile

    doug_hile Private E-2

    thanks,,, but,, I was just looking for a downloadable fix that seems to be the forte' of this site. I am not far enough along to even understand what I am reading here, but just about intelligent enough to click the appropriate boxes, as long as there aren't too many of 'em... ya know?
    Sorry to be such a novice, but, sometimes I just need a hint ...
     
  26. hrlow2

    hrlow2 MajorGeek

    You might want to start a new thread stating your problem, rather than resurect one from 5 years ago.
     
  27. foot loose

    foot loose Private E-2

    Wow man i have not been in this forum for a looonnnggggg time.. I got a email from major geeks saying to respond to this tread......i forgot all about this place... I'M am Back..
     
  28. hrlow2

    hrlow2 MajorGeek

    Welcome back.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds