Jump to content

Suspicious File: C:\windows\system32\PerfStringBackup.INI


Recommended Posts

I recently ran "Hitman Pro" and got the following message with a suspicious file.  

 

I also ran "Combofix" and the report seems to indicate a potential problem with a "win32 infection.  I have attached this report.

 

Should I be worried about these?

 

HitmanPro 3.7.9.225
www.hitmanpro.com
 
   Computer name . . . . : LEWIS-PC
   Windows . . . . . . . : 6.1.1.7601.X64/4
   User name . . . . . . : Lewis-PC\Lewis
   UAC . . . . . . . . . : Enabled
   License . . . . . . . : Free
 
   Scan date . . . . . . : 2014-10-04 19:37:21
   Scan mode . . . . . . : Normal
   Scan duration . . . . : 3m 58s
   Disk access mode  . . : Direct disk access (SRB)
   Cloud . . . . . . . . : Internet
   Reboot  . . . . . . . : No
 
   Threats . . . . . . . : 0
   Traces  . . . . . . . : 1
 
   Objects scanned . . . : 1,672,948
   Files scanned . . . . : 28,931
   Remnants scanned  . . : 256,507 files / 1,387,510 keys
 
Suspicious files ____________________________________________________________
 
   C:\windows\system32\PerfStringBackup.INI
      Size . . . . . . . : 7,052 bytes
      Age  . . . . . . . : 1908.8 days (2009-07-14 01:13:15)
      Entropy  . . . . . : 3.1
 
Thank you

ComboFix.txt

Link to post
Share on other sites

I am sorry we don't work on malware removal in this section of the forum, seeing that you believe your infected please follow the instructions in the link below for free assistance to clean your computer.

https://forums.malwarebytes.org/index.php?/topic/119858-available-assistance-for-possibly-infected-computers/#entry625816

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.