NNLOGON.EXE - Dangerous
NNLOGON.EXE
Jeff's Story:
My PC had gotten a bad rootkit that my ISP antivirus software (powered by McAfee) could not detect, nor could fix.
I sought a solution on the Internet and discovered your product and tried out the trial.
You quickly found the rootkit and SAVED my PC!
I haven't had any problems since, and I'm extremely grateful.
Manual removal instructions:
NNLOGON.EXE is known as: Trojan.Gen [PCTools] Trojan.Gen [Symantec] Trojan.Rootkit [Ikarus].
MD5 of NNLOGON.EXE = 4F8EC9279CE71A9FEAFD811A2A0FE8FC
NNLOGON.EXE size is 69632 bytes.
Full path on a computer: [PATHNAME WITH A STRING SHARE]\NNLOGON.EXE
Related Files:
C:\A88343AB5F8DB6A0D0\INSTALL.EXE
C:\A88343AB5F8DB6A0D0\INSTALL.RES.1033.DLL
%WINDIR%\INSTALLER\2015D.MSI
%APPDATA%\GMARKET.ICO
%TEMP%\DD_VCREDISTMSI0A65.TXT
%TEMP%\DD_VCREDISTUI0A65.TXT
%TEMP%\MSI230F9.LOG
%TEMP%\URL4.TMP
C:\NAUTOUP.LOG
[PATHNAME WITH A STRING SHARE]\AUTOUP.INI
[PATHNAME WITH A STRING SHARE]\BHO.LOG
[PATHNAME WITH A STRING SHARE]\BHOCFG.INI
[PATHNAME WITH A STRING SHARE]\BHOCODE.INI
[PATHNAME WITH A STRING SHARE]\BHOEXE.LOG
[PATHNAME WITH A STRING SHARE]\EFBBAR.DLL
[PATHNAME WITH A STRING SHARE]\EFSBAR.DLL
[PATHNAME WITH A STRING SHARE]\IEWINDOW.EXE
[PATHNAME WITH A STRING SHARE]\IEWINDOW.LOG
[PATHNAME WITH A STRING SHARE]\NAUTOUP.LOG
[PATHNAME WITH A STRING SHARE]\NAVIGATOR.ICO
[PATHNAME WITH A STRING SHARE]\NNLOGON.EXE
[PATHNAME WITH A STRING SHARE]\NNLOGON.INI
[PATHNAME WITH A STRING SHARE]\NNLOGON.LOG
[PATHNAME WITH A STRING SHARE]\NTMEND.EXE
[PATHNAME WITH A STRING SHARE]\NTMURL.DLL
%SYSTEM%\NSEARCHER.EXE
[PATHNAME WITH A STRING SHARE]\SSLAUNCH.DLL
[PATHNAME WITH A STRING SHARE]\SSLAUNCH.LOG
[PATHNAME WITH A STRING SHARE]\TAGS.INI
[PATHNAME WITH A STRING SHARE]\TAGS.MDB
[PATHNAME WITH A STRING SHARE]\TAGSTEMP.MDB
[PATHNAME WITH A STRING SHARE]\UNINST.EXE
[PATHNAME WITH A STRING SHARE]\URLD.EXE
[PATHNAME WITH A STRING SHARE]\URLUPDATE1.EXE
[PATHNAME WITH A STRING SHARE]\VERSION.INI
%WINDIR%\INSTALLER\MSIB.TMP
%SYSTEM%\DWSBC80.OCX
%SYSTEM%\DWSHENGINE80.DLL
%SYSTEM%\DWSHK80.OCX
%SYSTEM%\VB6KO.DLL