1
   

Golon-A Trojan

 
 
Kedge
 
Reply Tue 4 Jan, 2005 07:58 am
Hello

I have recently noticed my PC running very slowly and my software-firewall, has said that LOGON.EXE has changed.

On scanning my computer for viruses it says that I have Golon-A which does overwrite the LOGON.EXE file. I cannot seem to get rid of it.

Also I have noticed my laptop, connected via wireless network is getting very slow response on the internet (and poor ping and packet loss in online gaming) where before the connections was fine and no packet loss in games. (I am on a 1Mb DSL Connection)

Can anyone here help? If so what sort of information do you need?
  • Topic Stats
  • Top Replies
  • Link to this Topic
Type: Discussion • Score: 1 • Views: 1,541 • Replies: 12
No top replies

 
Don77
 
  1  
Reply Tue 4 Jan, 2005 09:10 pm
Hi Kedge,
Have a run through this Post
Probabaly a good place to start,
0 Replies
 
Kedge
 
  1  
Reply Wed 5 Jan, 2005 01:46 am
Will do, am at work at the moment.

FYI.
I have run an up-to-date Adaware Full Scan on both PC's, and CWShredder this appears to have frixed the slowness on my laptop, but the PC is more stubborn.

I'll do the online scans, and post back with the HJT log of both PC and the Laptop.

Cheers Don.
0 Replies
 
Don77
 
  1  
Reply Wed 5 Jan, 2005 05:32 am
Well thats a good start Kedge, Post back a log from both the pc and the lap top when you get a chance,
0 Replies
 
Kedge
 
  1  
Reply Fri 7 Jan, 2005 05:21 pm
I've done all the steps suggested, the laptop is clean now (had to re-format) the HJT log for the pc is below.

I am still getting the slowness as before, and my firewall has detected that C:\windows\system32\LOGON.EXE has changed.

Any ideas.....

Logfile of HijackThis v1.99.0
Scan saved at 23:18:48, on 07/01/2005
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
C:\Program Files\Common Files\Command Software\dvpapi.exe
C:\WINDOWS\System32\nvsvc32.exe
F:\Program Files\Kerio\Personal Firewall\persfw.exe
C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Documents and Settings\Rich Harvey\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Provided by RVnet
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = 127.0.0.1
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\SYSTEM32\msdxm.ocx
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [QuickTime Task] "C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime
O4 - HKLM\..\Run: [untray] C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe
O4 - HKLM\..\Run: [dvprpt] C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe
O4 - HKLM\..\Run: [CSAV_CheckViruses] C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe
O4 - HKLM\..\Run: [avtray] C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit
O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: Backward &Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cac&hed Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://F:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Si&milar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\MSMSGS.EXE
O16 - DPF: {2A32B14F-4D29-4EA3-AC54-E9B19F436CE7} (Scanner Class) - http://www.windowsecurity.com/trojanscan/TDECntrl.CAB
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/yinst/yinst_current.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://v5.windowsupdate.microsoft.com/v5consumer/V5Controls/en/x86/client/wuweb_site.cab?1093083069546
O16 - DPF: {74D05D43-3236-11D4-BDCD-00C04F9A3B61} (HouseCall Control) - http://a840.g.akamai.net/7/840/537/2004061001/housecall.trendmicro.com/housecall/xscan53.cab
O16 - DPF: {80DD2229-B8E4-4C77-B72F-F22972D723EA} (AvxScanOnline Control) - http://www.bitdefender.com/scan/Msie/bitdefender.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab
O16 - DPF: {B3872502-F9FD-4E96-93FF-0D37298F0689} (SOESysInfo Control) - http://swgbetareg.station.sony.com/soesysinfo.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (ZoneIntro Class) - http://messenger.zone.msn.com/binary/ZIntro.cab32846.cab
O16 - DPF: {E855A2D4-987E-4F3B-A51C-64D10A7E2479} (EPSImageControl Class) - http://tools.ebayimg.com/eps/activex/EPSControl_v1-0-3-0.cab
O16 - DPF: {F04F4F32-6457-401A-8169-D2773DDFF930} (Yahoo! Photos Easy Upload Tool Class) - http://us.dl1.yimg.com/download.yahoo.com/dl/installs/ydropper/ydropper1_3uk.cab
O16 - DPF: {F58E1CEF-A068-4C15-BA5E-587CAF3EE8C6} (MSN Chat Control 4.5) - http://fdl.msn.com/public/chat/msnchat45.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab
O23 - Service: avinitnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe
O23 - Service: pcAnywhere Host Service - Unknown - F:\Program Files\Symantec\pcAnywhere\awhost32.exe (file missing)
O23 - Service: DvpApi - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe
O23 - Service: Firebird Guardian - DefaultInstance - The Firebird Project - C:\Program Files\SysAidServer\firebird\bin\fbguard.exe
O23 - Service: Firebird Server - DefaultInstance - The Firebird Project - C:\Program Files\SysAidServer\firebird\bin\fbserver.exe
O23 - Service: NVIDIA Display Driver Service - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exe
O23 - Service: Kerio Personal Firewall - Kerio Technologies - F:\Program Files\Kerio\Personal Firewall\persfw.exe
O23 - Service: schscnt - Command Software Systems, Inc. - C:\Program Files\Command Software\Command AntiVirus\schscnt.exe
0 Replies
 
Don77
 
  1  
Reply Sat 8 Jan, 2005 08:39 am
Did you run the free online virus scans ?

Your log looks clean,

Please Download
Silent Runners
Please create a folder for it please, Then double click on the program, It will save a notebook file in the same folder, Open that, copy, paste the log back to this thread please
Let's see if something is hiding on us
0 Replies
 
Kedge
 
  1  
Reply Mon 10 Jan, 2005 02:54 pm
"Silent Runners.vbs", revision 29, launched at: 20:53
Output limited to non-default values, except where indicated by "{++}"
Operating System: Windows XP


Startup items buried in registry:
---------------------------------

HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"msnmsgr" = ""C:\Program Files\MSN Messenger\msnmsgr.exe" /background" [MS]
"Skype" = ""C:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimized" ["Skype Technologies S.A."]

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\ {++}
"SystemTray" = "SysTray.Exe" [MS]
"nwiz" = "nwiz.exe /install" ["NVIDIA Corporation"]
"NvCplDaemon" = "RUNDLL32.EXE C:\WINDOWS\System32\NvCpl.dll,NvStartup" [MS]
"QuickTime Task" = ""C:\WINDOWS\SYSTEM32\qttask.exe" -atboottime" ["Apple Computer, Inc."]
"untray" = "C:\PROGRA~1\COMMAN~1\COMMAN~1\untray.exe" ["Command Software Systems, Inc."]
"dvprpt" = "C:\PROGRA~1\COMMAN~1\COMMAN~1\dvprpt.exe" ["Command Software Systems, Inc."]
"CSAV_CheckViruses" = "C:\PROGRA~1\COMMAN~1\COMMAN~1\vchk.exe" ["Command Software Systems, Inc."]
"avtray" = "C:\PROGRA~1\COMMAN~1\COMMAN~1\avtray.exe" ["Command Software Systems, Inc."]
"TkBellExe" = ""C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot" ["RealNetworks, Inc."]
"DisplayTrayIcon" = (no data)
"NvMediaCenter" = "RUNDLL32.EXE C:\WINDOWS\System32\NvMcTray.dll,NvTaskbarInit" [MS]
"" = (data in unrecognized format!)

HKLM\Software\Microsoft\Active Setup\Installed Components\
"{306D6C21-C1B6-4629-986C-E59E1875B8AF}\(Default)" = (no title provided)
\StubPath = ""C:\WINDOWS\System32\rundll32.exe" "C:\Program Files\Messenger\msgsc.dll",ShowIconsUser" [MS]

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
{02478D38-C3F9-4efb-9B51-7695ECA05670}\(Default) = "Yahoo! Companion BHO" [from CLSID]
-> resolves to: {CLSID}\InprocServer32\(Default) = "C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_16_0.dll" ["Yahoo! Inc."]
{53707962-6F74-2D53-2644-206D7942484F}\(Default) = (no title provided)
-> resolves to: {CLSID}\InprocServer32\(Default) = "C:\Program Files\Spybot - Search & Destroy\SDHelper.dll" ["Safer Networking Limited"]

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
"{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Display Panning CPL Extension"
-> CLSID InProcServer32 resolves to: "deskpan.dll" [file not found]
"{88895560-9AA2-1069-930E-00AA0030EBC8}" = "HyperTerminal Icon Ext"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\hticons.dll" ["Hilgraeve, Inc."]
"{5b4dae26-b807-11d0-9815-00c04fd91972}" = "Menu Band"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{8278F931-2A3E-11d2-838F-00C04FD918D0}" = "Tracking Shell Menu"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{E13EF4E4-D2F2-11d0-9816-00C04FD91972}" = "Menu Site"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{ECD4FC4F-521C-11D0-B792-00A0C90312E1}" = "Menu Desk Bar"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{D82BE2B0-5764-11D0-A96E-00C04FD705A2}" = "IShellFolderBand"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{0E5CBF21-D15F-11d0-8301-00AA005B4383}" = "&Links"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{7487cd30-f71a-11d0-9ea7-00805f714772}" = "Thumbnail Image"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{450D8FBA-AD25-11D0-98A8-0800361B1103}" = "MyDocs Folder"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{FEF10FA2-355E-4e06-9381-9B24D7F7CC88}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{53C74826-AB99-4d33-ACA4-3117F51D3788}" = (no title provided)
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\system32\SHELL32.dll" [MS]
"{59850401-6664-101B-B21C-00AA004BA90B}" = "Microsoft Office Binder Explode"
-> CLSID InProcServer32 resolves to: "C:\MSOFFICE\OFFICE\explode.dll" [file not found]
"{B446400D-0030-457b-8F64-422A19605186}" = "Logitech Gallery"
-> CLSID InProcServer32 resolves to: "C:\PROGRAM FILES\LOGITECH\IMAGESTUDIO\NAMESPC.DLL" ["Logitech Inc."]
"{1CDB2949-8F65-4355-8456-263E7C208A5D}" = "Desktop Explorer"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A47}" = "Desktop Explorer Menu"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{30424D42-5946-11D2-B8E5-006097C9C6FF}" = "Norton WipeInfo"
-> CLSID InProcServer32 resolves to: "D:\PROGRAM FILES\NORTON UTILITIES\WFSHELEX.DLL" [file not found]
"{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4}" = "Shell Extensions for RealOne Player"
-> CLSID InProcServer32 resolves to: "C:\Program Files\Real\RealOne Player\rpshell.dll" ["RealNetworks, Inc."]
"{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
-> CLSID InProcServer32 resolves to: "F:\Program Files\Microsoft Office\Office10\msohev.dll" [MS]
"{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL" ["WinZip Computing, Inc."]
"{8505E441-1E15-11d5-8277-00104B16D178}" = "Mouse Shell Extension"
-> CLSID InProcServer32 resolves to: "Mousexpph.dll" ["Samsung"]
"{FFB699E0-306A-11d3-8BD1-00104B6F7516}" = "Play on my TV helper"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{A70C977A-BF00-412C-90B7-034C51DA2439}" = "NvCpl DesktopContext Class"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvcpl.dll" ["NVIDIA Corporation"]
"{1E9B04FB-F9E5-4718-997B-B8DA88302A48}" = "nView Desktop Context Menu"
-> CLSID InProcServer32 resolves to: "C:\WINDOWS\System32\nvshell.dll" ["NVIDIA Corporation"]
"{52B87208-9CCF-42C9-B88E-069281105805}" = "Trojan Remover Shell Extension"
-> CLSID InProcServer32 resolves to: "C:\PROGRA~1\TROJAN~1\Trshlex.dll" [file not found]

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
INFECTION WARNING! "PCANotify\DLLName" = "PCANotify.dll" ["Symantec Corporation"]


Enabled Scheduled Tasks:
------------------------

"PCHealth Scheduler for Data Collection" -> launches: "C:\WINDOWS\PCHEALTH\SUPPORT\PCHSCHD.EXE -c" [file not found]


Running Services (Display Name, Service Name, Path {Service DLL}):
------------------------------------------------------------------

avinitnt, avinitnt, "C:\Program Files\Command Software\Command AntiVirus\avinitnt.exe" ["Command Software Systems, Inc."]
DvpApi, dvpapi, "C:\Program Files\Common Files\Command Software\dvpapi.exe" ["Command Software Systems, Inc."]
Kerio Personal Firewall, PersFw, "F:\Program Files\Kerio\Personal Firewall\persfw.exe" ["Kerio Technologies"]
NVIDIA Display Driver Service, NVSvc, "C:\WINDOWS\System32\nvsvc32.exe" ["NVIDIA Corporation"]
schscnt, schscnt, "C:\Program Files\Command Software\Command AntiVirus\schscnt.exe" ["Command Software Systems, Inc."]


----------
This report excludes default entries except where indicated.
To see *everywhere* the script checks and *everything* it finds,
launch it from a command prompt or a shortcut with the -all parameter.
----------
0 Replies
 
Don77
 
  1  
Reply Mon 10 Jan, 2005 09:44 pm
Hi again Kedge,
Did you run the online virus scans ?
0 Replies
 
Kedge
 
  1  
Reply Tue 11 Jan, 2005 12:42 am
Yeah, both said all was ok, but my firewall still says that Logon.Exe has changed, I still get requests from my pc trying to connect to another machine (which my firewall is blocking) and it is going very slowly.
0 Replies
 
Don77
 
  1  
Reply Tue 11 Jan, 2005 08:08 pm
Please disable your current AV
Click Here and run RAV online scan, Copy and paste back the log into this thread when it has finished,
Be sure and enable your AV when done with the above
0 Replies
 
Kedge
 
  1  
Reply Wed 12 Jan, 2005 11:25 am
Scan started at 12/01/2005 16:12:31

Scanning memory...
Scanning boot sectors...
Scanning files...
C:\Documents and Settings\Rich Harvey\Application Data\Identities\{2C4970BE-7074-4408-8C4B-FFAFB1FB17A4}\Microsoft\Outlook Express\Deleted Items.dbx->Message.57: (Untitled)->(part0000:)->(IFRAME0000) - HTML/IFrame_Exploit* -> Infected
C:\Documents and Settings\Rich Harvey\Application Data\Identities\{2C4970BE-7074-4408-8C4B-FFAFB1FB17A4}\Microsoft\Outlook Express\Deleted Items.dbx->Message.57: (Untitled)->(part0001:avgury.exe) - Win32/Swen.A@mm -> Infected
C:\Documents and Settings\Rich Harvey\Application Data\Identities\{2C4970BE-7074-4408-8C4B-FFAFB1FB17A4}\Microsoft\Outlook Express\Deleted Items.dbx->Message.56: (Untitled)->(part0004:Q196173.exe) - Win32/Swen.A@mm -> Infected
C:\Documents and Settings\Rich Harvey\Application Data\Identities\{2C4970BE-7074-4408-8C4B-FFAFB1FB17A4}\Microsoft\Outlook Express\Deleted Items.dbx->Message.44: (Untitled)->(part0000:)->(IFRAME0000) - HTML/IFrame_Exploit* -> Infected
C:\Documents and Settings\Rich Harvey\Application Data\Identities\{2C4970BE-7074-4408-8C4B-FFAFB1FB17A4}\Microsoft\Outlook Express\Deleted Items.dbx->Message.44: (Untitled)->(part0001:eagxe.exe) - Win32/Swen.A@mm -> Infected

Scanned
============================
Objects: 66986
Directories: 5823
Archives: 1013
Size(Kb): 1627415
Infected files: 5

Found
============================
Viruses found: 2
Suspicious files: 0
Disinfected files: 0
Mail files: 4241
0 Replies
 
Don77
 
  1  
Reply Wed 12 Jan, 2005 06:39 pm
The only thing showing in the RAV scan is infected e-mails, you should clean them out, But aside from that all the other logs are not showing anything
0 Replies
 
Kedge
 
  1  
Reply Thu 13 Jan, 2005 12:47 am
Cheers Don.

What about the Logon.Exe which has been altered? How can I get the original one back?

If I copy Logon.Exe from my laptop will that work?
0 Replies
 
 

Related Topics

Clone of Micosoft Office - Question by Advocate
Do You Turn Off Your Computer at Night? - Discussion by Phoenix32890
The "Death" of the Computer Mouse - Discussion by Phoenix32890
Windows 10... - Discussion by Region Philbis
Surface Pro 3: What do you think? - Question by neologist
Windows 8 tips thread - Discussion by Wilso
GOOGLE CHROME - Question by Setanta
.Net and Firefox... - Discussion by gungasnake
Hacking a computer and remote access - Discussion by trying2learn
 
  1. Forums
  2. » Golon-A Trojan
Copyright © 2024 MadLab, LLC :: Terms of Service :: Privacy Policy :: Page generated in 0.04 seconds on 05/02/2024 at 10:00:08