nhatquanglan virus
When do you get infected?
When u put ur USB drive into some publicly accessed comp and then put it into urs!... similar to the way AIDS is transmitted!
How do you know you'v got infected?
Folder option goes missing
Taskmanager is diabled
Regedit is disabled
On ur flash drive every folder has another folder created by 'nhatquagalan'
What to do?
http://piyushlabs.wordpress.com/nhatquanglan-new-folder-svchost/
In case u get a 'framedyn.dll' missing error while running the 'heal' file, add the Path variable '%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\wbem' in the System Properties.
More on this
Run the Heal and sit and pray! :)
In my case i ran TrendMicro to delete the virus... unfortunately ... trend killed the virus but did not enable regedit, folder options & task manager. I had to run Heal to fix these... still the Folders Option was disabled.
To remove any other left-over side-effects.... directly run the registry enteries as given on piyushlab's website.... happy de-virusing!
When u put ur USB drive into some publicly accessed comp and then put it into urs!... similar to the way AIDS is transmitted!
How do you know you'v got infected?
Folder option goes missing
Taskmanager is diabled
Regedit is disabled
On ur flash drive every folder has another folder created by 'nhatquagalan'
What to do?
http://piyushlabs.wordpress.com/nhatquanglan-new-folder-svchost/
In case u get a 'framedyn.dll' missing error while running the 'heal' file, add the Path variable '%SystemRoot%\system32;%SystemRoot%;%SystemRoot%\System32\wbem' in the System Properties.
Run the Heal and sit and pray! :)
In my case i ran TrendMicro to delete the virus... unfortunately ... trend killed the virus but did not enable regedit, folder options & task manager. I had to run Heal to fix these... still the Folders Option was disabled.
To remove any other left-over side-effects.... directly run the registry enteries as given on piyushlab's website.... happy de-virusing!





