This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

[Resolved] Need help with Nhatquanglan Virus.

3 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

3 of my usb flash drives were infected with this virus.. I think I managed to get rid of the virus but I can`t open my usb flash drives anymore, there just comes a windows like this when trying to open it: LINK ( the language is finnish, but I guess youll get the idea.)

I have tried taking advices from this topic which i found in these forums, LINK

When I use the Flash Disinfector, the usb flash drives work fine for as long as the usb flash drive is inserted. But when I remove it and pluck it in again, there just comes the window which I earlier described.
Hi! Welcome to the WTT forums.
My name is Scotty. I would be glad to take a look at your log and help you with solving any malware problems. HijackThis logs can take a while to research.
Please be patient.

Download Deckard's System Scanner (DSS) to your Desktop. Note: You must be logged onto an account with administrator privileges.
  • Close all applications and windows.
  • Double-click on dss.exe to run it, and follow the prompts.
  • When the scan is complete, two text files will open - main.txt <- this one will be maximized and extra.txt<-this one will be minimized
  • Copy (Ctrl+A then Ctrl+C) and paste (Ctrl+V) the contents of main.txt and the extra.txt in your next reply
Thank you for your reply. I think I managed to fix my usb flash drives, by simply formating them, and probably getting rid of the virus taking advices from the topic which was similar to this. So I think this will mostly be "just making sure".

I did what you told, and here`s what I got:

MAIN:

Deckard's System Scanner v20071014.68
Run by [removed] on 2007-12-30 02:26:15
Computer is in Normal Mode.
——————————————————————————–

– System Restore ————————————————————–

Successfully created a Deckard's System Scanner Restore Point.


– Last 5 Restore Point(s) –
12: 2007-12-30 00:26:28 UTC - RP12 - Deckard's System Scanner Restore Point
11: 2007-12-30 00:16:01 UTC - RP11 - Software Distribution Service 3.0
10: 2007-12-30 00:14:41 UTC - RP10 - Asennettiin Windows Internet Explorer 7.
9: 2007-12-30 00:14:19 UTC - RP9 - Installed Windows IDNMitigationAPIs.
8: 2007-12-30 00:13:40 UTC - RP8 - Installed Windows NLSDownlevelMapping.


– First Restore Point –
1: 2007-12-29 18:49:47 UTC - RP1 - Järjestelmän tarkistuspiste


Backed up registry hives.
Performed disk cleanup.

Total Physical Memory: 256 MiB (512 MiB recommended).


– HijackThis Clone ————————————————————


Emulating logfile of Trend Micro HijackThis v2.0.2
Scan saved at 2007-12-30 02:28:08
Platform: Windows XP Service Pack 2 (5.01.2600)
MSIE: Internet Explorer (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\system32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\nvsvc32.exe
C:\WINDOWS\system32\slserv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\explorer.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\WINDOWS\system32\LVCOMSX.EXE
C:\Program Files\Logitech\Video\LogiTray.exe
C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe
C:\Program Files\Adobe\Reader 8.0\Reader\Reader_SL.exe
C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Logitech\Video\FxSvr2.exe
C:\Documents and Settings\Patrick\Työpöytä\dss.exe
C:\Program Files\Mozilla Firefox\firefox.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Linkit
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaul…rch/search.html
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Liven kirjautumisapuohjelma - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [LVCOMSX] C:\WINDOWS\system32\LVCOMSX.EXE
O4 - HKLM\..\Run: [LogitechVideoRepair] C:\Program Files\Logitech\Video\ISStart.exe
O4 - HKLM\..\Run: [LogitechVideoTray] C:\Program Files\Logitech\Video\LogiTray.exe
O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [IMJPMIG8.1] "C:\WINDOWS\IME\imjp8_1\IMJPMIG.EXE" /Spoil /RemAdvDef /Migration32
O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNC
O4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNC
O4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMEName
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\System32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Run: [Nokia.PCSync] "C:\Program Files\Nokia\Nokia PC Suite 6\PcSync2.exe" /NoDialog (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O8 - Extra context menu item: E&xport; to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: (no name) - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - (file missing)
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\network diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/…b?1182113368531
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftu…b?1183076159937
O16 - DPF: {8FFBE65D-2C9C-4669-84BD-5829DC0B603C} () - http://fpdownload.macromedia.com/get/flash…t/ultrashim.cab
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: ms-help - {314111c7-a502-11d2-bbca-00c04f8ec294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\Program Files\Windows Live\Messenger\msgrapp.8.5.1302.1018.dll
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\Program Files\Common Files\Skype\Skype4COM.dll
O18 - Filter: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE12\MSOXMLMF.DLL
O21 - SSODL: CDBurn - {fbeb8a05-beee-4442-804e-409d6c4515e9} - (no file)
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe
O23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exe
O23 - Service: SmartLinkService (SLService) - Unknown owner - C:\WINDOWS\system32\slserv.exe


–
End of file - 7318 bytes

– File Associations ———————————————————–

All associations okay.


– Drivers: 0-Boot, 1-System, 2-Auto, 3-Demand, 4-Disabled ———————

R1 StarOpen - c:\windows\system32\drivers\staropen.sys
R3 pfc (Padus ASPI Shell) - c:\windows\system32\drivers\pfc.sys
Hi

It does look ok. Let's just run a scan to be sure.

  • Please go HERE to run PandaActiveScan…

  • Once you are on the Panda site click the Scan your PC button
  • A new window will open…click the Check Now button
  • Enter your Country
  • Enter your State/Province
  • Enter your e-mail address and click send
  • Select either Home User or Company
  • Click the big Scan Now button
  • If it wants to install an ActiveX component allow it
  • It will start downloading the files it requires for the scan (Note: It may take a couple of minutes)

  • When download is complete, click on My Computer to start the scan
  • When the scan completes, if anything malicious is detected, click the See Report button, then Save Report and save it to your desktop.Then post it in your next reply.

Once you have installed the scanner and all the updates, you can disconnect from the Internet and disable your anti-virus, to reduce scanning time.
Thank you. Here are the results: Incident Status Location Possible Virus. Not disinfected C:\$CTJTMP\WIZARD.EXE Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Jorma\Application Data\Mozilla\Firefox\Profiles\jj4dyst2.default\cookies.txt[.advertising.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Jorma\Application Data\Mozilla\Firefox\Profiles\jj4dyst2.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Jorma\Application Data\Mozilla\Firefox\Profiles\jj4dyst2.default\cookies.txt[.adserver.easyad.info/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Jorma\Application Data\Mozilla\Firefox\Profiles\jj4dyst2.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.adserver.easyad.info/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.advertising.com/] Spyware:Cookie/Atlas DMT Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.atdmt.com/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.fastclick.net/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Karina\Application Data\Mozilla\Firefox\Profiles\jtl3rezd.default\cookies.txt[.tradedoubler.com/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.apmebf.com/] Spyware:Cookie/Com.com Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.com.com/] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Tribalfusion Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.tribalfusion.com/] Spyware:Cookie/BurstNet Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.burstnet.com/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.adserver.easyad.info/] Spyware:Cookie/bravenetA Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.bravenet.com/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[adserver.filefront.com/] Spyware:Cookie/Toplist Not disinfected C:\Documents and Settings\Patrick\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\cookies.txt[.toplist.cz/] Potentially unwanted tool:Application/NirCmd.A Not disinfected C:\Documents and Settings\Patrick\Local Settings\Application Data\Mozilla\Firefox\Profiles\gdfkuh59.default\Cache\426549C9d01[nircmd.exe] Spyware:Cookie/Doubleclick Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.doubleclick.net/] Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.tradedoubler.com/] Spyware:Cookie/Advertising Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.advertising.com/] Spyware:Cookie/Tradedoubler Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.tradedoubler.com/] Spyware:Cookie/YieldManager Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[ad.yieldmanager.com/] Spyware:Cookie/Adserver Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.adserver.easyad.info/] Spyware:Cookie/FastClick Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.fastclick.net/] Spyware:Cookie/Apmebf Not disinfected C:\Documents and Settings\Tess\Application Data\Mozilla\Firefox\Profiles\60mqixty.default\cookies.txt[.apmebf.com/]
Since this issue appears to be resolved … this Topic has been closed. Glad we could be of assistance. If you're the topic starter, and need this topic reopened, please contact a staff member with the address of the thread. Everyone else please begin a New Topic.

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI