 |
|
05-02-2008, 02:27 PM
|
#1 (permalink)
|
|
Right Off the Assembly Line
Join Date: Mar 2007
Posts: 37
|
Funny UST Scandal Virus
 Friends,
Can any one tell how to remove this virus....................It doesnot goes even after Reinstalling Windows..........
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
05-02-2008, 02:40 PM
|
#2 (permalink)
|
|
Wise Old Owl
Join Date: Dec 2006
Location: delhi
Posts: 1,429
|
Re: Funny UST Scandal Virus
|
|
|
05-02-2008, 02:47 PM
|
#3 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
Yeah, this one is going popular I guess!
Neways, the fix is simple! The virus simply copies 3 files in ALL THE PARTITIONS and then when u reinstall windows, it simply auto executes from the files copied to different drives/partitions.
Fix : U need to get those files removed FROM ALL THE PARTITIONS.
Files : 'smss.exe', 'Funny UST scandal.avi.exe', 'autorun.inf' (in all the partitions) and then 'killer.exe', 'net.exe', 'net1.exe' AFAIK in c:\windows\system32
U can search for where the last 3 files exist.
Probably, u won't be able to delete those files as the explorer closes if u open task manager, run anti-infection-ware or try to access those files.
So, the best way is to get a knoppix cd, and delete these files manually and may be then do a reformat+reinstall as a last option!!
__________________
Bad Bad server.....No candy for u!
|
|
|
05-02-2008, 03:40 PM
|
#4 (permalink)
|
|
dá ûnrêäl Kiñg
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
|
Re: Funny UST Scandal Virus
download kav 6 trial version and do a scan after update http://www.kaspersky.com/
i hav done the same in one of my friends computer,kav detects it.
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
|
|
|
05-02-2008, 03:56 PM
|
#5 (permalink)
|
|
damn busy...
Join Date: Sep 2006
Location: Jhansi/Meerut
Posts: 1,990
|
Re: Funny UST Scandal Virus
There is a thread in tut section to remove this virus
__________________
MSI GX660 with ATI 5870 :grin: ultimate gaming lappy :grin:
Dell Studio 15(1555)
1TB+1.5TB external|N86|ZTE Blade|5230|E63|EP-630|Soundmagic PL50|Sennheiser CXL 400|Meelec M11P+
www.techjunkiez.com
|
|
|
05-02-2008, 04:35 PM
|
#6 (permalink)
|
|
Guest
|
Re: Funny UST Scandal Virus
|
|
|
|
05-02-2008, 06:44 PM
|
#7 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
Even my PC is got infected with this virus and it's giving lot of trouble to me. I'm going to check the resolution provided by Abhishek in the posts!
|
|
|
05-02-2008, 07:09 PM
|
#8 (permalink)
|
|
Guest
|
Re: Funny UST Scandal Virus
I never founded Funny UST Scandal Virus in my pc..!!!
@ajayritik btw How do u got that Funny UST Scandal Virus
|
|
|
|
05-02-2008, 07:13 PM
|
#9 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
Damn, I cud have emailed it to u. Cleaned mah PC, just a week ago!!
__________________
Bad Bad server.....No candy for u!
|
|
|
05-02-2008, 10:40 PM
|
#10 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
mediator can you email the process to me at my address. You can leave a PM of email address I will mail then you can send me a reply. Vaibhav I connected my friend's iPod to my PC which had that virus.
|
|
|
05-02-2008, 11:03 PM
|
#11 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
The process is the same! What I did was
1. Fired up knoppix 5.1 (Linux distro) and deleted the files I mentioned
2. Formatted the C: drive and installed a clean copy of windows on it.
This one is a nasty virus. But wth, I was about to reformat/reinstall anyways as the windows was working slow again these days.
__________________
Bad Bad server.....No candy for u!
|
|
|
05-02-2008, 11:13 PM
|
#12 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
mediator thanks for the info! I don't have the knoppix cd with me. Any other work around for it. Is it really necessary for me to format the C: I was thinking if i can do without reinstalling and formatting C: I found the virus in other drives also do you think I need to format other drives as well. I have lot of data in other drives. I hope I dont have to format the other drives. Where can I get the knoppix CD?
|
|
|
05-02-2008, 11:27 PM
|
#13 (permalink)
|
|
damn busy...
Join Date: Sep 2006
Location: Jhansi/Meerut
Posts: 1,990
|
Re: Funny UST Scandal Virus
Either download it or get it frm me
__________________
MSI GX660 with ATI 5870 :grin: ultimate gaming lappy :grin:
Dell Studio 15(1555)
1TB+1.5TB external|N86|ZTE Blade|5230|E63|EP-630|Soundmagic PL50|Sennheiser CXL 400|Meelec M11P+
www.techjunkiez.com
|
|
|
05-02-2008, 11:33 PM
|
#14 (permalink)
|
|
Wise Old Owl
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
|
Re: Funny UST Scandal Virus
I think ive a copy of this funny UST SCandal virus on ma Phone W 700i which got copied into it due to autorun. Ive removed it from PC but its still there on ma phone. Nd i havnt plugged it again
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
|
|
|
05-02-2008, 11:35 PM
|
#15 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
Nah, u don't necessarily need knoppix CD. But having one can be more useful than u can think of. It can save u when ur Hardisk has gone nuts and refusing to boot or windows not showing its face. U can do word/presentations quickly, backup data and much more. Its a complete OS on a CD.
But even if u have recent DIGIT cds, then also Ubuntu can back up the data and help u delete those files.
But neways, u don't have to format!! U asked what I did, so I told. U only have to delete the files I mentioned and thats upto u whicheva way its convenient 4 u to delete em.
In 2nd post there is a link which doesn't mention all the files I did, bt mentions some additional files. U can delete all these files which I mentioned+the link one.
I think u shud give a try to windows 98 startup floppy if u don't have knoppix and then delete those nasty files.
But I wud really suggest knoppix to anyone who does thorough maintenence of his PC. Just check it out, its around 700 Mb download ( ISO file )and u have to burn it on a CD and then boot from CDROM.
__________________
Bad Bad server.....No candy for u!
|
|
|
06-02-2008, 12:05 AM
|
#16 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
mediator I have the latest kubuntu CD with me. Do you think that can help me in anyway? I'm trying to download the Knoppix. What is the exact procedure that I should follow if I have the Knoppix CD with me or if I have the kubuntu cd?
|
|
|
06-02-2008, 12:16 AM
|
#17 (permalink)
|
|
Wise Old Owl
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
|
Re: Funny UST Scandal Virus
Just use the live CD to boot into in nd u can clearly see those files in respective locations . U just delete those nd do a clean install of XP after formating the current one.
Me too once removed this funny thing using a LIVE windows disc nd a clean reinstall after a format of c.
It wont work if u dun format the current windows as the virs will get back from some system files[inside system 32 i think-nd the file name is different inside that].
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
|
|
|
06-02-2008, 07:36 AM
|
#18 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
What is Live CD?
|
|
|
06-02-2008, 08:02 AM
|
#19 (permalink)
|
|
dá ûnrêäl Kiñg
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
|
Re: Funny UST Scandal Virus
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
|
|
|
06-02-2008, 09:03 AM
|
#20 (permalink)
|
|
left this forum longback
Join Date: Sep 2005
Location: -
Posts: 7,536
|
Re: Funny UST Scandal Virus
Quote:
Originally Posted by ajayritik
What is Live CD?
|
basically,livecd's are GNU/Linux CD's/DVD's which can boot from CD and run the Linux OS from CD instead of hdd.
http://en.wikipedia.org/wiki/LiveCD
even live usb's are there
http://en.wikipedia.org/wiki/Live_USB
now so called win live-cd's are there.but they cant come near Linux livecd's when it comes to immunity as win viruses cant do anything in Linux
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
|
|
|
06-02-2008, 09:22 AM
|
#21 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
Thanks for the info praka! I have Kubuntu CD with me do you think that will server the purpose? Can you suggest me how I can remove this virus using kubuntu software?
|
|
|
06-02-2008, 12:00 PM
|
#22 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
I dunno abt Kubuntu, bt I guess it shud do. If u r downloading Knoppix then let it download as well.
1. Download the ISO file
2. Burn that image to a CD
3. Boot from that CD
4. "Search and destroy" the mentioned files.
5. Boot with XP CD
6. Reformat C:, Install Xp!!
__________________
Bad Bad server.....No candy for u!
|
|
|
06-02-2008, 01:38 PM
|
#23 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
Right now I'm downloading Knoppix. But I wanted to know how
I could do the step 4 that you have mentioned. Do I have to use any application to search the files? Thanks!
|
|
|
06-02-2008, 01:44 PM
|
#24 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
Nope! I guess u r thinking linux is difficult. But neways, u don't need to search also. The files smss,UST scandal,autorun etc reside in the roots of the partitions like in c:\,d:\,e:\. I have mentioned about all.
__________________
Bad Bad server.....No candy for u!
|
|
|
06-02-2008, 04:03 PM
|
#25 (permalink)
|
|
String Phreak
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
|
Re: Funny UST Scandal Virus
I wonder y others didn't post this before!
Funny UST Scandal.avi Virus---Tutorial
__________________
Bad Bad server.....No candy for u!
|
|
|
06-02-2008, 06:27 PM
|
#26 (permalink)
|
|
Wise Old Owl
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
|
Re: Funny UST Scandal Virus
there are fixes for this file nd the hack just stops the service of this virus....nd u can manually delete them from within windows itself, but it will not be removed from windows system32 folder. So after that do a format nd clean install of XP wud do the job...
DO u want that fix?
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
|
|
|
06-02-2008, 09:25 PM
|
#27 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
Sure I want the fix can you provide it to me?
|
|
|
06-02-2008, 09:49 PM
|
#28 (permalink)
|
|
Wise Old Owl
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
|
Re: Funny UST Scandal Virus
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
|
|
|
07-02-2008, 09:32 AM
|
#29 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal Virus
I ran the Kubuntu Live Cd but I dont know how I can access the files or how can I delete them. there are things like /etc /bin. The interface is not like Windows Explorer or command prompt. How do I locate the file? Do we have any application in kubuntu which resembles like command prompt. I think I have to figure it out which folder or directory I have to access. Is there anythhing called mount thing necessary here? Can I get Knopixx from Digit CD?
|
|
|
07-02-2008, 11:43 AM
|
#30 (permalink)
|
|
Jai Suresh
Join Date: Aug 2004
Location: Vellore, TN
Posts: 580
|
Re: Funny UST Scandal Virus
Some times, it takes time for our favourite AV company to find a cure for the damnest latest virus. In the mean time we will be suffering with our super secure Windows XP with Service Pack 2.
But most of the virus has some characteristics. First, they are files like any others and executables like many others. Two, they need to be run/triggered or they need any host to run like a parasite (like running under explorer.exe) or they may camouflage themselves as some other windows programs/services (svchost.exe, spoolsv.exe, smss.exe, csrss.exe). And most of them are have system attribute from being detected in the explorer. And yes, they disable/screw up folder options so that we don't see them any way. And lastly they all steal data and they all mass mail themselves to email ids they harvest from our systems.
Most of them can be removed by us manually. It would be time consuming, frustrating and irritating. But they can be removed. Most common places they reside are: %WINDIR%, %WINDIR%/system32, %TEMP%, My Documents, root of the drives. Some are triggered by opening the folder (Autorun.exe), custom script of the directory (desktop.ini) or by double clicking (like having the icon of an image file).
Most of us have forgot the lame, useless, complex (and what not) command line. Truth is, command line is more powerful, smart and effective than the gui. With combination of certain free tools, we can remove most virii/trojans using command line.
Tools required: ProcessExplorer and Autoruns from Sysinternals.com (now Microsoft) and cmd.
http://technet.microsoft.com/hi-in/s...lt(en-us).aspx
Run process explorer and endtask explorer.exe, and virii/trojans that run under it. Warning: donot end any task that run under 'Services', unless you know what your are doing. It is better to close any IE windows too. Need not worry about firefox/opera. Don't close ProcessExplorer yet. If your task manager is disabled you cannot start explorer again.
From the menu choose 'Run' and run 'Autoruns.exe' from where you have saved. This will list all the programs that run during startup. Note down the locations of malware and navigate to that location in the command window and delete the file. The file may be marked system, in that case, the attrib can be changed using the command '\>attrib -s -h -r filename.ext'. Delete all the autorun.inf files from the root directories. Now delete all the malware entries in Autoruns.exe. Now start the explorer again using "Run" in ProcessExplorer.
This can be effective against most malware that spread through portable storage devices and I use this method to remove Semo.exe, amvo.exe, d.com and some other malware that get into my system. Hope avast finds this soon.
Last edited by lywyre; 07-02-2008 at 11:50 AM.
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
|
|
|