Forum     

Go Back   Digit Technology Discussion Forum > Software > Software Q&A
Register FAQ Calendar Mark Forums Read

Software Q&A Having trouble with software? Find solutions here


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 05-02-2008, 02:27 PM   #1 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2007
Posts: 37
Thumbs down Funny UST Scandal Virus


Friends,

Can any one tell how to remove this virus....................It doesnot goes even after Reinstalling Windows..........
me_ankitroy is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 05-02-2008, 02:40 PM   #2 (permalink)
Wise Old Owl
 
hullap's Avatar
 
Join Date: Dec 2006
Location: delhi
Posts: 1,429
Default Re: Funny UST Scandal Virus

http://4paisa.blogspot.com/2007/12/f...dal-virus.html
hullap is offline  
Old 05-02-2008, 02:47 PM   #3 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

Yeah, this one is going popular I guess!
Neways, the fix is simple! The virus simply copies 3 files in ALL THE PARTITIONS and then when u reinstall windows, it simply auto executes from the files copied to different drives/partitions.

Fix : U need to get those files removed FROM ALL THE PARTITIONS.

Files : 'smss.exe', 'Funny UST scandal.avi.exe', 'autorun.inf' (in all the partitions) and then 'killer.exe', 'net.exe', 'net1.exe' AFAIK in c:\windows\system32

U can search for where the last 3 files exist.

Probably, u won't be able to delete those files as the explorer closes if u open task manager, run anti-infection-ware or try to access those files.

So, the best way is to get a knoppix cd, and delete these files manually and may be then do a reformat+reinstall as a last option!!
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 05-02-2008, 03:40 PM   #4 (permalink)
dá ûnrêäl Kiñg
 
zyberboy's Avatar
 
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
Default Re: Funny UST Scandal Virus

download kav 6 trial version and do a scan after update http://www.kaspersky.com/
i hav done the same in one of my friends computer,kav detects it.
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
zyberboy is offline  
Old 05-02-2008, 03:56 PM   #5 (permalink)
damn busy...
 
utsav's Avatar
 
Join Date: Sep 2006
Location: Jhansi/Meerut
Posts: 1,990
Default Re: Funny UST Scandal Virus

There is a thread in tut section to remove this virus
__________________
MSI GX660 with ATI 5870 :grin: ultimate gaming lappy :grin:
Dell Studio 15(1555)
1TB+1.5TB external|N86|ZTE Blade|5230|E63|EP-630|Soundmagic PL50|Sennheiser CXL 400|Meelec M11P+
www.techjunkiez.com
utsav is offline  
Old 05-02-2008, 04:35 PM   #6 (permalink)
vaibhavtek
Guest
 
Posts: n/a
Default Re: Funny UST Scandal Virus

just move here
 
Old 05-02-2008, 06:44 PM   #7 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

Even my PC is got infected with this virus and it's giving lot of trouble to me. I'm going to check the resolution provided by Abhishek in the posts!
ajayritik is offline  
Old 05-02-2008, 07:09 PM   #8 (permalink)
vaibhavtek
Guest
 
Posts: n/a
Default Re: Funny UST Scandal Virus

I never founded Funny UST Scandal Virus in my pc..!!!

@ajayritik btw How do u got that Funny UST Scandal Virus
 
Old 05-02-2008, 07:13 PM   #9 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

Damn, I cud have emailed it to u. Cleaned mah PC, just a week ago!!
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 05-02-2008, 10:40 PM   #10 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

mediator can you email the process to me at my address. You can leave a PM of email address I will mail then you can send me a reply. Vaibhav I connected my friend's iPod to my PC which had that virus.
ajayritik is offline  
Old 05-02-2008, 11:03 PM   #11 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

The process is the same! What I did was
1. Fired up knoppix 5.1 (Linux distro) and deleted the files I mentioned
2. Formatted the C: drive and installed a clean copy of windows on it.

This one is a nasty virus. But wth, I was about to reformat/reinstall anyways as the windows was working slow again these days.
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 05-02-2008, 11:13 PM   #12 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

mediator thanks for the info! I don't have the knoppix cd with me. Any other work around for it. Is it really necessary for me to format the C: I was thinking if i can do without reinstalling and formatting C: I found the virus in other drives also do you think I need to format other drives as well. I have lot of data in other drives. I hope I dont have to format the other drives. Where can I get the knoppix CD?
ajayritik is offline  
Old 05-02-2008, 11:27 PM   #13 (permalink)
damn busy...
 
utsav's Avatar
 
Join Date: Sep 2006
Location: Jhansi/Meerut
Posts: 1,990
Default Re: Funny UST Scandal Virus

Either download it or get it frm me
__________________
MSI GX660 with ATI 5870 :grin: ultimate gaming lappy :grin:
Dell Studio 15(1555)
1TB+1.5TB external|N86|ZTE Blade|5230|E63|EP-630|Soundmagic PL50|Sennheiser CXL 400|Meelec M11P+
www.techjunkiez.com
utsav is offline  
Old 05-02-2008, 11:33 PM   #14 (permalink)
Wise Old Owl
 
dOm1naTOr's Avatar
 
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
Default Re: Funny UST Scandal Virus

I think ive a copy of this funny UST SCandal virus on ma Phone W 700i which got copied into it due to autorun. Ive removed it from PC but its still there on ma phone. Nd i havnt plugged it again
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
dOm1naTOr is offline  
Old 05-02-2008, 11:35 PM   #15 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

Nah, u don't necessarily need knoppix CD. But having one can be more useful than u can think of. It can save u when ur Hardisk has gone nuts and refusing to boot or windows not showing its face. U can do word/presentations quickly, backup data and much more. Its a complete OS on a CD.

But even if u have recent DIGIT cds, then also Ubuntu can back up the data and help u delete those files.

But neways, u don't have to format!! U asked what I did, so I told. U only have to delete the files I mentioned and thats upto u whicheva way its convenient 4 u to delete em.

In 2nd post there is a link which doesn't mention all the files I did, bt mentions some additional files. U can delete all these files which I mentioned+the link one.

I think u shud give a try to windows 98 startup floppy if u don't have knoppix and then delete those nasty files.

But I wud really suggest knoppix to anyone who does thorough maintenence of his PC. Just check it out, its around 700 Mb download ( ISO file )and u have to burn it on a CD and then boot from CDROM.
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 06-02-2008, 12:05 AM   #16 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

mediator I have the latest kubuntu CD with me. Do you think that can help me in anyway? I'm trying to download the Knoppix. What is the exact procedure that I should follow if I have the Knoppix CD with me or if I have the kubuntu cd?
ajayritik is offline  
Old 06-02-2008, 12:16 AM   #17 (permalink)
Wise Old Owl
 
dOm1naTOr's Avatar
 
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
Default Re: Funny UST Scandal Virus

Just use the live CD to boot into in nd u can clearly see those files in respective locations . U just delete those nd do a clean install of XP after formating the current one.
Me too once removed this funny thing using a LIVE windows disc nd a clean reinstall after a format of c.
It wont work if u dun format the current windows as the virs will get back from some system files[inside system 32 i think-nd the file name is different inside that].
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
dOm1naTOr is offline  
Old 06-02-2008, 07:36 AM   #18 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

What is Live CD?
ajayritik is offline  
Old 06-02-2008, 08:02 AM   #19 (permalink)
dá ûnrêäl Kiñg
 
zyberboy's Avatar
 
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
Default Re: Funny UST Scandal Virus

^^ http://www.nu2.nu/pebuilder/
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
zyberboy is offline  
Old 06-02-2008, 09:03 AM   #20 (permalink)
left this forum longback
 
praka123's Avatar
 
Join Date: Sep 2005
Location: -
Posts: 7,536
Smile Re: Funny UST Scandal Virus

Quote:
Originally Posted by ajayritik View Post
What is Live CD?
basically,livecd's are GNU/Linux CD's/DVD's which can boot from CD and run the Linux OS from CD instead of hdd.
http://en.wikipedia.org/wiki/LiveCD

even live usb's are there
http://en.wikipedia.org/wiki/Live_USB

now so called win live-cd's are there.but they cant come near Linux livecd's when it comes to immunity as win viruses cant do anything in Linux
__________________
left this forum long back.Admin Can Delete this Account and posts Permanantly.Thank You
Get GNU/Linux - http://getgnulinux.org
praka123 is offline  
Old 06-02-2008, 09:22 AM   #21 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

Thanks for the info praka! I have Kubuntu CD with me do you think that will server the purpose? Can you suggest me how I can remove this virus using kubuntu software?
ajayritik is offline  
Old 06-02-2008, 12:00 PM   #22 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

I dunno abt Kubuntu, bt I guess it shud do. If u r downloading Knoppix then let it download as well.
1. Download the ISO file
2. Burn that image to a CD
3. Boot from that CD
4. "Search and destroy" the mentioned files.
5. Boot with XP CD
6. Reformat C:, Install Xp!!
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 06-02-2008, 01:38 PM   #23 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

Right now I'm downloading Knoppix. But I wanted to know how
I could do the step 4 that you have mentioned. Do I have to use any application to search the files? Thanks!
ajayritik is offline  
Old 06-02-2008, 01:44 PM   #24 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

Nope! I guess u r thinking linux is difficult. But neways, u don't need to search also. The files smss,UST scandal,autorun etc reside in the roots of the partitions like in c:\,d:\,e:\. I have mentioned about all.
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 06-02-2008, 04:03 PM   #25 (permalink)
String Phreak
 
mediator's Avatar
 
Join Date: Mar 2005
Location: In ur Evil Mind!
Posts: 2,457
Default Re: Funny UST Scandal Virus

I wonder y others didn't post this before!
Funny UST Scandal.avi Virus---Tutorial
__________________
Bad Bad server.....No candy for u!
mediator is offline  
Old 06-02-2008, 06:27 PM   #26 (permalink)
Wise Old Owl
 
dOm1naTOr's Avatar
 
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
Default Re: Funny UST Scandal Virus

there are fixes for this file nd the hack just stops the service of this virus....nd u can manually delete them from within windows itself, but it will not be removed from windows system32 folder. So after that do a format nd clean install of XP wud do the job...
DO u want that fix?
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
dOm1naTOr is offline  
Old 06-02-2008, 09:25 PM   #27 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

Sure I want the fix can you provide it to me?
ajayritik is offline  
Old 06-02-2008, 09:49 PM   #28 (permalink)
Wise Old Owl
 
dOm1naTOr's Avatar
 
Join Date: Mar 2005
Location: shhhh!!!!! on a sniper point
Posts: 4,200
Default Re: Funny UST Scandal Virus

http://www.mediafire.com/?1mhfm5wynha
__________________
G1: PII X4 B50 4.0 | TRUE 120*2 | TA790GXB A2+ | 4GB DDR2 GSkill 1200 | Audigy 2 | HD4870 | HEC 550 | MX 518.
G2: AII 240 | M2N 68AM+ | 3GB| 8800GT | Zebby Plat 500
G3: XPS M1530 |
FZ 16.
dOm1naTOr is offline  
Old 07-02-2008, 09:32 AM   #29 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal Virus

I ran the Kubuntu Live Cd but I dont know how I can access the files or how can I delete them. there are things like /etc /bin. The interface is not like Windows Explorer or command prompt. How do I locate the file? Do we have any application in kubuntu which resembles like command prompt. I think I have to figure it out which folder or directory I have to access. Is there anythhing called mount thing necessary here? Can I get Knopixx from Digit CD?
ajayritik is offline  
Old 07-02-2008, 11:43 AM   #30 (permalink)
Jai Suresh
 
lywyre's Avatar
 
Join Date: Aug 2004
Location: Vellore, TN
Posts: 580
Default Re: Funny UST Scandal Virus

Some times, it takes time for our favourite AV company to find a cure for the damnest latest virus. In the mean time we will be suffering with our super secure Windows XP with Service Pack 2.

But most of the virus has some characteristics. First, they are files like any others and executables like many others. Two, they need to be run/triggered or they need any host to run like a parasite (like running under explorer.exe) or they may camouflage themselves as some other windows programs/services (svchost.exe, spoolsv.exe, smss.exe, csrss.exe). And most of them are have system attribute from being detected in the explorer. And yes, they disable/screw up folder options so that we don't see them any way. And lastly they all steal data and they all mass mail themselves to email ids they harvest from our systems.

Most of them can be removed by us manually. It would be time consuming, frustrating and irritating. But they can be removed. Most common places they reside are: %WINDIR%, %WINDIR%/system32, %TEMP%, My Documents, root of the drives. Some are triggered by opening the folder (Autorun.exe), custom script of the directory (desktop.ini) or by double clicking (like having the icon of an image file).

Most of us have forgot the lame, useless, complex (and what not) command line. Truth is, command line is more powerful, smart and effective than the gui. With combination of certain free tools, we can remove most virii/trojans using command line.

Tools required: ProcessExplorer and Autoruns from Sysinternals.com (now Microsoft) and cmd.
http://technet.microsoft.com/hi-in/s...lt(en-us).aspx

Run process explorer and endtask explorer.exe, and virii/trojans that run under it. Warning: donot end any task that run under 'Services', unless you know what your are doing. It is better to close any IE windows too. Need not worry about firefox/opera. Don't close ProcessExplorer yet. If your task manager is disabled you cannot start explorer again.

From the menu choose 'Run' and run 'Autoruns.exe' from where you have saved. This will list all the programs that run during startup. Note down the locations of malware and navigate to that location in the command window and delete the file. The file may be marked system, in that case, the attrib can be changed using the command '\>attrib -s -h -r filename.ext'. Delete all the autorun.inf files from the root directories. Now delete all the malware entries in Autoruns.exe. Now start the explorer again using "Run" in ProcessExplorer.

This can be effective against most malware that spread through portable storage devices and I use this method to remove Semo.exe, amvo.exe, d.com and some other malware that get into my system. Hope avast finds this soon.

Last edited by lywyre; 07-02-2008 at 11:50 AM.
lywyre is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


Similar Threads
Thread Thread Starter Forum Replies Last Post
Funny UST Scandal.avi Virus---Tutorial Abhishek Dwivedi Tutorials 25 31-03-2008 01:06 PM
about a virus which attacked me,need guidence and giving info abt this virus-read mobileman Software Q&A 2 16-11-2007 12:43 PM
Virus problem, need online virus checking details-pls hava a read here. mobileman Software Q&A 2 14-04-2007 10:58 AM
mcafee virus scan 8.0 - problem updating virus definations infra_red_dude Software Q&A 3 26-06-2005 11:43 AM
VIRUS...RANDEX ZEN.......VIRUS MLORE HELP..??URGENT Writankar panja Software Q&A 9 19-09-2004 05:26 PM

 
Latest Threads
- by chris
- by abhidev
- by clmlbx

Advertisement




All times are GMT +5.5. The time now is 05:09 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2