 |
22-01-2008, 07:46 PM
|
#1 (permalink)
|
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Funny UST Scandal.avi Virus---Tutorial
Remove Funny UST Scandal.avi.exe (Vista and XP)
I came across many people (including me) who got infected by the Funny UST Scandal.avi virus. This tutorial guides you through the manual process of removing this Virus from Windows Vista and Windows XP systems.
Details:
1) This will block your Task Manager, Registry Editor and Command Prompt.
2) It hacks in your Yahoo Messenger and sends stupid and senseless messages to them and even a copy of itself. (ask gigacore if you don’t believe me!!! )
3) It will log your all key strokes and send them to an unknown email address through IM.
4) It slows down your system badly and reinstalling the OS will do no good.
5) It will disable the search and viewing of hidden files.
It’s built using AutoIt V3 virus programming software.--(source= some blog)
Windows XP:
This virus was made mainly to infect XP and Windows NT systems. In XP and NT systems, it makes the following files:
a) Killer.exe (4084 kb) in c:\windows\
b) lsass.exe (3920kb) in c:\documents and settings\all users\start menu\programs\startup
c) xmss.exe (4088kb) in all partitioned drives and in c:\windows
d) autorun.inf (1kb) in all partitioned drives with a script.
e) Funny UST Scandal.avi.exe in all partitions and Funny UST Scandal.exe in c:\Windows.
This Virus makes the following registry entries:
a) HKLM\Software\Microsoft\WindowNT\CurrentVersion\Wi nlogon
shell(killer.exe or xmss.exe)
b) HKCU\Software\Microsoft\windows\Currentversion\Run
Runonce(c:\windows\xmss.exe)
If the virus has completely installed itself, then you can find all these files in your system.
To remove this virus:
a) In order to removes the files, you’ll first have to stop the execution of this virus. To do so, download this file and run it.
b) Now open cmd.exe and go the above mentioned locations and unhide the files by typing: attrib –h –s Funny UST Scandal.exe for C:\windows and so on for all the other files in different locations. You might get an error while unhiding Funny UST Scandal.avi.exe which is placed in all partitions. If you get that error, just leave that file.
c) After unhiding all these files, delete them from your hard disk.
d) Download REPLACER and open it.
e) In the REPLACER type: c:\Funny UST Scandal.avi.exe and press enter. It will now ask you for another file. Create a text file named a.txt in C:\ and then type: c:\ a.txt and press enter. Press Y and press enter. Go to C: drive and there you’ll find 3 files named Funny UST Scandal.backup, Funny UST Scandal.exe and a Temp file. Delete them.
f) Repeat Step e) for all you partitions.
Windows Vista:
Files included:
a) xmss.exe (4088kb) in all partitioned drives and in c:\windows
b) autorun.inf (1kb) in all partitioned drives with a script.
c) Funny UST Scandal.avi.exe in all partitions and Funny UST Scandal.exe in c:\Windows.
Registry Entries:
a) HKLM\Software\Microsoft\WindowNT\CurrentVersion\Wi nlogon
shell(killer.exe or xmss.exe)
b) HKCU\Software\Microsoft\windows\Currentversion\Run
Runonce(c:\windows\xmss.exe)
The second key might no be present.
Removing the Virus:
To remove this virus:
a) In order to removes the files, you’ll first have to stop the execution of this virus. To do so, download this file and run it.
b) Now open cmd.exe and go the above mentioned locations and unhide the files by typing: attrib –h –s Funny UST Scandal.exe for C:\windows and so on for all the other files in different locations. You might get an error while unhiding Funny UST Scandal.avi.exe which is placed in all partitions. If you get that error, just leave that file.
c) After unhiding all these files, delete them from your hard disk.
d) Download REPLACER and open it.
e) In the REPLACER type: c:\Funny UST Scandal.avi.exe and press enter. It will now ask you for another file. Create a text file named a.txt in C:\ and then type: c:\ a.txt and press enter. Press Y and press enter. Go to C: drive and there you’ll find 3 files named Funny UST Scandal.backup, Funny UST Scandal.exe and a Temp file. Delete them.
f) Repeat Step e) for all you partitions.
As you can see that the procedure for both the OS is same just the files are different. I have tested the steps myself on Windows XP sp2 (my desktop), Windows Vista Home Basic (my lappy), Windows Vista Home Premium (my friends lappy) and Windows Vista Ultimate (my desktop).
Hope this guide is useful. Happy Removing…
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
|
|
|
|
Advertisements. Register and be a member of the community to get rid of them.
|
|
Advertisement
|
|
22-01-2008, 08:12 PM
|
#2 (permalink)
|
|
SivaChand
Join Date: Dec 2007
Location: TamilNadu
Posts: 108
|
Re: Funny UST Scandal.avi Virus---Tutorial
Good info.... But you pasted two times of removing method
__________________
Always look at what you have left.Never look at what you have lost
|
|
|
22-01-2008, 09:39 PM
|
#3 (permalink)
|
|
Guest
|
Re: Funny UST Scandal.avi Virus---Tutorial
thanks..
|
|
|
|
22-01-2008, 09:47 PM
|
#4 (permalink)
|
|
CG Artist
Join Date: May 2006
Location: New Delhi,India
Posts: 1,462
|
Re: Funny UST Scandal.avi Virus---Tutorial
I cant download that newfolderremoval.exe file
|
|
|
23-01-2008, 05:42 PM
|
#5 (permalink)
|
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Re: Funny UST Scandal.avi Virus---Tutorial
thx guys....i didn't double posted da steps...just reppeated den again for vista....
@gaurav: u moght not b able 2 DW da file as the virus migh b running on ur sys....try to terminate da XMSS.EXE file running as Admin. n den DWing...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
|
|
|
23-01-2008, 06:22 PM
|
#6 (permalink)
|
|
In The Zone
Join Date: Oct 2006
Location: Mumbai
Posts: 430
|
Re: Funny UST Scandal.avi Virus---Tutorial
nice tutorial. thanx
__________________
The statistics on sanity are that 1 out of every 4 humans is suffering from some form of mental illness:shock:
Think of your 3 best friends. If they are OK, then it's YOU:grin::grin::grin:
|
|
|
23-01-2008, 07:56 PM
|
#7 (permalink)
|
|
UBERGEEK
Join Date: Dec 2005
Location: Oxford of da east
Posts: 397
|
Re: Funny UST Scandal.avi Virus---Tutorial
Thanx a ton man...
my pc is infected with the same virus..
|
|
|
24-01-2008, 10:07 PM
|
#8 (permalink)
|
|
The Thread Killer >:)
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
|
Re: Funny UST Scandal.avi Virus---Tutorial
Very informative. Thanks
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
|
|
|
25-01-2008, 05:39 PM
|
#9 (permalink)
|
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Re: Funny UST Scandal.avi Virus---Tutorial
thx for da comment...hope it helped u all
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
|
|
|
05-02-2008, 10:33 AM
|
#10 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal.avi Virus---Tutorial
Thanks for the information. I have tried with couple of suggestions from the net but they didnt work. I will try your suggestion and see whether it helps. This Virus has created a menace.
If these steps have worked for anyone can they reply please. I'm having hell of trouble with it.
Last edited by ajayritik; 05-02-2008 at 10:33 AM.
Reason: Automerged Doublepost
|
|
|
05-02-2008, 05:37 PM
|
#11 (permalink)
|
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Re: Funny UST Scandal.avi Virus---Tutorial
it has wrkd for me...try it...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
|
|
|
05-02-2008, 05:48 PM
|
#12 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal.avi Virus---Tutorial
Abhishek the virus actually infected my PC through iPod. Do you know how we can remove it from the iPod?
|
|
|
05-02-2008, 05:56 PM
|
#13 (permalink)
|
|
UBERGEEK
Join Date: Dec 2005
Location: Oxford of da east
Posts: 397
|
Re: Funny UST Scandal.avi Virus---Tutorial
Quote:
Originally Posted by ajayritik
Abhishek the virus actually infected my PC through iPod. Do you know how we can remove it from the iPod?
|
If there's any provision of formatting ur player,,,do it,,,i did with my pendrive
and the file was wipedout,,,
And thanx topic-creator,,ur solution has worked 4 my pc,,,thanx a lot...!!!!
|
|
|
05-02-2008, 06:31 PM
|
#14 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal.avi Virus---Tutorial
Quote:
Originally Posted by PCWORM
If there's any provision of formatting ur player,,,do it,,,i did with my pendrive
and the file was wipedout,,,
And thanx topic-creator,,ur solution has worked 4 my pc,,,thanx a lot...!!!!
|
Hey I got confused when you were Thanking topic-creator I was actually searching for someone by that name in the posts but I think you were thanking Abhishek. I will try the steps given by Abhishek.
I heard somewhere that we should not format the iPod. We need to restore it. Since I'm not able to connect to the internet can I restore(format) the iPod using some software that I can download from my friend's PC. I have the CD that came with the iPod but that has an older version I think.
Last edited by ajayritik; 05-02-2008 at 06:31 PM.
Reason: Automerged Doublepost
|
|
|
05-02-2008, 11:57 PM
|
#15 (permalink)
|
|
C# Be Sharp !
Join Date: Jun 2006
Location: Toronto
Posts: 1,805
|
Re: Funny UST Scandal.avi Virus---Tutorial
Quote:
Originally Posted by Abhishek Dwivedi
It slows down your system badly and reinstalling the OS will do no good.
|
I have a doubt with this One .
How can Reinstalling the OS , NOT remove the virus ?
__________________
There are 10 types of people in the world: those who understand binary and those who do not.
|
|
|
06-02-2008, 12:11 AM
|
#16 (permalink)
|
|
dá ûnrêäl Kiñg
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
|
Re: Funny UST Scandal.avi Virus---Tutorial
^^becoz it easily gets infected again when opening other drives.
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
|
|
|
06-02-2008, 12:46 AM
|
#17 (permalink)
|
|
Šupər♂ - 超人
Join Date: Oct 2004
Location: Look up... up in da sky... see me yet? Nah... Use a telescope, dumbo!
Posts: 1,626
|
Re: Funny UST Scandal.avi Virus---Tutorial
=I never faced big prob from this harmless virus. all i do is Ctrl+alt+delete... close xmss.exe, funny....exe in task manager processes, "search"(incl hidden files) in the suspicious usb/drive for xmss, autorun.inf & funny terms and delete these 3 culprit files. Remove the usb & put it back into slot. Then it's as good as new !!!! No dos, no live cds...!!!
Never got that killer.exe.. in my drives at all!!! Now, why did that happen?
What i did is tried and tested... worked for all the drives/usb sticks my friend's got/brought...
__________________
Windows ka tashan... koolbluez ishtyle - http://lin.cr/ss
I almost forgot this - http://www.thinkdigit.com/forum/showthread.php?t=6242
|
|
|
06-02-2008, 09:24 AM
|
#18 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal.avi Virus---Tutorial
I was able to access my computer and other drives using the New Folder thing but I'm unable to use the attrib command to delete the files. Infact I can't locate these files.When I use Replacer to replace the file it gives Access denied message.
|
|
|
07-02-2008, 03:26 PM
|
#19 (permalink)
|
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Re: Funny UST Scandal.avi Virus---Tutorial
@ajayritk: which OS do u use...try booting up with Linux and searching all 2-4MB sized file with X,S,M,A,U,AUTORUN wrd in them and delete the one which are marked above...
also download ULBLOCKER and install it and unblock da files in which u get access denied
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
|
|
|
07-02-2008, 05:56 PM
|
#20 (permalink)
|
|
Wise Old Owl
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
|
Re: Funny UST Scandal.avi Virus---Tutorial
Thanks for the information Abhishek! Just a small update after my last post. When I logged into Safe mode I was able to locate the files and delete them as well. Same was the case with deletion of the keys in registry. I have Windows XP SP2. With regards to Linux I dont' have any Linux CD except for Kubuntu. I tried Kubuntu but I dont know how to access or browse through the directories in Kubuntu. Can you explain about it?
|
|
|
07-02-2008, 06:25 PM
|
#21 (permalink)
|
|
UBERGEEK
Join Date: Dec 2005
Location: Oxford of da east
Posts: 397
|
Re: Funny UST Scandal.avi Virus---Tutorial
Quote:
Originally Posted by ajayritik
Hey I got confused when you were Thanking topic-creator I was actually searching for someone by that name in the posts but I think you were thanking Abhishek.
|
sorry 4 that,,use slax os to delete the files...the interface is simple as winxp
|
|
|
20-02-2008, 08:40 PM
|
#22 (permalink)
|
|
Fast 'N' Furious
Join Date: Jul 2006
Location: Geek's Heaven
Posts: 11,169
|
Re: Funny UST Scandal.avi Virus---Tutorial
Great Trick 
Keep up the good work
Last edited by topgear; 23-02-2008 at 06:55 PM.
|
|
|
29-02-2008, 06:58 PM
|
#23 (permalink)
|
|
Right Off the Assembly Line
Join Date: Jan 2007
Posts: 11
|
Re: Funny UST Scandal.avi Virus---Tutorial
Thanks dude Nice tuts
|
|
|
24-03-2008, 03:35 AM
|
#24 (permalink)
|
|
Right Off the Assembly Line
Join Date: Mar 2008
Posts: 5
|
Re: Funny UST Scandal.avi Virus---Tutorial
I think this link would be usefull in addition to the above
Last edited by kalpik; 24-03-2008 at 08:21 AM.
|
|
|
24-03-2008, 07:37 AM
|
#25 (permalink)
|
|
Om Ma Ni Pä Me Hum
Join Date: Jun 2007
Location: sikkim
Posts: 383
|
Re: Funny UST Scandal.avi Virus---Tutorial
Nice info . . I had this virus and i removed those files with ubuntu cd . .
__________________
Om Ma Ni Pä Me Hum: (perfection of-)
Om: generosity,- Ma: pure ethics,-Ni: tolerance n patience.- Pä: perseverance,- Me: concentration,-Hum: wisdom... Using Opera Mini Airtel NOP
|
|
|
31-03-2008, 01:06 PM
|
#26 (permalink)
|
|
TechFreakiez.com
Join Date: Sep 2006
Location: New Delhi
Posts: 621
|
Re: Funny UST Scandal.avi Virus---Tutorial
what do u mean nirjhar???
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
|
|
|
| Thread Tools |
|
|
| Display Modes |
Linear Mode
|
Posting Rules
|
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts
HTML code is Off
|
|
|
LinkBacks (?)
LinkBack to this Thread: http://www.thinkdigit.com/forum/tutorials/78794-funny-ust-scandal-avi-virus-tutorial.html
|
| Posted By |
For |
Type |
Date |
| 4 Paisa: Funny UST Scandal virus |
This thread |
Refback |
26-09-2010 09:02 AM |
|
|
|