Forum     

Go Back   Digit Technology Discussion Forum > Community > Tutorials
Register FAQ Calendar Mark Forums Read

Tutorials This section offers tutorials and How to's on just about anything related to computers and IT. Note: All tutorials are courtesy the posters and not verified by Digit


Closed Thread
 
LinkBack (1) Thread Tools Display Modes
Old 22-01-2008, 07:46 PM   1 links from elsewhere to this Post. Click to view. #1 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Funny UST Scandal.avi Virus---Tutorial


Remove Funny UST Scandal.avi.exe (Vista and XP)


I came across many people (including me) who got infected by the Funny UST Scandal.avi virus. This tutorial guides you through the manual process of removing this Virus from Windows Vista and Windows XP systems.

Details:
1) This will block your Task Manager, Registry Editor and Command Prompt.
2) It hacks in your Yahoo Messenger and sends stupid and senseless messages to them and even a copy of itself. (ask gigacore if you don’t believe me!!!)
3) It will log your all key strokes and send them to an unknown email address through IM.
4) It slows down your system badly and reinstalling the OS will do no good.
5) It will disable the search and viewing of hidden files.

It’s built using AutoIt V3 virus programming software.--(source= some blog)


Windows XP:
This virus was made mainly to infect XP and Windows NT systems. In XP and NT systems, it makes the following files:
a) Killer.exe (4084 kb) in c:\windows\
b) lsass.exe (3920kb) in c:\documents and settings\all users\start menu\programs\startup
c) xmss.exe (4088kb) in all partitioned drives and in c:\windows
d) autorun.inf (1kb) in all partitioned drives with a script.

e) Funny UST Scandal.avi.exe in all partitions and Funny UST Scandal.exe in c:\Windows.


This Virus makes the following registry entries:
a) HKLM\Software\Microsoft\WindowNT\CurrentVersion\Wi nlogon
shell(killer.exe or xmss.exe)
b) HKCU\Software\Microsoft\windows\Currentversion\Run

Runonce(c:\windows\xmss.exe)

If the virus has completely installed itself, then you can find all these files in your system.

To remove this virus:
a) In order to removes the files, you’ll first have to stop the execution of this virus. To do so, download this file and run it.
b) Now open cmd.exe and go the above mentioned locations and unhide the files by typing: attrib –h –s Funny UST Scandal.exe for C:\windows and so on for all the other files in different locations. You might get an error while unhiding Funny UST Scandal.avi.exe which is placed in all partitions. If you get that error, just leave that file.
c) After unhiding all these files, delete them from your hard disk.
d) Download REPLACER and open it.
e) In the REPLACER type: c:\Funny UST Scandal.avi.exe and press enter. It will now ask you for another file. Create a text file named a.txt in C:\ and then type: c:\ a.txt and press enter. Press Y and press enter. Go to C: drive and there you’ll find 3 files named Funny UST Scandal.backup, Funny UST Scandal.exe and a Temp file. Delete them.
f) Repeat Step e) for all you partitions.


Windows Vista:
Files included:
a) xmss.exe (4088kb) in all partitioned drives and in c:\windows
b) autorun.inf (1kb) in all partitioned drives with a script.

c) Funny UST Scandal.avi.exe in all partitions and Funny UST Scandal.exe in c:\Windows.

Registry Entries:
a) HKLM\Software\Microsoft\WindowNT\CurrentVersion\Wi nlogon
shell(killer.exe or xmss.exe)
b) HKCU\Software\Microsoft\windows\Currentversion\Run

Runonce(c:\windows\xmss.exe)
The second key might no be present.

Removing the Virus:

To remove this virus:
a) In order to removes the files, you’ll first have to stop the execution of this virus. To do so, download this file and run it.
b) Now open cmd.exe and go the above mentioned locations and unhide the files by typing: attrib –h –s Funny UST Scandal.exe for C:\windows and so on for all the other files in different locations. You might get an error while unhiding Funny UST Scandal.avi.exe which is placed in all partitions. If you get that error, just leave that file.
c) After unhiding all these files, delete them from your hard disk.
d) Download REPLACER and open it.
e) In the REPLACER type: c:\Funny UST Scandal.avi.exe and press enter. It will now ask you for another file. Create a text file named a.txt in C:\ and then type: c:\ a.txt and press enter. Press Y and press enter. Go to C: drive and there you’ll find 3 files named Funny UST Scandal.backup, Funny UST Scandal.exe and a Temp file. Delete them.
f) Repeat Step e) for all you partitions.

As you can see that the procedure for both the OS is same just the files are different. I have tested the steps myself on Windows XP sp2 (my desktop), Windows Vista Home Basic (my lappy), Windows Vista Home Premium (my friends lappy) and Windows Vista Ultimate (my desktop).
Hope this guide is useful. Happy Removing…
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 22-01-2008, 08:12 PM   #2 (permalink)
SivaChand
 
Join Date: Dec 2007
Location: TamilNadu
Posts: 108
Default Re: Funny UST Scandal.avi Virus---Tutorial

Good info.... But you pasted two times of removing method
__________________
Always look at what you have left.Never look at what you have lost
kpmsivachand is offline  
Old 22-01-2008, 09:39 PM   #3 (permalink)
vaibhavtek
Guest
 
Posts: n/a
Default Re: Funny UST Scandal.avi Virus---Tutorial

thanks..
 
Old 22-01-2008, 09:47 PM   #4 (permalink)
CG Artist
 
gaurav_indian's Avatar
 
Join Date: May 2006
Location: New Delhi,India
Posts: 1,462
Default Re: Funny UST Scandal.avi Virus---Tutorial

I cant download that newfolderremoval.exe file
gaurav_indian is offline  
Old 23-01-2008, 05:42 PM   #5 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Funny UST Scandal.avi Virus---Tutorial

thx guys....i didn't double posted da steps...just reppeated den again for vista....
@gaurav: u moght not b able 2 DW da file as the virus migh b running on ur sys....try to terminate da XMSS.EXE file running as Admin. n den DWing...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 23-01-2008, 06:22 PM   #6 (permalink)
In The Zone
 
pushkaraj's Avatar
 
Join Date: Oct 2006
Location: Mumbai
Posts: 430
Default Re: Funny UST Scandal.avi Virus---Tutorial

nice tutorial. thanx
__________________
The statistics on sanity are that 1 out of every 4 humans is suffering from some form of mental illness:shock:
Think of your 3 best friends. If they are OK, then it's YOU:grin::grin::grin:
pushkaraj is offline  
Old 23-01-2008, 07:56 PM   #7 (permalink)
UBERGEEK
 
PCWORM's Avatar
 
Join Date: Dec 2005
Location: Oxford of da east
Posts: 397
Smile Re: Funny UST Scandal.avi Virus---Tutorial

Thanx a ton man...
my pc is infected with the same virus..
PCWORM is offline  
Old 24-01-2008, 10:07 PM   #8 (permalink)
The Thread Killer >:)
 
phreak0ut's Avatar
 
Join Date: Apr 2006
Location: Bangalore
Posts: 1,185
Default Re: Funny UST Scandal.avi Virus---Tutorial

Very informative. Thanks
__________________
Want to make this world a better place? Then, start seeding and don't be just a leecher :)
phreak0ut is offline  
Old 25-01-2008, 05:39 PM   #9 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Funny UST Scandal.avi Virus---Tutorial

thx for da comment...hope it helped u all
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 05-02-2008, 10:33 AM   #10 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal.avi Virus---Tutorial

Thanks for the information. I have tried with couple of suggestions from the net but they didnt work. I will try your suggestion and see whether it helps. This Virus has created a menace.

If these steps have worked for anyone can they reply please. I'm having hell of trouble with it.

Last edited by ajayritik; 05-02-2008 at 10:33 AM. Reason: Automerged Doublepost
ajayritik is offline  
Old 05-02-2008, 05:37 PM   #11 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Funny UST Scandal.avi Virus---Tutorial

it has wrkd for me...try it...
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 05-02-2008, 05:48 PM   #12 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal.avi Virus---Tutorial

Abhishek the virus actually infected my PC through iPod. Do you know how we can remove it from the iPod?
ajayritik is offline  
Old 05-02-2008, 05:56 PM   #13 (permalink)
UBERGEEK
 
PCWORM's Avatar
 
Join Date: Dec 2005
Location: Oxford of da east
Posts: 397
Smile Re: Funny UST Scandal.avi Virus---Tutorial

Quote:
Originally Posted by ajayritik View Post
Abhishek the virus actually infected my PC through iPod. Do you know how we can remove it from the iPod?
If there's any provision of formatting ur player,,,do it,,,i did with my pendrive
and the file was wipedout,,,
And thanx topic-creator,,ur solution has worked 4 my pc,,,thanx a lot...!!!!
PCWORM is offline  
Old 05-02-2008, 06:31 PM   #14 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal.avi Virus---Tutorial

Quote:
Originally Posted by PCWORM View Post
If there's any provision of formatting ur player,,,do it,,,i did with my pendrive
and the file was wipedout,,,
And thanx topic-creator,,ur solution has worked 4 my pc,,,thanx a lot...!!!!
Hey I got confused when you were Thanking topic-creator I was actually searching for someone by that name in the posts but I think you were thanking Abhishek. I will try the steps given by Abhishek.

I heard somewhere that we should not format the iPod. We need to restore it. Since I'm not able to connect to the internet can I restore(format) the iPod using some software that I can download from my friend's PC. I have the CD that came with the iPod but that has an older version I think.

Last edited by ajayritik; 05-02-2008 at 06:31 PM. Reason: Automerged Doublepost
ajayritik is offline  
Old 05-02-2008, 11:57 PM   #15 (permalink)
C# Be Sharp !
 
Zeeshan Quireshi's Avatar
 
Join Date: Jun 2006
Location: Toronto
Posts: 1,805
Default Re: Funny UST Scandal.avi Virus---Tutorial

Quote:
Originally Posted by Abhishek Dwivedi View Post
It slows down your system badly and reinstalling the OS will do no good.
I have a doubt with this One .

How can Reinstalling the OS , NOT remove the virus ?
__________________
There are 10 types of people in the world: those who understand binary and those who do not.
Zeeshan Quireshi is offline  
Old 06-02-2008, 12:11 AM   #16 (permalink)
dá ûnrêäl Kiñg
 
zyberboy's Avatar
 
Join Date: Feb 2006
Location: kerala/calicut
Posts: 992
Default Re: Funny UST Scandal.avi Virus---Tutorial

^^becoz it easily gets infected again when opening other drives.
__________________
My Stomach pains:D:D
http://tinyurl.com/32jj4m
zyberboy is offline  
Old 06-02-2008, 12:46 AM   #17 (permalink)
Šupər♂ - 超人
 
koolbluez's Avatar
 
Join Date: Oct 2004
Location: Look up... up in da sky... see me yet? Nah... Use a telescope, dumbo!
Posts: 1,626
Default Re: Funny UST Scandal.avi Virus---Tutorial

=I never faced big prob from this harmless virus. all i do is Ctrl+alt+delete... close xmss.exe, funny....exe in task manager processes, "search"(incl hidden files) in the suspicious usb/drive for xmss, autorun.inf & funny terms and delete these 3 culprit files. Remove the usb & put it back into slot. Then it's as good as new !!!! No dos, no live cds...!!!

Never got that killer.exe.. in my drives at all!!! Now, why did that happen?

What i did is tried and tested... worked for all the drives/usb sticks my friend's got/brought...
__________________
Windows ka tashan... koolbluez ishtyle - http://lin.cr/ss
I almost forgot this - http://www.thinkdigit.com/forum/showthread.php?t=6242
koolbluez is offline  
Old 06-02-2008, 09:24 AM   #18 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal.avi Virus---Tutorial

I was able to access my computer and other drives using the New Folder thing but I'm unable to use the attrib command to delete the files. Infact I can't locate these files.When I use Replacer to replace the file it gives Access denied message.
ajayritik is offline  
Old 07-02-2008, 03:26 PM   #19 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Funny UST Scandal.avi Virus---Tutorial

@ajayritk: which OS do u use...try booting up with Linux and searching all 2-4MB sized file with X,S,M,A,U,AUTORUN wrd in them and delete the one which are marked above...
also download ULBLOCKER and install it and unblock da files in which u get access denied
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Old 07-02-2008, 05:56 PM   #20 (permalink)
Wise Old Owl
 
ajayritik's Avatar
 
Join Date: Aug 2007
Location: Hyderabad
Posts: 1,675
Default Re: Funny UST Scandal.avi Virus---Tutorial

Thanks for the information Abhishek! Just a small update after my last post. When I logged into Safe mode I was able to locate the files and delete them as well. Same was the case with deletion of the keys in registry. I have Windows XP SP2. With regards to Linux I dont' have any Linux CD except for Kubuntu. I tried Kubuntu but I dont know how to access or browse through the directories in Kubuntu. Can you explain about it?
ajayritik is offline  
Old 07-02-2008, 06:25 PM   #21 (permalink)
UBERGEEK
 
PCWORM's Avatar
 
Join Date: Dec 2005
Location: Oxford of da east
Posts: 397
Smile Re: Funny UST Scandal.avi Virus---Tutorial

Quote:
Originally Posted by ajayritik View Post
Hey I got confused when you were Thanking topic-creator I was actually searching for someone by that name in the posts but I think you were thanking Abhishek.
sorry 4 that,,use slax os to delete the files...the interface is simple as winxp
PCWORM is offline  
Old 20-02-2008, 08:40 PM   #22 (permalink)
Fast 'N' Furious
 
topgear's Avatar
 
Join Date: Jul 2006
Location: Geek's Heaven
Posts: 11,169
Default Re: Funny UST Scandal.avi Virus---Tutorial

Great Trick
Keep up the good work
__________________
ToPsPeEeD = FaSt BuT StEaDy

AMD Radeon HD 6850 OverClocked to 1 Ghz !!!

Blog : http://topgeartopspeed.wordpress.com/
----------------------------------------------------
Never buy viewsonic products : http://tinyurl.com/ykwx4oa

Last edited by topgear; 23-02-2008 at 06:55 PM.
topgear is offline  
Old 29-02-2008, 06:58 PM   #23 (permalink)
Right Off the Assembly Line
 
Join Date: Jan 2007
Posts: 11
Default Re: Funny UST Scandal.avi Virus---Tutorial

Thanks dude Nice tuts
sun_rane007 is offline  
Old 24-03-2008, 03:35 AM   #24 (permalink)
Right Off the Assembly Line
 
Join Date: Mar 2008
Posts: 5
Default Re: Funny UST Scandal.avi Virus---Tutorial

I think this link would be usefull in addition to the above

Last edited by kalpik; 24-03-2008 at 08:21 AM.
angad.ssingh is offline  
Old 24-03-2008, 07:37 AM   #25 (permalink)
Om Ma Ni Pä Me Hum
 
phuchungbhutia's Avatar
 
Join Date: Jun 2007
Location: sikkim
Posts: 383
Default Re: Funny UST Scandal.avi Virus---Tutorial

Nice info . . I had this virus and i removed those files with ubuntu cd . .
__________________
Om Ma Ni Pä Me Hum: (perfection of-)
Om: generosity,- Ma: pure ethics,-Ni: tolerance n patience.- Pä: perseverance,- Me: concentration,-Hum: wisdom... Using Opera Mini Airtel NOP
phuchungbhutia is offline  
Old 31-03-2008, 01:06 PM   #26 (permalink)
TechFreakiez.com
 
Abhishek Dwivedi's Avatar
 
Join Date: Sep 2006
Location: New Delhi
Posts: 621
Default Re: Funny UST Scandal.avi Virus---Tutorial

what do u mean nirjhar???
__________________
Personal Log | Star date 05.04.2009: TDF Meet Kanpur was Awesome :D
www.TechFreakiez.com
Abhishek Dwivedi is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://www.thinkdigit.com/forum/tutorials/78794-funny-ust-scandal-avi-virus-tutorial.html
Posted By For Type Date
4 Paisa: Funny UST Scandal virus This thread Refback 26-09-2010 09:02 AM

Similar Threads
Thread Thread Starter Forum Replies Last Post
TUTORIAL: All About Resource Hacker! A Brief Tutorial Vishal Gupta Tutorials 278 27-11-2007 11:46 AM
about a virus which attacked me,need guidence and giving info abt this virus-read mobileman Software Q&A 2 16-11-2007 12:43 PM
Virus problem, need online virus checking details-pls hava a read here. mobileman Software Q&A 2 14-04-2007 10:58 AM
mcafee virus scan 8.0 - problem updating virus definations infra_red_dude Software Q&A 3 26-06-2005 11:43 AM
VIRUS...RANDEX ZEN.......VIRUS MLORE HELP..??URGENT Writankar panja Software Q&A 9 19-09-2004 05:26 PM

 
Latest Threads
- by chris
- by icebags
- by Tenida

Advertisement




All times are GMT +5.5. The time now is 01:30 AM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2