10 March 2008

Worm removal - Funny UST Scandal.avi.exe

One of the viruses which i have tackled off late is Funny UST SCandal.avi.exe

Some of the Symptoms Of Funny UST SCandal.avi.exe are

  • A orange icon with image of a Foot.
  • Files missing, Not able to view hidden files.
  • Every time you click on My Computer opens a new instance of it.
  • Task Manager automatically disappearing after few seconds, not able to view process.
  • System deadly slow
  • Installations not occurring.

If your case can be matched with the conditions given above, in all probability, you’ve got the Autoit.BD worm, better known by Funny UST Scandal.avi.exe. AVG, Norton, Avast! - all don’t detect the virus.

This Virus replicates itself on the various disk partitions. So even if you have deleted it from C:\ or formated your PC it will still persist in some other partition leaving you in the same dilemma again. So one of the best ways to tackle this is.....

Steps to Follow in order to remove it
    1. Download and install TaskKiller. TaskKiller forcefully kills the task and hence stops virus from replicating. Run Task Killer, and a red skull icon will appear on the system tray.Left click it, and click Processes
    2. Select to kill these processes -
      • killer.exe
      • lsass.exe
      • smss.exe
    3. Now open up Command Prompt (Start>Run>command). Type each command and press Enter to run it -
      • cd\
      • attrib -h -s smss.exe
      • attrib -h -s autorun.inf
    4. Open My Computer and go to "C:\", then "C:\Windows\System32" and "C:\Windows\System".
    5. Delete the following files -
      • smss.exe
      • autorun.inf
      • Funny UST Scandal.avi.exe
    6. Now, go to C:\Documents and Settings\All users\Startmenu\Programs\Startup and delete the file lsass.exe.
    7. Open Registry Editor (Start>Run>regedit)
    8. Delete the key HKEY_LOCAL_MACHINE\Software\
      Microsoft\WindowNT\CurrentVersion\
      Winlogon=shell(killer.exe
    9. Delete the key HKEY_CURRENT_USER\Software\
      Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)
    10. Check For the virus in the other root partitions and remove the Funny UST Scandal.avi.exe
If you want to read about other method's click here.



Sphere: Related Content

5 comments:

pradeep said...

Hi. The information which you had mentioned above is very useful. If the funny scandal virus resides in Pen drive what to do..?? Please reply me as soon as possible

Angad Singh said...

You can manually delete this virus from pen drive go to command prompt:

1.Type cmd
2.Change the current directory to your pen drive directory.
3.Now Type dir \a look for Funny UST SCandal.avi.exe .
4.Then delete this File by typing
del /f Funny UST SCandal.avi.exe

IMPORTANT--do not double click to open the drives..

I have also read now we can remove this virus using updated version of anti-virus kaspersky.

uday said...

hi...this information is very usefull.But i got a problem that is
i delete all the exe files but the main smss.exe(which is stored in
c:/windows/system32) is not deleted.when iam was trying to delete this i got a message like "access denied".so please tell me how to delete it as early as possible.

Angad Singh said...

Try restore default setting using smart av here is the link....... http://technize.com/content/downloads/Smart_AV.exe

Kaushik Veluru said...

hi,
I do have problem with Funny UST Scandal.avi.exe. I followed the steps as you said. I downloaded task killer and selected processes on the red icon. But when I select to kill smss.exe the system is shuttin down automatically and one more thing is there is no killer.exe in the processes list.Tell me what to do. Plz.