<?xml version='1.0' encoding='UTF-8'?><?xml-stylesheet href="http://www.blogger.com/styles/atom.css" type="text/css"?><feed xmlns='http://www.w3.org/2005/Atom' xmlns:openSearch='http://a9.com/-/spec/opensearchrss/1.0/' xmlns:georss='http://www.georss.org/georss' xmlns:gd='http://schemas.google.com/g/2005' xmlns:thr='http://purl.org/syndication/thread/1.0'><id>tag:blogger.com,1999:blog-867421095796877676</id><updated>2012-02-16T01:17:32.450-08:00</updated><title type='text'>Virus Fighter</title><subtitle type='html'></subtitle><link rel='http://schemas.google.com/g/2005#feed' type='application/atom+xml' href='http://virusfighter.blogspot.com/feeds/posts/default'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/867421095796877676/posts/default?max-results=100'/><link rel='alternate' type='text/html' href='http://virusfighter.blogspot.com/'/><link rel='hub' href='http://pubsubhubbub.appspot.com/'/><author><name>Virus Fighter</name><uri>http://www.blogger.com/profile/01404661285164757185</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><generator version='7.00' uri='http://www.blogger.com'>Blogger</generator><openSearch:totalResults>1</openSearch:totalResults><openSearch:startIndex>1</openSearch:startIndex><openSearch:itemsPerPage>100</openSearch:itemsPerPage><entry><id>tag:blogger.com,1999:blog-867421095796877676.post-2369165583775714119</id><published>2007-12-18T10:36:00.000-08:00</published><updated>2007-12-18T11:21:41.691-08:00</updated><title type='text'>Removing Funny UST Scandal.avi.exe virus</title><content type='html'>&lt;strong&gt;&lt;span style="font-size:85%;"&gt;VIRUS INFO&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Software used to build the virus= AutoIt V3&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;Dropped Files&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;killer.exe(4084 kb) in c:\windows\&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;lsass.exe(3920kb) in c:\documents and settings\all users\start menu\programs\startupsmss.exe(4088kb) in all root drives and in c:\windows&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;autorun.inf(1kb) in all root drives with a script &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;[autorun]&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;open=smss.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;shell\Open\Command=smss.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;shell\open\Default=1&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;shell\Explore\Command=smss.exe&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;shell\Autoplay\command=smss.exe &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Funny UST Scandal.avi.exe(228kb) in all root drives&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;&lt;span style="font-size:85%;"&gt;Registry Entries&lt;/span&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;HKLM\Software\Microsoft\WindowNT\CurrentVersion\Winlogon=shell(killer.exe)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;HKCU\Software\Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;Manual Removal&lt;/strong&gt; &lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;1. First download &lt;a href="http://www.rsdsoft.com/zip/tksetup.exe"&gt;Task Killer&lt;/a&gt; and install it to your computer because you can’t use Task Manager to terminate the virus (the virus automatically closes Task Manager). &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;2. Run Task Killer and left click it on the system tray(the one with a skull icon)&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;3. Click processes &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;4. To close the virus, select the processes(killer.exe, lsass.exe, smss.exe) and click yes. &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;strong&gt;&lt;/strong&gt;&lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;Note: Close only file that have the same icon of Funny UST Scandal.avi.exe &lt;/span&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;strong&gt;CMD Steps&lt;/strong&gt;&lt;br /&gt;1. Now, click "start" then "run"&lt;br /&gt;2. Type "cmd" without quotes&lt;br /&gt;3. Type "cd\" without quotes&lt;br /&gt;4. Type "attrib -h -s smss.exe" without quotes&lt;br /&gt;5. Type "attrib -h -s autorun.inf" without quotes&lt;br /&gt;6. Type "start c:" without quotes (a new window will open) 7&lt;br /&gt;. Select smss.exe, autorun.inf, Funny UST Scandal.avi.exe and delete it&lt;br /&gt;&lt;br /&gt;If there’s any other drive or a partition type "d:" in command prompt without quotes "d" is the drive letter then repeat the steps 4 - 7 above.......&lt;br /&gt;Now type this on the command prompt "cd windows" without quotes.&lt;br /&gt;Type "attrib -h -s smss.exe" (without quotes)&lt;br /&gt;Type "start c:\windows" (without quotes)&lt;br /&gt;Delete the file smss.exe&lt;br /&gt;Now, go to c:\documents and settings\all users\startmenu\programs\startup&lt;br /&gt;Delete lsass.exe&lt;br /&gt;Click "start" then "run"&lt;br /&gt;Type "regedit" without quotes then delete the registry entries above.&lt;br /&gt;&lt;span style="font-size:0;"&gt;&lt;/span&gt;&lt;/span&gt;&lt;br /&gt;&lt;strong&gt;Download &lt;a href="http://www.4shared.com/file/32405634/cc68cdf3/funny_UST_scandal_Remover.html"&gt;Removal Tool&lt;/a&gt;&lt;/strong&gt;&lt;br /&gt;&lt;span style="font-size:85%;"&gt;&lt;br /&gt;&lt;span style="font-size:0;"&gt;&lt;/span&gt;&lt;br /&gt;&lt;/span&gt;&lt;br /&gt;&lt;br /&gt;&lt;/span&gt;&lt;div class="blogger-post-footer"&gt;&lt;img width='1' height='1' src='https://blogger.googleusercontent.com/tracker/867421095796877676-2369165583775714119?l=virusfighter.blogspot.com' alt='' /&gt;&lt;/div&gt;</content><link rel='replies' type='application/atom+xml' href='http://virusfighter.blogspot.com/feeds/2369165583775714119/comments/default' title='Post Comments'/><link rel='replies' type='text/html' href='http://www.blogger.com/comment.g?blogID=867421095796877676&amp;postID=2369165583775714119' title='0 Comments'/><link rel='edit' type='application/atom+xml' href='http://www.blogger.com/feeds/867421095796877676/posts/default/2369165583775714119'/><link rel='self' type='application/atom+xml' href='http://www.blogger.com/feeds/867421095796877676/posts/default/2369165583775714119'/><link rel='alternate' type='text/html' href='http://virusfighter.blogspot.com/2007/12/removing-funny-ust-scandalaviexe-virus.html' title='Removing Funny UST Scandal.avi.exe virus'/><author><name>Virus Fighter</name><uri>http://www.blogger.com/profile/01404661285164757185</uri><email>noreply@blogger.com</email><gd:image rel='http://schemas.google.com/g/2005#thumbnail' width='16' height='16' src='http://img2.blogblog.com/img/b16-rounded.gif'/></author><thr:total>0</thr:total></entry></feed>
