Wednesday, November 28, 2007

Funny UST Scandal Avi.Exe Remover

Funny UST Scandal Virus Removal Tool

Automatic remover = Download this: Funny UST Scandal Avi.exe Remover

Manual:

Software used to build the virus= AutoIt V3
drop Files- killer.exe(4084 kb) in c:\windows\
lsass.exe(3920kb) in c:\documents and settings\all users\start menu\programs\startup
smss.exe(4088kb) in all root drives and in c:\windows
autorun.inf(1kb) in all root drives with a script

[autorun]
open=smss.exe
shell\Open\Command=smss.exe
shell\open\Default=1
shell\Explore\Command=smss.exe
shell\Autoplay\command=smss.exe

Funny UST Sandal.avi.exe(228kb) in all root drives

Registry Entries-HKLM\Software\Microsoft\WindowNT\CurrentVersion\Winlogon=shell(killer.exe)
HKCU\Software\Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)


HOw to remove this lame virus????

-first download taskiller in http://www.rsdsoft.com/task_killer/index.php4 and install it to
your computer because you cant use taskmanager to terminate the virus(the virus automatically close taskmanager).

-run taskiller and left click it on the system tray(the one with a skull icon)

-click processes

-to close the virus, select process and click yes to the question

(process to close)
1.killer.exe
2.lsass.exe
3.smss.exe

note: close only file that have the same icon of Funny UST S*andal.avi.exe


CMD STEPS
1-now, click "start" then "run"
2-type "cmd" without quotes
3-type "cd\" without quotes
4-type "attrib -h -s smss.exe" without quotes
5-type "attrib -h -s autorun.inf" without quotes
6-type "start c:" without quotes(a new window will open)
7-select smss.exe,autorun.inf,Funny UST Scal.avi.exe and delete it

-if theres any drive or a partition type "d:" in command prompt without quotes
"d" is the drive letter then repeat the CMD STEPS number 4-7 above.......

-now type this on the command prompt "cd windows" without quotes(na naman!)
-type "attrib -h -s smss.exe" without quotes(uli)
-type "start c:\windows" without quotes(hay naku!)
-delete the file smss.exe
-now, goto c:\documents and settings\all users\startmenu\programs\startup
-delete lsass.exe

-click "start" then "run"
-type "regedit" without quotes then delete the registry entries above....

special thanks to fs6519 of TPC


Any suggestion, question or violent reaction? Feel free to leave a comment.

View Random Post

72 comments:

  1. Thanks for this it really helps. (i hope your not the creator.)

    ReplyDelete
  2. Thanks! napakagaling!!! natuwa ako sa virus hehe! pahirap!!!!!!!

    ReplyDelete
  3. Thanks for this it really helps. (i hope your not the creator.)

    ReplyDelete
  4. Ang lupit mo BORDS!
    Slamat ng maraming marami. :D

    ReplyDelete
  5. NICE NAMANN,,, AYOS NA AYOS TO... PINABILIS, PINADALI ANG PAGTANGGAL NG TANGAHING VIRUS!!!!

    ReplyDelete
  6. hai... dko alam kung tanga lang ako at dko naayos... pero eto ang tumulong sa akin http://www.techsupportforum.com/sectools/sUBs/ComboFix.exe
    combofix... ayos na ayos :D if ever bumalik

    ReplyDelete
  7. Thanx For The Detailed Help Manual....I Just Downloaded It & Hope That It Really Helps....One Thing...Does iT Damages Any Of The Files Of My PC? 'Coz I Have Loads Of Data Backups In My HDD......

    ReplyDelete
  8. HI Sir this Ram from India. Thank u for ur valuable information. Now my messenger is working properly

    ReplyDelete
  9. WoW!! haNep!! thanK u VerY mUch!

    Im sO glaD i foUnd Ur Site. It Helps Me tOo mUch!! 2 daYS Ko d TinUlugaN anG vIrus na Yan.. eTo paLA anG site NA Wer I caN cOunt On. In JusT oNE cLick. maIntaIned Na lahAt./.

    ThaNk U sO muCh!!!!

    GooDlUck!! MorE Power!!!

    ReplyDelete
  10. Pare sanan d ikaw ang gumawa-aldrin mquinana

    ReplyDelete
  11. that virus erased my SD card - may documentation pa ng workshop doon. I was going to burn the pictures - I left the SD card on the slot because I got called over to attend a meeting. Pagbalik ko, yun virus na lang laman ng SD card. Grrrrrrr. Salamat sa remover.

    ReplyDelete
  12. Guys, i've tired the remover, the manual procedure, and perhaps FIVE BLOODY ANTI-VIRUS!! they worked, partially, coz check out your C:\windows\system32. The LSASS.exe and SMSS.exe are still there.. Sana ma-rape ng bakla ang gumawa ng virus!!

    ReplyDelete
  13. @anonymous

    hehe brutal ka naman. actually, lsass.exe and smss.exe are legitimate window files. so you don't have to worry about it

    ReplyDelete
  14. regarding po sa regedit. sabi po kasi ssa instruction>>> type "regedit" without quotes then delete the registry entries above.... thus it means "ALL" registry entries????? curious lang po.. di kasi me tech specialist eh...

    ReplyDelete
  15. eto lang po delete nyo:

    Registry Entries-HKLM\Software\Microsoft\WindowNT\CurrentVersion\Winlogon=shell(killer.exe)

    HKCU\Software\Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)

    ReplyDelete
  16. thanks for the reply sir TechPinoy... question po ulit... heheheh yung sa HKLM entry, delete lang po ba ay yung killer.exe??? same din po ba sa HK_current_user;smss.exe lang??? kasi yung nakita ko sa HKLM is explorer.exe,killer.exe.... tapos sa runonce is c:\WINDOWS\smss.exe.. thanks alot.. noob lang kasi ako...

    ReplyDelete
  17. @PT

    delete mo yung buong entry. ayaw ba gumana sayo nong automatic remover? para di ka na mahirapan

    ReplyDelete
  18. automatic remover??? nag manual lang po kasi ako eh... kaya di ko alam masyado.. do you have the link for the automatic remover???

    ReplyDelete
  19. my bad..... SORRY!!!! nakita ko na po... sensya na....

    ReplyDelete
  20. that's okay! hope it helps!

    ReplyDelete
  21. Hello,

    Please help. I can't run the automatic remover. There's an error with the file. The error says the application can't run because there's a certain file missing.

    Thanks a Lot

    ReplyDelete
  22. can you post the exact wording of the error?

    ReplyDelete
  23. tq 4 ur help. its help a lot -

    ReplyDelete
  24. kilala ko creator, harhar

    ReplyDelete
  25. After doing the manual removal as well as using the quick remover, i suspect that the virus is still there...I cant open my c drive thru windows explorer...this message occurs: "C:\ application cannot be run in Win32 mode". Moreso, i still can't view all my hidden files and some other weird stuffs...I can't afford to reformat my pc at this time...can anybody help me on this!! I really need it badly!!

    ReplyDelete
  26. pano po ba maalis ng 2luyan kc pag restart ko ng pc nandun parin tsaka po d ko tlga ma gets yung manual way of removing...

    ReplyDelete
  27. i cant do it, the task manager appear and says, program not responding. i closed all applications and restart my pc, but then again it says, not responding. what shall i do?

    please try to ym or email me if you can, prbc_marketing@yahoo.com

    ReplyDelete
  28. Hi! I did the automatic and manual removal of the virus and successful naman xa with drive C and D kaso everytime na may maiinsert na mga usb devices may autorun.inf na naddtect yung antivirus ko. does this mean na nasa system ko pa rin yung virus? and is it true na kht ire4mat ko yung pc andun pa rin yung virus? annoying na kc eh... pls reply...i badly need your help...u guys rock btw...tnx!

    ReplyDelete
  29. @bubbles20

    baka ang nadedetect ng antivirus mo yung autorun galing sa flash drive hindi sa computer mo mismo. pag ganon, hindi pc mo may problema, yung flash drive ang may virus

    pa scan mo yung flash drive mo sa antivirus mo, pag di kinaya ng AV mo, palit ka ng avast. yun ang gamit ko. so far so good, wala namang virus na nakakalusot

    ReplyDelete
  30. thnks for the remover.. BUt sTill i can't view my hidden files.. i check view hidden and system files but it automatically go back to "Do not show hidden and system file" plzz Help?? what should i do.. i need help on that...

    ReplyDelete
  31. tnx a lot techpinoy!galing mo tlg...idol!Ü nod32 gamit q, and naddtect naman nya ung virus...alarmed lng ako kc bka pc ko yung nagsspread s mga usb...hehehe... tnx ult!

    ReplyDelete
  32. tnx bro, pahirap....

    ReplyDelete
  33. ang galing niyo
    i swear!
    im officially a fan of you guys
    natanggal na ung pesteng virus..
    and you have a great sense of humor
    so great tlga
    thanks a lot
    Godbless!

    ReplyDelete
  34. thanks po sa help!!!! u saved my computer!!!

    ReplyDelete
  35. ok na. Thank you believe ako sayo. Pero congrats dinsa gumawa ng virus kc first time kong di nasolve ito. Kailangan ko pa ang task killer. Congats to both of you.

    ReplyDelete
  36. i have a new prob! nddtect pa rin ng AV ko yung virus sa drive C days after the removal...d ata xa natatanggal permanently...shud i re4mat my pc? wud this solve the prob?yoko sana eh kc may vital files ako... yung AV ko nman trial version lang so pag expired na xa bka mas vulnerable nko sa virus... one more thing, i remember dti nung gamit ko ung taskkiller may lumabas na msg na system shutdown or something after atempting to delete the processes. nagwork b ung pgdelete or not? help plz! huhu...

    ReplyDelete
  37. Thanks! it really helps.

    ReplyDelete
  38. Hi
    Thanks a lot. My AVG Free version was no help. I used the REMOVER and followed the steps. My system is clean now. Thanks a lot once again
    Gopinath S

    ReplyDelete
  39. mga tol pnu namn alisin ung spywer?my remover b kau?pasend nman.

    ReplyDelete
  40. THANK GOODNESS!!!!!!

    that virus has been causing me problems and I was soo worried that Id have to get my laptop fixed at some overkill shop.

    My laptop is my life and you just saved it!

    *hugs*

    ReplyDelete
  41. I'm sorry, i had to remove some comments here. i am having problem with adsense. It suddenly stop showing ads. weird thing is, only on this page. if any of you can help me, i would be grateful.

    ReplyDelete
  42. thanx ha..sa gumawa ng gamot na ito...

    it's really of a great help..


    marjouricey ng cebu...

    ReplyDelete
  43. thanx ha..sa gumawa ng gamot na ito...

    it's really of a great help..


    marjouricey ng cebu...

    ReplyDelete
  44. THANK YOU, THANK YOU, THANK YOU!!!! Words cannot describe how grateful I am. That program removed the little piece of shit in like 3 seconds! Thank you! :D

    ReplyDelete
  45. Thanks talaga idol! Shit kasi ung virus nakakinis tlga.. Ang lupit mo pre. Ayos na ayos na ang messenger ko.. :D

    ReplyDelete
  46. hi.. slamat ha.. la na ung pesting virus na un..
    hehehehe.

    ReplyDelete
  47. thx! it really did wOrk!;)

    ReplyDelete
  48. tnx po s pgremove nung ust scandal n un.. tnx po tlga.. more power Godblesz!!!!!!!!!

    ReplyDelete
  49. thank you very much!! you saved my life!! i thought i was going to be grounded for life!! thank you!!

    ReplyDelete
  50. Thanks,

    It really worked

    thanks alot

    ReplyDelete
  51. i have wat this needs....
    lets see if it does what u say it shud...
    well thanks for this ray of hope.

    ReplyDelete
  52. hi thanks for the steps
    i installed the task killer ended the process and the virus is gone
    but the process keep showing up
    i cant see my hidden files plz
    plz help me

    ReplyDelete
  53. Mga pards, no need to download the software... SYSTEM RESTORE lang ayus na!!! =)

    ReplyDelete
  54. Mga pards, no need to download the software... SYSTEM RESTORE lang ayus na!!! =)

    ReplyDelete
  55. Funny UST Scandal.avi.exe?! san ba nakukuha ito?! Where can I get this virus?! If ever I watched porn movies do I get this virus?!

    ReplyDelete
  56. @anonymous

    nope. you can get it through yahoo messenger and/or flash drives

    ReplyDelete
  57. That's the only sensible reply I have seen on net. I am sure my problem will be solved.

    ReplyDelete
  58. Isa kang alamat... letch tlga ung virus na un...

    ReplyDelete
  59. is "smss.exe" a legitimate window file??? bakit most of the posts of removing that UST scandal virus said that its a virus?!

    pls verify...

    ReplyDelete
  60. i just want to know if that virus would still run though i didnt open it nung natapos na sya mdownload,.. please email me,.. paul.lhet@lycos.com,.. that same virus infected my pc last year kxo hindi ko alam ung gnawa nung nag-ayos nito,..

    ReplyDelete
  61. Super Thankyou po. Sa wakas, naalis na rin xa sa system ko. XD

    ReplyDelete
  62. Sana yung malalaki na ang biniktima, para siyang si goliath, kayankayanan lang ang maliliit, mapang-aping lahi!

    ReplyDelete
  63. Kala nung gumawa nung virus na yun! Me araw din sya! Sana nga marape sya ng bakla! Wehehe. Evilness eh no? Bat ba? Namroblema ku dahil dyan sa virus na yan!

    Nga pala, i used this link to remove na that pesky virus: sobrang helpful! Download nyo lang tas irun nyo yung application tas tapos na! :) Sana makatulong to.

    ReplyDelete
  64. You deserve a lot of praise... i formatted my entire drive then also cunt get thru this virus.. but u did it in 5 mins ! ! amazin ! thanx a ton !!

    ReplyDelete
  65. mine was detected by avg but i still can not open my drive C. how can i revert the effects of the virus without using system restore?

    ReplyDelete
  66. holy shit.....you guys are genius....

    tnx for the remover.....

    that fucking virus is iritating...

    tnx again......(even if you're the creator)

    ReplyDelete
  67. it is a great help really, that is so much dangerious virus. i was damn sick of this and want to kill this bastard, guys i have never seen such a dagerious threat in my life. big thanks of this site and those people who really giving us wonderful opportunities to get rid of this. GOD SPEICAL BLESS THESE PEOPLE

    ReplyDelete
  68. may prob pa rin ako sa virus na to..kaka bad trip na...na try ko na po lahat pati remover ayaw pa din.. pag nag mamanual nmn ako...pag katype ko ng attrib -h -s smss.ex - file not found nmn daw...ayaw na rin mag boot sa safemode pc ko...kahit ano safemode...tapos try ko task killer..pagka end ko ng slss.exe nag blue screen na...ayaw na magboot kahit san...try ko mag boot sa cd..may error..[press any key to boot from cd...] tpos nun may lalabas na mga codes...parang gap vault ata...help!!! ayaw ko mawala mga files ko sa work...

    ReplyDelete
  69. thanks for the inkormation it really worked

    ReplyDelete
  70. hi. please help me. kasi pag in-open ko yung firefox nagko close eh. kahit anong i open ko nagko close o minsan nagha hang. thanks

    ReplyDelete
  71. This is a very nasty virus which can trick the people easily into believing that this is a safe program for their computer.

    ReplyDelete
  72. Thank you for guiding us through this process! This is a big help for those suffering from this nasty virus. Unfortunately for me, I have a different problem: a laptop spill. Now I need to send my hardware in to be repaired, or simply purchase a new computer.

    ReplyDelete