I Killed The Funny UST Scandal Virus

Funny UST ScandalI got this virus about a month ago when suddenly my colleagues plugged in his USB flashdisk into my laptop. It was like “Argh” moment of despair and anger. But this helps me to solve the problem eventually. My friend, Fandi, used to chat around about computers and viruses. He used to breed some, too (keeping virus in his local harddisk, ZIP it, and show it to his friends). It’s not that he wants to harm everybody, but to share his knowledge about the virus. The same way I’m doing this to you now.

Here is the summary I got from TechPinoy Online:

General Overview:

Software used to build the virus= AutoIt V3
drop Files- killer.exe(4084 kb) in c:\windows\
lsass.exe(3920kb) in c:\documents and settings\all users\start menu\programs\startup
smss.exe(4088kb) in all root drives and in c:\windows
autorun.inf(1kb) in all root drives with a script

Autorun Command:

[autorun]
open=smss.exe
shell\Open\Command=smss.exe
shell\open\Default=1
shell\Explore\Command=smss.exe
shell\Autoplay\command=smss.exe

The Symptoms:

Creating hidden file of Funny UST Scandal.avi.exe(228kb) in all root drives
Disabling “Show Hidden File” and “Show System File” in Folder Option
Immediately closing down every Folder Option and Regedit windows opened (Disabling you from changing it)

How to Kill it?

If you are already got the symptoms, you can either follow my steps or just download the 1 type virus removal from PinoyTech.
The point of this steps is to disable the task already run in Task Manager and recover your registry regarding Folder Option items.

There are two alternatives, you can either download task killer from here or download processxp from here

For Task killer:

run taskiller and left click it on the system tray(the one with a skull icon)

click processes

to close the virus, select process and click yes to the question

(process to close)

  1. killer.exe
  2. lsass.exe (careful with this, this is also valid Microsoft process)
  3. smss.exe (in my case it was xmss.exe, also careful with this)

Note: close only file that have the same icon of Funny UST Scandal.avi.exe

For ProcessXP:

Run ProcessXP

It will run as a replacement of your Task Manager, which will be closed by the virus immediately. But fear not, it won’t closed, but it will be minimized to your system tray icons.

Quickly search for the “alien” process and press Del to kill it. In my case, I only delete the xmss.exe, and it’s gone! The virus will not be active anymore, unless you accidentally double click it.

This is how the icon looks like (it’s a masterpiece of an icon, but dangerous!):
Funny UST Scandal

The steps doesn’t end here, you still need to remove the funnyustscandal.avi.exe file from any hard disk drives directory that you have (only the hard disk directory, not deeper than that).

Another Two Alternatives:

Since you can’t view the file (it was hidden by the registry entry made by the virus), you must clear the registry first:
Download ANSAV antivirus from here.

Run the antivirus, select the Registry FX plugin by Eko Sugiarto. Check the “Show Hidden File”, “Enable Folder Option”, and “Show File Extension”. Click Restart Explorer. Then You can see those hidden files.

Delete the funnyustscandal.avi.exe from every drives directory (including your removable disks)

Other way, with Command Prompt (from TechPinoy Online):

1-now, click “start” then “run”
2-type “cmd” without quotes
3-type “cd\” without quotes
4-type “attrib -h -s smss.exe” without quotes
5-type “attrib -h -s autorun.inf” without quotes
6-type “start c:” without quotes(a new window will open)
7-select smss.exe,autorun.inf,Funny UST Scandal.avi.exe and delete it

If theres any drive or a partition type “d:” in command prompt without quotes
“d” is the drive letter then repeat the CMD STEPS number 4-7 above…….

  • now type this on the command prompt “cd windows” without quotes
  • type “attrib -h -s smss.exe” without quotes
  • type “start c:\windows” without quotes
  • delete the file smss.exe
  • now, goto c:\documents and settings\all users\startmenu\programs\startup
  • delete lsass.exe

Final steps

Destroy these registry entries by running REGEDIT from start menu, “run”, then type “regedit” and enter:



This is how ProcessXP looks like:
ProcessXP

Don’t let such a virus disturbs you and don’t rely on antivirus too much. Read this article for more information (in Indonesian):

Update (January 26th, 2008):
I just try out a remover tool by ghigz (you can see his/her comment down below) and found out that it can remove the funny ust scandal automatically. But still, it doesn’t throughly search your PC for the source. For this experiment I run the virus in my PC from a compressed zip file. It’s true that the virus had vanished, but the registry wasn’t fully fixed and the source file were not deleted. Yet I tried again those steps above to manually remove the virus permanently.
However, I recommend this remover tool for you to download from ghigz’s link or mine. All you need to do is:
1. run the remover tool,
2. fix the registry, and
3. search for funny ust scandal.exe or xmss.exe or smss.exe in every hard drive directory

Tags: , , , ,

65 Responses to I Killed The Funny UST Scandal Virus


  1. comment from gelly at 6 January, 2008

    thank you…^^::^^

  2. comment from Amit at 9 January, 2008

    nice tutorial ! is really working, got rid of this f**King Virus ! Thanks

  3. comment from razer at 10 January, 2008

    i know how to remove funny virus .step 1 first close all the applications that are running on your systen and then install quick evaluation copy then go to antirootkit run and it will delete all your funny uts scandal virus

  4. comment from razer at 10 January, 2008

    thankuuuuuu verrrrrry mucccch.It is working now i will not be fed up of this virus

  5. comment from firewalker at 10 January, 2008

    @Gelly:

    Glad it could help you, dear. :)

    @Amit:

    Thank you, Amit. Trust me, every people says so ;)

    @Razer:

    Could you be more specific on:
    1. which program you are going to close? Because not all applications are harmful. Failure to answer this will result in dangerous system failure
    2. What software did you use to run the Antirootkit that you mentioned?

    I see you are satisfied, I think there is no need for further answer to my previous questions :)

  6. comment from Niranjan at 11 January, 2008

    Thanks a lot, u helped me a lot.
    i never forget u my dear friend

  7. comment from michael at 11 January, 2008

    wow…. thanks for this info….
    matutuwa ang mga friends ko nito….
    sa wakas madedelete n din sa kanilang pc ang virus na ito…

    thks a lot…. ^^

  8. comment from firewalker at 11 January, 2008

    @Niranjan & Michael:

    No problem, folks. Save the files, you’ll never know when you need it :)

    This is great, I think most of the people who read the tutorials understand clearly.

  9. comment from karan kang at 11 January, 2008

    good tutorial, thankz dude

  10. comment from dandrev at 11 January, 2008

    thank you for this information… i learned a lot from this and truly effective… thanks again…

  11. comment from capub at 11 January, 2008

    i dont understand the last step.the regedit things.I typed regedit in start\run:What should i do next?

  12. comment from firewalker at 11 January, 2008

    @capub:

    You should search the registry entry within this directory: HKEY_LOCALMACHINE\Software\Microsoft\WindowNT\CurrentVersion\Winlogon and search whether there is an entry data with Name= shell and Value=(killer.exe)

    If you didn’t found it, it means that you are safe. You should also search for this:
    HKEY_CURRENT_USER\Software\Microsoft\windows\Currentversion\Run and search whether there is an entry data with Name=runonce and Value=(c:\windows\smss.exe)

  13. comment from Bobby at 15 January, 2008

    Thank you for alot of info about the virus!

    But I’m still having trouble though. It seems the one I accidentaly have is a heavier version of the virus. I followed your steps but once I start running the TaskKiller, it would crash to desktop after a few seconds. I still managed to install though by being quick the second time around.

    I then ran TaskKiller and I was surprised to find only smss.exe, without killer.exe, and there was only 1 lsass.exe which I cant tell whether its a small L or a capital i.

    Another problem would be the command prompt or cmd which the virus seems to be blocking as well because it closes as soon as I run it.

    I hope there are ways to fix my problem because I virtually cant use my laptop right now :(

  14. comment from firewalker at 15 January, 2008

    @Bobby:

    I hope you don’t give up yet. There is one way left. Using ProcessXP from this link, you don’t have to install anything. Just copy the file and run it. It will shows you like the picture above.

    Like you just said, it will close the program as soon as you run it. But not with ProcessXP, it will only hide the program. You can see from the system tray icon that ProcessXP is still running.

    You should search for the suspicious process immediately before the virus hides the program again. If you couldn’t find the false smss.exe (the valid smss.exe will show a description of “Windows NT Session Manager”), then search for other process such as xmss.exe (which I found in my case)

    Quickly, killed the process by pressing Del key.

    I hope this will solve the problem :)

  15. comment from Sahil at 15 January, 2008

    Thank you sooooooooooo much the regedit thing helped me get rid of this virus

  16. comment from Leon at 15 January, 2008

    Never heard of the virus, but I will sure keep my eyes open for it.

  17. comment from Magic at 22 January, 2008

    Jan 22nd 2008- I will let you know how I do. From what I read, this will work. By the way, who turn was it to watch the virus when it got loose?

  18. comment from Magic at 23 January, 2008

    I found a link:

    http://www.4shared.com/file/30402575/d70dafa8/Remover.html

    I need the original Virus back to see if it worked.
    My ‘A’ drive is quiet now though. can someone sen me the virus in a zip file?

  19. comment from JP at 23 January, 2008

    cheers mate..

    that virus is a real pain in the ass.. >.<

  20. comment from firewalker at 23 January, 2008

    @Sahil:

    Glad we could solve your problems

    @Leon:

    You heard it now ;)

    @Magic:

    I can’t send you a ZIP containing the virus because the email provider (Gmail or Yahoo) will consider it as a threat and won’t download/upload it.

    But I will send you the virus file via uploader called mihd.net.

    @JP:

    Yeah, but if the virus remover from Magic comes in handy, it will be a great help :)

  21. comment from ghigz at 26 January, 2008

    http://www.geocities.com/six519/Remover.zip

    download nio lng toh

  22. comment from firewalker at 26 January, 2008

    @Ghigz:

    Hey, I just tried it out. It works! Thanks for sharing, ghigz. But there are some points need to be look at. See my updates above (January 26th 2008)

  23. comment from billy at 27 January, 2008

    thanks for the path to the truth. but i don’t think disabling the regedit is necessary. anyway, you saved me from formatting! thanks a lot!

  24. comment from sujeetkumar at 4 February, 2008

    hello friends,,,,

    this is the removeal of funny scandal.avi.exe and autirun.inf…. pls download this exe..file and install it….

    the funny virus is to funny when ever ur instaling any software it automatically remove the installing file….so pls dont clik on the funnny.avi.exe….ok thank

  25. comment from Matthew at 6 February, 2008

    When I wenr through regeit,it said THe value of shell was explorer.exe………..is it safe?Or should I delete it?

  26. comment from Aev at 6 February, 2008

    thanks to this guide. ^__^

  27. comment from firewalker at 6 February, 2008

    @Matthew:

    No, don’t erase that. Explorer.exe is the application to run Windows Explorer. It’s safe

  28. comment from Big Tiger at 15 February, 2008

    hi

  29. comment from ice road at 15 February, 2008

    nice post!

  30. comment from jason at 16 February, 2008

    please help me i dont know how to kill the f****ng virus!!

  31. comment from firewalker at 16 February, 2008

    @Jason:

    Okay, what do you need to know, Jason? You can follow those steps above, but you can always ask when you don’t understand

  32. comment from sid at 19 February, 2008

    dude thanks a ton man thanks a lot trust me u have saved me i had my presentation tomoro thanks a lo again!!!

  33. comment from firewalker at 19 February, 2008

    @Sid:

    Glad you can make it to your presentation, Sid. Good luck.

  34. comment from Suhaib at 21 February, 2008

    Thanks alot this really helped me. Its very interesting………..

  35. comment from amit kumar srivastava at 6 March, 2008

    sir this vorus has fully damaged my pc please send the removal ….

  36. comment from aeronaegean at 7 March, 2008

    My sister’s PC got infected last night after I had plugged in my USB pendrive which I was not aware had UST virus on it. I saved the remover on diskettes and it only got infected and I cannot open it anymore. I wonder if it will do the same If I burn a copy of the remover and other programs to a CD then run everything as per instructed here. I only had one USB pendrive which I believe will infect my PC here at work if I plugged it in here to copy my remover…Please advice, thanks a lot….

  37. comment from firewalker at 8 March, 2008

    @amit:

    You can get the removal, here

    @aeronagean:

    If you afraid of having your PC infected, you could disable your autorun by following the steps here (choose the “other removable media” section). This way your PC wouldn’t infected by inserting your USB.

    However, you must always SHOW HIDDEN FILE and SYSTEM FILE to make sure that you can delete the UST file manually.

    And one more thing: don’t ever use RIGHT CLICK > EXPLORE anymore. Because the autorun.inf file will also run the virus automatically besides double clicking. Use the Windows+E button to explore your removable disk from the Explorer Tree.

  38. comment from lost at 8 March, 2008

    hey help…i got infected with this f*ckin virus i try evrything just to get rid of these but nothin works…..am desperate for help…whoever did these virus wish him luck….am so mad…

  39. comment from lost at 8 March, 2008

    hi why it didnt work for me
    evrytime i type those command it says file not found..now i cant open the internet…am lost o dont know what to do..help…

  40. comment from Ravi at 13 March, 2008

    hi, my problem is not this virus,
    my problem is i have my ‘folder option’
    its there in tools menu and its opening also, but whenever i click on show files radio btn, it accepts, bt when i apply settings and again open folderoption all settings are restored as original,

    means i cant register my values of folder option,
    i also tried to change few registry values like show superhidden and show hidden files to 1.

    bt still its not showing,

    i have changed local machine and current user both settings,

    please help, i have not formatted my laptop for 2 years already, and i dont want to do this, just one problem left, all others are fixed already!

    thank you

    _rAvi

  41. comment from firewalker at 13 March, 2008

    @Ravi:

    Actually I already answered it above, but here it is:

    Download ANSAV antivirus from this link.

    Run the antivirus, select the Registry FX plugin by Eko Sugiarto. Check the “Show Hidden File”, “Enable Folder Option”, and “Show File Extension”. Click Restart Explorer. Then You can see those hidden files.

  42. comment from Moorthi at 15 March, 2008

    sir , i have follwed your advice but it delete that’s time only when i restart my computer it will come again . what i shoud do plz tell me. i wait for ur hournable reply. i used windows xp

  43. comment from firewalker at 15 March, 2008

    @Moorthi:

    One thing I can be sure about is that the virus still resides in any of your harddisk drives. The virus will not come again if it is deleted thoroughly. If you want to delete thoroughly, you should change the folder option to “View Hidden File” and disable the “Hides System File”. That way you can see and delete it forever.

    Important: Don’t use right-click > Explore to browse your hard disk drive. Use the tree from View > Explorer Bar > Folder, instead. Otherwise you will activate the virus again.

    Other thing is that there might be other removable disk (USB FLash Disk) that is the cause/source of this annoying virus.

  44. comment from bharat at 2 April, 2008

    thanx sir,

  45. comment from moin at 9 April, 2008

    awesome dear…thanks for the information…i was wandering hw to remove funny ust scandal virus frm my computer…but lemme thanks ANSAV antivirus…it gr8

  46. comment from mrinal at 25 April, 2008

    hey brother thanks verry much i was know of the fact that my computer have virus but never done anything for this but when day i found my disk space is going low and i m not able to open folder option and task manager then realised to do something about that
    then downloaded software ansav and scanned and found 63 viruses
    first word came on my mouth is “sh*t”

    but u helped me a lot thanks bro

    *strong words edited

  47. comment from hareesh at 2 May, 2008

    hi gr8 job
    my problem is ,only my “show hidden files and folders” in the folder option is not working. I dont know much about a pc and please help me to solve my prob in a simple way plz ………

  48. comment from chadrey at 7 May, 2008

    u said that lsass.exe and smss.exe are valid Windows process. if that so, how will i be able to determine the valid one from not?
    i used already task killer to delete those two exe but whenever i turn on the pc, it keeps coming back.. though, my task manager and folder options are working properly.

    pls help..

  49. comment from firewalker at 8 May, 2008

    @hareesh:

    You can “show hidden files and folders” through ANSAV’s plugin called Registry FX. It will re-write the registry that is usually “damaged” after virus attack. Just pick the registry that you wanted to re-write and click the “Restart Explorer” button. Credit goes to the developer.

    @chadrey:

    Isass.exe sometimes manipulates you. The correct Windows system process starts with lowercase “L”. The one with uppercase “i” is usually Trojan.

    See this article: lsass.exe

    While smss.exe is a hideous fox. Sometimes you can’t distinguish the different without additional software. Here you can download the Security Task Manager
    And here is an article explained about it: smss.exe

  50. comment from Ashish at 19 May, 2008

    Need help.. My laptop was infected with UST. and I managed to clean it by format(though needed to format all the drives).

    How can I clean USB - Do I right click on the drive and format that?

    I wan know how can i be sure that the cds that I have played during the time of system infection are infected or not.

    Also I used the USB drive in laptop and used the same USB in my car stereo. I am sure that USB is infected. Will it effected my car stereo system?

  51. comment from vivek at 19 May, 2008

    in folder option whenever i enable “show hidden file” option and press ok it automatically changes to “dont show hidden files”
    rest all other problems are solved.
    is the virus still in my pc
    if yes how to solve this problem..

  52. comment from firewalker at 21 May, 2008

    @Ashish:

    As far as this virus concern, I think it only affect Windows Operating System.

    The trick to know whether your USB flash disk is infected is by selecting “show hidden file” in Folder Option. If you can’t show hidden files, then you have the same problem as vivek

    @vivek

    I also experience this, vivek. No need to worry. There are two possibilities:

    1. The virus still in your computer and active
    2. The virus is already deleted but you still can’t show hidden files

    My guess is that the registry that is tampered by the virus is still damaged. You need to manually reconfigure it or just download ANSAV antivirus from the link I provide above.

    This answer is the same as my previous answer to hareesh. ;)

  53. comment from Tony H at 17 June, 2008

    I picked up this virus whilst on a business trip to Sri Lanka. It began to eat my laptop! Thank you for taking the trouble to find a bullet for this one, much appreciated. The guidance was very clear. Keep up the good work!

  54. comment from amit kumar at 26 June, 2008

    i want to remove funny ust scandal virus from my computer

  55. comment from JABBAR at 12 July, 2008

    THANKS…………………..

  56. comment from pocoyo at 14 August, 2008

    I use ANSAV I was able to show the hidden files. But folder options:
    Do not show hidden files and folders
    Show hidden files and folders
    are not marked.
    and after i marked the Show hidden files and folders, all the hidden files will not be shown again and i need to use ANSAV again to show the hidden files. Can I do somthing to fix this? thanks for your help.

  57. comment from firewalker at 14 August, 2008

    @pocoyo:

    Like I said in my tutorial, after downloading ANSAV:

    Run the antivirus(ANSAV), select the Registry FX plugin by Eko Sugiarto. Check the “Show Hidden File”, “Enable Folder Option”, and “Show File Extension”. Click Restart Explorer. Then You can see those hidden files.

    If you still need to “show hidden files”, then the virus still active, so you need to stop their process with ProceXP.

    And check whether the Virus is still running by using ProceXP. When it’s done, repeat the steps with ANSAV.

    Don’t forget to delete Delete the funnyustscandal.avi.exe from every drives directory (including your removable disks)

  58. comment from pocoyo at 15 August, 2008

    followed the tutorial and thanks again for sharing

  59. comment from Nike Ray at 16 August, 2008

    thanks a lot mate… helped a lot

  60. comment from paperboy at 4 September, 2008

    could someone possibly upload the virus zipped for me?
    would like to test my self made remover which should
    even fix the “show hidden file” issue…

  61. comment from firewalker at 4 September, 2008

    It’s unfortunate that any email provider will scan it as a virus before you can download it -.-

  62. comment from paperboy at 4 September, 2008

    no chance via rapidshare or mihd.net?
    or any other filehoster?

  63. comment from firewalker at 4 September, 2008

    Oh, crap, I forgot those. Unfortunately, mine already deleted -.-

  64. comment from paperboy at 4 September, 2008

    too bad…
    well some lost hours more coding stuff i can’t actually use…
    thanks anyway

  65. comment from paperboy at 4 September, 2008

    got my hands on the virus and finished the remover…
    if the solution by firewalker and the app from PinoyTech did work out for you just ask here and i’ll upload the tool… its also fixes the restore
    hidden file issue…

Post a Comment