Google searching with pronounciation? Is Web 2.0 a bubble? Video v1.1 by Richter Scales
Jan 09

Files missing?
My Computer not opening?
Programs not opening?
Installations not occurring?
Task Manager not opening?
System deadly slow?

If your case can be matched with the conditions given above, in all probability, you’ve got the Autoit.BD worm, better known by a file it deposits in your C:\ drive, Funny UST Scandal.avi.exe. Pretty annoying. Almost nothing you can do. Only NOD32 v3 with updates can detect this trouble maker worm. Kaspersky can detect, but cannot remove. AVG, Norton, Avast! - all don’t even detect the virus.

Wait! Don’t format your system yet! Its a pretty simple virus to remove, and won’t take more than 10 minutes. It is recommended that you start up in Safe Mode before you do the following steps to remove the virus -

[scroll down for a file which automates all this]

    1. Download and install TaskKiller (326 KB freeware). We’re doing this because we need to remove a few tasks running, and Windows Task Manager (Alt + Ctrl + Del) gets killed by the virus
    2. Run Task Killer, and a red skull icon will appear on the system tray
    3. Left click it, and click Processes
    4. Select to kill these processes -
      • killer.exe
      • lsass.exe
      • smss.exe
    5. Now open up Command Prompt (Start>Run>command). Type each command and press Enter to run it -
      • cd\
      • attrib -h -s smss.exe
      • attrib -h -s autorun.inf
        [NOTE : Type each command exactly as its given here]
    6. Open My Computer and go to C:\ or whichever partition in which you’ve installed Windows.
    7. Delete the following files -
      • smss.exe
      • autorun.inf
      • Funny UST Scandal.avi.exe
    8. Go to Command Prompt again. Run this command -
      • attrib -h -s smss.exe
    9. Go to C:\Windows or wherever else you’ve installed Windows, and delete the file smss.exe.
    10. Now, go to C:\Documents and Settings\All users\Startmenu\Programs\Startup and delete the file lsass.exe.
    11. Open Registry Editor (Start>Run>regedit)
    12. Delete the key HKEY_LOCAL_MACHINE\Software\
      Microsoft\WindowNT\CurrentVersion\
      Winlogon=shell(killer.exe
    13. Delete the key  HKEY_CURRENT_USER\Software\
      Microsoft\windows\Currentversion\Run=runonce(c:\windows\smss.exe)
    14. You’re done!

 

OR, you can just download a remover file : Download Autoit.BD remover

  • After downloading, unzip, and run the exe file.
  • Then, do the steps 11, 12 and 13 as mentioned above.
  • You’re done :)

Thanks to fs6519 for recommending these steps, and making the remover file.

I hope that this post was useful. Cheers :)

Technorati Tags: , , , , , , , , , ,

Post-Plugin Library missing

48 Responses to “Autoit.BD worm removal - Funny UST Scandal.avi.exe”

  1. vinod Says:
    Gravatar!

    request for remove the virous name funny UST scandal.avi.exe

    thanks
    vinod rawat

  2. Mohan Says:
    Gravatar!

    Thats what I’ve given above…

    Good luck :)

  3. How to Remove the Funny UST Scandal AVI Virus Says:
    Gravatar!

    [...] Autoit.BD worm removal - Funny UST Scandal.avi.exe [...]

  4. Angad Says:
    Gravatar!

    hi

    Thankx for the soultion, it has helped…………..

  5. Mohan Says:
    Gravatar!

    My pleasure Angad :)

  6. jitender Says:
    Gravatar!

    Funny ust Scandal avi.exe

    Removing funny ust scandal avi.exe virus without any antivirus just installing fresh copy of windows. This is done by jitender kumar , MIET engineering college meerut, meerut , UP ,
    For any problem regarding this virus contact me

    Jitender kumar
    MIET engineering college, meerut
    UP, INDIA

    —- :: EDITED BY ADMIN TO WEED OUT POSSIBLY DANGEROUS ACTIONS :: —-

  7. Mohan Says:
    Gravatar!

    Jitender, sorry, thats a very crooked way, and a lot of things may go wrong while doing that. Its better to follow the way listed above, which is easy, and wont take too much time.

  8. SHUVRA BANIK Says:
    Gravatar!

    < < EDITED BY ADMIN FOR HAVING MALICIOUS CONTENT >>

  9. jitender Says:
    Gravatar!

    < < EDITED YET AGAIN BY ADMIN >>

    JITENDER, PLEASE STOP SPAMMING MY BLOG!

  10. Mohan Says:
    Gravatar!

    Please STOP spamming Jitender and Shuvra!!!

  11. seeee4 Says:
    Gravatar!

    can u plz tell a solution for New Folder (i dont know exact name of the virus, but it creates new folders, folder options are missing, regedit is disabled) virus

  12. Nish.. Says:
    Gravatar!

    Thanx a lot buddy :)

  13. Mohan Says:
    Gravatar!

    Most welcome Nish :)

    @seeee4 : I think thats the Heap41a virus.
    http://www.bloggingindia.net/2007/09/15/the-orkut-mozilla-hater-virus-w32usbworm-complete-removal/

  14. Akah Says:
    Gravatar!

    Use Avira anti-virus it will remove all virus,spyware,malware even Funny ust scandal .avi

  15. adz Says:
    Gravatar!

    when i downloaded Download Autoit.BD remover, i cant seem to open it the message appeared says “the archive is either unknown format or damaged.” what should i do?

  16. Mohan Says:
    Gravatar!

    @adz: Download again. Mail me if it didnt work. Try using WinRar as well.

    @Akah : Avira is in itself a malware. Beware.

    Cheers,
    Mohan

  17. rosh Says:
    Gravatar!

    system is restarting while clicking isass.exe

  18. Akah Says:
    Gravatar!

    hey adz! use HijackThis to enable to replace all damages system32 windows to your computer. because your computer is already infected. then use avira anti virus

  19. Akah Says:
    Gravatar!

    hey mr. mohan adz registry is already infected too he can’t use any antivirus unless he format his pc, my suggestion is use HijackThis then restart your pc then install antivirus i already encountered this problem too but i already fix it using HijackThis. I think Autoit.Bd is the same as worm/Sohanad.Bh. em i right Mohan?? =)

  20. Mohan Says:
    Gravatar!

    Hi Akah,
    You are partly right. Sohanad is a part of Autoit.BD, but Autoit goes a step further.

    And no, you haven’t completely removed the virus. I remember doing this at first, but side effects started showing up - in the form of drives and folders missing. Dunno what was wrong, but what I’ve mentioned above is a more complete way, and is not showing any side effects.

    BTW, drop the Mr., just call me Mohan :)

  21. magesh peter Says:
    Gravatar!

    HOW CAN I REMOVE FUNNY UST SCANDAL .AVI.EXE

  22. Mohan Says:
    Gravatar!

    Please read the post above…

  23. abhi Says:
    Gravatar!

    thanks a lot it really helped

  24. siva Says:
    Gravatar!

    im unable to remove funny scandal
    I have installed task killer and ended smss.exe and funny scandal.avi n then opened the cmd but it says no files found on typing smss.exe in it
    I have the virus in my i-pod too n it is working because of the virus can u plz help me out

  25. siva Says:
    Gravatar!

    though deleting the funny scandal.avi from my ipod by following the cmd steps it is coming back againn again

  26. dinesh Says:
    Gravatar!

    pls sugges me for removing this virous.
    i am a student oh hardware.
    i can’t purches antivirous.

  27. jun Says:
    Gravatar!

    how can i totally remove this worm? it disables my autorun to all of my programs and when i show the hidden files in the folder option, it automatically return to hidden.. i think my pc isn’t really fixed..

  28. Siddharth Says:
    Gravatar!

    THANKS THANKS A TONN

  29. Mohan Says:
    Gravatar!

    @Sid : You’re most welcome :)

    @jun: Well, yeah, you’re PC isnt totally fixed, and I think you haven’t followed the last part of the solution? Do the steps 11, 12 and 13. And the autorun infection, do you get a message which says some .bod thingy? If yes, then thats another virus…

    @siva: You can use the remover program. But I dont know about how to remove the virus from your iPod. I suggest you format it. You can, additionally, download the latest version of NOD32 v3, which successfully removes the virus.

    @abhi : No probs!

    Cheers all, and sorry for the very late reply :)

  30. Omed Says:
    Gravatar!

    Hello everybuddy………..
    Well, i have the same problem ,,,, BUT
    when i am installing task killer ….. at first the interent explorer gets closed, but still when i m getting some time and after i save the application its installation gets closed ….. so i cannot install that at all…
    What can i do ? PLEASE help me….

  31. dany Says:
    Gravatar!

    thank u

  32. jun Says:
    Gravatar!

    im done with all the steps.. i can already show my hidden files as before.. But the autorun whenever i insert any flash drive is still disabled. even to my optical drive.. Tnx for the help Mohan..

  33. raghukrishna Says:
    Gravatar!

    hi,
    i have downloaded the tash killer . while removilg the files isass.exe the pc is getting restarted , but after restarting the pc funny ust…. files rare reapearing so how to delet it completely? pleses do reply me

  34. raghukrishna Says:
    Gravatar!

    hi,
    I have downloaded the tash killer . while removilg the files isass.exe the pc is getting restarted , but after restarting the pc funny ust…. files are reapearing so how to delete it completely? please do reply me r can reply 2 my id raghukrishnas85@rediffmail.com

  35. Mohan Says:
    Gravatar!

    @raghu, I think you have the Sasser virus as well.

    Visit http://www.symantec.com/security_response/writeup.jsp?docid=2004-050114-1706-99

  36. angelo Says:
    Gravatar!

    {{}}
    I’m a bloody noob spammer who wants to have his a%% kicked. And I got it kicked by this Admin

    ====

    ADMIN : Hope you love the new message :P

  37. umesh Says:
    Gravatar!

    Nice blog.
    And good post.

    thanks

  38. Mohan Says:
    Gravatar!

    @Umesh : Cheers :)

    @Angelo : STOP SPAMMING. I’ve edited your post.

  39. abgsani Says:
    Gravatar!

    I use to clear FUNNY UST SCANDAL .AVI.EXE by using this 2 file :
    1. autoit.bd worm remover.exe
    2. Flash_Disinfector.exe

    Download this 2 files then
    1. Run “autoit.bd worm remover.exe” to remove Funny UST Virus
    2. Then run “Flash_Disinfector.exe” to clear autoit virus.
    (make sure to insert your thumdrive when you run “Flash_Disinfector.exe”)

    Your pc and thumdrive is now free FUNNY UST SCANDAL .AVI.EXE
    its take less then 5 min to clear and you pc smooth as usual, your task manager unlock and you can run msconfig and regedit.

  40. Funny UST Scandal.exe « Bli Wayan lah ne Says:
    Gravatar!

    [...] 1. …Autoit.BD [...]

  41. Review: Funny UST Virus « Paraluman Podcast Says:
    Gravatar!

    [...] Autoit.BD worm removal - Funny UST Scandal.avi.exe [...]

  42. Leny Says:
    Gravatar!

    Thank you so much Mohan…

  43. Mohan Says:
    Gravatar!

    My pleasure Leny! :)

  44. Prakash Says:
    Gravatar!

    I am not able to map my hard drives on double click.When i double click the drive the window for “open with” opens up.Can any one help me in this regard?

  45. satyanarayan mohanty Says:
    Gravatar!

    sir please send me all tools or detail tips to delete this funny UST scandal.avi.exe virus permanently.

  46. amrit anand Says:
    Gravatar!

    plese help to remove funn scandal AVI virus.no anti virus software arerunning.

  47. Mohan Says:
    Gravatar!

    Just read the post Anand… I’ve detailed the steps to take :)

  48. rimmi Says:
    Gravatar!

    i try it through rapid share send me more easy ways about it

Leave a Reply