• February 16th, 2008

      How to Remove Win32 AutoRun Worm - Funny UST Scandal - XMSS.exe How to Remove Win32 AutoRun Worm - Funny UST Scandal - XMSS.exe

      xmss-exe-funny-ust-scandal.png image by chaoskaizerYesterday I got a new type of “Stupid Worm” hidding in background as xmss.exe. It copied itself on Local disk and Windows Directory (%Windir%). Terminated “Windows Task Manager”, Windows Command Prompt (DOS-Prompt) & crashed System Internal Process Explorer (procxp.exe).

      Its not a funny video

      According to McAfee, this worm is known as W32/Autorun.worm.g.

      It can propagate itself over removable media and network drives and cause execution of malicious code via an autorun.inf file.

      XMSS.exe Win32 AutoRun Files

      • x:autorun.inf
      • x:xmss.exe
      • x:Funny UST Scandal.avi.exe
      • %Windir%\autorun.inf
      • %Windir%\xmss.exe
      • %Windir%\Funny UST Scandal.avi.exe

      Fixes Win32 AutoRun.* Worm

      Here’s a few step to prevent Win32 AutoRun Worm.

      1. Disabled System Restore for Temporary - KB 264887
      2. Boot Windows in Safe Mode - KB 315222
      3. In Windows Safe Mode, Open Windows Registry Editor

        Windows Start > Run > Regedit

      4. Browse to the following registry settings ↓

        HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\Shell

      5. Replace
        explorer.exe, xmss.exe with exporer.exe
        xmss-exe-regedit.png
      6. Delete all the following files
        • C\autorun.inf
        • C\xmss.exe
        • C\Funny UST Scandal.avi.exe
        • X:\autorun.inf
        • X:\xmss.exe
        • X:\Funny UST Scandal.avi.exe
        • %Windir%\autorun.inf
        • %Windir%\xmss.exe
        • %Windir%\Funny UST Scandal.avi.exe

        %Windir% refers to the Windows folder (e.g. C:\Windows, C:\WindowsNT) and X: is drive letters used by a removable or network drive

      7. Clean All Windows Temporary Files
      8. Restart Windows

      XMSS.exe Win32 Autorun Variants

      VirusTotal.com - Dec 2007 Results.

      Antivirus Version Last Update Result
      AhnLab-V3 - - -
      AntiVir - - -
      Authentium - - -
      Avast - - -
      AVG - - -
      BitDefender - - -
      CAT-QuickHeal - - Worm.AutoRun.abt
      ClamAV - - Trojan.Autoit-6
      DrWeb - - -
      eSafe - - suspicious Trojan/Worm
      eTrust-Vet - - -
      Ewido - - -
      FileAdvisor - - -
      Fortinet - - W32/Autoit.BG!tr
      F-Prot - - W32/Trojan!c4a4
      F-Secure - - Trojan.Win32.Autoit.bg
      Ikarus - - Virus.Win32.AutoRun.pc
      Kaspersky - - Trojan.Win32.Autoit.bg
      McAfee - - -
      Microsoft - - -
      NOD32v2 - - Win32/HackAV.P
      Norman - - -
      Panda - - Suspicious file
      Prevx1 - - Trojan.DoS.Win32.Opdos
      Rising - - Worm.Win32.Autorun.jax
      Sophos - - -
      Sunbelt - - -
      Symantec - - -
      TheHacker - - Trojan/Autoit.bg
      VBA32 - - Virus.Win32.AutoRun.pc
      VirusBuster - - Trojan.AutoIt.BB
      Webwasher-Gateway - - Riskware.HackAV

      External Links

      Bookmarks

8 Responses to “How to Remove Win32 AutoRun Worm - Funny UST Scandal - XMSS.exe”

    • Noah Ark's photo Noah Ark
    • RE: How to Remove Win32 AutoRun Worm - Funny UST Scandal - XMSS.exe
      2 months, 3 weeks ago on February 19th, 2008 at 10:02 pm 3 url · microId
      2

      here's a quickie.

      • restart windows → press ctrl+alt+del twice
      • boot in safe mode: after you see the bios startup screen press F8 this will let you choose "Windows Startup Mode" select safe mode.
      • in windows safe mode. Press the Windows Start key (the windows Logo), select Run.
      • on the "Run" input box, type In "Regedit"
      • Regedit Editor. Browse like you normally do with windows Explorer ..
      • click HKEY_LOCAL_MACHINE first then find SOFTWARE and so on. The directory is like in step 4 "HKEY_LOCAL_MACHINE → SOFTWARE → Microsoft → Windows NT → CurrentVersion → Winlogon → Shell"
      • read step 5 and continue.

    • jitender kumar's photo jitender kumar
    • RE: How to Remove Win32 AutoRun Worm - Funny UST Scandal - XMSS.exe
      2 months ago on March 10th, 2008 at 10:39 am 3 url · microId
      6

      Remove Funny Scandal without any anti virus

      Remove completely funny ust scandal avi.exe(virus) from your hard disk without using any anti virus and just installing fresh copy of window. This is done by jitender kumar. For any problem regarding viruses contact me on my e mail id

      Funny ust scandal.avi.exe run these files :

      • Funny.exe
      • Killer.exe
      • Smss.exe or xmss.exe

      If your computer corrupted with funny with xmss.exe then you :

      • can’t open Command prompt by run CMD command
      • can’t install most of software
      • can’t open task manager
      • can’t restore your system
      • can’t open folder options
      • can’t see hidden files and folders

      And if funny with smss.exe then you are in some better condition . ok now apply this steps and give me reply and your experience on my e mail id and you can be my friend. Ok best of luck so for removing this virus you must install windows at one time and following these steps you will remove this virus.

      1. install a fresh copy of window by formatting any drive.
      2. do not open any drive(after installation of window) before removing virus from your system.
      3. make a restore point
      4. in folder options
        • (a).check mark before shows hidden files and folders.
        • (b).unmark the option hide protected operating system files ( recommended )
      5. after applying this options check one more time that they are applied or not they must be applied-shows virus is not corrupted your windows
      6. open search and select all files and folders and mark on more advance options (search hidden files and folders,search system folders, search subfolders)
      7. search autorun file from all drives(just within drive) and delete them, after deleting these files right click on each drive and check there is autorun option or not, it shows virus in your drive now restart your system the autorun option will not be there in right click on drives
      8. now open drive and delete virus like funny ust scandal, smss.exe, xmss.exe
      9. now again check the folder option selected option must be applied if they are not applied or it does not show hidden files and folders it means you did any mistake by following these steps and virus corrupt your windows, now restore your system and repeate from step 4.
      10. delete this viruses from the folder RECYCLER in every drive, this virus must be at least one folder in recycler folder of each drive .
      11. from folder option unmark the option hide protected operating system files.
      OR

      another solution for removing this virus first follow above 4 steps and then try this trick

      1. open media player and from file option select open
      2. select type of file as "any file"
      3. and open your all drive one by one and delete autorun, funny,smss.exe,xmss.exe files from your all drive then restart your system
      4. and check virus on your computer by right clicking on all drive and if their is autoplay or autorun option then virus is their in your drive othervise virus is removed then use your full system then follow 10 and 11 step.

      I am a student and struggling for bright career in IT company so please must reply me your experience about viruses if you feel good by my solution. It will motivate me.

      Jitender kumar
      MCA student of software engineering
      MIET Engineering college, Meerut
      UP, INDIA

      Gmail email icon generator by http://services.nexodyne.com/email/ ~ed

    • khairul afandi's photo khairul afandi
    • RE: How to Remove Win32 AutoRun Worm - Funny UST Scandal - XMSS.exe
      3 weeks, 3 days ago on April 18th, 2008 at 3:19 pm 3 url · microId
      8

      firstly you have to downloads killbox.exe to enable you to delete the xmss.exe file....you must delete it in every partition of your computer and after that you can adjust the regsitry and use the antivirus,the other 2 file just ignore it and delete it using antivirus...i use ↓ bitdefender

      but must remember to turn off the system restore first...anythings...ask me at yahoo messenger...afandi_mustaffa

Have your say

  • Hint: Write as if you were talking to a good friend (in front of your mother).

Disclaimer: For any content that you post, you hereby grant to Kakkoi the royalty-free, irrevocable, perpetual, exclusive and fully sublicensable license to use, reproduce, modify, adapt, publish, translate, create derivative works from, distribute, perform and display such content in whole or in part, world-wide and to incorporate it in other works, in any form, media or technology now known or later developed. Some rights reserved.