The file extension .avi.exe is to confuse the executable file to an avi movie. In a windows system with all default settings only Funny UST Scandal.avi is visible[.exe extension is hidden].
Software used to build the virus= AutoIt V3
drop Files- killer.exe(4084 kb)
in c:\windows\lsass.exe(3920kb)
in c:\documents and settings\all users\start menu\programs\startup\smss.exe(4088kb)
in all root drives and in c:\windows
autorun.inf(1kb) in all root drives with a script
I actually have a copy of the script open in notepad right now.
I am not supposed to help with HJT logs yet, as I am still learning but if it was on my machine this is what I would do.
1) Download
Taskkiller
2)run taskiller and left click it on the system tray(the one with a skull icon)
click processes to close the virus
Close the following:
killer.exe
lsass.exe
smss.exe
close only files that have the same icon of Funny UST Scandal.avi.exe
3)
now, click “start” then “run”
- type “cmd” without quotes
- type “cd\” without quotes
- type “attrib -h -s smss.exe” without quotes
- type “attrib -h -s autorun.inf” without quotes
- type “start c:” without quotes (a new window will open)
- select smss.exe, autorun.inf, Funny UST Scandal.avi.exe and delete it
If theres any other drive or a partition type “d:” in command prompt without quotes “d” is the drive letter then repeat the CMD STEPS above
- now type on the command prompt “cd windows” without quotes.
- type “attrib -h -s smss.exe” (without quotes)
- type “start c:\windows” (without quotes)
- delete the file smss.exe
- now, goto c:\documents and settings\all users\startmenu\programs\startup
- delete lsass.exe
4)click “start” then “run”
- type “regedit” without quotes
- Navigate and remove the following entry HKLM\Software\Microsoft\WindowNT\CurrentVersion\Winlogon=shell(killer.exe)
HKCU\Software\Microsoft\windows\Currentversion\Run=runonce(c:\wind