The Black Internet Virus

V_R

¯\_(ツ)_/¯
Moderator
Joined
Jan 31, 2005
Messages
13,572
Reaction score
1,888
This is possibly the strangest virus i've heard about lately....

Seems a site that hosts custom maps, mods etc etc for various games, CoD4, TF2 and alike have been hijacked by this. :(

Have a read....

http://forums.steampowered.com/forums/showthread.php?t=1360060

About this Virus
The new FPSBanana virus is a Rootkit virus known as "Black Internet". It is extremely dangerous to your system and security on your computer. A Rootkit virus buries itself into your Master Boot Record which forces the virus to load upon startup. You cannot disable the virus through safe-mode or "msconfig".
!NOTE!
VIRUS SCANNERS WILL NOT DETECT OR FIND THIS VIRUS! ONLY REAL-TIME VIRUS PROTECTION CAN DETECT AND STOP THIS VIRUS FROM BEING INSTALLED.

As of right now, the only working real-time detection and stopping of this virus is Kaspersky. Kaspersky will NOT remove the virus if you already have it.
The virus is obtained through a Java exploit from the advertisements on FPSBanana. Adblock will NOT stop you from getting this virus. Even if you have Ripe, you can still get this virus.

What does it do?
First, the virus buries itself into your Master Boot Record to keep you from detecting and removing the virus easily with any type of virus protection software. Afterwards, it loads up an application that will keep Internet Explorer open and showing you ads in the background or hidden voice ads. There are also reports of this being a Backdoor virus also which can transfer your sensitive information to the creators.

Symptoms
- Internet Explorer opens with ads randomly
- Windows keep minimizing
- Your computer sound will keep turning up and down randomly
- You will hear the clicks of pages being browsed in the background
- Visiting websites might not work

Do I have the Virus?
Even if you think you do not have the virus, you could still be infected!
There is an easy way to test if you have the virus. Follow these steps...

Step 1)
Press CTRL+ALT+DEL on your keyboard. Click "Open Task Manager".

Step 2)
On the Task Manger, click the "Processes" tabs.

Step 3)
Look through your processes for "loader.exe". If you have that file running, there will also be one or multiple instances of "iexplorer.exe". If so, You are infected!
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,738
Reaction score
1,204
old news, but thanks

fixmbr, delete crap, run AV :)


:wave:
 

nivrip

Yorkshire Cruncher
Joined
Mar 21, 2007
Messages
10,880
Reaction score
2,137
Thanks for that, Mucks.

I (e-mail address removed) have loader.exe under the Processes tab but there are two instances of iexplore.exe present ( not iexplorer.exe as you have stated)

Can I assume that I'm OK?
 

muckshifter

I'm not weird, I'm a limited edition.
Moderator
Joined
Mar 5, 2002
Messages
25,738
Reaction score
1,204
nivrip said:
Thanks for that, Mucks.

I (e-mail address removed) have loader.exe under the Processes tab but there are two instances of iexplore.exe present ( not iexplorer.exe as you have stated)

Can I assume that I'm OK?
I expect to see iexplore.exe if you use internet explorer. ;)

You ain't been anywhere near that site anyway, have you!


:user:
 

Ian

Administrator
Joined
Feb 23, 2002
Messages
19,873
Reaction score
1,499
Thanks for the heads up - I'd not heard of this before... it sounds pretty harsh to say the least! Glad I've Kaspersky :D

Just a reminder to anyone that doesn't have Secunia PSI that it's a very good (free!) tool to check that all your software is patched and up to date. It should help minimise any Java/PDF/etc. exploits on the net : http://secunia.com/vulnerability_scanning/personal/
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Similar Threads

Virus scan for the "bad guys" 1
Virus Attack 6
Virus alert. 5
Internet Security Software 2
Cannot Browse Anti Virus Websites 6
New Driveby Email Virus 0
Major Virus 15
Virus Warning 2

Top