Blackcom: Difference between revisions
Nemesis6051 (talk | contribs) mNo edit summary |
No edit summary |
||
(5 intermediate revisions by one other user not shown) | |||
Line 4: | Line 4: | ||
|image = VBScript_icon.png | |image = VBScript_icon.png | ||
|maker = FlashUpload | |maker = FlashUpload | ||
|type = | |type = Application | ||
|date = 2009 | |date = 2009 | ||
|imagecaption = The '''BLACKCOM.VBS''' icon. | |imagecaption = The '''BLACKCOM.VBS''' icon. | ||
}} | }} | ||
'''Blackcom''' is a [[screamer]] | '''Blackcom''' is a [[screamer]] [[application]] created by FlashUpload. It was written in [[wikipedia:VBScript|VBScript]]. | ||
When launched, it displays a false MSWORD.exe error message that reads: | When launched, it displays a false MSWORD.exe error message that reads: "Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant". | ||
After a couple seconds, it displays a false binary error message that reads:<pre> | After a couple seconds, it displays a false binary error message that reads:<pre> | ||
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks | Microsoft Word Cannot Complete The Operation Requested Due To Security Risks | ||
Line 18: | Line 17: | ||
Please include the following in your error report | Please include the following in your error report | ||
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 | |||
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 | |||
</pre> | </pre> | ||
This message is then followed by [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] saying: "CAUTION! A virus has been detected." | This message is then followed by [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] saying: "CAUTION! A virus has been detected." | ||
Blackcom then displays more | Blackcom then displays more fake error messages about svchost.exe and DRVSTORE, then displays a message stating: "An important system file is not found and WINDOWs can no longer run." | ||
After several seconds pass, the trojan initiates a system shutdown and corrupts | After several seconds pass, the trojan initiates a system shutdown and corrupts "hal.dll" in the System32 directory, rendering Windows unbootable. Furthermore. Blackcom will change the homepage to a [[YouTube]] [[screamer]], but it is unknown what the screamer was. | ||
== Showcases== | == Showcases== | ||
<u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcases. | <u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcases. | ||
Line 34: | Line 33: | ||
{{Maliciousnav}} | {{Maliciousnav}} | ||
{{Comments}} | {{Comments}} | ||
[[Category: | [[Category:Malware]][[Category:2009]] | ||
[[Category:2009]] | |||
[[Category:Other makers]] | [[Category:Other makers]] | ||
[[Category:Malicious scripts]] | [[Category:Malicious scripts]] | ||
[[Category:Applications]] | [[Category:Applications]] | ||
[[Category:Other scary images]] | [[Category:Other scary images]] |
Latest revision as of 22:24, 17 December 2023
This screamer/shock site is lost. |
This screamer/shock site is lost. |
Blackcom is a screamer application created by FlashUpload. It was written in VBScript.
When launched, it displays a false MSWORD.exe error message that reads: "Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant".
After a couple seconds, it displays a false binary error message that reads:
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks Please include the following in your error report 01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000
This message is then followed by Microsoft Sam saying: "CAUTION! A virus has been detected."
Blackcom then displays more fake error messages about svchost.exe and DRVSTORE, then displays a message stating: "An important system file is not found and WINDOWs can no longer run."
After several seconds pass, the trojan initiates a system shutdown and corrupts "hal.dll" in the System32 directory, rendering Windows unbootable. Furthermore. Blackcom will change the homepage to a YouTube screamer, but it is unknown what the screamer was.
Showcases
NOTE: Although this trojan contains a screamer, it is not visible in these showcases.