Blackcom: Difference between revisions

Nemesis6051 (talk | contribs)
No edit summary
No edit summary
 
(11 intermediate revisions by 4 users not shown)
Line 1: Line 1:
{{Lost}}
{{PLS}}{{Infobox  
{{Infobox  
|title = Blackcom
|title =  
|image = VBScript_icon.png
|maker = FlashUploads
|maker = FlashUpload
|type = [[Application]]
|type = Application
|date = 2009
|date = 2009
|imagecaption = The '''BLACKCOM.VBS''' icon.
}}
}}
'''Blackcom''' is a [[screamer]] trojan created by FlashUpload. It was written in Visual Basic Script.


When launched, it displays a false MSWORD.exe error message that reads:
'''Blackcom''' is a 2009 [[screamer]] [[application]] that was created by FlashUpload and written in [[wikipedia:VBScript|VBScript]]. The download for it is currently lost, though there is still some footage confirming its existence.
Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant
 
After a couple seconds, it displays binary false error message that reads:<pre>
When launched, it displays a false MSWORD.exe error message that reads: "Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant".
After a couple seconds, it displays a false binary error message that reads:<pre>
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks  
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks  


Please include the following in your error report  
Please include the following in your error report  


01011011 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000
</pre>
This message is then followed by a [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] voice saying: "Caution: A virus has been detected."
 
Blackcom then displays more fake error messages about nonexistent applications titled "svchost.exe" and "DRVSTORE", then displays a message stating: "An important system file is not found and WINDOWs can no longer run."


01011011 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000
After several seconds pass, the trojan initiates a system shutdown and corrupts the "hal.dll" in the System32 directory, something required for Windows to boot up. Furthermore, even if Windows were bootable at that point, Blackcom will go further to change the homepage to a [[YouTube]] [[screamer]]; though it is currently unknown what this screamer really was.
</pre>
This message is then followed by [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] saying: "CAUTION! A virus has been detected."


Blackcom then displays more bogus fake error messages about svchost.exe and DRVSTORE, then displays a message stating:
== Showcase Videos==
An important system file is not found and WINDOWs can no longer run.
<u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcase videos.  
After several seconds pass, the trojan initiates a system shutdown and corrupts <code>hal.dll</code> in the System32 directory, rendering Windows unbootable. Furthermore. Blackcom will change the homepage to a [[YouTube]] [[screamer]], but it is unclear what the [[screamer]] was.
==Showcases==
<u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcases.  
<div style="text-align: center;">
<div style="text-align: center;">
<youtube width="320" height="180">zh8ceqtyGVI</youtube>
<youtube width="320" height="180">zh8ceqtyGVI</youtube>
<youtube width="320" height="180">zIXIJCopsDo</youtube>
<youtube width="320" height="180">zIXIJCopsDo</youtube>
</div>
</div>
{{Maliciousnav}}
{{Maliciousnav}}
{{Comments}}
{{Comments}}
[[Category:Malicious softwares]]
 
[[Category:Partially lost]]
[[Category:Malware]]
[[Category:2009]]
[[Category:2009]]
[[Category:Other makers]]
[[Category:Other makers]]
Line 38: Line 42:
[[Category:Applications]]
[[Category:Applications]]
[[Category:Other scary images]]
[[Category:Other scary images]]
[[Category:Non-indicative title]]