1,545
edits
Nemesis6051 (talk | contribs) mNo edit summary |
No edit summary |
||
(4 intermediate revisions by one other user not shown) | |||
Line 4: | Line 4: | ||
|image = VBScript_icon.png | |image = VBScript_icon.png | ||
|maker = FlashUpload | |maker = FlashUpload | ||
|type = | |type = Application | ||
|date = 2009 | |date = 2009 | ||
|imagecaption = The '''BLACKCOM.VBS''' icon. | |imagecaption = The '''BLACKCOM.VBS''' icon. | ||
}} | }} | ||
'''Blackcom''' is a [[screamer]] | '''Blackcom''' is a [[screamer]] [[application]] created by FlashUpload. It was written in [[wikipedia:VBScript|VBScript]]. | ||
When launched, it displays a false MSWORD.exe error message that reads: | When launched, it displays a false MSWORD.exe error message that reads: "Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant". | ||
After a couple seconds, it displays a false binary error message that reads:<pre> | After a couple seconds, it displays a false binary error message that reads:<pre> | ||
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks | Microsoft Word Cannot Complete The Operation Requested Due To Security Risks | ||
Line 18: | Line 17: | ||
Please include the following in your error report | Please include the following in your error report | ||
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 | |||
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 | |||
</pre> | </pre> | ||
This message is then followed by [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] saying: "CAUTION! A virus has been detected." | This message is then followed by [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] saying: "CAUTION! A virus has been detected." | ||
Blackcom then displays more | Blackcom then displays more fake error messages about svchost.exe and DRVSTORE, then displays a message stating: "An important system file is not found and WINDOWs can no longer run." | ||
After several seconds pass, the trojan initiates a system shutdown and corrupts | After several seconds pass, the trojan initiates a system shutdown and corrupts "hal.dll" in the System32 directory, rendering Windows unbootable. Furthermore. Blackcom will change the homepage to a [[YouTube]] [[screamer]], but it is unknown what the screamer was. | ||
== Showcases== | == Showcases== | ||
<u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcases. | <u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcases. | ||
Line 34: | Line 33: | ||
{{Maliciousnav}} | {{Maliciousnav}} | ||
{{Comments}} | {{Comments}} | ||
[[Category: | [[Category:Malware]][[Category:2009]] | ||
[[Category:2009]] | |||
[[Category:Other makers]] | [[Category:Other makers]] | ||
[[Category:Malicious scripts]] | [[Category:Malicious scripts]] | ||
[[Category:Applications]] | [[Category:Applications]] | ||
[[Category:Other scary images]] | [[Category:Other scary images]] |
edits