Blackcom: Difference between revisions
Nemesis6051 (talk | contribs) mNo edit summary |
mNo edit summary |
||
(7 intermediate revisions by 3 users not shown) | |||
Line 1: | Line 1: | ||
{{ | {{PLS}}{{Infobox | ||
{{Infobox | |||
|title = Blackcom | |title = Blackcom | ||
|image = VBScript_icon.png | |image = VBScript_icon.png | ||
|maker = FlashUpload | |maker = FlashUpload | ||
|type = | |type = Application | ||
|date = 2009 | |date = 2009 | ||
|imagecaption = The '''BLACKCOM.VBS''' icon. | |imagecaption = The '''BLACKCOM.VBS''' icon. | ||
}} | }} | ||
'''Blackcom''' is a [[screamer]] | '''Blackcom''' is a 2009 [[screamer]] [[application]] that was created by FlashUpload and written in [[wikipedia:VBScript|VBScript]]. The download for it is currently lost, though there is still some footage confirming its existence. | ||
When launched, it displays a false MSWORD.exe error message that reads: | When launched, it displays a false MSWORD.exe error message that reads: "Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant". | ||
After a couple seconds, it displays a false binary error message that reads:<pre> | After a couple seconds, it displays a false binary error message that reads:<pre> | ||
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks | Microsoft Word Cannot Complete The Operation Requested Due To Security Risks | ||
Line 18: | Line 16: | ||
Please include the following in your error report | Please include the following in your error report | ||
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 | |||
01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 | |||
</pre> | </pre> | ||
This message is then followed by [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] saying: " | This message is then followed by a [[wikipedia:Microsoft_text-to-speech_voices#Windows_2000_and_Windows_XP|Microsoft Sam]] voice saying: "Caution: A virus has been detected." | ||
Blackcom then displays more | Blackcom then displays more fake error messages about nonexistent applications titled "svchost.exe" and "DRVSTORE", then displays a message stating: "An important system file is not found and WINDOWs can no longer run." | ||
After several seconds pass, the trojan initiates a system shutdown and corrupts | After several seconds pass, the trojan initiates a system shutdown and corrupts the "hal.dll" in the System32 directory, something required for Windows to boot up. Furthermore, even if Windows were bootable at that point, Blackcom will go further to change the homepage to a [[YouTube]] [[screamer]]; though it is currently unknown what this screamer really was. | ||
== | == Showcase Videos== | ||
<u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these | <u>NOTE</u>: Although this trojan contains a [[screamer]], it is not visible in these showcase videos. | ||
<div style="text-align: center;"> | <div style="text-align: center;"> | ||
<youtube width="320" height="180">zh8ceqtyGVI</youtube> | <youtube width="320" height="180">zh8ceqtyGVI</youtube> | ||
Line 34: | Line 32: | ||
{{Maliciousnav}} | {{Maliciousnav}} | ||
{{Comments}} | {{Comments}} | ||
[[Category: | [[Category:Partially lost]] | ||
[[Category:2009]] | [[Category:Malware]][[Category:2009]] | ||
[[Category:Other makers]] | [[Category:Other makers]] | ||
[[Category:Malicious scripts]] | [[Category:Malicious scripts]] | ||
[[Category:Applications]] | [[Category:Applications]] | ||
[[Category:Other scary images]] | [[Category:Other scary images]] | ||
[[Category:Non-indicative title]] |
Latest revision as of 12:26, 18 April 2025
![]() |
This page is about a screamer that is partially lost. |
---|
Blackcom is a 2009 screamer application that was created by FlashUpload and written in VBScript. The download for it is currently lost, though there is still some footage confirming its existence.
When launched, it displays a false MSWORD.exe error message that reads: "Microsoft Word cannnot open this document because it contains characters MSWORD.EXE does not understant".
After a couple seconds, it displays a false binary error message that reads:
Microsoft Word Cannot Complete The Operation Requested Due To Security Risks Please include the following in your error report 01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000 01011001 01101111 01110101 00100000 01000111 00100000 01110100 00100000 01100101 00100000 00100000 00100000
This message is then followed by a Microsoft Sam voice saying: "Caution: A virus has been detected."
Blackcom then displays more fake error messages about nonexistent applications titled "svchost.exe" and "DRVSTORE", then displays a message stating: "An important system file is not found and WINDOWs can no longer run."
After several seconds pass, the trojan initiates a system shutdown and corrupts the "hal.dll" in the System32 directory, something required for Windows to boot up. Furthermore, even if Windows were bootable at that point, Blackcom will go further to change the homepage to a YouTube screamer; though it is currently unknown what this screamer really was.
Showcase Videos
NOTE: Although this trojan contains a screamer, it is not visible in these showcase videos.