So FPSBANANA got infected (and will infect you too) menu

User Tag List

Results 1 to 13 of 13
  1. #1
    Dragonshadow's Avatar ★ Elder ★
    Reputation
    1170
    Join Date
    Apr 2007
    Posts
    3,858
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)

    So FPSBANANA got infected (and will infect you too)

    The site is currently infected with the 'Black Internet' trojan.

    It's embedded in the site itself somehow, which means all you have to do is go there-- you don't have to download anything, and you'll be infected. All the following programs did not detect the trojan AVG, Ad-Aware and Windows Defender.

    If you've been to FPSBanana in the last day or less, check your task manager. Look for iexplore.exe running-- or multiple instances of it if you are surfing with internet explorer, of course. You might also be hearing audio advertisements and/or multiple weird noises and mouseclicks.

    About this Virus
    The new FPSBanana virus is a Rootkit virus known as "Black Internet". It is extremely dangerous to your system and security on your computer. A Rootkit virus buries itself into your Master Boot Record which forces the virus to load upon startup. You cannot disable the virus through safe-mode or "msconfig".
    !NOTE!
    VIRUS SCANNERS WILL NOT DETECT OR FIND THIS VIRUS! ONLY REAL-TIME VIRUS PROTECTION CAN DETECT AND STOP THIS VIRUS FROM BEING INSTALLED.

    As of right now, the only working real-time detection and stopping of this virus is Kaspersky. Kaspersky will NOT remove the virus if you already have it.
    The virus is obtained through a Java exploit from the advertisements on FPSBanana. Adblock will NOT stop you from getting this virus. Even if you have Ripe, you can still get this virus.

    What does it do?
    First, the virus buries itself into your Master Boot Record to keep you from detecting and removing the virus easily with any type of virus protection software. Afterwards, it loads up an application that will keep Internet Explorer open and showing you ads in the background or hidden voice ads. There are also reports of this being a Backdoor virus also which can transfer your sensitive information to the creators.

    Symptoms
    - Internet Explorer opens with ads randomly
    - Windows keep minimizing
    - Your computer sound will keep turning up and down randomly
    - You will hear the clicks of pages being browsed in the background
    - Visiting websites might not work

    Do I have the Virus?
    Even if you think you do not have the virus, you could still be infected!
    There is an easy way to test if you have the virus. Follow these steps...

    Step 1)
    Press CTRL+ALT+DEL on your keyboard. Click "Open Task Manager".

    Step 2)
    On the Task Manger, click the "Processes" tabs.

    Step 3)
    Look through your processes for "loader.exe". If you have that file running, there will also be one or multiple instances of "iexplorer.exe". If so, You are infected!



    Removing the Virus
    To remove this virus, you are REQUIRED to have a Windows disk corresponding to your version of Windows OR a recovery drive that came from factory. If you do not, you are pretty much screwed... There are other ways but they have a 10% chance of working.

    So now, insert your Windows disk into your CD/DVD drive and restart your computer. When it says to "Press any key to continue..." do so. If you have a recovery drive, you will either have to press a key that is defined on the Bios screen or press F8 before Windows loads. Choose to recover your Windows installation.

    After you choose the option to recover your Windows Installation, you can choose to use Command Prompt to do so. Once the Command Prompt opens, type the following...

    Windows XP: fixmbr
    Vista or 7: bootrec.exe /FixMbr

    After the process completes, you can then close command prompt and Restart your computer. When the computer loads up again, the Virus has been disabled. You just need to delete the file.

    You can either use CCleaner to delete all over your Windows Temporary Files or goto your temp folder in the following location...
    Windows XP: C:\Documents and Settings\Application Data\temp
    Vista or 7: C:\Users\[YOUR USERNAME]\AppData\Local\Temp

    Find the files "loader.exe" and "smss.exe", and delete them.

    You should be all set now and the infection should be gone. Double check by following the the steps to check for the virus above.
    Copypasta'd, removed minor retardation, added some info. Lol java exploit.

    unmodified source: WARNING: Avoid FPSBanana!!!! - Steam Users' Forums


    And no "mac is better" shit.
    Look at your post, now back to mine; Now back to your post, now back to mine. Sadly, it isn't mine, but if you stopped trolling and started posting legitimate content, it could look like mine. Look down, backup, where are you? You're scrolling through threads, reading the post your post could look like. What did you post? Back at mine; It's a reply saying something you want to hear. Look again and the reply is now diamonds.

    Anything is possible when you think before you post. The moon is shrinking.

    So FPSBANANA got infected (and will infect you too)
  2. #2
    Dombo's Avatar Banned
    Reputation
    622
    Join Date
    Nov 2008
    Posts
    1,421
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Thanks for the headsup, I download there regularly.

  3. #3
    2dgreengiant's Avatar ★ Elder ★


    Reputation
    1190
    Join Date
    Feb 2007
    Posts
    7,129
    Thanks G/R
    1/1
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    How was this discovered?
    If you need me you have my skype, if you don't have my skype then you don't need me.

  4. #4
    Dombo's Avatar Banned
    Reputation
    622
    Join Date
    Nov 2008
    Posts
    1,421
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by 2dgreengiant View Post
    How was this discovered?
    Perhaps it's best to ask that on the official thread on the steam fora.

  5. #5
    Dragonshadow's Avatar ★ Elder ★
    Reputation
    1170
    Join Date
    Apr 2007
    Posts
    3,858
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Yes 2d how does someone find out a website is infected and infecting everyone who visits... oh wait
    Last edited by Dragonshadow; 07-13-2010 at 06:39 PM.
    Look at your post, now back to mine; Now back to your post, now back to mine. Sadly, it isn't mine, but if you stopped trolling and started posting legitimate content, it could look like mine. Look down, backup, where are you? You're scrolling through threads, reading the post your post could look like. What did you post? Back at mine; It's a reply saying something you want to hear. Look again and the reply is now diamonds.

    Anything is possible when you think before you post. The moon is shrinking.

  6. #6
    JD's Avatar Fedora Potato Johnson V
    Reputation
    1113
    Join Date
    Jan 2008
    Posts
    3,129
    Thanks G/R
    12/89
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    A mac user probably popped by and saw "Would you like to download this file?"... (Yeah, we do get those popups (unless the hacker is a very very good one))




  7. #7
    Rock Lee's Avatar Banned
    Reputation
    41
    Join Date
    Jul 2010
    Posts
    155
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by Dragonshadow View Post
    And no "mac is better" shit.
    Originally Posted by -JD- View Post
    A mac user probably popped by and saw "Would you like to download this file?"... (Yeah, we do get those popups (unless the hacker is a very very good one))
    Wait wat....?

  8. #8
    Dragonshadow's Avatar ★ Elder ★
    Reputation
    1170
    Join Date
    Apr 2007
    Posts
    3,858
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by SombreroShark View Post
    Wait wat....?
    Yea, I facepalmed.
    Look at your post, now back to mine; Now back to your post, now back to mine. Sadly, it isn't mine, but if you stopped trolling and started posting legitimate content, it could look like mine. Look down, backup, where are you? You're scrolling through threads, reading the post your post could look like. What did you post? Back at mine; It's a reply saying something you want to hear. Look again and the reply is now diamonds.

    Anything is possible when you think before you post. The moon is shrinking.

  9. #9
    sgtmas2006's Avatar Member
    Reputation
    7
    Join Date
    Oct 2007
    Posts
    103
    Thanks G/R
    0/0
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Ooh, I want a link!

  10. #10
    JD's Avatar Fedora Potato Johnson V
    Reputation
    1113
    Join Date
    Jan 2008
    Posts
    3,129
    Thanks G/R
    12/89
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Originally Posted by SombreroShark View Post
    Wait wat....?
    I didn't actually say Mac is better... I just think that's how they found out.




  11. #11
    d3rrial's Avatar Contributor Authenticator enabled
    Reputation
    127
    Join Date
    Apr 2010
    Posts
    527
    Thanks G/R
    0/5
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Hmm, I have never been to FPSBanananana tho. Don't even know what it is oO

  12. #12
    Opirity's Avatar Contributor
    Reputation
    139
    Join Date
    Apr 2010
    Posts
    462
    Thanks G/R
    6/2
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    Nanananananananana fpsba ....

  13. #13
    d3rrial's Avatar Contributor Authenticator enabled
    Reputation
    127
    Join Date
    Apr 2010
    Posts
    527
    Thanks G/R
    0/5
    Trade Feedback
    0 (0%)
    Mentioned
    0 Post(s)
    Tagged
    0 Thread(s)
    You're doing it wrong:

    |nananananananana FPSbananana|

Similar Threads

  1. recall this acc 4 me and i will give you an acc
    By hummer92 in forum WoW Scams Help
    Replies: 1
    Last Post: 09-18-2008, 06:41 AM
  2. Replies: 21
    Last Post: 08-26-2008, 06:58 PM
  3. [WORKING] Gold Scam, AND A GM WILL HELP YOU DO IT!!!
    By ram_kalam in forum WoW Scam Prevention
    Replies: 16
    Last Post: 04-25-2008, 11:23 PM
All times are GMT -5. The time now is 02:45 AM. Powered by vBulletin® Version 4.2.3
Copyright © 2024 vBulletin Solutions, Inc. All rights reserved. User Alert System provided by Advanced User Tagging (Pro) - vBulletin Mods & Addons Copyright © 2024 DragonByte Technologies Ltd.
Digital Point modules: Sphinx-based search