FPSBanana

A forum for computer hardware and software issues
Dog
Server Ops
Server Ops
User avatar
Posts: 14317
Joined: Sun Oct 15, 2006 12:12 am
Location: In the bath, having a good think....

Games Played

Ville Awards

Dog - RIP Stevo’s avatar
Loading…

FPSBanana

Post by Dog » Tue Jul 13, 2010 9:44 pm

Apparently it has been compromised by a virus.

http://forums.steampowered.com/forums/s ... ostcount=1
http://forums.steampowered.com/forums/s ... ?t=1347821

From GTFO
The site is currently infected with the 'Black Internet' trojan.

It's embedded in the site itself somehow, which means all you have to do is go there-- you don't have to download anything, and you'll be infected. All the following programs did not detect the trojan AVG, Ad-Aware and Windows Defender.

If you've been to FPSBanana in the last day or less, check your task manager. Look for iexplore.exe running-- or multiple instances of it if you are surfing with internet explorer, of course. You might also be hearing audio advertisements and/or multiple weird noises and mouseclicks.

Apparently this trojan infects the MBR, to fix the virus problem make all folders viewable in the control panel -> large icons -> folder options -> view -> show hidden files, folders and drives, then reboot in Safe Mode and go here:

C:\Users\YOURUSERNAME\Appdata\Local\Temp

and deleting these two files:

Loader.exe
Smss.exe

And until further notice I strongly suggest that you avoid going to the website.
Originally Posted by GTFO wrote:
About this Virus
The new FPSBanana virus is a Rootkit virus known as "Black Internet". It is extremely dangerous to your system and security on your computer. A Rootkit virus buries itself into your Master Boot Record which forces the virus to load upon startup. You cannot disable the virus through safe-mode or "msconfig".
!NOTE!
VIRUS SCANNERS WILL NOT DETECT OR FIND THIS VIRUS! ONLY REAL-TIME VIRUS PROTECTION CAN DETECT AND STOP THIS VIRUS FROM BEING INSTALLED.

As of right now, the only working real-time detection and stopping of this virus is Kaspersky. Kaspersky will NOT remove the virus if you already have it.
The virus is obtained through a Java exploit from the advertisements on FPSBanana. Adblock will NOT stop you from getting this virus. Even if you have Ripe, you can still get this virus.

What does it do?
First, the virus buries itself into your Master Boot Record to keep you from detecting and removing the virus easily with any type of virus protection software. Afterwards, it loads up an application that will keep Internet Explorer open and showing you ads in the background or hidden voice ads. There are also reports of this being a Backdoor virus also which can transfer your sensitive information to the creators.

Symptoms
- Internet Explorer opens with ads randomly
- Windows keep minimizing
- Your computer sound will keep turning up and down randomly
- You will hear the clicks of pages being browsed in the background
- Visiting websites might not work

Do I have the Virus?
Even if you think you do not have the virus, you could still be infected!
There is an easy way to test if you have the virus. Follow these steps...

Step 1)
Press CTRL+ALT+DEL on your keyboard. Click "Open Task Manager".

Step 2)
On the Task Manger, click the "Processes" tabs.

Step 3)
Look through your processes for "loader.exe". If you have that file running, there will also be one or multiple instances of "iexplorer.exe". If so, You are infected!

Image

Removing the Virus
To remove this virus, you are REQUIRED to have a Windows disk corresponding to your version of Windows OR a recovery drive that came from factory. If you do not, you are pretty much screwed... There are other ways but they have a 10% chance of working.

So now, insert your Windows disk into your CD/DVD drive and restart your computer. When it says to "Press any key to continue..." do so. If you have a recovery drive, you will either have to press a key that is defined on the Bios screen or press F8 before Windows loads. Choose to recover your Windows installation.

After you choose the option to recover your Windows Installation, you can choose to use Command Prompt to do so. Once the Command Prompt opens, type the following...

Windows XP: fixmbr
Vista or 7: bootrec.exe /FixMbr

After the process completes, you can then close command prompt and Restart your computer. When the computer loads up again, the Virus has been disabled. You just need to delete the file.

You can either use CCleaner to delete all over your Windows Temporary Files or goto your temp folder in the following location...
Windows XP: C:\Documents and Settings\Application Data\temp
Vista or 7: C:\Users\[YOUR USERNAME]\AppData\Local\Temp

Find the file "loader.exe" and delete it.

You should be all set now and the infection should be gone. Double check by following the the steps to check for the virus above.
Image

TheCarpe
Server Admin
Server Admin
User avatar
Posts: 9717
Joined: Sun Nov 04, 2007 11:32 pm
Location: Inside a refrigerator in Guatemala

Games Played

Ville Awards

TheCarpe’s avatar
Loading…

Re: FPSBanana

Post by TheCarpe » Tue Jul 13, 2010 10:00 pm

Huh, how about that. I haven't really been there in some time but I used to quite a bit.

Thanks for the heads up, Dog.
Image
Heck's Kitchen - TVC'08 & '11 ** The Axecutioners - TVC'09 ** Hale's Angels - TVC'10 ** CCCP - TVC'12 ** Ville Cuppin' Cakes - TVC'13 ** TheCarpetbaggers - TVC'14 CHAMPIONS

Dirty Dan
Server Admin
Server Admin
User avatar
Posts: 2622
Joined: Tue Mar 03, 2009 12:33 am
Location: Portland, OR

Games Played

Ville Awards

Dirty Dan.TVR’s avatar
Loading…

Re: FPSBanana

Post by Dirty Dan » Tue Jul 13, 2010 10:05 pm

Wow, I didn't know viruses could do that, scary.
Image

Flobee
Retired Admin
Retired Admin
User avatar
Posts: 1850
Joined: Sun Feb 10, 2008 2:48 am
Location: Rad Coast, Awestralia

Games Played

Ville Awards

Re: FPSBanana

Post by Flobee » Tue Jul 13, 2010 10:15 pm

Holy cow. :afraid:
where doing this man.
where MAKING THIS HAPEN.

ShadyIMG
Villun
Villun
User avatar
Posts: 277
Joined: Sun May 24, 2009 10:24 pm

Games Played

Ville Awards

ShadyIMG’s avatar
Loading…

Re: FPSBanana

Post by ShadyIMG » Tue Jul 13, 2010 11:05 pm

Oh wow. Guess I'll never go to that site...ever.

Buzzy Beetle
Retired Admin
Retired Admin
User avatar
Posts: 2899
Joined: Wed Oct 17, 2007 10:43 pm
Location: Subterranean cavern systems, Mushroom Kingdom

Games Played

Ville Awards

Buzzy Beetle’s avatar
Loading…

Re: FPSBanana

Post by Buzzy Beetle » Wed Jul 14, 2010 12:09 am

*recovers from loads 'o paranoia*


I just re-downloaded walkway yesterday from FPSBanana. However, I don't have any loader or iexplorer processes running. I dodged a bullet there...
Image
I proudly support Independent Developers, Local Businesses, and SNAILGOSH.

Supreveio
Retired Admin
Retired Admin
User avatar
Posts: 1506
Joined: Wed Jun 18, 2008 12:36 pm
Location: Michigan
Minecraft name: Supreveio
Blizzard tag: Supreveio#1728

Games Played

Ville Awards

Supreveio’s avatar
Loading…

Re: FPSBanana

Post by Supreveio » Wed Jul 14, 2010 6:38 am

When isn't FPSbanana compromised by a virus?
"So what have you been up to, man? Haven't seen you in so long!"
"Ah, you know how it is. Doin' a lot of side projects, some consulting, maybe a little freelance... Those are words that people say when they haven't actually been doing anything, right?"

M's
Server Admin
Server Admin
Posts: 7594
Joined: Fri May 25, 2007 6:09 am
Location: Vilonia, Arkansas

Games Played

Ville Awards

<eVa> M's’s avatar
Offline

Re: FPSBanana

Post by M's » Wed Jul 14, 2010 6:45 am

I found this on mine "iexplore.exe*32" is that bad?

KRG
Retired Admin
Retired Admin
User avatar
Posts: 5213
Joined: Thu Nov 09, 2006 2:17 pm

Games Played

Ville Awards

Re: FPSBanana

Post by KRG » Wed Jul 14, 2010 7:07 am

That sounds fine mlite. You must be running Windows 7 or Vista?

You would usually be looking for iexplorer.exe as opposed to iexplore.exe, note the extra "r" at the end. Also note that the new IE is supposed to run 2 instances of iexplore.exe whenever you surf. It is part of the in-built tab recovery feature of IE which is used to prevent a problematic web page, (would normally cause IE to hang/crash) from affecting any other open tabs.

One simple way to check is to close all open internet windows (exit Steam too) then CTRL+ALT+DEL and bring up the task manager. Stop all instances of iexplore.exe (do not stop "explorer.exe"). Watch the task manager for a few moments. If any form of iexplore.exe or iexplorer.exe randomly generates, then you could have some malware or this trojan. If not, then you are probably fine.
I have a butt and you do too. Let's be friends.

Plinko
Server Admin
Server Admin
User avatar
Posts: 8568
Joined: Fri May 23, 2008 11:23 am
Location: Georgia, USA

Games Played

Ville Awards

Plinko’s avatar
Loading…

Re: FPSBanana

Post by Plinko » Wed Jul 14, 2010 7:26 am

This is getting more and more common, I got this on my work laptop a couple of weeks ago from visiting someone's blog that had an ad compromised this way and had to have my the laptop reformatted and re-installed.
It's think it's not FPSBanana that has been compromised per se, it's the ad service and it can happed on any website that uses such a service if it's compromised.
"I made all my gold into pants" - Ignatius
Image

M's
Server Admin
Server Admin
Posts: 7594
Joined: Fri May 25, 2007 6:09 am
Location: Vilonia, Arkansas

Games Played

Ville Awards

<eVa> M's’s avatar
Offline

Re: FPSBanana

Post by M's » Wed Jul 14, 2010 8:06 am

KRG wrote:That sounds fine mlite. You must be running Windows 7 or Vista?

You would usually be looking for iexplorer.exe as opposed to iexplore.exe, note the extra "r" at the end. Also note that the new IE is supposed to run 2 instances of iexplore.exe whenever you surf. It is part of the in-built tab recovery feature of IE which is used to prevent a problematic web page, which would normally cause IE to hang/crash, from affecting any other open tabs.

One simple way to check is to close all open internet windows (exit Steam too) then CTRL+ALT+DEL and bring up the task manager. Stop all instances of iexplore.exe (do not stop "explorer.exe"). Watch the task manager for a few moments. If any form of iexplore.exe or iexplorer.exe randomly generates, then you could have some malware or this trojan. If not, then you are probably fine.
Thanks I am running vista. And checked everything and I'm good.

gator
Retired Admin
Retired Admin
User avatar
Posts: 2225
Joined: Sun Oct 29, 2006 8:34 am

Games Played

Ville Awards

gator’s avatar
Loading…

Re: FPSBanana

Post by gator » Wed Jul 14, 2010 9:46 am

Plinko wrote: It's think it's not FPSBanana that has been compromised per se, it's the ad service and it can happed on any website that uses such a service if it's compromised.
That's what it sounded like to me as well.

Boss Llama
Site Admin
Site Admin
User avatar
Posts: 10179
Joined: Mon Mar 24, 2008 12:45 pm

Games Played

Ville Awards

<eVa> Boss Llama’s avatar
Loading…

Re: FPSBanana

Post by Boss Llama » Wed Jul 14, 2010 12:21 pm

That's one of the most aggravating things about adverts on sites - not only do they waste space and waste bandwidth, but they're full of all kinds of crap. If I ever were some kind of hacker, which I'm not, I would totally go after companies like doubleclick.net. Not to compromise other people's stuff or anything, just to destroy them and knock them offline.
-Boss Llama

Bronze Fox
Villun
Villun
User avatar
Posts: 4050
Joined: Tue Aug 19, 2008 3:15 pm
Location: Baltimore, Ohio

Games Played

Ville Awards

Bronze Fox’s avatar
Loading…

Re: FPSBanana

Post by Bronze Fox » Wed Jul 14, 2010 12:29 pm

These viruses just keep getting more and more advanced. :/
Image

Stevo
Everlasting Villun
Everlasting Villun
User avatar
Posts: 8753
Joined: Sun Oct 22, 2006 10:01 pm
Location: Orange County, CA
Minecraft name: StevoTVR
Uplay name: StevoTVR
Contact:

Games Played

Ville Awards

StevoTVR’s avatar
Loading…

Re: FPSBanana

Post by Stevo » Wed Jul 14, 2010 12:36 pm

Rootkits have been around for a long time actually. I'm guessting this one uses an IE exploit to get in...

Post Reply

Who is online

Users browsing this forum: No registered users and 10 guests