SpecialAttack.net
https://forum.specialattack.net/

Might want to avoid FPSbanana for a while!
https://forum.specialattack.net/viewtopic.php?t=7569
Page 1 of 1

Author:  [SpA]WildBlaze [ 13 Jul 2010, 23:57 ]
Post subject:  Might want to avoid FPSbanana for a while!

Just a bit of a heads up if your planning on looking for new maps or skins, looks like FPSbanana has been infected with a rather nasty virus, so you might want to avoid it for a while, and if you've been there recently you might want to check if you have Loader.exe running in your processes.

http://www.gtfogaming.co.uk/community/w ... t8945.html
Quote:
The site is currently infected with the 'Black Internet' trojan.

It's embedded in the site itself somehow, which means all you have to do is go there-- you don't have to download anything, and you'll be infected. All the following programs did not detect the trojan AVG, Ad-Aware and Windows Defender.

If you've been to FPSBanana in the last day or less, check your task manager. Look for iexplore.exe running-- or multiple instances of it if you are surfing with internet explorer, of course. You might also be hearing audio advertisements and/or multiple weird noises and mouseclicks.

Apparently this trojan infects the MBR, to fix the virus problem make all folders viewable in the control panel -> large icons -> folder options -> view -> show hidden files, folders and drives, then reboot in Safe Mode and go here:

C:\Users\YOURUSERNAME\Appdata\Local\Temp

and deleting these two files:

Loader.exe
Smss.exe

And until further notice I strongly suggest that you avoid going to the website.
about the virus if your wondering what it does
Glad i decided to check the steam forums, was going to go to FPSbanana to see if there were any interesting skins for the new engi equipment :?

Author:  annarack [ 14 Jul 2010, 00:48 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

Nice find, thankfully I don't have it :5:

Author:  sebas [ 14 Jul 2010, 00:54 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

If it infects the MBR it's not gonna go away by just soft deleting those files. And fixmbr is a bit of a risky command unless you want to format. Anyway, nice catch Wildblaze. :)

Author:  Lim-Dul [ 14 Jul 2010, 01:10 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

fixmbr is not risky if you're not multibooting. If you are, then you're probably using other loaders like GRUB anyway and should stick to *nix-like recovery methods...

Speaking of using *nix to fix Windows - an excellent distro is Parted Magic - http://partedmagic.com/ - better recovery tools than the ones that Windows has and most of them are compatible with a wide range of filesystems.

Author:  [SpA]Scatterbrain [ 14 Jul 2010, 10:04 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

good find man, thanks!

Author:  dckjns [ 14 Jul 2010, 11:46 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

Quote:
There are other ways but they have a 10% chance of working.
uh

Good thing I read this, might have winded up there one way or another.

Author:  ProtectMyBalls [ 14 Jul 2010, 12:21 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

i was about to download the heavy bear skin :S

Author:  [SpA]Loke [ 14 Jul 2010, 13:33 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

'kay, I'm staying away from that site now. I have an account there with some of my stuff uploaded but luckily have it uploaded elsewhere as well.

Thanks, Blaze.

Author:  [SpA]WildBlaze [ 14 Jul 2010, 20:45 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

Looks like this might have been fixed now, though you may want to be careful and keep an eye on your processes if you go there :?

http://forums.steampowered.com/forums/s ... ?t=1360060
Quote:
Update:This has been fixed. FPSBanana is safe to use again for the time being. Even though it's safe at the moment, if you plan on going there, make sure you're protected against this kind of thing before you go there to be safe. Also, just be careful on other sites as well - they could also get something similar and it doesn't hurt to be sure.

I'll update this if FPSBanana is compromised again. Untill then though, thank you for sticking with this.

Adiggity claims that FPSBanana is still not safe to use:
Quote:
Originally Posted by adiggity View Post
FPSBanana is still not safe to use.

ESETNod32 found Trojans in several downloads--including SteamCleaner, ironically--and SpyBot S&D regularly detected spyware after I visited the site.

Play it safe and avoid. And please upload custom content somewhere else so we can enjoy it in peace ^^
This is the only report I've got so far of the site still being infected but keep it safe and make sure you are protected.

This is also going to be used as a sort of support thread for the time being now that FPSBanana is safe. This is so users who were affected can post and get help from other members - happening already. Post if your PC was infected(or if you think you may be infected/curious/want to make sure) and you need help to get rid of it. There should be someone around sometime who is willing to help.

Author:  [SpA]SaintK [ 16 Jul 2010, 23:28 ]
Post subject:  Re: Might want to avoid FPSbanana for a while!

God damn wankers. Now i finally know were i got that rootkit virus. I've been downloading maps for the SpA servers from there when i noticed i got a rootkit virus on my PC. I couldn't find it's source on my PC, leading to a full format and reinstall. I was also completely unaware on how the fuck i got infected in the first place....

Page 1 of 1 All times are UTC+02:00

Powered by phpBB® Forum Software © phpBB Limited