Click to See Complete Forum and Search --> : Serious BlackIce security issue
I just downloaded Norton's latest update and rebooted my W2K machine. Upon boot up it said that the blackd.exe file was infected with the Backdoor.BlackD virus. Has anyone heard of this? I just completely reformatted this machine last week and downloaded the lasted version of BlackIce. Any solutions on getting rid of it or how I got it?
daveleau
09-22-2000, 07:58 AM
Only thing I could find even remotely related on the netwrokice site is this : http://advice.networkice.com/advice/support/kb/q000135/default.htm
Dave
It looks like the blackd file could be the a log as it is named blackd.log. So this link could be related.
[This message has been edited by daveleau (edited 09-22-2000).]
Thanks for the reply and the link. The problem is with the blackd.exe file. I just downloaded a fresh copy of blackice from their website and while trying to install norton pops up about the same virus. Either network ice is packaging a virus in with blackice, or norton is going haywire. Maybe norton did it on purpose to make people lose faith in blackice and buy their firewall. Who knows. I have sent email to network ice and am awaiting a reply.
daveleau
09-22-2000, 08:38 AM
Network Ice did have a link about people inserting trojans into the BID DL but not from their site. It is from pirated sites so it wouldn't be that. I am suprised BID hasn't posted anything yet about that on their website unless it is specific to a recent update.
Dave
I ran a virus check using Norton Virus 2000 and it didn't report any infected files of my Black Ice Defender. I have the most recent definition update on my NAV. Are other people getting this message that blackd.exe is infected also???
Just an FYI I am using the latest build of Black Ice (2.1 cn) which I downloaded from the networkice site. Also I am using Norton antivirus 2000 with the 9/21/00 definitions. I am going to see if I get the same results on another machine that I have that has Blackice and norton installed
Dave_H
09-22-2000, 09:24 AM
I have seen posts at the Black-Ice support forum with people reporting the same problem. All of them were after the latest Norton AV update of 9-21. The thinking is that it is a "false positive" reported by Norton's. You can read some of the posts here:
http://www.egroups.com/messages/bidissues
I checked over at the Symantec support site (ask Symantec) and there is also a new post there as well.
So far, no representitives of BI or NAV have responded yet.
Dave
Edit- I'm having problems posting the link to the Symantec support site, but it was very similar the to posts at the BI site. -edit
[This message has been edited by Dave_H (edited 09-22-2000).]
Fixed for you-Mntsnow
[This message has been edited by Mntsnow (edited 09-22-2000).]
Dave_H
09-22-2000, 09:32 AM
What the heck is going on?
I'll try again with the BI link. http://www.egroups.com/messages/bidissues
Dave
jad1097
09-22-2000, 09:58 AM
Dave that has been going on for a couple of weeks. http://sysopt.earthweb.com/forum/Forum17/HTML/001062.html
Dave_H
09-22-2000, 04:55 PM
Thanks Jad, I forgot about that happening after an edit.
Here is an article from Network-Ice about the issue. http://advice.networkice.com/Advice/Support/KB/q000207/
Dave
Dave_H
09-22-2000, 05:14 PM
Sorry for making all the posts, but I didn't want to go back and add to my last one.
I think the issue might have been resolved.
This mourning I was at my home computer, and the same thing was happening to me after getting the Norton 9-21 virus update.
I'm on my system at work now, but I just noticed a new AV update dated 9-22. I installed it and it does not detect blackd.exe as a trojan or virus.
I guess I'll know for sure when I get home later tonight.
Dave
Thanks for the advice and link. I feel a lot better now knowing that it isn't really infected.
socalgal
09-22-2000, 09:57 PM
Thanks for the clearing this up, Dave. http://sysopt.earthweb.com/forum/smile.gif
I've had the BID release 2.1.cn for awhile and running NAV7 CE. I've run several scans since, and just ran another scan on the blackd.exe file to test it and it did not show up as a virus/trojan, so I suppose it reports false-positive only with NAV2000 (or: it doesn't report with NAV7 CE).
[This message has been edited by socalgal (edited 09-22-2000).]
SysOpt.com
Copyright Internet.com Inc. All Rights Reserved.