Add new Bookmark
Do you need some help? Enter your problem or question below and an Exhibited Guru will get back to you. If you have a serious problem, it might be best to ask a moderator instead by selecting "Mod Box" from the drop down. Remember, this isn't for reporting bugs.



L25 EXC AMF h2_src=ng8.del.[Win32:Shoerec].exe

Back Assign Food Feed
Heal
Battle Enclosure Refresh Image Next

Basics

Care

Biology

Skills

Relationships

Design

Name
h2_src=ng8.del.[Win32:Shoerec].exe
Species Gender Age
Herrerasaurus Male 49 (20 years old)
Owner Breeder
UnwrittenTale (#3511) UnwrittenTale (#3511)
Contract
This dinosaur has no contract tied to it.
Notes
~ {Shoerec } ~

Source: Securelist.com

This is a very dangerous encrypted parasitic Win95 virus about 10Kb in length. It is a direct action virus - it scans current a drive directory three times, looks for PE EXE files there and infects them; but it does it in the background of a host process (in process thread), and as a result, can stay in memory for a long time up to the moment the host process is terminated, or all files on a drive are scanned. Because of this, the virus can be classified as per-process memory resident.

While infecting a file, the virus writes itself to the end of the file in the last file section, increases this section size and modifies necessary PE header fields.

To obtain addresses for file access and other functions, the virus uses an address that is valid for Win95/98 only, and as a result, causes standard a Windows "error in application" message when infected files are run under other Windows versions.

In about 4 month after infecting a file, and being run on the same computer (the virus stores the current date and computer name while infecting), the virus runs its trigger routine. This routine gains access to a Windows desktop, and moves icons out of the mouse cursor when the mouse cursor is being moved to the icons. It appears as though the programs' icons run out away from the cursor, trying to escape.

When the files are infected on the 1st, 2nd or 3rd of any month, the virus randomly infects them with its Trojan routine. When such Trojanized files are run in about 7 months after being infected, the Trojan routine erases all files on the current drive, creates and randomly overwrites the WIN.COM file with garbage or the text:

(c) 1999 Brain & Amjads (pvt) Ltd
VIRUS_SHOE RECORD v20.0
Dedicated to the dynamic memories of millions of virus
who are no longer with us today - Thanks
Hunger
Happiness
Health
No vaccinations!
Sickness & Injuries None
Personality Pack Position Inbred Can Breed Again
Assertive Alpha 0% Anytime
Genetics Eye Genetics
BbGGiiJJOoRrssttVv
aaCCDdhh
ee EE EE
Color
Buttercup (#f0a812)
Markings
Ebony (#0c1123): Tribal (Heavy)
Eye Color
Yellow
Level
25
Intelligence
2126.80
Speed
3222.75
Strength
3182.11
Length
Okay Length
Head
Big
Feathering
Perfect Coverage
Height
Perfect Height
Tail
Perfect Size
Teeth
Perfect Amount
Total Trials Unrun Trials Battle Battles Left
Total: 350 Wins: 100
View Results
10 n/a 5
Wins Losses Points Skill Points
Battle: 184
Hunting: 0
Battle: 1
Hunting: 0
5,221
(8,495 to LVL)
0
Hunting Prowess Trialling Prowess Battling Prowess
0 25 0
Medal

All Hall of Fame

Species Hall of Fame


Battle Moves Unlocked:
Coming soon.
Clip Ons and Overlays
Overlay Under Markings Underlay

Watsn.fn - Background (All Species)