Following catbox being excluded from the wayback machine, many parts of googlevideo.com (a backend YouTube domain used for videos) have been excluded.
Learn how to use IPFS!

Strimage.exe: Difference between revisions

From Screamer Wiki
Jump to navigation Jump to search
No edit summary
Tags: Mobile edit Mobile web edit
strimage.exe was created in 2001 in the source code files.
 
(27 intermediate revisions by 13 users not shown)
Line 1: Line 1:
{{Malicious Scripts}}
{{Deleted}}
Strimage.exe is a [[screamer]] program written in VB6 which spread across China in around 2005.  
{{Infobox
|title = Strimage.exe
|image = ScreamerWarning.png
|maker = Unknown
|type = Application
|date = 2001
}}
'''Strimage.exe''' (Chinese: 女鬼2阴魂不散) is a Chinese [[screamer]] [[program]] that was created by an unknown user in 2001 and gained popularity during the year 2005. It was developed using the [[wikipedia:Visual_Basic_(classic)|Visual Basic]] 6.0 programming language and its icon resembled a [[wikipedia:Windows_9x|Win9X]]-style folder, likely to disguise itself as a regular directory.  


It has an icon of folder in Win9X style, attempt to make the user think it's a normal folder and run it. When executed, it seems that nothing happened. However the program has already copied itself to several system directories, deleted the original file, and set itself to the default application for opening JPEG files. So each time the user double click on a JPEG file, the program will be called to run., Then, the program will check the date on the local computer. If the date it's not Friday, Saturday or Sunday, the program will terminate itself. Otherwise the [[screamer]] will begin countdown for a random amount of time between 5 minutes and 15 minutes in the background. After finished counting, the program will show its main payload, which is a ghostly girl and half of her face is skeleton. The eyeball on the other half can move and a crying sound effect will be played. Click anywhere will exit the [[screamer]].
== Payload ==
When launched, Strimage.exe self-replicated across various system directories, removed the original file, and assigned itself as the default application for opening [[wikipedia:JPEG|JPEG]] files. The malware was executed every time a JPEG file was double-clicked.


It can be found in source code that the project was firstly named ''StarField'' and the caption of the [[screamer]] window is also the same. There is a '''Type''''' ''class in the code named ''Star ''which featured ''X, Y, Speed, Size ''and'' Color. ''It seems like that the author was initially wanted to write a screensaver or some visual program.
The screamer payload only activated on Friday, Saturday, and Sunday. The program waited a minimum of 5 minutes and a maximum of 15 minutes before displaying the screamer, which displayed an full-screen image of a girl with half of her face a skull accompanied by a somber crying sound effect.  Users could exit the screamer by clicking anywhere on the screen.
 
The program's source code reveals the initial project name "StarField". The screamer window's caption also shares the same name. The code includes a "Type" class named "Star", featuring properties such as "X", "Y", "Speed", "Size", and "Color", which may suggest that the author was initially planning to write a screensaver or a similar visual program.


== Links ==
== Links ==
=== '''Download''' ===
<u>NOTE</u>: The following download link contains a [[screamer]] application and a well known <span style="color:red"><span style="color:yellow">[[malicious script]]</span> that could potentially harm your computer!</span>
<u>NOTE</u>: The following download link contains a [[screamer]] application, <span style="color:red">as a well-known <span style="color:yellow">malicious script</span> that may could potentially harm your computer!</span>
* files.screamer.wiki/other/Strimage.zip (Including the cleaner program and VB6 source code)
 
* '''Showcase:''' bilibili.com/video/BV1mt41177jP
<br>
{{Maliciousnav}}
{{Comments}}
[[Category:Malware]]
[[Category:Applications]]
[[Category:Applications]]
[[Category:Other scary images]]
[[Category:Other scary images]]
[[Category:Other makers]]
[[Category:Other makers]]
[[Category:2005]]
[[Category:2001]]
[[Category:China]]
[[Category:China]]
[[Category:Malicious scripts]]
[[Category:Malicious scripts]]
{{Comments}}

Latest revision as of 14:06, 6 October 2024

This page is about a screamer or shock site, whose original copy has been deleted.
This screamer's original copy is deleted, but the article links to an archive on the Wayback Machine or another saved copy.

Strimage.exe (Chinese: 女鬼2阴魂不散) is a Chinese screamer program that was created by an unknown user in 2001 and gained popularity during the year 2005. It was developed using the Visual Basic 6.0 programming language and its icon resembled a Win9X-style folder, likely to disguise itself as a regular directory.

Payload

When launched, Strimage.exe self-replicated across various system directories, removed the original file, and assigned itself as the default application for opening JPEG files. The malware was executed every time a JPEG file was double-clicked.

The screamer payload only activated on Friday, Saturday, and Sunday. The program waited a minimum of 5 minutes and a maximum of 15 minutes before displaying the screamer, which displayed an full-screen image of a girl with half of her face a skull accompanied by a somber crying sound effect. Users could exit the screamer by clicking anywhere on the screen.

The program's source code reveals the initial project name "StarField". The screamer window's caption also shares the same name. The code includes a "Type" class named "Star", featuring properties such as "X", "Y", "Speed", "Size", and "Color", which may suggest that the author was initially planning to write a screensaver or a similar visual program.

Links

NOTE: The following download link contains a screamer application and a well known malicious script that could potentially harm your computer!

  • files.screamer.wiki/other/Strimage.zip (Including the cleaner program and VB6 source code)
  • Showcase: bilibili.com/video/BV1mt41177jP


Comments

Comments

Loading comments...