Actions

MrsMajor.exe

From Screamer Wiki

Revision as of 01:06, 14 May 2023 by SkyTheWanderer (talk | contribs) (We don't actually use those anymore)

MrsMajor.exe (also known as BossDaMajor.exe) is a screamer trojan developed by Elektro Berkay, The trojan gained notoriety after Siam Alam created a video about it. It later had a better version known as MrsMajor2.0.exe, which was also featured in Siam Alam's video.

According to the description. It originated in Turkey and was created in 2017. Surprisingly, despite the fact that the virus is called MrsMajor, the executable is called bossdamajor.exe.

Payload

 
The warning message that appears before running the virus (2.0 version only)

A video of the MrsMajor game is displayed by Windows Media Player. The game is a terrifying maze. It shows a maze room with a green tint, followed by a 'scareface.' The wallpaper is later changed to schemes, as are the icons. When it is fully loaded, a flashing and moving image of a frightening doll named "Mrs. Major" appears on the screen. while Thresh's Theme from League of Legends plays in the background.

It includes rules in Version 2.0 of the virus. One of the rules instructs users not to use Task Manager to remove the virus. If the user tries to open Task Manager, a message with the letter "T" will appear. The rules (v2.0) are as follows:

Your computer has been infected by MrsMajor.
If you dont attend rules, your computer will be "Trash"
Theese are rules:

+If timer runs out, your computer won't work anymore
+If you ATTEMPT to kill any process, your PC will die
+Do NOT delete any virus files.
+Uninstall your antivirusses. They may try to remove virus.
+Do not run Taskmanager, cmd, sethc,
+Do NOT use safe mode.
+Do NOT Remove any registries from msconfig etc..

Or Your PC Will not be able to boot up..

If the user violates the virus's rules, an RSoD (Red Screen of Death) screen will appear informing the user that they have violated the virus's rules. The error code is "TROJANS NEVER JOKE RESPECT THE TROJANS," which may indicate that the malware is a Trojan. If the user turns off their computer while the virus is still active, the virus will destroy the operating system by deleting some boot files. The RSoD screen (v2.0) reads as follows:

A problem has been detected and windows has been shutdown to prevent damage to your computer.

TROJANS_NEVER_JOKE_RESPECT_THE_TROJANS

If this is first time you have seen this screen you are infected by MrsMajor.exe and you broke rules. It is unacceptable. However, your computer wont be able to boot up. Because logonui.exe is missing..

If problems continue, contact the virus owner or disable ur bios memory. Jk second way wont work. Do not waste your time. Everytime you boot up your computer, this screen will appear. If you want to contact virus creator, here is the mail: mskonsol11@gmail.com
Theese are fake technical informations:

*** STOP: 0x00D1 (0x00C,0x002,0x00,0xF86B5A89)
Address F86B5A89 base at F86B5000, DateStamp 3dd9919eb ***

Beginning dump of physical memory..
Physical memory dump complete.

Windows can't reboot. shutdown.exe is missing. Fix your system. Eh, if its possible.

Link

NOTE: the following application contains a screamer as well as a malicious script that may harm your computer!

  • github.com/acastillorobles77/MalwareDatabase/blob/master/MrsMajor%202.0.txt


Comments

Loading comments...