Fandom

Malware Wiki

Resonate

1,336pages on
this wiki
Add New Page
Comments26 Share



Resonate is a non-resident prepending parasitic virus on Microsoft Windows, specifically Windows 7 and up. It was originally created as a learning experience, however it was later submitted to Danooct1's "viewer-made malware" segment.

Due to its popularity, its second counterpoint was made that contains deadly payloads and can work on Windows XP and up as ResonateII.

Viewer-Made Malware 4 - Resonate (Win32)10:23

Viewer-Made Malware 4 - Resonate (Win32)

File Structure

Resonate is actually 2 seperate programs, a file infecting virus and a trojan. The virus holds the trojan as a resource to be extracted and executed at infection time. Resonate is prepending, so it infects files by inserting itself into the front of the file and pushing the file contents back. This causes Resonate to run instead of the intended file at run time.

Removal

Its payloads can be cancelled in Task Manager, and to remove the file itself simply delete the file.

Installation Routine

When an infected file is run, Resonate finds the end of the virus so that it can extract the host file. Once it has read the host file into memory, it writes a temporary hidden file containing this host and executes it, attempting to pass command line arguments then waits for the host to terminate. Once the host has terminated, Resonate deletes the temporary file and drops its trojan to %userprofile% as "tdrop.scr" and executes it. The trojan portion then installs itself to the system by copying itself to %userprofile% as "svchost.scr" and adding itself to the Run key. The .scr extensions are a way of keeping the virus from infecting the trojan.

Payloads

Resonate features several non-destructive payloads. It checks the date at every boot, and if the date matches one of several prerequisite dates, it will activate one of its payloads.

  • January 2nd - Drops a copy of Blast Button and executes it.
  • February 16th - Plays "Grass Beach" by Youtube user LtKittenKiss on loop.
  • April 20th - Attempts to replace the wallpaper with a cannabis leaf (only on Windows 7).
  • May 24th - Drops a recreation of "You Are An Idiot" and runs it. This is a Microsoft Word macro and it does not block Alt+F4 or Ctrl+Shift+Del, thus can be terminated via Task Manager. However, Alt+F4 acts like closing it and thus will produce more windows.
72297291020f48d8aae7f2036fd6849f

December 30th payload

  • September 4th - Attempts to open FitTea.org every 15 seconds, but due to a programming error, it opens the site every 15000 seconds (4 hours and 10 minutes) instead.
  • September 6th - Covers the screen with a pixelated picture of Fred Durst with a caption telling the user to go play outside, attempting to block any effort to terminate it. The word "outside" is misspelled as "outsie".
  • December 30th - Covers the screen in a window that slowly shifts through hues, typing out a message, allowing the user to continue once the message has been typed out.

Ad blocker interference detected!


Wikia is a free-to-use site that makes money from advertising. We have a modified experience for viewers using ad blockers

Wikia is not accessible if you’ve made further modifications. Remove the custom ad blocker rule(s) and the page will load as expected.