- Not to be confused with Shoe, a DOS virus.
Shoerec appears to be an application made in Shockwave Flash player, featuring a small boxing game with the supportive text, directions, and credits in Turkish, leading most people to believe the viruses origin is Turkey; the person getting punched is also supposedly Turkish.
However, it is infected with the Shoerec virus. Shoerec is a very dangerous virus. It is an encrypted parasitic Win95 virus about 10Kb in length (due to its code of the infected files it will not work on Windows NT or Windows ME). It is a direct action virus - it scans current a drive directory three times, looks for PE EXE files there and infects them; but it does it in the background of a host process (in process thread), and as a result, can stay in memory for a long time up to the moment the host process is terminated, or all files on a drive are scanned. Because of this, the virus can be classified as per-process memory resident.
While infecting a file, the virus writes itself to the end of the file in the last file section, increases this section size and modifies necessary PE header fields.
To obtain addresses for file access and other functions, the virus uses an address that is valid for Win95/98 only. It causes a standard Windows "error in application" message when infected files are run under Windows NT or ME.
In about 4 months after infecting a file (and assuming the operating system still works), and being run on the same computer (the virus stores the current date and computer name while infecting), the virus runs its trigger routine. This routine gains access to the desktop, and moves icons out of the mouse cursor when the it is being moved to the icons. It appears as though the programs' icons run out away from the cursor, trying to escape, similar to one of Magistr's payload.
When the files are infected on the 1st, 2nd or 3rd of any month, the virus randomly infects them with its routine. When such files are run in about 7 months after being infected, the Trojan routine erases all files on the current drive, creates and randomly overwrites the WIN.COM file with garbage or the text, revealing the full name of the virus on the drive the OS was installed on:
(c) 1999 Brain & Amjads (pvt) Ltd VIRUS_SHOE RECORD v20.0 Dedicated to the dynamic memories of millions of virus who are no longer with us today - Thanks
Shoerec was originally posted to newsgroups as the files FUN.EXE, BOXING.EXE or NOSTRESS.EXE. Its icon made it look like a Shockwave file. When executed, it launches a Shockwave file of a boxer, from which the user can carry out a range of varying moves on.
Securelist (Kaspersky Labs), Virus.Win9x.Shoerec
Proland, Shoerec virus