View Single Post
Cpp Cpp's Avatar

JCF Member

Joined: Mar 2001

Posts: 1,557

Cpp is doing well so far

May 18, 2002, 02:26 AM
Cpp is offline
Reply With Quote
Good news, people!

Yesterday me and Alberto examined this virus a bit. As Alberto said, the virus spreads itself with a program called TSF Warper, exe name: Warper.exe, Icon: An exclamation mark in a yellow 3angle. His discovery was confirmed by me. When you run this warper.exe it creates a file named "Msacdlg.exe" in windows/system directory. It aslo adds this file to startup so it runs every time windows start. This is the reason why the virus didn't disappear when you deleted all the trainers you had(including warper.exe). When this file (Msacdlg.exe) is executed it creates another file in windows directory under random file name making it hard to find. This file has a windows icon so it looks like just like it was a non-exe or a file with unknown extension. Its file size is around 16,5 kb. And when this file is executed it creates the "Initcent" virus that messes with the game.

So shortly:
Warper.exe => Msacdlg.exe in windows/system directory => Initcent virus with a random file name in windows directory.

I'm not sure if there are any more files that were created by this virus but if you delete them the virus is gone for sure.

How to get rid of it:
1. Delete Warper.exe, don't spread it.
2. Run registry editor and delete this key: "Mscadlg" in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run
3. Delete Msacdlg.exe from your windows/system directory
4. If Initcent is running restart your computer otherwise skip this step
5. And finally find the virus file in the windows directory and remove it. It has a random name, windows icon, file size = 16896 b

This should take care of the virus.
Me and Alberto also winhacked this file and discovered a few things. It actually has a name. It's called Jazz 2 Annoying Virus. We also found all the bad words in it. LOL "Naked lori" :P Thanks, Alberto for the copy :P
But we still have one question unsolved. Who made it?
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a>