May 18, 2002, 02:29 AM | |
The mistery of the TSF Virus
Hey hey!
Overlord, Eagle and me found how the TSF virus work and how to remove it. Well, the virus is caused by the program TSF Warper (Warper.exe). ![]() After is ran it copies a file to C:\Windows\System folder (where C: is your hard drive letter) called Msacdlg.exe. ![]() Also it adds a key to the RUN section on the registry called Msacdlg so the program starts when your computer starts. ![]() In some cases when that file is run it creates a third file with a random name such as Gygxk.exe. ![]() And that file is the "Initcent" program, when that program is on and you're on a TSF game, names will change, you'll be warped often and the scores will change sometimes too. |
May 18, 2002, 02:30 AM | |
For those who are wondering what the program does in memory I took some pics when I analyzed it.
Warper.exe contains a weird message by it's author: ![]() Also you can find the registry key, the name of the file that it copies and the word "sux0rs". ![]() On the third file that is created (Initcent one) you can find the title of the virus: ![]() And some bad words.. Click here to view the image [Fquist - Image changed into a link because of the bad words. The jcf will not be held responsible for them] Last edited by FQuist; May 18, 2002 at 06:15 AM. |
May 18, 2002, 02:31 AM | |
How to remove the virus?
Really easy. If you ran Warper.exe go to your Windows\System folder and look for a file called Mscadlg.exe like this one: ![]() Then delete that file. After is deleted go to Start menu and then click on run, in the white box type "regedit" without the quoutes. ![]() And follow this path: HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run and then in the right window look for that Msacdlg key and delete it, look the pic above for more info. With this done the virus won't start again (unless you run Warper.exe again). To remove it definitely go to your Windows folder and look for a file with EXACTLY the same icon as on the pic. ![]() Remember that the name can change, but it has the same icon, exactly the same one. After you find it just delete it and done! It seems this is just a funny joke of someone, nothing dangerous. ![]() this will make you cheaters to don't cheat again. :P Bye bye! |
May 18, 2002, 02:56 AM | |
For more info visit Overlord's post http://www.jazz2online.com/jcf/showt...1751#post71751
|
May 18, 2002, 05:18 AM | |
It's a quit good story for the war tavren:
Once upon a time, there was a little fat chicken who wanted to punish all the poor cheathers, so it made a lama virus, but our heroes, Eagle, Alberto, and Overlord saved us poor cheathers from it ;P Happy ending with lots of spell errors |
May 18, 2002, 11:29 AM | |
Its just so strange that I dont have the virus
![]() ![]() Ow yeah this virus thingy has to be NEW, because almost noone knew about Bin Laden before the Twin Tower attack. So its made after it...duh. The virus is quite made 'smart'...
__________________
Bla. |
May 18, 2002, 12:31 PM | |
Seems to be there was someone who said "I am the Alpha and the Omega", but I don't remember who.
Anyway, very nice detective work, or whatever you did. |
May 18, 2002, 01:36 PM | |
Overlord put that in one of his programs. I think it was project omega.
The phrase was made popular by UT. Xan (the end boss) used it as a taunt. I could list a bunch of people who play UT, but I don't want to make them seem like suspects.
__________________
Download my JJ2 Episodes! (5 episodes) Visit My JJ2 Blog (HOLD YOUR HORSES I'M WORKING ON IT SHEESH) |
May 19, 2002, 02:56 AM | ||
Quote:
O_o That person should get a humor. |
May 19, 2002, 08:37 AM | |
It's true that I put the taunt into Omega. But I always say Alpha and Omega with uppercase beginning. If you look at the picture or in UT you can see that it's lowercase.
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a> |
May 20, 2002, 03:38 AM | |
Interesting.... *snickers* I also would like to know who did it...if only to laugh about it. Heh I bet they will think twice before running trainers now.
![]() And no it was not me ![]() EDIT: interestingly enough its a VB work. That narrows it down to everyone but me, mirrow, and lama. Joy. =P Could someone send me this virus? I would like to take a look at it.
__________________
"Are we not threatened with a flood of information? And is this not the monstrousness of it: that it crushes beauty by means of beauty, and annihilates truth by means of truth? For the sound of a million Shakespeares would produce the very same furious din and hubbub as the sound of a herd of prairie buffalo or sea billows." —Stanisław Lem, Imaginary Magnitude (1973) |
May 22, 2002, 06:42 PM | ||
Quote:
![]() Great job! This is interesting to hear about a virus for jj2! maybe someone made it because he was sick of that rabbit! (Iknow I aint!) ![]() |
May 28, 2002, 05:38 AM | ||
Quote:
__________________
<table cellpadding="0" cellspacing="0" border="0" width="100%" height="32"><tbody><tr><td>Status: N/A. [<a href="http://home.attmil.ne.jp/a/ocasio/">My Empty Webpage</a>][<a href="http://cesar-ocasio.deviantart.com/">My Deviants</a>][<a href="http://www.cugy.net/">Computer Users Group of Yokota (Japan)</a>]</td><td align="right"><img src=http://home.attmil.ne.jp/a/ocasio/images/nibble6.gif alt="You never saw me" (-)(-)(-)(-)(-)(-)(-)="alert('...aww it\'s so cute!\n ^_____^');return true;"></img></td></tr></tbody></table> |
May 28, 2002, 03:50 PM | |
Whoever made this program is very VERY slick, for trying to hide a program with boring icons and names, and knows extensive knowledge about VB process stuff and Jazz2's memory locations.
__________________
<table cellpadding="0" cellspacing="0" border="0" width="100%" height="32"><tbody><tr><td>Status: N/A. [<a href="http://home.attmil.ne.jp/a/ocasio/">My Empty Webpage</a>][<a href="http://cesar-ocasio.deviantart.com/">My Deviants</a>][<a href="http://www.cugy.net/">Computer Users Group of Yokota (Japan)</a>]</td><td align="right"><img src=http://home.attmil.ne.jp/a/ocasio/images/nibble6.gif alt="You never saw me" (-)(-)(-)(-)(-)(-)(-)="alert('...aww it\'s so cute!\n ^_____^');return true;"></img></td></tr></tbody></table> |
May 28, 2002, 09:43 PM | |
Yea, let's poll the athour of the program home! I think he/she really gets scared of something like that
![]() |
![]() |
Trafton AT |
This message has been deleted by Trafton AT.
|
![]() |
«
Previous Thread
|
Next Thread
»
Thread Tools | |
|
|
All times are GMT -8. The time now is 05:57 PM.
Jazz2Online © 1999-INFINITY (Site Credits). Jazz Jackrabbit, Jazz Jackrabbit 2, Jazz Jackrabbit Advance and all related trademarks and media are ™ and © Epic Games. Lori Jackrabbit is © Dean Dodrill. J2O development powered by Loops of Fury and Chemical Beats. Powered by vBulletin® Copyright ©2000 - 2025, Jelsoft Enterprises Ltd.
Original site design by Ovi Demetrian. DrJones is the puppet master. Eat your lima beans, Johnny.