Register FAQ Search Today's Posts Mark Forums Read
Go Back   JazzJackrabbit Community Forums » Open Forums » General Jazz Jackrabbit Talk

The mistery of the TSF Virus

Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

May 18, 2002, 02:29 AM
Alberto is offline
Reply With Quote
The mistery of the TSF Virus

Hey hey!

Overlord, Eagle and me found how the TSF virus work and how to remove it.

Well, the virus is caused by the program TSF Warper (Warper.exe).



After is ran it copies a file to C:\Windows\System folder (where C: is your hard drive letter) called Msacdlg.exe.



Also it adds a key to the RUN section on the registry called Msacdlg so the program starts when your computer starts.



In some cases when that file is run it creates a third file with a random name such as Gygxk.exe.



And that file is the "Initcent" program, when that program is on and you're on a TSF game, names will change, you'll be warped often and the scores will change sometimes too.
Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

May 18, 2002, 02:30 AM
Alberto is offline
Reply With Quote
For those who are wondering what the program does in memory I took some pics when I analyzed it.

Warper.exe contains a weird message by it's author:



Also you can find the registry key, the name of the file that it copies and the word "sux0rs".



On the third file that is created (Initcent one) you can find the title of the virus:



And some bad words..

Click here to view the image

[Fquist - Image changed into a link because of the bad words. The jcf will not be held responsible for them]

Last edited by FQuist; May 18, 2002 at 06:15 AM.
Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

May 18, 2002, 02:31 AM
Alberto is offline
Reply With Quote
How to remove the virus?
Really easy.

If you ran Warper.exe go to your Windows\System folder and look for a file called Mscadlg.exe like this one:



Then delete that file.

After is deleted go to Start menu and then click on run, in the white box type "regedit" without the quoutes.



And follow this path:
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Curr entVersion\Run and then in the right window look for that Msacdlg key and delete it, look the pic above for more info.

With this done the virus won't start again (unless you run Warper.exe again).

To remove it definitely go to your Windows folder and look for a file with EXACTLY the same icon as on the pic.



Remember that the name can change, but it has the same icon, exactly the same one.
After you find it just delete it and done!

It seems this is just a funny joke of someone, nothing dangerous.

this will make you cheaters to don't cheat again. :P

Bye bye!
Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

May 18, 2002, 02:56 AM
Alberto is offline
Reply With Quote
For more info visit Overlord's post http://www.jazz2online.com/jcf/showt...1751#post71751
Rage

JCF Member

Joined: Aug 2001

Posts: 440

Rage has disabled reputation

May 18, 2002, 04:12 AM
Rage is offline
Reply With Quote
YAY for Alberto, Overlord and Eagle!
Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

May 18, 2002, 04:23 AM
Alberto is offline
Reply With Quote
You're all welcome hehehe.
Teej

JCF Member

Joined: Apr 2001

Posts: 208

Teej is doing well so far

May 18, 2002, 05:03 AM
Teej is offline
Reply With Quote
Talking

Yeah, but now we gotta find out who made it.


Why?


Well........um......because it makes an interesting story....
>>Møønßlãzé<<

JCF Member

Joined: Apr 2002

Posts: 459

>>Møønßlãzé<< is doing well so far

May 18, 2002, 05:18 AM
>>Møønßlãzé<< is offline
Reply With Quote
It's a quit good story for the war tavren:
Once upon a time, there was a little fat chicken who wanted to punish all the poor cheathers, so it made a lama virus, but our heroes, Eagle, Alberto, and Overlord saved us poor cheathers from it ;P
Happy ending with lots of spell errors
defalcon

JCF Member

Joined: Apr 2001

Posts: 2,366

defalcon has disabled reputation

May 18, 2002, 06:07 AM
defalcon is offline
Reply With Quote
Go 'Berto. Go Eagle too. Woo for them.
Alberto, when I say 'what's up?' or 'whacha doin?' on MSN/ICQ, THIS is the sort of stuff I'm asking about.
Super Saiyan

JCF Member

Joined: Nov 2001

Posts: 416

Super Saiyan is doing well so far

May 18, 2002, 11:29 AM
Super Saiyan is offline
Reply With Quote
Its just so strange that I dont have the virus Hmmz maybe My Computer ROckZz
Ow yeah this virus thingy has to be NEW, because almost noone knew about Bin Laden before the Twin Tower attack. So its made after it...duh. The virus is quite made 'smart'...
__________________
Bla.
Newspaz Newspaz's Avatar

JCF Member

Joined: Jan 2001

Posts: 2,678

Newspaz has disabled reputation

May 18, 2002, 12:14 PM
Newspaz is offline
Reply With Quote
Way to go guys!
Violet CLM Violet CLM's Avatar

JCF Éminence Grise

Joined: Mar 2001

Posts: 10,983

Violet CLM has disabled reputation

May 18, 2002, 12:31 PM
Violet CLM is offline
Reply With Quote
Seems to be there was someone who said "I am the Alpha and the Omega", but I don't remember who.

Anyway, very nice detective work, or whatever you did.
__________________
KRSplat KRSplat's Avatar

JCF Member

Joined: Mar 2001

Posts: 4,942

KRSplat is a forum legendKRSplat is a forum legend

May 18, 2002, 12:33 PM
KRSplat is offline
Reply With Quote
Cool.

If warper is on J2O, remove it.
__________________
Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

May 18, 2002, 01:08 PM
Alberto is offline
Reply With Quote
Hehehe.
Yes, if it's on J2O, FQuist remove it.
Also, Unknow, try to remember who said it, it would be interesting to find who made this joke.
EvilMike EvilMike's Avatar

JCF Member

Joined: Jun 2001

Posts: 3,478

EvilMike is OFF DA CHARTEvilMike is OFF DA CHARTEvilMike is OFF DA CHARTEvilMike is OFF DA CHART

May 18, 2002, 01:36 PM
EvilMike is offline
Reply With Quote
Overlord put that in one of his programs. I think it was project omega.

The phrase was made popular by UT. Xan (the end boss) used it as a taunt.

I could list a bunch of people who play UT, but I don't want to make them seem like suspects.
__________________
Download my JJ2 Episodes! (5 episodes)

Visit My JJ2 Blog (HOLD YOUR HORSES I'M WORKING ON IT SHEESH)
KRSplat KRSplat's Avatar

JCF Member

Joined: Mar 2001

Posts: 4,942

KRSplat is a forum legendKRSplat is a forum legend

May 18, 2002, 03:08 PM
KRSplat is offline
Reply With Quote
Yes, it is in Overlord's Project Omega, so that could be anybody (even me.)

._.
__________________
Newspaz Newspaz's Avatar

JCF Member

Joined: Jan 2001

Posts: 2,678

Newspaz has disabled reputation

May 19, 2002, 12:51 AM
Newspaz is offline
Reply With Quote
Doesn't Dethman play UT Mike?
>>Møønßlãzé<<

JCF Member

Joined: Apr 2002

Posts: 459

>>Møønßlãzé<< is doing well so far

May 19, 2002, 02:56 AM
>>Møønßlãzé<< is offline
Reply With Quote
Quote:
Originally posted by Alberto
Also, Unknow, try to remember who said it, it would be interesting to find who made this 'joke'.
Joke, joke....JOKE?!?!?
O_o

That person should get a humor.
Stijn Stijn's Avatar

Administrator

Joined: Mar 2001

Posts: 6,964

Stijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to beholdStijn is a splendid one to behold

May 19, 2002, 05:43 AM
Stijn is offline
Reply With Quote
It's Dethman! He's angry at the community because not every JJ2 player is a Christian!

Great you found it out. Also great I don't have TSF Warper
Cpp Cpp's Avatar

JCF Member

Joined: Mar 2001

Posts: 1,557

Cpp is doing well so far

May 19, 2002, 08:37 AM
Cpp is offline
Reply With Quote
It's true that I put the taunt into Omega. But I always say Alpha and Omega with uppercase beginning. If you look at the picture or in UT you can see that it's lowercase.
__________________
<a href="http://nmap.org/"><img border="0" alt="Nmap Security Scanner" src="http://images.insecure.org/nmap/images/prop/nmap_bnr_matrix_pfos.gif"/></a>
Krezack Krezack's Avatar

JCF member

Joined: Nov 2001

Posts: 5,156

Krezack has disabled reputation

May 20, 2002, 03:38 AM
Krezack is offline
Reply With Quote
Interesting.... *snickers* I also would like to know who did it...if only to laugh about it. Heh I bet they will think twice before running trainers now.

And no it was not me

EDIT: interestingly enough its a VB work. That narrows it down to everyone but me, mirrow, and lama. Joy. =P Could someone send me this virus? I would like to take a look at it.
__________________
"Are we not threatened with a flood of information? And is this not the monstrousness of it: that it crushes beauty by means of beauty, and annihilates truth by means of truth? For the sound of a million Shakespeares would produce the very same furious din and hubbub as the sound of a herd of prairie buffalo or sea billows."
—Stanisław Lem, Imaginary Magnitude (1973)
Puffie40 Puffie40's Avatar

JCF Member

Joined: May 2002

Posts: 894

Puffie40 is doing well so far

May 22, 2002, 06:42 PM
Puffie40 is offline
Reply With Quote
Quote:
Originally posted by Unknown Rabbit
Seems to be there was someone who said "I am the Alpha and the Omega", but I don't remember who.

Anyway, very nice detective work, or whatever you did.
Dosen't the Bible say somthing like that???


Great job! This is interesting to hear about a virus for jj2! maybe someone made it because he was sick of that rabbit! (Iknow I aint!)
Cesar Cesar's Avatar

JCF Member

Joined: Apr 2001

Posts: 508

Cesar has disabled reputation

May 28, 2002, 05:38 AM
Cesar is offline
Reply With Quote
Quote:
Originally posted by Puffie40
Dosen't the Bible say somthing like that???
Yes. Jesus Christ said, "I am the Alpha and the Omega, the First and the Last, the Beginning and the End." - Revelation 22:13
__________________
<table cellpadding="0" cellspacing="0" border="0" width="100%" height="32"><tbody><tr><td>Status: N/A.
[<a href="http://home.attmil.ne.jp/a/ocasio/">My Empty Webpage</a>][<a href="http://cesar-ocasio.deviantart.com/">My Deviants</a>][<a href="http://www.cugy.net/">Computer Users Group of Yokota (Japan)</a>]</td><td align="right"><img src=http://home.attmil.ne.jp/a/ocasio/images/nibble6.gif alt="You never saw me" (-)(-)(-)(-)(-)(-)(-)="alert('...aww it\'s so cute!\n ^_____^');return true;"></img></td></tr></tbody></table>
Teej

JCF Member

Joined: Apr 2001

Posts: 208

Teej is doing well so far

May 28, 2002, 12:46 PM
Teej is offline
Reply With Quote
Yeah. Thats nice. Now, who really did it...
Cesar Cesar's Avatar

JCF Member

Joined: Apr 2001

Posts: 508

Cesar has disabled reputation

May 28, 2002, 03:50 PM
Cesar is offline
Reply With Quote
Whoever made this program is very VERY slick, for trying to hide a program with boring icons and names, and knows extensive knowledge about VB process stuff and Jazz2's memory locations.
__________________
<table cellpadding="0" cellspacing="0" border="0" width="100%" height="32"><tbody><tr><td>Status: N/A.
[<a href="http://home.attmil.ne.jp/a/ocasio/">My Empty Webpage</a>][<a href="http://cesar-ocasio.deviantart.com/">My Deviants</a>][<a href="http://www.cugy.net/">Computer Users Group of Yokota (Japan)</a>]</td><td align="right"><img src=http://home.attmil.ne.jp/a/ocasio/images/nibble6.gif alt="You never saw me" (-)(-)(-)(-)(-)(-)(-)="alert('...aww it\'s so cute!\n ^_____^');return true;"></img></td></tr></tbody></table>
>>Møønßlãzé<<

JCF Member

Joined: Apr 2002

Posts: 459

>>Møønßlãzé<< is doing well so far

May 28, 2002, 09:43 PM
>>Møønßlãzé<< is offline
Reply With Quote
Yea, let's poll the athour of the program home! I think he/she really gets scared of something like that
Old Jun 24, 2002, 01:16 PM
Trafton AT
This message has been deleted by Trafton AT.
Alberto

JCF Member

Joined: Mar 2001

Posts: 459

Alberto is doing well so far

Jun 25, 2002, 02:44 AM
Alberto is offline
Reply With Quote
Heh, well, at first it spread thru e-mail.
Then probably people sending it to another people without the knowledge that it was a bad program.
Reply

Thread Tools

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is On

Forum Jump

All times are GMT -8. The time now is 12:16 PM.