PDA

View Full Version : Virus?


Bugsy
28 Jan 2008, 13:42
My antyvir detected virus on dir folder of WA:

Virus or unwanted program 'CC/Agent.FJ [CC/Agent.FJ]'
detected in file 'C:\Program Files\Worms Armageddon\madCHook.dll.
Action performed: Delete file

I deleted it.Since then I can't start the game. cleaning the registry and reinstalling hasn't helped. Please help me.

ErrorLog:

http://www.sendspace.pl/file/OITWOPxs/ (click "pobierz plik")

yakuza
28 Jan 2008, 13:48
What version of the game is that? I do not have that file and AFAIK default installations are usually C:\Micropose or Team17,you could have just selected a custom install path though.
Google says it's malware, though.

Bugsy
28 Jan 2008, 13:52
Program files/worms armageddon (PL version) the newest patch.

KRD
28 Jan 2008, 15:03
That's a WormKit file, so most likely a false alarm. Don't know why deleting it would break WA though, unless you're running it via WormKit.exe. In which case you should just unpack it there again and all should be fine.

Bugsy
28 Jan 2008, 21:53
Ok ,thanks. i will try tomorrow.

CyberShadow
29 Jan 2008, 00:44
If your anti-virus falsely detects a code hooking library (http://www.madshi.net/madCodeHookDescription.htm) used in hundreds of security utilities today as malware, I recommend a better anti-virus.

Bugsy
29 Jan 2008, 22:44
I don't know better anty-virus. I use antyvir personal edition. Wormkit didn't helped too ;/

Rainman_
30 Jan 2008, 10:30
Use NOD32 or AVG antivirus.

Bugsy
10 Feb 2008, 11:27
New antyvirus will not solve my problem...

CyberShadow
10 Feb 2008, 11:33
You do not have a problem. Your antivirus has a problem.

Bugsy
19 Mar 2008, 21:16
I told you. i cleared register and reinstall many times WA and still isn't work. In this time I closed my antyvirus.Does errorlog show you anything what is the problem?
Sorry for my english

MrBunsy
19 Mar 2008, 21:47
I told you. i cleared register and reinstall many times WA and still isn't work. In this time I closed my antyvirus.Does errorlog show you anything what is the problem?
Sorry for my english

What happens when you try to run WA?

Muzer
20 Mar 2008, 09:39
1) Run WA.EXE instead of WormKit.EXE.
2) If that works, reinstall WormKit. Then run it from wormkit as normal.

If you didn't have WormKit installed, I'm willing to believe you're a pirate.

Meszka
20 Mar 2008, 09:54
What happens when you try to run WA?

What I know from talking with Bugsy: the game crashes as soon as he runs it and generates an errorlog. So it would be nice if someone who knows how to read these errorlogs had a look at it.
And as far as I know he's running WA.exe, not WormKit.exe (although he's probably tried both while trying to get W:A to work).

Bugsy
20 Mar 2008, 18:07
What happens when you try to run WA?


The game menus are working but when i want to load a map it crashes during loading (radioactive sign animation).

Bugsy
20 Mar 2008, 18:21
errorlog (new link)

http://www.speedyshare.com/187444570.html

greyze
20 Mar 2008, 18:24
AntiVir (Avira) im assuming your using this since you said antivir.

this is a very good anti virus compared to other lamers like NOD and AVG. the hook contains code that can be considered dangerous, loads of anti viruses can detect this. The reason why it does is because the Heusteric analyzer is set to high, set it to medium. If it still happens with the anti virus then you actually do have a virus on the hook.

for worms not starting, that wouldn't have anything to do with the anti-virus unless you have blocked the program in some sort of way. re-installing wont help because there's actually something on your computer preventing it.

Bugsy
20 Mar 2008, 18:32
AntiVir (Avira) im assuming your using this since you said antivir.

this is a very good anti virus compared to other lamers like NOD and AVG. the hook contains code that can be considered dangerous, loads of anti viruses can detect this. The reason why it does is because the Heusteric analyzer is set to high, set it to medium. If it still happens with the anti virus then you actually do have a virus on the hook.

for worms not starting, that wouldn't have anything to do with the anti-virus unless you have blocked the program in some sort of way. re-installing wont help because there's actually something on your computer preventing it.

Yes. In my opinion it is very good antyvirus. My option is: medium detection level (win32 file heuristic).

CyberShadow
20 Mar 2008, 20:18
Detecting a general-purpose hooking library which contains no malicious code by itself as a threat is not a good trait of any anti-virus program. Now stay on topic or be moderated.

Regarding the crash: Did you try reinstalling the game?

If yes - where did you buy your game CD from? What company names are on the CD, aside Team17?

Bugsy
21 Mar 2008, 17:11
Detecting a general-purpose hooking library which contains no malicious code by itself as a threat is not a good trait of any anti-virus program. Now stay on topic or be moderated.

Regarding the crash: Did you try reinstalling the game?

If yes - where did you buy your game CD from? What company names are on the CD, aside Team17?

In Poland... this is a oryginal cd.

CyberShadow
21 Mar 2008, 20:16
What company names are on the CD, aside Team17?

Can you scan or take a photo of the CD or CD case/box?

Bugsy
21 Mar 2008, 21:54
I dont have scanner.

This is my version of game:

http://www.3kropki.pl/p/2/worms_armageddon.php

CyberShadow
22 Mar 2008, 11:37
Please run the command
cmd /C dir /S W:\ > C:\filelist.txt
substituting W with the drive letter of the drive you have the W:A CD in. Then, compress and upload the file filelist.txt from your C:\ drive.

Also, please post the contents of W:\Data\Resource\version.txt, if such a file is present on your CD.

Bugsy
22 Mar 2008, 12:49
Here you are:

http://www.speedyshare.com/258780980.html

Meszka
1 Apr 2008, 16:02
Hmmm, does anybody still remember this thread? Looks like it's getting lost under the pile of new threads but the problem hasn't been solved yet...

CyberShadow
1 Apr 2008, 16:34
Bugsy's problem seems to be a damaged CD. He should check if the file W:\Data\Water\Blue\Water.dir is readable.

Bugsy
1 Apr 2008, 17:24
Thanks a lot! You were right. I got a working Water.dir file from a friend (I hope that's not piracy) and used wkFileOverride.dll with it. Now W:A works fine with wormkit.:D

Patrick_
1 Apr 2008, 18:12
Detecting a general-purpose hooking library which contains no malicious code by itself as a threat is not a good trait of any anti-virus program. Now stay on topic or be moderated.

Wow... think you're being a bit harsh there? I've seen many other posts that were extremely questionable on this forum that have been ignored. You're a moderator, so it's up to you, but I think you might be taking your power a bit far there with that threat. Being off-topic is unavoidable in public forums...

Have you ever heard of heuristics (http://en.wikipedia.org/wiki/Heuristics)? Most AVs have them. False positives _are_ normal. AntiVir has a very good detection rate... much better than most. See here (http://www.av-comparatives.org/seiten/ergebnisse_2008_02.php) and here (http://www.virus.gr/portal/en/content/23-april-10-may-2007). Just because a false positive is detected does not mean the antivirus isn't good.

Looking at MadCodeHook's website, it says: "Unfortunately madCodeHook has been misused by malware in the past.". Hooking can indeed be used for malicious purposes. Surely your purpose with WormKit isn't malicious, but others who use madCodeHook might be using it for malicious purposes. I would certainly appreciate my antivirus warning me about a potential problem, so I can do further research, rather than having it ignore it and not know what could possibly happen with the program in question. Better to be safe than sorry.

Anyway, back on topic, glad that your problem is fixed, Bugsy. :)