Mike
Re: Cover Your Tracks V3.1 - Task 2
Thu Dec 17 17:31:31 1998




Thu Dec 17 03:35:54 1998


Didn't have too much time to bit twiddle too much but seems to create (2) hidden files: win640s.cpl and msffs.dll
(in the c:winnt directory). These files are constructed from static global memory in which each address stores two
byte character pairs to build the file name string. Creates it's own .ini file (cyt.ini) with which to store initialization
time, etc. Creates its own registry entry "software etscape etscape navigatorinitialize (initialization ? can't
remember). Delete all files and registry entry to reserialize application.

Also is set up for ability to handle separate string resource (foreign language?) if file cyt.enu is present (loaded as
dll read resource only).

If either hidden files are missing but registry entry is present, knows it has been tampered with. Compares time
stamps for hidden files by forcing the seconds bits to same value. Hopefully you never install at the stroke of
midnight and have two files created on successive days…. Haven't had time to disassemble the structure of the
hidden files.

Not the most efficient program (and hopefully for the compilers sake, the optimize option was turned off) as some
looping code beats the processor (ex: 401A67: recalculates the same base offset, and unnecessarily clears a
register each time through the loop - be thankful the days of the 8/10 megahertz processors are gone…!)

Back to work in the real world….

Mike


edited by jeff; Thats it folks; No more editing; no more cut & pasteing & moving;
From here on; I'm just gona delete ya.........2:05.. 12.17.98