Page 1 of 1

UT99Butler

Posted: Sun Sep 05, 2021 9:25 pm
by Meht
Hello everybody. I do not know how to take himself and did this. The program starts with the "Unreal Tournament" when you enter the player to the server will give a signal. Due to the fact that I was banned on a popular server I have to wait for players on another accessible. Of course, she does not claim the role of a useful program, but relates to UT.
The program is managed from the initialization file "Ini".

[UT99Butler']
FName_Entered=C:\Pro\Common\snd\Excellent.WAV
FName_Left=C:\Pro\Common\snd\Moo.WAV
FName_UT=C:\UT99\System\UnrealTournament.exe
Runcount=2
Enablelogfile=1
Enablemessage=1
Fontsize=44
Colorfont=Yellow
Enablesound=1
Timeoutsound=14

1. FName_Entered - the name of the audio file will play when entering the player to the server.
2. FName_Entered - the name of the audio file will play when player exit.
3. FName_UT - this is the name of the program "Unreal Tournament".
4. Runcount - number of program startup.
5. Enablelogfile - to record the log if 0 - no.
6. Enablemessage - show a message when entering or output player, if 0 - no.
7. Fontsize - font size message.
8. Colorfont - the color of the message text, 12 colors are available or specify "Random".
9. Enablesound - sound, 0 - no.
10. Timeoutsound - 14 seconds by default, 0 - infinite
* stop clicking on the message or key combination "Ctrl + Alt + S".

---
Initially, a welcome screen with a hint is launched. Then the program will propose
"please, select three files using Browse":
1. Unreal Tournament.exe
2. WAV - the player entered
3. WAV - the player left

After that, the program launches "Unreal Tournament" and works in the background. When the player appears - someone comes to the server, the message will be displayed and a beep sounds.
--- !!! --- | --- !!! --- | --- !!! ---
ATTENTION: The program is written in the VC Version 6.0 1998 due to this some antiviruses Do not want to skip and show that this is a virus! Do not believe - this is a lie !!! Microsoft wants to get everyone danced under his drawing!

***FILE REMOVED*** by Dr.Flay

Re: UT99Butler

Posted: Mon Sep 06, 2021 3:44 am
by EvilGrins
Darn... was kinda hoping it was a monster dressed in a tux that cleaned up after everyone else.

Re: UT99Butler

Posted: Mon Sep 06, 2021 3:58 am
by TankBeef
EvilGrins wrote: Mon Sep 06, 2021 3:44 am Darn... was kinda hoping it was a monster dressed in a tux that cleaned up after everyone else.
:lol2:
What a great idea!!! :rock: Someone please, make it happen.

Re: UT99Butler

Posted: Mon Sep 06, 2021 7:39 am
by SteadZ
Not exactly a butler but I did make a Nali waiter skin years back which could be put to use for such an idea lol

Re: UT99Butler

Posted: Mon Sep 06, 2021 9:07 am
by papercoffee
perfect fit for the chef of hell skin.

@Meht
I don't quiet understand what your little tool is doing.

Re: UT99Butler

Posted: Mon Sep 06, 2021 1:36 pm
by TankBeef
papercoffee wrote: Mon Sep 06, 2021 9:07 am @Meht
I don't quiet understand what your little tool is doing.
It seems to me that it is some tool to play sounds and message when a player enters or leaves the server? Maybe?
I agree that the explanation is very confusing. :?

Re: UT99Butler

Posted: Mon Sep 06, 2021 9:58 pm
by Feralidragon
I don't know what to make of this either...

I kinda understand the idea here and everything, but there are too many red flags here:
  • the post was written in a very... confusing way to say the least;
  • the file does get flagged by 10 AVs out of 61 in VirusTotal (like the user said would happen);
  • the user makes up a conspiracy theory about the above, instead of providing an actual good verifiable reason (when non-Microsoft AVs flag this file);
  • this is the user's first and only post in the forum, without any previous history of releasing any trusted stuff of this kind;
  • what it apparently does could have been achieved in plenty of other ways that didn't involve a separate executable and getting it flagged by AVs.
Here's the VirusTotal report:
https://www.virustotal.com/gui/file/d88 ... /detection

So I am not really sure what to think here, but I don't trust this myself, for now.

If there was a public repository with the source code someone could verify and compile by themselves, and get the same AV warnings, then maybe we could sort of trust it, but otherwise not really.
But this is just my opinion...

Re: UT99Butler

Posted: Mon Sep 06, 2021 10:11 pm
by Meht
Good. I'll tell you now - it will be a whole book.
I play this game since 1998, though it was the Unreal.
In a word - I love to play only on the deck (only, only only d16)!
After Madixis left, more precisely, the "Min400" has already appeared at that moment.
(Madixis if you read - I say hello!).
So. I never cheated in the game, I didn't even think about it !!!
But once I got into the hands of the Hazard code, I gathered him and tried it - it's on "Min400".
After that, I was banned for always, even the whole provincial area.
Yes. Admin was very brutally enrolled. I did not even think that there are such who remembers evil so long!
Well, nothing to do. Over the years, but only a few times played.
Somewhere I recently discovered that there is a server and I liked it in all respects.
This server creates my compatriot, and also has an account here, his name is a "sosed".
Of course. There was a lot of time and I'm not very playing at all and in general we raised.
I do not want to continue - it is sad!
So far I will send this message, and a little later we will use more about the program and make several pictures.

Re: UT99Butler

Posted: Mon Sep 06, 2021 10:32 pm
by TankBeef
Feralidragon wrote: Mon Sep 06, 2021 9:58 pm
Here's the VirusTotal report:
https://www.virustotal.com/gui/file/d88 ... /detection
Yikes!!! :shock: No way I am touching that file. Thanks Ferali.

Re: UT99Butler

Posted: Tue Sep 07, 2021 12:48 am
by Meht
Tank, I talked about it above.
I am the second guild programmer, I do not cheat, I have a program that is also defined as a virus, but what to do - everyone wants money, I do not want to be a sponsor and pay Bill for botnet.
Everyone knows that the OS of which we use two-door.
No choice it is a monopolist. And I will not have time to do a new OS in this life.

--- I do not force anyone to upload anything - just talking to myself.

So. Program Butler - Made as - Well, for example, I thought that if you run in the background and just sit and wait for someone, but in fact it was utopia.

Here is a small sketch. Caution Sometimes the program falls along with UT more precisely.
Image

I added item "Faworite", you can write the server there if nothing is indicated by the deck starts.

In full screen mode, the program crashes. You need to start with minimal.
The program is packaged
Image
***FILE REMOVED*** by Dr.Flay

Re: UT99Butler

Posted: Tue Sep 07, 2021 2:29 am
by EvilGrins
SteadZ wrote: Mon Sep 06, 2021 7:39 amNot exactly a butler but I did make a Nali waiter skin years back which could be put to use for such an idea lol
Thanks, I've been looking for that for ages.
Do you mind if I team color it and make it into a skin?

Re: UT99Butler

Posted: Tue Sep 07, 2021 4:16 am
by TankBeef
I think it would be cooler if the waiter showed up in the middle of a match, like every 10 frags or something, and went like "Sir, would you like something to drink?" :lol2:

Re: UT99Butler

Posted: Tue Sep 07, 2021 8:24 am
by Dr.Flay
As you are obviously using an online translator to convert Russian to English, I suggest that you avoid "writing a book" when you make a post.
Some of what you pasted does not make sense in English.
Please write with your best Russian grammar when using online translators.
Meht wrote: Sun Sep 05, 2021 9:25 pm ATTENTION: The program is written in the VC Version 6.0 1998 due to this some antiviruses Do not want to skip and show that this is a virus! Do not believe - this is a lie !!! Microsoft wants to get everyone danced under his drawing!
No it has nothing to do with Micro$oft. They do not control the AV companies.
More likely the biggest problem with your exe is that you used "PECompact", and it has an "invalid-rich-pe-linker-version", or it contains malware.
The new build is worse than the previous version. The previous version did not trigger so many warnings in a sandbox.

Upload a regular version with no extra fancy compression or resources stripped out, and then it will not trigger so many AV.
Anything new using PE or UPX compression will be flagged as a virus, so stop using it.
Unless the code contains trade secrets, please include the source with the distro (or allow the staff here access to the source code).
Nothing about the functionality of this addon is worth keeping secret.

-----------
OK the bit everyone else is interested in.
Sandbox tests in VT and OPSWAT show some suspicious behaviour.
It seems to be very nosey, and is checking multicast UDP for attached devices, and also looking to see what drives are attached.
https://www.virustotal.com/gui/file/af0 ... 02/details
https://metadefender.opswat.com/results ... ox/summary

If you can explain the reasons why it is checking the system and network, or provide the code, we can allow it to be hosted here, but until then it is too much of a risk. Sorry.
Please also make sure your SDK environment is not compromised, including tools like Bitsum PECompact. Any pirated software may be a cause for injected extras

Re: UT99Butler

Posted: Tue Sep 07, 2021 1:31 pm
by SteadZ
EvilGrins wrote: Tue Sep 07, 2021 2:29 am
SteadZ wrote: Mon Sep 06, 2021 7:39 amNot exactly a butler but I did make a Nali waiter skin years back which could be put to use for such an idea lol
Thanks, I've been looking for that for ages.
Do you mind if I team color it and make it into a skin?
Go for it! I have a couple others ("Agent" & "Bellboy" Nali skins) from the same time I'd be happy to share too if you're interested?

(though we should probably stop hi-jacking this thread now lol)

Re: UT99Butler

Posted: Tue Sep 07, 2021 2:10 pm
by TankBeef
SteadZ wrote: Tue Sep 07, 2021 1:31 pm (though we should probably stop hi-jacking this thread now lol)
Last one SteadZ, I promise. :lol2: (And he really should do something about that malware warning, Flay did the right thing by blocking it for now)
SteadZ wrote: Tue Sep 07, 2021 1:31 pm "Bellboy" Nali skins
"Would you like me to take your luggage, sir?" :lol2:

Ok, no more hijacking people, back to subject :wink: