Warcraft II Forum

Warcraft II => Server.War2.ru => Topic started by: Biggie on October 01, 2015, 04:44:55 PM

Title: Please Ban 'UPNP' for trying to spread virus program
Post by: Biggie on October 01, 2015, 04:44:55 PM
UPNP has link to a Trojan program in profile.

Downloaded it and uploaded to virustotal.com, 3 antivirus programs flagged it as a trojan

/finger UPNP

 Login: UPNP             #01512064 Sex:
 Created: Thu Oct 01 16:09 2015
 Location:                         Age:
 Client: Warcraft II    Ver:    Country: USA
 On since Thu Oct 01 16:17 2015 from unknown
 Idle 11 minutes 45 seconds
 UPNP Auto Port Forward for WarCraft II - http://rghost.net/*REMOVED* (http://rghost.net/)


http://s14.postimg.org/ucn783ptd/download_link.png (http://s14.postimg.org/ucn783ptd/download_link.png)
http://s21.postimg.org/wcjvnymhz/tupac_virus.png (http://s21.postimg.org/wcjvnymhz/tupac_virus.png)

Admins please post IP Address of "UPNP" so we can all be aware of who this malicious hacker is and also ban him
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: {Lance} on October 01, 2015, 06:20:46 PM
This is the same person (probably USA~Archer) that was trying to spread war2_trainer.exe which is the exact same virus seen here.  It's more or less a backdoor to turn your machine into a zombie or do whatever archer wants.
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: EviL~Ryu on October 01, 2015, 06:37:28 PM
Who else but Riley? [emoji39]


Sent from my Motorola DynaTAC 8000X using Tapatalk
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: Biggie on October 01, 2015, 06:40:23 PM
This is USA~Archer its not me, nor did I try to spread war trainer... I have my ideas about who it is but I'm not saying anything without proof

I got backdoored by the guys that tried to split War2Combat and do War2Custom instead back in 2010

That was you right Lance? Or who was it that was trying to spread the War2Custom trojan
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: Winchester on October 01, 2015, 06:49:03 PM
War2Custom actually fixed hosting and joining game issues on my desktop. I never got trojaned.
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: EviL~Ryu on October 01, 2015, 07:29:38 PM

War2Custom actually fixed hosting and joining game issues on my desktop. I never got trojaned.




Sent from my Motorola DynaTAC 8000X using Tapatalk
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: Delete mine too on October 02, 2015, 12:07:30 AM
See that's why i wanted a good reputation system. To prevent new people from downloading from unknown people. If anyone has used any of these files mentioned above WIPE your system immediately. Also start using a virtual machine to run files or a sandbox. You can make someones virus become detected by uploading to virus total website.
Title: Please Ban 'UPNP' for trying to spread virus program
Post by: EviL~Ryu on October 02, 2015, 01:15:26 AM
They close the connection to this idiot yet?


Sent from my Motorola DynaTAC 8000X using Tapatalk
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: Delete mine too on October 02, 2015, 01:59:27 AM
You can also try reversing this newbs back door. Who has a copy of this these files? If you are infected and want to shut down the rat. netstat and sniff out the ip or dns then block in host file. Also might find an email with an hex editor.
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: {Lance} on October 02, 2015, 11:28:41 AM
The only thing you got backdoored on was a call to your step father LMAO.  But if you think you know who it is (since its you) then you should make that claim known so we can make fun of it/you some more :D
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: Biggie on October 02, 2015, 12:27:57 PM
Obviously I was hinting at it being Tupac (Biggie, "tupac_virus.png" lol GET IT??? jeez you guys are slow sometimes)

I didnt have any proof, just suspicion so I didnt say it directly. But now after reading Tupac's post, it doesnt make sense that Tupac would offer suggestions on how to find the hacker if it was him!

Sure he could just be offering suggestions to defer himself as a suspect but I dont think that is the case.


I'm the one calling this virus uploader out, why would I call myself out LOL seriously??

I tend to doubt that it would be {Lance}, since he is so friendly with the FBI. I wouldnt think someone who tries to get hackers in trouble with the FBI wouldnt be a hacker himself... because it doesnt make sense - he wouldnt want any attention on himself if he was also a hacker.


So my list of suspects is empty now.


You guys always blame everything on me, but the fact is I actually never DDoSed the server

Title: Please Ban 'UPNP' for trying to spread virus program
Post by: EviL~Ryu on October 02, 2015, 12:54:52 PM
..... jeez you guys are slow sometimes)....


You sure about that? Or are we just not mentally handicapped as yourself [emoji50]

Sent from my Motorola DynaTAC 8000X using Tapatalk
Title: Please Ban 'UPNP' for trying to spread virus program
Post by: EviL~Ryu on October 02, 2015, 01:22:02 PM
But Riley,

I mean come on when are you seriously gonna stop acting all retarded for once in your life. People hate you in this community, that's a fact. Even your so called "friends" in the pball community think your a idiot. You think your all badass, but bro honestly....your not. Your a clown which people laugh at. Either contribute by gaming or just leave.



Sent from my Motorola DynaTAC 8000X using Tapatalk
Title: Re: Please Ban 'UPNP' for trying to spread virus program
Post by: {Lance} on October 02, 2015, 09:29:11 PM
I'm the one calling this virus uploader out, why would I call myself out LOL seriously??

Well, one logical reason would uhm, well lets see....  Because you've done just that many times in the past?  LOL.  Just sayin :D