Cracked client for TrueClassic.

07/26/2011 04:26 IAmHawtness#91
The people behind TrueClassic are just average DDoS kids.
I'm looking forward to seeing if TrueClassic starts using a custom source or implements a homemade anti-cheat system.
07/26/2011 08:05 NocturnalG#92
The latest patch of True Classic infects your computer and recruits you into a Botnet. For those who do not know a botnet is a collection of compromised computers connected to the Internet, termed bots, that are used for malicious purposes. When a computer becomes compromised, it becomes a part of a botnet. This botnet is used to commit illegal activites such as DDOSing webhosts or stealing information.

But please don't take my word for it, read on.

[Only registered and activated users can see links. Click Here To Register...]
Proof that TCAntibot.exe installed with the latest patch is using my connection unauthorized to attack Love2Hater. My internet was slowed to a crawl (couldn't even load webpages properly) during this btw. I found this by running CMD (Command Prompt) and typing "netstat -nbt" without the quotes.

[Only registered and activated users can see links. Click Here To Register...] - File I removed from my system, installed by the latest

patch. They even go as far as to lie and claim it's an antibot!

[Only registered and activated users can see links. Click Here To Register...]
- Hmm connecting to 76.2.180.71 wonder

who's website that is? Oh look it's Kris' He's using out computer to follow commands giving to us using the same webhost that hosts coderzcafe


Let's confront him about it shall we?
[Only registered and activated users can see links. Click Here To Register...]
- MSN Conversation of him using us to Hack
Wow he doesn't even deny it? He admits to illegally using YOUR INTERNET CONNECTION and computer

WITHOUT YOUR PERMISSION in a Botnet to ILLEGALY attack a webhost and not only slow down your

internet connection but commit illegal attacks against other computers. He claims it's OK to use your computer for illegal activity because 'he's going to remove it after'

You can't even connect to TC without first installing the patch that infects your computer. And they use big bold letters on the homepage to ensure you do so.

But if you ask random about the viruses found in their program

[Only registered and activated users can see links. Click Here To Register...]
He will claim in chat that it is a FALSE POSITIVE and urge you to disable your antivirus programs.

But don't trust me check your computer yourself...
[Only registered and activated users can see links. Click Here To Register...]
They even made the file hidden out of hopes you wouldn't discover it. And I'm not going to lie, if it didn't slow down my internet connection while he was conducting attacks on L2H prompting me to investigate, I wouldn't of discovered it either.

AND THIS IS THE SERVER YOU WANT TO PLAY ON? THESE ARE THE PEOPLE YOU WANT TO GIVE YOUR MONEY TO?

They shouldn't be getting paid, they belong in a jailcell for this! It just proves they care more about Love2Hater than fixing bugs, than their players trust, than 4-60 years in a US prison cell.

Please visit your system32 folder, make sure you enable the ability to view hidden files and delete the file in question.
07/26/2011 08:26 godders3000#93
I found TCAntibot.exe same filesize in True Classic\c3\effect\601289

[Only registered and activated users can see links. Click Here To Register...]
07/26/2011 08:38 NocturnalG#94
Lol and now their website is gone. I honestly think that last patch was a last ditch effort to recruit people into Chris/AgNi's personal army before taking down/abandoning the server. They even held a buy one get one free donation just to milk alittle bit more money before abandoning the sinking ship.

Please search your computer and remove all instances of TCAntibot....and uninstall their whole trueclassic while your at it.

Check True Classic\c3\effect\601289
C:\windows\system32
C:\Users\YOUR NAME HERE\AppData\Roaming



If you find it in any other places please post here. You can also try running the Task Manager. Going to "Processes" and look for "TCAntiBot.exe" on the list. Right click on it and go to Open File Location. End the process and remove the file.
07/26/2011 08:42 AcF#95
Once I ate cookies AND milk.

Quote:
Originally Posted by IAmHawtness View Post
The people behind TrueClassic are just average DDoS kids.
I'm looking forward to seeing if TrueClassic starts using a custom source or implements a homemade anti-cheat system.
Quote:
Originally Posted by NocturnalG View Post
The latest patch of True Classic infects your computer and recruits you into a Botnet. For those who do not know a botnet is a collection of compromised computers connected to the Internet, termed bots, that are used for malicious purposes. When a computer becomes compromised, it becomes a part of a botnet. This botnet is used to commit illegal activites such as DDOSing webhosts or stealing information.

But please don't take my word for it, read on.

[Only registered and activated users can see links. Click Here To Register...]
Proof that TCAntibot.exe installed with the latest patch is using my connection unauthorized to attack Love2Hater. My internet was slowed to a crawl (couldn't even load webpages properly) during this btw. I found this by running CMD (Command Prompt) and typing "netstat -nbt" without the quotes.

[Only registered and activated users can see links. Click Here To Register...] - File I removed from my system, installed by the latest

patch. They even go as far as to lie and claim it's an antibot!

[Only registered and activated users can see links. Click Here To Register...]
- Hmm connecting to 76.2.180.71 wonder

who's website that is? Oh look it's Kris' He's using out computer to follow commands giving to us using the same webhost that hosts coderzcafe


Let's confront him about it shall we?
[Only registered and activated users can see links. Click Here To Register...]
- MSN Conversation of him using us to Hack
Wow he doesn't even deny it? He admits to illegally using YOUR INTERNET CONNECTION and computer

WITHOUT YOUR PERMISSION in a Botnet to ILLEGALY attack a webhost and not only slow down your

internet connection but commit illegal attacks against other computers. He claims it's OK to use your computer for illegal activity because 'he's going to remove it after'

You can't even connect to TC without first installing the patch that infects your computer. And they use big bold letters on the homepage to ensure you do so.

But if you ask random about the viruses found in their program

[Only registered and activated users can see links. Click Here To Register...]
He will claim in chat that it is a FALSE POSITIVE and urge you to disable your antivirus programs.

But don't trust me check your computer yourself...
[Only registered and activated users can see links. Click Here To Register...]
They even made the file hidden out of hopes you wouldn't discover it. And I'm not going to lie, if it didn't slow down my internet connection while he was conducting attacks on L2H prompting me to investigate, I wouldn't of discovered it either.

AND THIS IS THE SERVER YOU WANT TO PLAY ON? THESE ARE THE PEOPLE YOU WANT TO GIVE YOUR MONEY TO?

They shouldn't be getting paid, they belong in a jailcell for this! It just proves they care more about Love2Hater than fixing bugs, than their players trust, than 4-60 years in a US prison cell.

Please visit your system32 folder, make sure you enable the ability to view hidden files and delete the file in question.
Quote:
Originally Posted by godders3000 View Post
I found TCAntibot.exe same filesize in True Classic\c3\effect\601289

[Only registered and activated users can see links. Click Here To Register...]
Quote:
Originally Posted by NocturnalG View Post
Lol and now their website is gone. I honestly think that last patch was a last ditch effort to recruit people into Chris/AgNi's personal army before taking down/abandoning the server. They even held a buy one get one free donation just to milk alittle bit more money before abandoning the sinking ship.

Please search your computer and remove all instances of TCAntibot....and uninstall their whole trueclassic while your at it.

Check True Classic\c3\effect\601289
and system32

If you find it in any other places please post here. You can also try running the Task Manager. Going to "Processes" and look for "TCAntiBot.exe" on the list. Right click on it and go to Open File Location. End the process and remove the file.
yeah, those dDos kids.
07/26/2011 09:10 stealarcher#96
Just incase you forgot. Binaries are illegal period.
07/26/2011 10:15 Janix-L2H#97
...Lol..
07/26/2011 10:56 NocturnalG#98
For the record I have no stake in this pathetic "war". Just attempting to warn users who could be potentially infected as I have some friends who (as of a few hours ago) still played True Classic and may be an innocent victims in this nonsense. No matter who wins this shit the players lose. (Though to be fair with games like GW2/D3/Dragon Nest/Tera Online/SWTOR/Black Prophecy nobody with a decent PC should be playing a 2003 game like CO anyway. So TC shall go down as my last server.)

I don't care if what L2H is doing (running a binary server) is illegal because it doesn't effect me(or anybody besides greedy TQ DIGITAL's intellectual property) in anyway. But your actions has harmed users who legitimately played on your server and some even spent money and had nothing to do with this nonsense. The people who botted on your server will read these posts and learn how to quickly remove it. The people who are associated with L2H uninstalled your server a long time ago. Sad thing is those legit users who never hacked, botted, flooded, spammed, ddos'd or do anything negative to TC may not even see this post because they don't visit this website. Although I'm sure you are aware of that as you and simply wanted to expand your personal army at the expense of jihad suicide bombing your own server.

It's fucked up and a huge breech of trust. However it's nothing unheard of and shouldn't be surprising. I ain't even mad, In fact I thank you for giving me a few laughs and some interesting stuff to read up via google on an otherwise boring end to a Monday.

Fortunately the trojan/worm/whatever the fuck (I have no experience in security or any computer related field) is so poorly designed that a complete n00b could stumble upon it and remove it. However just in case deleting the files simply isn't enough (Really this seemed to go away too easily. They cant be this stupid.) I suggest you install [Only registered and activated users can see links. Click Here To Register...] that actually detected it. Those scanners are [Only registered and activated users can see links. Click Here To Register...], [Only registered and activated users can see links. Click Here To Register...], [Only registered and activated users can see links. Click Here To Register...], [Only registered and activated users can see links. Click Here To Register...], or [Only registered and activated users can see links. Click Here To Register...] and running a complete scan with one of them, ideally at run-time.

Anyway hope this helped at least one person. I will only post if I discover more information about this particular infection, it's really the only thing relevant to my interest here. :mofo:
07/26/2011 11:29 Lateralus#99
Quote:
Originally Posted by NocturnalG View Post
-Informative and correct post-
Thank you so much for educating people about this, because I didn't even notice. I decompiled it, and though it's obfuscated, I can see lots of sketchy shit in here. It even looks like a P2P spread worm is implemented in here... If anyone's interested or doesn't believe me, send me a message, and I'll e-mail you the code.

That's terrible. They really don't give a shit about their players. Hopefully your post will open people's eyes to this.

As for the honest players, my apologies. Call me an asshole, but these exploits were there from the beginning. All I've done was bring them to the general public. Instead of fixing them, they decided to take the extremely low road, so whatever. I really don't care about the war; all I did was release a few hacks, sit back, and watch. :o
07/26/2011 12:20 Captivate#100
This seriously is pathetic.
07/26/2011 14:54 SkyTearZz#101
Wow. Using players as ddosers. Pathetic if you tell me.
07/26/2011 16:17 BoSsHoggOutLaW#102
So.. no more TrueClassic? Damm.. Oh well.. Hey Lateralus, I'm so looking forward to that KylinCo project you got going, keep us informed! :handsdown:
07/26/2011 16:46 XuSo15#103
ZeusBotnet :(
07/26/2011 17:07 IAmHawtness#104
Quote:
Originally Posted by AcF View Post
yeah, those dDos kids.
I hope you're not implying that this shitty piece of malware you guys made makes you any better than simple DDoS kids..
Making the file hidden so the users won't detect it, oh my god. You are obviously new to this game.
07/26/2011 18:40 AcF#105
I am new to all games, I didn't make anything, I can barely code HTML o.o