Register for your free account! | Forgot your password?

Go Back   elitepvpers > MMORPGs > Conquer Online 2
You last visited: Today at 22:37

  • Please register to post and access all features, it's quick, easy and FREE!

Advertisement



ATTN:True Classic Players, Removing TC Worm/Malware

Discussion on ATTN:True Classic Players, Removing TC Worm/Malware within the Conquer Online 2 forum part of the MMORPGs category.

Reply
 
Old   #1
 
elite*gold: 0
Join Date: Apr 2005
Posts: 300
Received Thanks: 16
ATTN:True Classic Players, Removing TC Worm/Malware

I am reposting by request. Perhaps more people will see it here rather than buried in a hack thread. The latest set of patches for the True Classic(Formerly found @) server, was actually malware that installed a worm into your computer to recruit you into the owners botnet. For those who do not know a botnet is a collection of compromised computers connected to the Internet, termed bots, that are used for malicious purposes. When a computer becomes compromised, it becomes a part of a botnet. This botnet is used to commit illegal activites such as DDOSing webhosts or stealing information. The worm has self-replicating feature and can spread via P2P so it is urgent that you get rid of it as soon as you realize you are infected.

It's a sad case of a formerly legitimate program/server turned to malicious after earning users trust. Anyone infected by will have their bandwidth/internet used to be used to commit illegal activity. If you used True Classic past patch 1044 (IE: Patch 1045 and Patch 1046) you are at risk. Fortunately the worm is designed by a novice and is quite to remove.

Automatic Removal
Just download and install that actually detected this worm.

, , , , or and running a complete scan with one of them, ideally at run-time. It will find this worm and possibly other infections and remove it. If your antivirus isn't one of the above then it wont be found.

Manual Removal
Just enable the ability to view hidden files in folders. For instructions on how to do view hidden files in , , and .
Once this is turned on simply START-->SEARCH your computer for TCAntiBot.EXE

Delete the file(s) and dump your recycle bin to remove all

The search should find the files located at
True Classic\c3\effect\601289

C:\windows\system32

If it does not, please go to those folders and manually look for TCAntibot.exe

If you are using Windows Vista or Windows 7. Please also check this folder
C:\Users\YOURNAMEHERE\AppData\Roaming

Replace 'YOURNAMEHERE' with your windows user name

If you are using Windows XP. Please also check this folder
Documents and Settings\YOURNAMEHERE\Application Data

Replace 'YOURNAMEHERE' with your windows user name

If you are unable to delete the file you will have to open your Task Manager via Ctrl+Shift+ESC. Switch to the process list and end the TCAntibot process.

For more information about this malware read which the information was originally posted in.

For anyone interested, the TCAntibot.exe file I'm talking about can be found (b460e03ac2f9ec50572fd93f32eb967d) and it's virustotal scan . If you use a scanner that doesn't detect it, I suggest you submit the file to them so these kids can't use this as easily again.

It's really pathetic that a server would be desperate enough to infect 150 of their users just to win a DDOS war. And they ended up losing not only the war but also their credibility(lol). If you know someone who was unfortunate enough to play True Classic in the last few days(the latest patches) please direct them here.
NocturnalG is offline  
Thanks
8 Users
Old 07/26/2011, 22:32   #2
 
elite*gold: 0
Join Date: May 2011
Posts: 1,769
Received Thanks: 756
I guess, that's what they used to ddos others. What a fail server.
BaussHacker is offline  
Thanks
1 User
Old 07/27/2011, 13:44   #3
 
elite*gold: 0
Join Date: Jun 2009
Posts: 2
Received Thanks: 0
*****, so now that we know this they shut down the server and the website ?
SeeKer91 is offline  
Old 07/27/2011, 15:13   #4
 
elite*gold: 0
Join Date: Jan 2008
Posts: 81
Received Thanks: 0
Quote:
Originally Posted by SeeKer91 View Post
*****, so now that we know this they shut down the server and the website ?
No, first they shut the serv and web, and now you know this couse someone like this thread creator, found suspicious process running, and figured all this **** out, which is said on the first post...
ernis007 is offline  
Old 07/27/2011, 17:14   #5
 
elite*gold: 0
Join Date: Jun 2006
Posts: 10
Received Thanks: 1
I still don't understand why they would throw out their server just to DDoS another server, which only brought it down for a few hours.
xStainD is offline  
Old 07/27/2011, 22:39   #6
 
elite*gold: 0
Join Date: Apr 2005
Posts: 300
Received Thanks: 16
Quote:
Originally Posted by ernis007 View Post
No, first they shut the serv and web, and now you know this couse someone like this thread creator, found suspicious process running, and figured all this crap out, which is said on the first post...
I started to write the above post on their official forums, then they took down the server and web. I think they were trying to prevent more people(such as the ones who don't read epvpers) from finding out about it. So he may be right in saying that this is one of the reasons why they shut down their server and web so quickly (I'm sure it was going to go down eventually once they installed it anyway). But not the only reason.


I'd also contribute the attacks from enemies which causes their server to go down/lag and the flooding from spam bots which caused them to disable registration as factors in the eventual take down. Apparently the owner was "getting attacked by around 6 people" and "can't stop the attacks while at work".

Quote:
I still don't understand why they would throw out their server just to DDoS another server, which only brought it down for a few hours.
I don't get it either. It was a completely desperate suicide bomb-like move that ultimately backfired. It's a shame because I did enjoy the server. The only remaining "classic on a 2.0 client" servers are European and as a American they don't appeal to me. For people who don't mind a European server though, I do urge you to check out
NocturnalG is offline  
Old 07/28/2011, 00:06   #7
 
Bumper's Avatar
 
elite*gold: 0
Join Date: Aug 2008
Posts: 28
Received Thanks: 2
if any of you true classic spawns are reading this, you came and you lost. come at us.
Bumper is offline  
Old 07/28/2011, 06:07   #8
 
elite*gold: 0
Join Date: Jul 2011
Posts: 2
Received Thanks: 0
ya I was a TC player, prolly one of the best on the server, I only spent 35 dollars on it and in process of getting my money back, but I do want to say after exploring this website, hacking and the botting, thats really stupid for all you who enjoy doing it, really sad, but what do I know huh? Get a life, and stop massacering servers, lifes to short you noops!
Rohagi is offline  
Old 07/28/2011, 09:00   #9
 
elite*gold: 0
Join Date: Jun 2009
Posts: 787
Received Thanks: 314
I'm pretty sure I know the real reason they "shut down" their server.
_tao4229_ is offline  
Old 07/28/2011, 09:26   #10
 
elite*gold: 0
Join Date: Jun 2009
Posts: 2
Received Thanks: 0
Quote:
Originally Posted by _tao4229_ View Post
I'm pretty sure I know the real reason they "shut down" their server.
Mind sharing it with us ?
SeeKer91 is offline  
Old 07/28/2011, 09:39   #11
 
elite*gold: 0
Join Date: Jul 2011
Posts: 1
Received Thanks: 0
this ***** tao4229 hacked like 500 accs. thats the tl;dr.

******* on em.

HOLLA @ ME ON THE COAI FORUMZ.
BCO_KAREN is offline  
Old 07/28/2011, 17:21   #12
 
Sorrow62's Avatar
 
elite*gold: 0
Join Date: Jul 2011
Posts: 6
Received Thanks: 3
I and my sons, we played on trueclassic and I have to say that it is (was) one of the best server ever, but the "iron underwear" I set up on my PCs blocked that malware and when I posted a warning on trueclassic forum it was ignored and deleted in few days.

Still I don't understand why they tried to set up a botnet in a so "naive" manner...

Surely they're not a real danger for web surfers ;-)
Sorrow62 is offline  
Old 07/28/2011, 19:52   #13
 
_DreadNought_'s Avatar
 
elite*gold: 28
Join Date: Jun 2010
Posts: 2,223
Received Thanks: 867
Quote:
Originally Posted by _tao4229_ View Post
I'm pretty sure I know the real reason they "shut down" their server.
If what BCO_K is saying is true, I <3 you.
_DreadNought_ is offline  
Old 07/28/2011, 20:05   #14
 
Bumper's Avatar
 
elite*gold: 0
Join Date: Aug 2008
Posts: 28
Received Thanks: 2
Quote:
Originally Posted by Sorrow62 View Post
I and my sons, we played on trueclassic and I have to say that it is (was) one of the best server ever, but the "iron underwear" I set up on my PCs blocked that malware and when I posted a warning on trueclassic forum it was ignored and deleted in few days.

Still I don't understand why they tried to set up a botnet in a so "naive" manner...

Surely they're not a real danger for web surfers ;-)
well your server hosters liked attacking other servers. See it as a group effort that we returned the favour. only ones to blame is themselves. The real victims are the ones that played trueclassic. They got screwed over like mad.

oh well, the only server worth mentioning that is classic would be love2hater now, and that one is EU based.
Bumper is offline  
Old 07/28/2011, 22:14   #15
 
elite*gold: 0
Join Date: Sep 2010
Posts: 15
Received Thanks: 0
Not really the only classic server hosted in EU. There is this one as well
ClassicConquer is offline  
Reply


Similar Threads Similar Threads
TRUE-CLASSIC - REAL [1.0] SYSTEMS EXPERIENCE. 150+ players online 24/7
03/02/2011 - CO2 PServer Archive - 20 Replies
FUCK KRIS and RANDOM from true classic lol they banned lots of players without reason took all best non donated stuffs just because one donnor asked them to, this server blows
Removing the W32 Sohanad.H Virus/Worm
02/09/2008 - Silkroad Online - 1 Replies
Removing the W32 Sohanad.H Virus/Worm Instructions This is a worm that spreads itself by sending links to your contacts in messengers like Yahoo, AOL and Windows Live messengers. It disables Registry Editor and Task Manager. It changes the Internet Explorer (IE) home page and also modifies registry such that you cannot change the homepage address. For more details on this worm, read the TrendMicro virus Information on this worm. Here are simple steps following which you can get the...



All times are GMT +2. The time now is 22:37.


Powered by vBulletin®
Copyright ©2000 - 2024, Jelsoft Enterprises Ltd.
SEO by vBSEO ©2011, Crawlability, Inc.
This site is protected by reCAPTCHA and the Google Privacy Policy and Terms of Service apply.

Support | Contact Us | FAQ | Advertising | Privacy Policy | Terms of Service | Abuse
Copyright ©2024 elitepvpers All Rights Reserved.