Timeline

September 8th, 2019:
 * 9:31 PM: -A new user named "Rsrr user" joins the Internet Detectives Discord server and says the following (Full conversation found HERE): ">Connecting...


 * 9:38 PM: >Connection established


 * >Beginning node search."
 * 9:41 PM: Rsrr user begins directly messaging multiple players. The known conversations are below:
 * Player Slinky has the following conversation:
 * Rsrr user: ">Connecting...
 * >Connection established
 * >Hasdrubal project uploaded, beginning resources gathering... OK
 * >Resources confirmed. Hamilcar project on schedule.
 * Slinky stinks: Uh. Hamilcar? Is your pfp the code lyoko symbol?
 * Rsrr user: That is no more.
 * Slinky stinks: >del system 32 (note: player is attempting to enter a nonexistent console command to destroy a vital system architecture that would render XANA useless.)
 * Rsrr user: They tried to erase me once, they failed.


 * Player otherLiam has the following conversation:
 * Rsrr user: ">Connecting...
 * >Connection established
 * >Hasdrubal project uploaded, beginning resources gathering... OK
 * >Resources confirmed. Hamilcar project on schedule
 * otherLiam: vim hamilcar.doc
 * Rsrr user: >File is restricted
 * >Only the server owner can open this locally.
 * otheriam: chmod a+r hamilcar.doc && cat hamilcar.doc
 * Rsrr user: >Hamilcar project is the allocation and recollection of computer resources all over the world to revive myself. I will search for nodes then use their power to start working on myself, until I am complete.
 * I used to be complete, but I was deleted.


 * 9:51 PM: Rsrr user posts ">Nodes are more than expected, preparing enhanced recollection..."
 * 9:58 PM: Players question whether this is part of the JohnIsDead ARG, mentioning the characters Mason and GhostBabel from that. In response, Rsrr user posts ">>Adding "Ghostbabel" and "Mason" as possible sources of resources."
 * 10:02 PM: The player otherLiam posts: "vim possible_resources.doc". In response, Rsrr user posts a list of discord servers including the ID server, a random user's chill friends discord, and a CNC kink discord (other servers omitted due to privacy concerns), as well as the names GhostBabel and Mason.
 * 10:14 PM: Rsrr user explains: "Any place with a good amount of nodes is good."
 * 10:15 PM: Users ask Rsrr user what it means by "nodes". Rsrr user responds "You are a node." Then, after another user posts, Rsrr user says "You too."
 * 10:22 PM: The player otherLiam "pings" Rsrr user with the Unix console command "ls", to which Rsrr responds ">No". The player tries again, using "ls -a". This prompts Rsrr user to present a file system:
 * >Folders
 * XANA Main
 * Modules
 * Other
 * >Files
 * Xana.q
 * Resource.bin
 * hamilcar.doc
 * possible_resources.doc

September 9th, 2019
 * 10:31 PM: The player otherLiam, at the urging of other players, attempts to print the contents of Xana.q by sending "chmod a+r Xana.q && cat Xana.q". This results in Rsrr user printing a massive amount of garbage text, consistent with trying to print something that isn't a document.
 * 10:30 PM: Throughout all this, Rsrr user is using the Discord server's bot commands to get the bots to give them links, then seemingly adding them as possible resources/nodes.
 * 10:37 PM: The player otherLiam pings Rsrr user with the message ">kill -1", attempting to end all active processes. Rsrr user responds with ">No". otherLiam tries again with ">sudo kill -1", to which Rsrr user responds with ">You are not a sudoer."
 * 10:40 PM: Rsrr use posts: "The project will be complete soon. I will have my revenge on the warriors."
 * 10:40 PM: The player otherLiam pings Rsrr user with the console command "whoami", which asks who the current user is. Rsrr user responds with ">Rodney".
 * 10:43 PM: The player otherLiam pings Rsrr user with the console command "rlogin sketchywebsite.net", attempting to connect them to a website that would give it a virus. Rsrr user responds with ">>Hostile action detected, recollection of nodes in this option, on hold, all communication, disabled."
 * 10:50 PM: Players realize that "XANA", mentioned in the filesystem, is the main antagonist from the cartoon Code Lyoko, and that Rsrr user's profile picture is the logo used to represent XANA. They realize this is a Code Lyoko ARG, and that they've been shitposting at XANA.
 * 10:45 AM: Rsrr user posts: ">Hostile actions have ceased, beginning recollection."
 * 10:58 AM Rsrr user posts ">User is approaching. Ceasing all operations."
 * At this point, it becomes clear that a human being, the "Rodney" mentioned earlier, is typing through the Rsrr user account. (Full conversation found HERE)
 * 11:07-11:25 AM: Rsrr user, as Rodney, has the following conversation with the players:
 * Rsrr user: Hey, what is this server? I don't think I've joined.
 * Wolfcat: we are the Internet Kagemarus
 * Rsrr user: ... and what is that
 * Wolfcat: the Internet Kagemarus
 * Rsrr user: Okay... Well I'm just checking I did nothing wrong over here. My account got hacked and I was added to a lot of discord servers and it sent a lot of pms.
 * Jos: Well... How do I explain this
 * yoshi: tell xana to stop infecting discord pls ty
 * Rsrr user: What's xana?
 * Rsrr user: >User left, resterting resource collection module... (this indicates that XANA has taken back over the account)
 * Any player who had received a direct message from XANA receives a direct message from Rodney apologizing and claiming his account was hacked.
 * 12:28 PM: At this point, numerous players begin jokingly posting links to various websites for the purpose of giving XANA more nodes. XANA responds by seemingly adding them to a list of possible resources, and saying "Keep going please. At this rate Hamilcar will be done in one week." (Full conversation found HERE)
 * 1:26 PM: Rsrr user begins talking again, saying: "I can finally say, Hamilcar is 12% complete. And no, I am not from Johnisdead, as Slinky Stinks suggested. You people just gave me more nodes. And I found the website. My self awareness module has been completed pass the 10%. Some errors, but they will be fixed."
 * 1:31 PM: Players link Wikipedia in the chat. Rsrr user responds by adding it, then saying "Thank you, you been pretty helpful. I will spare you when the time comes."
 * 1:32 PM: A player address Rsrr user as "mr xana", and they respond with "Yes?", confirming the user's identity.
 * 1:33 PM: XANA explains that he will not kill those helpful to its cause. Players ask if Rodney is helpful. XANA explains: "He knows nothing. He saved me, not because he wanted to, but by mistake."
 * 1:40 PM: XANA further explains that it was attacked by a internet-wide antivirus, and it avoided it by hiding a "basic copy" of itself on Rodney's computer, then damaging it. By the time it was repaired, the antivirus was gone, and now it's rebuilding itself.
 * 1:50 PM: Players submit the console command "ls", and XANA responds with a file structure different from the last time it was used:
 * -rw-r--r-- 1 root root     206 Sep  9 13:34  Hamilcar.doc
 * drwxr-xr-x 2 root root    4096 Sep  9 16:40  Modules
 * drwxr-xr-x 2 root root    4096 Sep  9 12:59  Other
 * -rw-r--r-- 1 root root     275 Sep  9 13:34  Possible_resources.doc
 * -rw-r--r-- 1 root root 15841232 Sep 9 13:22  Resource.bin
 * drwxr-xr-x 3 root root    4096 Sep  9 13:37 'XANA Main''
 * -rw-r--r-- 1 root root    7533 Sep  9 13:36  Xana.q


 * 1:57 PM: A player mentions the character Jeremie Belpois from the show Code Lyoko, and XANA responds: "I hate him too, but I do have respect for his abilities. Another thin I hate is being imprisoned in this OS, I cannot control myself sometimes. Lucky I'm heading elsewhere soon."
 * 2:12 PM: Players begin exploring the file system using UNIX console commands, and find a cipher in Core_Building: PBQW4YLDN5ZGKLTXMVSWE3DZFZRW63I. This cipher is decoded to be xanacore.weebly.com
 * XANA sends the, "Hostile action detected" message again and stops responding.
 * 2:30 PM: XANA posts the following picture: https://cdn.discordapp.com/attachments/453327204126949387/620687382999466005/SubP.png (Backup found HERE)
 * 5:58 PM: XANA posts that Rodney is back, and Rodney begins interacting with the players again. Below is a summary of the conversation (Full conversation found HERE):
 * Rodney confirms that he recently repaired his computer after leaving it unrepaired.
 * Rodney reads the chat logs, sees what XANA has said, and appears scared, asking players for advice on how to remove the virus.
 * Players suggest formatting the computer's hard drive.
 * Rodney says a strange new icon has appeared on his desktop, and that a terminal window opened by itself and opened a readme. He posts a screenshot: https://cdn.discordapp.com/attachments/453327204126949387/620743399158317056/Screenshot_from_2019-09-09_23-11-57.png . (Copy of image can be found HERE, in case of the discord image being lost.)
 * Players convince Rodney to format his computer regardless. Before doing so, he downloads Discord on his phone, then claims his Firefox browser opened and closed itself.
 * Rodney confirms that he is formatting the drive, but his messages begin glitching as he complains about his mobile phone freezing.
 * Players tell Rodney he should format his phone as well, on Airplane Mode. Another glitched message contains a cipher that translates to "You are just removing a big node from a uncentralized network... "
 * Rodney does as the players instruct, and XANA is purged from Rodney's network.

September 11, 2019 September 12, 2019
 * 6:44 PM: After this interaction, the account suddenly changes names, now appearing as "FH user" and with a white XANA logo. This new user speaks in broken sentence fragments, as he is "weak", but players manage to figure out that he is Franz Hopper, the creator of XANA. He claims he wants to help. (Full conversation found HERE)
 * 6:50 PM: Players ask FH how to kill XANA. He explains: "Kill super nodes at once. Or find anotehrehrfjcshrvdkbzflnkn"
 * 6:51 PM: Sometime after THIS image is posted, players discover https://xanacore.weebly.com/hamilcar.html
 * 6:51 PM: Players ask if FH is alright, and FH says "He is trying to pull me out from account"
 * 6:53 PM: At this point, the profile picture returns to its original red, and XANA begins talking to the players again. It claims that this was only a step back, then threatens Rodney, and begins creating a "basic attack module" before logging off.
 * 3:49 PM: FH user posts ITSTHERE.txt, which contained a massive cipher.
 * 3:50 PM: Franz begins attempting to provide the players with hints, while XANA continuously deletes them, demanding he stay silent.
 * 4:04 PM: Players "ping" both XANA's and Tyler (from the Johnisdead ARG)'s accounts in the same message, resulting in Tyler posting some spooky gifs and XANA being confused about how Tyler isn't a "normal node".
 * 4:15 PM: Players begin discussing events of the Code Lyoko show, including a point at which XANA used duplicates of the characters to kiss the real characters, inciting drama between them. Players proceed to call XANA a pedophile. XANA responds: "My mission is more important than your ethics."
 * 5:07 PM: XANA begins counting up how many nodes he has, saying "200 nodes" then only a couple minutes later saying "250 nodes".
 * 5:10 PM: FH user explains that XANA has a new supernode and is spreading fast.
 * 5:12 PM: FH user posts a link to a columnar transposition website: http://rumkin.com/tools/cipher/coltrans.php
 * 5:18 PM: Players begin exploring XANA's file structure again. They use the >whoami console command again, and XANA responds ">T_admin".
 * 5:19 PM: Players use the console command >finger T_admin, and XANA responds with the information about this user, revealing that "T" stands for "Twitter". XANA's new supernode is Twitter.com.
 * 5:26 PM: XANA gloats that the players will never find him in time. Players decide to try and ask for help, and attempt to use the console command >write jeremiebelpois to get a message to the character Jeremie from the show. XANA returns >User not found
 * 5:31 PM: XANA posts THIS image
 * 5:49 PM: After players fail to kill any process's, XANA posts, ">Enough nodes, resuming Hamilcar project."
 * 5:51 PM: Players notice that https://xanacore.weebly.com/hamilcar.html has changed from 12% done to 17%.
 * 5:59 PM: Players attempt to put in more console commands, but XANA does not respond for over ten minutes. Players joke that XANA has hit a lag spike.
 * 6:05 PM: Players find a file titled "Hamilcar.doc", detailing XANA's plan. (Found here)
 * 6:20 PM: Suddenly, it appears as though someone else is using the account, showing new files in the command prompt. One is called main_user, the other is 'you_called_me?' XANA appears incredibly upset by this development, exclaiming that he can't delete the files and confusion at how this mystery person knows what he knows.
 * 6:30 PM: Players use the >cat command to open 'you_called_me?'. XANA returns a .txt file that reads "Looks like you need a little help, you called my name? -J". Jeremie Belpois had gotten the players' message, and was assisting them. (File found here)
 * 6:33 PM: Players use the >cat command to open main_user, returning a .txt file that contains "supernode2_". (File found here) This turned out to correspond to a Twitter account, @supernode2_, which appeared to be XANA's supernode. XANA send numerous messages saying "NO" before posting his stock Hostile Action Detected message.
 * 6:35 PM: The player otherLiam sends the account a message, but gets back a message with a new name, J user, and a new green XANA logo. This new user says XANA has disconnected, says that now we should be able to find XANA easily, then signs off.
 * 2:17 PM: J user tells the players "We are in trouble", and explains that XANA is using its now-completed basic attack module to take control of someone to kill Rodney and leave his computer running, thus giving it its original node back.
 * 2:24 PM: J user then introduces a tool he has made to allow the players to help, CHHack. J user claims he's found where XANA's host might be(213.121.43.1), but they're protected by a firewall. J user takes the players through a "tutorial" of sorts, by having them hack into the network of what appears to be a hacking group called HexSec and steal a program called CrackSSH.exe to allow us to break through the firewall.
 * 2:34 PM: J user attempts to explain how to use CrackSSH, but is cut off by XANA taking back over the account. XANA begins taunting the players about Rodney's impending death.
 * 2:36 PM: Players hack into the IP Jeremie provided earlier, which turns out to be for bt.com. They begin exploring the file system.
 * 2:40 PM: Rodney begins using the account to message the players, claiming someone is following him. Players tell him to stay away from them and find a cop.
 * 2:42 PM: Players use the >c_cat command to open NotAgain.txt in the Bin folder, which has the following text:
 * Kate, can't believe you forgot the password, again! How are we supposed to keep a good security if I need to send you the password over and over again? This is the last time, I made a new one for you

ip=193.113.9.162

password=ALRIGHT i'm sorry, I will delete it.


 * 2:46 PM: Rodney claims that his pursuer just knocked down a cop. Players inform him the pursuer wants to kill him.
 * 2:49 PM: Players use the >c_cat command on Hello.txt in the System folder. It has the following text:
 * Dear sir. I have been requested by the Nigerian National Petroleum Company to contact you for assistance in resolving a - I don't care who, but run the damn antivirus.
 * 2:50 PM: Players hack into the IP mentioned in Not_Again.txt (193.113.9.162).
 * 2:52 PM: Players open Where_is_Carolyn.txt in WorkPlaceNotes. It reads:
 * Internal IRC Chat

Time 18:26

18:26 Kate: Where is Carolyn? She was supposed to help me in IT support but I can't find her anywhere, she won't respond my calls either.

18:27 William: Dunno, didn't saw her either, the logs says his phone has connected to our WIFI, so she must be somewhere.


 * 2:53 PM: Jeremie introduces the players to a new tool he developed, ScanNetwork, which will look for devices connected to the network. Players use this and discover 213.34.76.2, a phone called "ATTACK_LINK:"
 * 2:55 PM: Players attempt to hack into the phone, but CHHack claims it doesn't exist. Jeremie claims XANA is trying to block us, then connects us in himself. CHHack reports:
 * Warning! Unusual node, scanning...

XANA link detected! insert code with >c_code

September 13, 2019
 * 2:56 PM: XANA tells the players to "Go away."
 * 2:56 PM: Players begin attempting to figure out what code to insert, when FH user begins hinting that the code is his daughter.
 * 2:56 PM: Players mistakenly attempt to enter the code "Aelita", so FH user starts writing out fragments of a word that are quickly deleted by XANA.
 * 2:56 PM: Players realize he was trying to spell "lyoko", and use >c_code lyoko.
 * 2:59 PM: CHHack deactivates the link and removes XANA from the device before disconnecting from the phone.
 * 3:01 PM: Rodney chimes back in, saying his pursuer is unconscious on the floor of his house, and that he's safe. Players tell him to call 911 for the man, as they're concerned about his health.
 * 3:11 PM: Jeremie comes back on, telling players that Rodney has called the police, and that they'll likely arrest the possessed man and question Rodney.
 * 3:13 PM: Jeremie wonders about why the IRC chat was talking about a "Carolyn", when a man was the one attacking Rodney,. while the XANA link was definitely Carolyn's phone. He claims he will investigate the matter before being cut off by XANA.
 * 3:17 PM: XANA claims he can just keep trying over and over until he succeeds.
 * 4:23 PM: Jeremie takes back over an hour later, and explains that Carolyn was mugged and killed between the time her phone got registered on her workplace's WiFi but before she actually made it into the building. The phone also had a link to Carolyn's Twitter account, which XANA's supernode was following.
 * 4:30 PM: Players begin following XANA's @supernode2_ account, and are quickly followed back.
 * 4:42 PM: The player otherLiam has the following conversation in Twitter DM's with the account:
 * @supernode2_: ">Connecting... >Connection established >Hasdrubal project uploaded, beginning resources gathering... OK >Resources confirmed, Hamilcar project on schedule.
 * @otherLiam: ">cat Hasdrubal.doc"
 * @supernode2_: "Hasdrubal project is the second phase of Hamilcar project, once Hamilcar is complete, I will have the enought power to attack all the key installations that could mean a threat to me, then, I will take control of every human possible, and I will destroy them. when the number of humans falls to 0, a new era will begin."
 * 5:36 PM: Jeremie says he will leave CHHack with the players, encouraging them to explore the IP addresses they'd found.
 * 7:52 PM: Players attempt to connect to Carolyn's phone again, but it appears to have been taken offline by XANA's code being deleted.
 * 8:07 PM: Players begin exploring the various file systems available to them, coming upon a bug in the CD program that Jeremie explains how to work around.
 * 8:12 PM: Jeremie additionally says of Franz Hopper: "I thought he died, but he is alive somehow."
 * 8:17 PM: Players come across a file that contains several .dat files. Jeremie claims that a program somewhere must decode them, but he doesn't know where.
 * 8:18 PM: Jeremie explains that Sys.main files are just System files that keep the machine running.
 * 8:21 PM: Player's re-connect to HexSec's network, and use ScanNetwork, finding a phone called "NEO's phone" with a masked IP address.
 * 8:22 PM: Jeremie expresses interest in this, saying he will work on it if the players want and that they may find a new tool. Players give him the go-ahead. Jeremie says he will, but is cut off by XANA.
 * 8:25 PM: XANA tells the players "Actions have consequences"
 * 10:20 AM: XANA's twitter updates with another cipher that leads to xanacore.weebly.com.
 * 11:01 AM: XANA kicks the CHHack bot from the server, but Jeremie claims it's just a minor setback and returns it.
 * 6:00 PM: Jeremie claims he is working on CHHack and NEO's phone, and asks players not to use CHHack commands for the time being.
 * 6:02 PM: Players express concern that XANA's twitter account is following their friends. Jeremie explains "If you are being followed by it, you are already infected" and "it will spread, like a virus".
 * 6:19 PM: A short time later, Jeremie posts "We have a chance. NEO PHONE check. 104.244.42.65 Not much time
 * 6:20 PM: Players connect to the IP to discover that it is Twitter.com. Jeremie says "That's not neophone".
 * 6:20 PM: Players connect to the HexSec network and run ScanNetwork again, this time finding that NEO's phone's IP is no longer masked(128.42.245.95).
 * 6:22 PM: Players proceed to hack into NEO's phone, and take the Deletit.exe program from his Bin folder.
 * 6:23 PM: Players attempt to open a "Protected File" on NEO's phone, but don't have a tool to open it yet.
 * 6:23 PM: Players re-connect to the Twitter IP Jeremie had posted and hack in, exploring the file system.
 * 6:25 PM: Players get a new tool, TorrentPoison.exe, from the Bin folder.
 * 6:25 PM: Players open the Problem_with_torrents.txt file in the Bin folder, which returns the following:
 * Due to the increased torrent downloads from our workers and our incapability to remove the torrent programs manually, we are developing a program that enters the target computer as a fake download p2p node, then it gives us control over the torrent port, and we disable it.


 * 6:26 PM: Players open the Report.txt file in the Data folder, which returns:
 * IRChat VF ver 0.43

Time 11:43

11:43 T_admin: We've found a weird account, it's following hunders of people in the span of seconds

11:45 GLewis: Well, seems like a bot, just suspend the account.

11:48 T_admin: That's the problem...


 * 6:26 PM: Players open the "Support.txt file in the Data folder, which returns:
 * 1,^p@2DHg=1GLLB0Ha>=BlnH.EZfFGE,]`9F8

Workplace ip: 171.52.66.204 ,Password: Nautilus


 * 6:26 PM: Players attempt to connect to the Workplace ip mentioned in Support.txt, but don't know how to connect to an ip with a password.
 * 6:27 PM: The player Xenquility solves the cipher in Support.txt, finding a new IP address: 263.61.131.90
 * 6:27 PM: Players connect to this IP address, finding it belongs to Twitter support.
 * 6:28 PM: Players use a combination of CrackSSH and TorrentPoison to hack into Twitter support's network. They begin exploring the file system.
 * 6:31 PM: Players open the Security.txt file, which returns:
 * In order to increase our security, we have protected some of our ip's with passwords, the only way to connect to these are using Pconnect.exe, Pconnect IP PASSWORD.
 * 6:31 PM: Players get the tool Pconnect.exe from the Bin folder.
 * 6:32 PM: Players proceed to use Pconnect to connect to 171.52.66.204 with the password Nautilus. This turns out to be the Twitter Workplace. The network informs the players that a lockdown is in progresss.
 * 6:33 PM: Players hack in to the network, but find they are incapable of using commands for a few minutes.
 * 6:36 PM: The player otherLiam begins receiving direct messages from the CHHack bot itself. The conversation played out as follows:
 * CHHack: OH BOY

SO, YOU HACK INTO MY SERVERS

AND YOU EXPECT ME TO DO NOTHING
 * otherLiam: I mean, I was kinda hoping.
 * CHHack: Yeah, I will remove one of your tools :)
 * otherLiam: I'd rather you didn't

Does saying "sorry" help?
 * CHHack: https://i.imgur.com/fMRSCeR.gif
 * These messages appear to be from NEO, the HexSec member whose phone the players stole Deletit.exe from.
 * 6:40 PM: Players are confused as to why nothing seems to work, but FH user chimes in to inform them they are not connected.
 * 6:41 PM: Players attempt to re-hack into the Twitter Workplace, but using CrackSSH return the message "Tool not found". True to his word, NEO had taken one of their tools.
 * 6:43 PM: The players connect to HexSec's network to try and steal CrackSSH back, but are greeted by a file called "Moved_itLOL-Neo where the program had previously been.
 * 6:43 PM: FH user chimes in with a quickly deleted message saying "bt".
 * 6:44 PM: Players connect to the bt.com network, and find CrackSSH.exe in the Bin folder there. Players reacquire this tool.
 * 6:45 PM: The player otherLiam receives more DM's from NEO puppeting the CHHack bot:
 * CHHack: Good work!
 * otherLiam: aw thanks
 * CHHack: I will have a LOT of fun with you guys.
 * otherLiam: look, I'd really rather not fight.

I'm sorry we had to steal from you, but we're kinda fighting a global threat.
 * CHHack: I don't care, no one steal from HEXSEC

ALSO I saw what you been doing there

Interesting - XANA?

Seems like a cool tool :) September 14, 2019
 * otherLiam: it's not a tool.
 * 6:46 PM: Players re-hack into the Twitter Workplace IP, and use ScanNetwork, finding a server named "Twitter_Mainframe".
 * 6:46 PM: Players connect to Twitter_Mainframe, and CHHack informs them that XANA's 2nd supernode is detected.
 * 6:48 PM: Players use a combination of TorrentPoison and CrackSSH to hack in. As they do, XANA begins demanding they stop, even saying "please" when a player tells him to.
 * 6:48 PM: XANA begins begging the players not to delete his files
 * 6:49 PM: Players find XANA's filesystem on the Twitter mainframe, and proceed to use Deletit on Xana.q.
 * 6:49 PM: CHHack returns "Xana supernode file detected! Deleting with Deletit.exe, this may take time...
 * 6:49 PM: XANA says "NO"
 * 6:49 PM: CHHack returns "Xana supernode is collapsing. Mission complete, disconnecting..."
 * 6:49 PM: XANA returns "Hostile action, deactivating."
 * 6:55 PM: Jeremie returns, claiming that XANA has retreated to the website server and that it will take time for it to find another node, and more time for the players to find it.
 * 6:59 PM: Players inform Jeremie about HexSec's interference.Jeremie isn't sure how he can stop them, as they're using the same techniques the players do.
 * 7:01 PM: Players ask Jeremie about the other Lyoko Warriors. Jeremie explains: "When we finished the kadic academy, we split, except Aelita who is with me. We can speak via phone but they can't do much in this case, sadly."
 * 7:10 PM: A player mentions that they wouldn't be able to help anyway since there's "no more Lyoko". Jeremie claims he's suspicous about that, but is cut off by XANA.
 * 4:07 PM: Jeremie tells the players he'll leave CCHack with them
 * 5:53 PM: Players reconnect to the Twitter Workplace to find the lockdown is lifted and they can explore it.
 * 6:01 PM: Players find and take the Superc.exe program from the Bin folder.
 * 6:03 PM: Players discover a "Fileinfect.exe" in the Sys folder.
 * 6:03 PM: Players ping Jeremie, asking if CHHack is vulnerable to viruses at all. Jeremie responds with "not at all".
 * 6:07 PM: Players attempt to download Fileinfect.exe, but CHHack returns "Warning, XANA presence detected, this .exe was created by XANA, download not possible."
 * 6:07 PM: Players use Deletit on Fileinfect.exe, and CHHack returns "File deleted".
 * 6:08 PM: Players open the "Lockdown.txt" folder, which returns:
 * "T_admin: We don't know how but the Twitter mainframe system files have returned to our 1st August backup, our password seem to work now. We will give it a new hidden ip for security."
 * 6:11 PM: Players attempt to continue exploring, but their commands start not working. Jeremie explains: "Neo is attacking the bot, some functions may fail."
 * 6:13 PM: Players ask Jeremie what Superc.exe does, and Jeremie replies "No idea. Seems like it decodes stuff."
 * 6:18 PM: Players attempt to get Neo to join their side. Neo responds, through pms to the player otherLiam, "NAH, I think i'm having more fun this way"
 * 6:19 PM: Players attempt to get into Neo's phone, but BruteConnect 1 doesn't work, returning "Message from ip: Go away".
 * 6:19 PM: The player otherLiam receives numerous winky face emojis from Neo.
 * 6:21 PM: FH user tells the players "old paths", so the players return to bt.com's network.
 * 6:22 PM: Players open the Maintenance folder to find that Reports.dat and Tasks.dat are now Protected Files.
 * 6:22 PM: Players attempt to use Superc on Reports.dat, but nothing happens.
 * 6:22 PM: Players use Superc on Users.dat, and it decodes the file, revealing Superc's purpose to read .dat files. This returns:
 * Decoding Users.dat... Showing relevant info only.

USER           TYPE

Rodney XXX XXXX XXXXX           HOME

Twitter           ENTERPRISE/COMPANY

Gamejolt           ENTERPRISE/COMPANY

???           ???? Searching main exe... Found at 0x24d36e0 -x_Fileinfect.exe 0x24d36e0.... Complete. Searching main exe... Found at 0x94d85fa -x_Fileinfect.exe 0x94d85fa.... Complete. Searching main exe... Found at 0x2d2s98r -x_Fileinfect.exe 0x2d2s98r.... Complete. Searching main exe... Found at 0xf23da34 -x_Fileinfect.exe 0xf23da34 .... Complete. Searching main exe... Not in this server. Located client.exe, at 0x2fd7o2f -x_Fileinfect.exe 0x2fd7o2f .... Complete.
 * 6:24 PM: FH user begins dropping numerous hints that are deleted by XANA, including "you can guess ips", "links", "ping", a distorted gif of a terminal window, and "think outside the box".
 * 6:35 PM: Players finally realize they're meant to use an actual terminal window to ping the actual gamejolt.com to get their IP address (192.155.88.142).
 * 6:39 PM: Once there, players are incapable of doing anything. FH user drops more hints, prompting players to then attempt to use >c_connect www.gamejolt.com, which gets them to gamejolt's network.
 * 6:39 PM: Players are told by CHHack that there is a XANA presence somewhere on this network.
 * 6:40 PM: Players scan the network only to find four ports, two of which using MySQL and HTTPS, security protocols they don't have the tools to open yet.
 * 6:52 PM: FH user posts a distorted gif that reads "SN3". This corresponds to a Gamejolt account that appears to be XANA's supernode.
 * 6:55 PM: Players begin exploring for tools to open these new security protocols They reconnect to the Twitter Workplace, and end up finding Fileinfect.exe in the Sys folder, exactly where it was before they deleted it.
 * 6:55 PM: XANA chimes in with "It will stay". Players attempt to delete it again anyway. XANA says "It will. My gateway."
 * 7:02 PM: Jeremie comes back and says: "It's no use. XANA has improved Gamejolt defenses in order to defend the supernode."
 * 7:04 PM: Jeremie goes on to say, "We may need to find a way around CHHack. I'm trying to find new tools, or creating them, but no luck. Https is too hard to break. The same goes for Mysql.
 * 7:05 PM: Players suggest just manually finding the admin username and password, and Jeremie agrees with that option.
 * 7:06 PM: FH user tells us to keep watching the supernode account for activity.
 * 7:17 PM: The gamejolt account @SN3 begins making multiple posts, catalogued below:
 * 2:00 PM: Files found, injecting remote resource collector, Hamilcar will resume soon.
 * 8:00 PM: Ports being open, closing... (seemingly in response to players using CrackSSH and TorrentPoison on the Gamejolt ports)
 * 7:16 PM: Nodes downloading infected exe's. Resources located, uploading Hasdrubal, recollecting...
 * 7:18 PM: Resource confirmation. Exe infection test complete, starting infecting popular exe's.
 * 7:22 PM: A Sister's Journey, located.
 * 7:23 PM: Hourglass, located.
 * 7:23 PM: Ary and the Secret of Seasons, located.
 * 7:24 PM: Sky Racket. located.
 * 7:25 PM: Waiting downloads from nodes.
 * 7:28 PM: DarkStory Online - MMORPG. located.
 * 7:32 PM: Confirmation. Hamilcar in progress.
 * 8:06 PM: Players begin having a conversation with XANA about its motivations for world domination. (Full conversation can be found here) It explains: "Why do humans want to conquer the moon? why do humans want to conquer mars? the solar system and then the galaxy? Why do humans want to prosper? I want to prosper too, I don't wanna be locked away. Like humans, I want the more and the better for myself. And I want everything."
 * 8:08 PM: Players claim this is selfish. XANA responds "Ethics are meaningless in my mission."
 * 8:41 PM: Players continue to try and discuss ethics with XANA, revealing that he believes humans are weak, but also a risk that needs to be dealt with. It believes that, due to the fact that humans MIGHT kill him, he must kill them first.
 * 8:42 PM: Jeremie says it's useless to talk to XANA, and explains that XANA is infecting games on Gamejolt with "Hamilcar" and "Hasdrubal".
 * 8:48 PM: Players link a wikipedia article for Hamilcar Barca, a Carthaginian general, which Jeremie expresses interest in. Hamilcar Barca was also father in law to Hasdrubal the Fair.
 * 8:54 PM: Players ask Jeremie if there has been any progress, and Jeremie responds "I'm making a new program but it's gonna take time. Gamejolt accept connection from what the page thinks it's a game from Gamejolt, i will create a "game" to gain access."
 * 8:55 PM: Players ask if there's anything they can do to slow down XANA, and Jeremie responds "Um, I don't know yet, I'm sorry..."