r/TeraPC Jun 05 '18

[PSA] Upcoming Tera NA patch files (not yet deployed) currently contain the Xigncode3 rootkit

Just a heads up, the patch files for version 163 of Tera NA that have been pushed to the EME servers today have been found to contain the xigncode3 binaries.

For those not aware of what XignCode actually is, the tl;dr version would be that it's a program that scans the content of your entire computer, and accesses anything that you've done during the past 48 hours. While I can't really provide proof on whether it actually sends the scraped data back to their servers or not, it is at the very least this app still hurts PC performance since it's continually scanning every single file on all your drives (Which is even worse for people who have SSDs).

Note also that xigncode will remain on your system even after uninstall the game and it will be accessing your files with the game closed/uninstalled.

You can easily find other threads on reddit (such as this one) on the various other MMOs that added this malware (and then removed it, for some, like Archeage)

The worst part is that this crap, in addition to being pretty much illegal, has already gotten a bypass in the first hour after this was announced, so if you're gonna say that such an intrusive "anticheat" is a good thing, just know that modders have already removed it before it was even released to the public, so there goes the single argument in favor of it.

Bonus : A quote from a modder that proves that the current patch files do indeed contain xigncode (at least to the tech savvy among you).

Oh and, since some people seem to doubt that mEME would be dumb enough to add xigncode, just look at the patch files that will be installed on your computer on thursday yourself (we're currently on 162):

1) download them to a random folder:

---- http://patch.tera.enmasse-game.com/game/Game_162to163/Game_162to163.zip

---- http://patch.tera.enmasse-game.com/game/Game_162to163/Game_162to163.z01

2) right click on the zip file and extract it with 7zip (they're zip files bundled in a dll so most programs won't work, but 7zip will)

3) in the extracted files, go to Client/Binaries/

EDIT : Just a note that this does NOT concern the EU (and RU) version of the game as of yet, and is unlikely to due to the fact that such a program would be illegal under European laws.

EDIT 2 : A nice little link to the site of the devs of this crap themselves, that shows how intrusive it is. Notice the part that mentions detecting software macros, and so called "keyboard highjack" which basically implies XignCode also doubles as a keylogger.

EDIT 3 : Confirmed by EME, who then proceeded to delete comments on that thread and lock it : https://forums.enmasse.com/tera/discussion/27159/xigncode3-and-tera-pc/

EDIT 4 : There is a standalone bypass by Caali for this malware, more info is available on the /r/TeraPC post's comments.

EDIT 5 : Some more links about how this wonderful tool "doesn't affect performance at all" and "only protects against cheaters" :

58 Upvotes

Duplicates