Rootkit and Invasive DRM Information Thread

40sTheme

Golden Member
Sep 24, 2006
1,607
0
0
I've had no problems with FEAR, but I know other people have. Good thread, good information.
 

KeithTalent

Elite Member | Administrator | No Lifer
Administrator
Nov 30, 2005
50,231
118
116
Wow, I did not know that about FEAR. Thanks so much for the heads up! Great thread!

KT
 

Ika

Lifer
Mar 22, 2006
14,264
3
81
Good information on Securom 7. I also didn't realize Starforce could physically make your drive fail.
 

MichaelD

Lifer
Jan 16, 2001
31,528
3
76
This is a superb thread. I have FEAR installed...and now I'm afraid I'm infected.

/cymbal crash

I will run the rootkit revealer software when i get home today.

This thread deserves a sticky! :thumbsup:
 

Aikouka

Lifer
Nov 27, 2001
30,383
912
126
Won't cracks remove the StarForce anyway? It seems you need to actually run the executable for the game for StarForce to install. I prefer installing No-CD cracks for every game as I hate leaving CDs/DVDs in my drives.
 

Schadenfroh

Elite Member
Mar 8, 2003
38,416
4
0
Draft2 is now up for everyone to review, changes include:

[*]Text fixes
[*]Content expansion and addition
[*]Links added as evidence of problems with SecuROM
[*]Layout improvements
[*]Clarification of what this thread is intended to focus on

Enjoy and do give feedback:)
 

Pr0d1gy

Diamond Member
Jan 30, 2005
7,774
0
76
Wierd, when I installed Quake4 I got some wierd message from Kaspersky & it didn't seem to like it.
 

Acanthus

Lifer
Aug 28, 2001
19,915
2
76
ostif.org
I dont really have much of a problem with securom7, i run nwn2 from an image and have no issues.

However, Atari patched it into nwn2 without telling anyone, which isnt cool for those of us that do care.

 

Jaxidian

Platinum Member
Oct 22, 2001
2,230
0
71
twitter.com
Great post!! I don't know if it would be appropriate but perhaps it would be a good idea to add to the post some counter-rootkit techniques? I'm very ignorant to them but I've heard of somebody spoofing the SecuROM system somehow.

Thanks!! :)
 

xtknight

Elite Member
Oct 15, 2004
12,974
0
71
I think this tidbit really needs to be added about rootkits:

They can run at ring-0 (kernel level) and intercept crucial system calls. This makes them hard to detect and in some cases they may be completely undetectable. They could introduce bugs and cause hardware problems (like StarForce). It's important to realize that these kernel rootkits essentially have control over your whole system, not just your hard disk. They have access to your CPU, its memory timings, and direct access to the BIOS too. Most of them are infact drivers and since drivers have these capabilities, so do the rootkits. The rootkits will be loaded as drivers first and then intercept enumeration calls (the OS will ask for a list of drivers, to be presented to the user, and the rootkit will just take itself out of the list and pass it on). It appears unharmed to the receiving application.
 

apoppin

Lifer
Mar 9, 2000
34,890
1
0
alienbabeltech.com
Originally posted by: Acanthus
Also note that Securom-7 doesnt run at the kernel level, it runs at ring 3, with is the lowest level of control.

although it may be not as *invasive* as StarFarce it is still plays havok with many installed and legitimate programs ...
:thumbsdown:

i would avoid it whenever possible

and it is becoming impossible ... my new *strategy* is to have *suspect programmes and games* on a separate HD
;)
 

Dethfrumbelo

Golden Member
Nov 16, 2004
1,499
0
0
Originally posted by: Acanthus
I dont really have much of a problem with securom7, i run nwn2 from an image and have no issues.

However, Atari patched it into nwn2 without telling anyone, which isnt cool for those of us that do care.

I believe they added it with patch 1.02 and onward. Very deceptive behavior... they were using an earlier version of SecuRom in the retail release, which was less invasive, and then "upgraded" it via the patch to the most recent version. v7 has been around for a while, so you have to wonder about their intentions here.


 

apoppin

Lifer
Mar 9, 2000
34,890
1
0
alienbabeltech.com
Originally posted by: Dethfrumbelo
Originally posted by: Acanthus
I dont really have much of a problem with securom7, i run nwn2 from an image and have no issues.

However, Atari patched it into nwn2 without telling anyone, which isnt cool for those of us that do care.

I believe they added it with patch 1.02 and onward. Very deceptive behavior... they were using an earlier version of SecuRom in the retail release, which was less invasive, and then "upgraded" it via the patch to the most recent version. v7 has been around for a while, so you have to wonder about their intentions here.

so ... Atari cancelled their nwn2 EULA with Patch v1.02
:p

can i get my money back?
:Q

how?



 

Acanthus

Lifer
Aug 28, 2001
19,915
2
76
ostif.org
Originally posted by: apoppin
Originally posted by: Acanthus
Also note that Securom-7 doesnt run at the kernel level, it runs at ring 3, with is the lowest level of control.

although it may be not as *invasive* as StarFarce it is still plays havok with many installed and legitimate programs ...
:thumbsdown:

i would avoid it whenever possible

and it is becoming impossible ... my new *strategy* is to have *suspect programmes and games* on a separate HD
;)

Thats actually not a bad idea, i may break my stripe array to do just that.
 

apoppin

Lifer
Mar 9, 2000
34,890
1
0
alienbabeltech.com
Originally posted by: Acanthus
Originally posted by: apoppin
Originally posted by: Acanthus
Also note that Securom-7 doesnt run at the kernel level, it runs at ring 3, with is the lowest level of control.

although it may be not as *invasive* as StarFarce it is still plays havok with many installed and legitimate programs ...
:thumbsdown:

i would avoid it whenever possible

and it is becoming impossible ... my new *strategy* is to have *suspect programmes and games* on a separate HD
;)

Thats actually not a bad idea, i may break my stripe array to do just that.

thank-you

i have been pondering this for awhile ... i had "weirdness" with some of these mentioned games -- especially NWN2 and FEAR's xpack ... and they DO cause problems with some legitimate installed programs. ... and i HATE reinstalling OSes or editing the registry to rid myself of this junk.

By keeping SecureCrap and StarFarce infected apps on a separate HD [or separate RAID array] will keep them from interacting with my *regular* programs.

... still looks like i have a long weekend coming up :(
[but i have my Sapphire x1950p coming today!] :)
:confused:

. . . at least till all programs have it :p
:Q