Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack (1) Thread Tools Display Modes
Old 29-08-2007, 01:02 AM   1 links from elsewhere to this Post. Click to view. #1 (permalink)
ToTheBeatOfUrHeart
 
Harvik780's Avatar
 
Join Date: Feb 2006
Location: Boston,Newyork
Posts: 1,882
Smile Both Bioshock and Bioshock Demo install Rootkit


BioShock Demo Installs SecuROM Service

2K Games recently issued at statement addressing the DRM protection and widescreen problems for the BioShock PC game. In the statement 2K reveals a change in number of activations available with each copy of BioShock. Consumers are now allowed to activate their copy of BioShock a total of five times via the SecuROM network. Problems have already surfaced on the third-party severs preventing users from activating their copy of the game.

What 2K has failed to address is the the SecuROM service installed on your computer when installing BioShock, which is also included in the demo.

Microsoft offers a utility called RootkitRevealer located: here. The program will scan your system for rootkits. Once you scan your system, the program will reveal the SecuROM service with this message:

…\Software\SecuROM\!CAUTION! NEVER DELETE OR CHANGE ANY KEY*

This is due to the * character at the end, causing the “Key Name Contains Embedded Nuls” message. Unfortunately, you may have to follow this lengthly procedure posted by a 2K forum member to remove the service installed by SecuROM (Thanks Wingsong):

Download RegDelNull here and place in C:
http://www.microsoft.com/technet/sys…egDelNull.mspx

Download MoveOnBoot from here:
http://www.snapfiles.com/get/moveonboot.html

Regedit (or more specifically..Securom) will not allow deleting of Securom Registry keys, hence the need for Regnull.

From command prompt (assuming RegDelNull is in root of C, type/paste

C:\regdelnull HKEY_USERS\S-1-5-21-2052111302-1757981266-725345543-500
\Software\SecuROM -s

(Im assuming this key is the same for all users..you can check yourself using Regedit)
When asked to delete..choose Yes

Do the same with this Key from command prompt (Start..Run):
C:\regdelnull HKEY_CURRENT_USER\Software\SecuROM -s

Now run MoveOnBoot and navigate to the “hidden” securom folder in:

Docs and Settings\Admin\AppData\Securom

I chose 3 files for removal upon reboot. After I rebooted, Securom
wasnt in registry or Docs & settings folder.

Delete UAService7.exe from your windows/system32 folder.

The demo doesn’t require activation to play, so why is the SecuROM service included? This will most likely prompt another response from 2K Games to calm this ensuing anger from consumers on yet another problem despite the high ratings of the game.

Additional Information:

The SecuROM website defines its service, which might clarify what is being installed and how to remove it in a more simple manner:

SecuROM™ will install a Windows™ service module called “User Access Service” (UAService) on your system. This is a standard interface commonly used by several other applications as well. It is no spyware or rootkit at all. This module has been developed to enable users without Windows™ administrator rights the ability to access all SecuROM™ features. Please be assured that this service is installed only for security and convenience purposes. Since it is a standard Windows™ service, you can stop and delete this service, like any other Windows™ service. If deleted, the access for non-administrator users to SecuROM™ protected applications will be affected.

*REFERENCES TO ROOTKIT HAVE BEEN REMOVED, FURTHER INVESTIGATION HAS REVEALED A MISUNDERSTANDING IN THE SECUROM SERVICE

Source-
http://www.gametab.com/news/1017115/
__________________
Mobo - P5N32-E SLI,P5N-E SLI|GFX - 2x8800GTS,8800GT|Processor - E6550,E6600|PSU - CM EP 600,HX620W|Physics - 2x8600GT
Harvik780 is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 29-08-2007, 01:04 AM   #2 (permalink)
You gave been GXified
 
gxsaurav's Avatar
 
Join Date: Jan 2007
Location: New Delhi
Posts: 5,633
Default Re: Both Bioshock and Bioshock Demo install Rootkit

Damn u Symantec & Mcafee...just because of U Vista isn't protected of this rootkit
__________________
about.me/gxsaurav
gxsaurav is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


LinkBacks (?)
LinkBack to this Thread: http://www.thinkdigit.com/forum/technology-news/66769-both-bioshock-bioshock-demo-install-rootkit.html
Posted By For Type Date
TR Forums • View topic - Need Total Securom Removal This thread Refback 07-07-2010 07:37 PM

Similar Threads
Thread Thread Starter Forum Replies Last Post
Bioshock Demo out snake Gamerz 124 30-08-2007 09:52 PM
Bioshock reviewed by Gamer TV gets 5/5 Harvik780 Gamerz 3 16-08-2007 07:50 AM
Xbox 360 Demo: Advanced Warfighter 2 demo confirmed Kiran.dks Gamerz 6 30-01-2007 02:52 PM
Rootkit? Charan Software Q&A 2 15-04-2006 08:40 AM

 
Latest Threads
- by abhidev
- by abhidev
- by Krow
- by Tenida
- by iGamer
- by icebags

Advertisement




All times are GMT +5.5. The time now is 01:19 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2