View Single Post
  #12  
Old 25-12-2005, 05:38
ApocalypseNow ApocalypseNow is offline
Junior Member
 
Join Date: Dec 2005
Location: Podgorica, Serbia & Montenegro
Posts: 2
Thanks: 0
Thanked 0 Times in 0 Posts
ApocalypseNow is on a distinguished road
Lightbulb Suggestion

This is just logical suggestion. Facts:
  • games use 3/4 SF drivers for copy protection when they start
  • when they start, they replace all the registry values of driver services in HKEY_LOKCAL_MACHINE\SYSTEM\CurrentControlSet\ & all the sf driver files in sys32

So, 2 tactics:
  • try to deny permissions 4 these files & reg values
  • some bruteforcing prog to replace the driver files & their reg values every couple of seconds or less

& ur asking "replace with what"?! I say replace reg path with path to sfdrvxx.sys with path to sfcure01.sys & sf driver sys files crap with sfcure01.sys (renamed to their name, of course!)

This is just theoreticising, dunno does it work, so anyone can make bruteforcer/ hasn't got so complicated user, group & permission structure, should try this and post the results here
__________________
[COLOR="Gray"](\__/)
([COLOR="Blue"]O[/COLOR].[COLOR="Blue"]o[/COLOR] )
([COLOR="Magenta"]> <[/COLOR] ) [/COLOR]<-- This is Bunny. Copy Bunny into your signature to help him on his way to world domination.

Last edited by ApocalypseNow; 25-12-2005 at 05:43.
Reply With Quote