Securom string found in Process Explorer dump of TheSims3.exe

<< < (4/7) > >>

J. M. Pescado:
SecuROM is evil malware. Period.

Nightmare:
Quote from: J. M. Pescado on 2009 June 16, 11:30:16

SecuROM is evil malware. Period.


Evil malware in RING3 doesn´t fall in the same category as a possible low-level operation, RING0 malware.

The first one is an annoying bug, the second is a deadly compromising software. The distinction must be done.

J. M. Pescado:
Quote from: Nightmare on 2009 June 16, 11:35:22

Evil malware in RING3 doesn´t fall in the same category as a possible low-level operation, RING0 malware.

The first one is an annoying bug, the second is a deadly compromising software. The distinction must be done.
Yes, but how does stating the obvious change anything?

Nightmare:
Quote from: J. M. Pescado on 2009 June 16, 11:37:19

Quote from: Nightmare on 2009 June 16, 11:35:22

Evil malware in RING3 doesn´t fall in the same category as a possible low-level operation, RING0 malware.

The first one is an annoying bug, the second is a deadly compromising software. The distinction must be done.
Yes, but how does stating the obvious change anything?


I want indicators to the Average Joe users that can be understood by bureaucrat CEO´s. I know a few men on the industry, but they want reliable data. If you give me indicators of Kernel code use/low-level operations of Securom I will appreciate it.

I found some interesting string dumping Securom executables strings on latest versions.

\Device\sony_ssm.sys
\DosDevices\sony_ssm.sys
VS_VERSION_INFO
StringFileInfo
Comments
SecuROM Security Module.
CompanyName
Sony DADC Austria AG.
FileDescription
SecuROM Security Module.
FileVersion
LegalCopyright
Copyright (C) 2004/05 Sony DADC Austria AG
OriginalFilename
sony_ssm.sys

A .sys file would be some kind of indicator of low level operation, just as the Aries.sys in XCP

Thoughts

J. M. Pescado:
Or, more likely, it's the stripped detritus of something no longer in service that was left behind. There's tons of rubbish like this in the game.

Navigation

[0] Message Index

[#] Next page

[*] Previous page