Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > Filemon
  New Posts New Posts RSS Feed: Securom detects Filemon and won’t run
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Securom detects Filemon and won’t run

 Post Reply Post Reply
Author
Message
throx View Drop Down
Newbie
Newbie


Joined: 11 December 2006
Location: United States
Online Status: Offline
Posts: 23
Post Options Post Options   Quote throx Quote  Post ReplyReply Direct Link To This Post Topic: Securom detects Filemon and won’t run
    Posted: 11 December 2006 at 9:13pm
This seems almost offensive.  I purchased a game and happened to have run Filemon within the time since I last rebooted my PC (usually measured in months).  Now it demands I reboot my machine before it will allow me to run the software I've purchased.

Anyway - thought Mark or the other guys at Sysinternals may be interested in knowing they've been directly targetted by Securom and their customers are being harmed as a result.


Back to Top
Karlchen View Drop Down
Senior Member
Senior Member
Avatar

Joined: 18 June 2005
Location: Germany
Online Status: Offline
Posts: 5121
Post Options Post Options   Quote Karlchen Quote  Post ReplyReply Direct Link To This Post Posted: 12 December 2006 at 6:00am
Hi, throx.

Thanks for reporting this issue: Securom refuses to run if it sees the Filemon/Regmon drivers in memory.
(Guess it is their type of tamper protection.)

By the way, it has been reported before: Filemon vs TR:Legend’s SecuROM

Kind regards,
Karl
--
P.S.:
Cany anybody report on how much Securom likes ProcessMonitor?
Back to Top
throx View Drop Down
Newbie
Newbie


Joined: 11 December 2006
Location: United States
Online Status: Offline
Posts: 23
Post Options Post Options   Quote throx Quote  Post ReplyReply Direct Link To This Post Posted: 12 December 2006 at 7:49am
Sorry for the duplicate post in that case.

No issue with Process Monitor at the moment, but you can bet they'll have it in the next update of their software.  I just hate the assumption that people who use these sorts of tools are "hackers".  If anything, it drives the more sophisticated users away from endorsing their products and finding ways to remove the offensive code.
Back to Top
Karlchen View Drop Down
Senior Member
Senior Member
Avatar

Joined: 18 June 2005
Location: Germany
Online Status: Offline
Posts: 5121
Post Options Post Options   Quote Karlchen Quote  Post ReplyReply Direct Link To This Post Posted: 12 December 2006 at 2:55pm
Originally posted by throx

Sorry for the duplicate post in that case.

Worse things happen than this.

No issue with Process Monitor at the moment, but you can bet they'll have it in the next update of their software.

Thanks for reporting that at the time of writing SecuRom and ProcessMonitor still co-operate fine, ProcMon uses a different kernel level driver than Filemon or Regmon.

We'll see if SecuRom will refuse to run if ProcMon is found in memory in the future.

Kind regards,
Karl
Back to Top
mrfrazzlebottom View Drop Down
Newbie
Newbie


Joined: 28 February 2006
Location: Afghanistan
Online Status: Offline
Posts: 4
Post Options Post Options   Quote mrfrazzlebottom Quote  Post ReplyReply Direct Link To This Post Posted: 25 December 2006 at 6:07pm
Originally posted by Karlchen


Thanks for reporting this issue: Securom refuses to run if it sees the Filemon/Regmon drivers in memory.
(Guess it is their type of tamper protection.)

By the way, it has been reported before: Filemon vs TR:Legend’s SecuROM


As mentioned in the refered to thread, even after Filemon is exited, Secrom is detecting something in memory that Filemon leaves behind.

Is Filemon perhaps leaving a file handle/thread/mutex/whatever behind and not cleaning up after itself?

This is a real annoying "feature" of Securom. According to Securom, the "fix" for this "error message" of theirs is to run their "System Analysis" program that probes your system and produces a very large, encrypted "analysis file" that you are supposed to e-mail to them.
Back to Top
Karlchen View Drop Down
Senior Member
Senior Member
Avatar

Joined: 18 June 2005
Location: Germany
Online Status: Offline
Posts: 5121
Post Options Post Options   Quote Karlchen Quote  Post ReplyReply Direct Link To This Post Posted: 25 December 2006 at 6:23pm
Filemon leaves behind a driver which will not be reloaded on next reboot.
(Reason: Unloading the driver might be unsafe and produce a bluescreen.)

Karl
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down