Wednesday, April 30, 2008

GameGuard - do you know?

Gameguard is an application that is bundled with some of the MMORPGs. The program uses kernel driver that allows any process to access it and it allows unrestricted IO access in a user mode. That leads to some problems. Even without malicious software problems with the system and bad data can be expected. In other hand any process can get access to direct read/write the hard disk, etc ..
Now you will think that when you are not playing you are safe? Nop. The driver is installed as a system service and runs even when GameGuard is closed. Also it wont uninstall itself when the application is removed.
Why am I writing about this now?
Because few days ago I got my registry file deleted.

