Working BIOS driver crack for Vista released

, posted: 13-MAR-2007 16:14

VistaJohn the Bluespark Flashboy pointed me to this Digg entry on what appears to be a new, working crack for Windows Vista. It's basically a BIOS driver used by OEMs that tells Vista it doesn't need to validate the copy, as it's deemed inconvenient for users.

A cracking group called Paradox got hold of it and... here's what they say:

*************************************************************
*** OEM BIOS Emulation Toolkit For Windows Vista x86 v1.0 ***
*************************************************************

What's the purpose of this release?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
Bypassing the product activation requirement of Microsoft Windows Vista x86.

How does it work?
~~~~~~~~~~~~~~~~~
Microsoft allows large hardware manufacturers (e.g. ASUS, HP, Dell) to ship their products containing a Windows Vista installation that does NOT require any kind of product activation as this might be considered an unnecessary inconvenience for the end-user. Instead these so-called 'Royalty OEMs' are granted the right to embed certain license information into their hardware products, which can be validated by Windows Vista to make obtaining further
activation information (online or by phone) obsolete. This mechanism is commonly referred to as 'SLP 2.0' ('system-locked pre-installation 2.0') and consists of the following three key elements:

1. The OEM's hardware-embedded BIOS ACPI_SLIC information signed by Microsoft.
2. A certificate issued by Microsoft that corresponds to the specific ACPI_SLIC information.

The certificate is an XML file found on the OEM's installation/recovery media, ususally called something like 'oemname.xrm-ms'.

3. A special type of product key that corresponds to the installed edition of Windows Vista.

This key can usually be obtained from some installation script found on the OEM's installation/recovery media or directly from a pre-installed OEM system.

If all three elements match Windows Vista's licensing mechansim considers the given installation a valid system-locked pre-activated copy (that does not require any additional product activation procedures).

So the basic concept of the tool at hand is to present any given BIOS ACPI_SLIC information to Windows
Vista's licensing mechanism by means of a device driver. In combination with a matching product key and OEM certificate this allows for rendering any system practically indistinguishable from a legit pre-activated system shipped by the respective OEM.

How do I use it?
~~~~~~~~~~~~~~~~
Preliminary hint:
Most operations described below require elevated privileges, so disabling UAC (Run->MSCONFIG.EXE->
Tools->Disable UAC) for the time being is recommended, Of course, it can be safely re-enabled after all steps have been performed. Otherwise OEMTOOL.EXE and some SLMGR.VBS operations must be explicitly run with adminstrative privileges.

1. Install the Windows Vista x86 edition of your choice without entering any product key during setup. Basically any Windows Vista x86 installation media will do, regardless if it's MSDN/Retail/OEM/..., MSDN/Retail are recommended though.

2. Install the emulation driver.

Run OEMTOOL.EXE, select the OEM BIOS information to emulate (ASUS might be a good choice given the fact that it's the only OEM for which a complete set of product keys is provided ;)) and hit the '' button.

Alternatively you can just right-click the ROYAL.INF file and chose 'Install' from the appearing menu. This only allows for installing the default OEM BIOS information (ASUS) though and is strongly discouraged unless OEMTOOL.EXE fails for some unknown reason.

When prompted about whether to install an unsigned driver, allow it. (For some odd reason Microsoft didn't wanna sign this one...;))

3. Reboot your machine.

4. Install the OEM certificate matching your OEM selection during driver installation by running

SLMGR.VBS -ilc .XRM-MS

e.g. "SLMGR.VBS -ilc C:\ASUS.XRM-MS" if you chose to install the default driver and extracted the certificate file to C:\)

Note that this operation might take quite a while depending on your system, so be patient.

5. Install an OEM product key matching the installed edition of Windows Vista x86 by running

SLMGR.VBS -ipk

(e.g. "SLMGR.VBS -ipk 6F2D7-2PCG6-YQQTB-FWK9V-932CC" if you're running Windows Vista Ultimate using the default emulation driver)

Note that this operation might take quite a while depending on your system, so be patient.

See PKEYS.TXT for a list of OEM product keys published by different OEMs.

6. Run 'SLMGR.VBS -dlv' or right-click 'Computer' and chose 'Properties' to verify your licensing status.

Due to the variety of possible combinations of different earlier Vista activation hacks we're not gonna provide details on 'persuading' existing installations to accept this method. During our test the general procedure depicted above worked out fine though, i.e. installing the emulation driver, rebooting the machine and then using the officially documented ways of installing a matching OEM certificate and product key should do the trick in all but the most messed up cases.

What's that '' button in OEMTOOL.EXE for?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
It dumps the BIOS ACPI_SLIC information of any SLP 2.0-enabled OEM system. The dump can consecutively be used to emulate ('clone') that information on any other system by specifying the 'Custom' option. Using this function on a system booted using the emulation driver will give a dump identical to the currently emulated OEM BIOS information, so be sure to uninstall the driver and reboot the source machine first if you intend to dump the actual hardware-embedded OEM BIOS data.

What are all those files for?
~~~~~~~~~~~~~~~~~~~~~~~~~~~~~
DIFXAPI.DLL - a runtime dll for Microsoft's DIFx API used by oemtool.exe
OEMTOOL.EXE - an application for installing/uninstalling the emulation driver
and dumping BIOS ACPI_SLIC information from any SLP 2.0-enabled Windows Vista OEM system
PKEYS.TXT - contains a list of validated OEM product keys
README.TXT - this file
ROYAL.INF - driver .INF file, can be (ab)used to install the emulation driver in case oemtool.exe fails to perform this task
ROYAL.SYS - the emulation device driver

CERTS\ACER.XRM-MS - the certificate that corresponds to the ACPI_SLIC information
emulated by the driver when 'Acer' has been selected during driver installation
CERTS\ASUS.XRM-MS - the certificate that corresponds to the ACPI_SLIC information
emulated by the driver when 'ASUS' has been selected during driver installation
CERTS\HEWLETT-PACKARD.XRM-MS - the certificate that corresponds to the ACPI_SLIC information
emulated by the driver when 'Hewlett-Packard' has been selected during driver installation
CERTS\LENOVO.XRM-MS - the certificate that corresponds to the ACPI_SLIC information emulated by the driver when 'Lenovo' has been selected during driver installation

Enjoy,
TEAM PARADOX '07"


So does it work then? Umm... it looks like several people have tried it out and been successful with it.

It'll be interesting to see what Microsoft will do to kill this one.






Tag(s):             


Other related posts:
Today’s incomprehensible Windows security warning
Today's strange Internet Explorer 8 error message
Microsoft takes the wind out of Windows 7's sails


 





Comment by paradoxsm, on 13-MAR-2007 18:17

Now just to find that DRM crack (not yet released or produced), And I'll then tear down the road to buy vista! I hate this copy protection, I CD-Crack all the games I buy as it's just unnecessary junk.


Comment by Daniel, on 14-MAR-2007 09:58

Whoa, paradoxsm, you have the wrong idea about the Vista DRM like so many other people. Vista will not stop you from doing what you have just said above.

The DRM in Vista is to comply with new DRM requirements of new formats such as HDDVD and SACD. It won't stop you from downloading off BitTorrent, it won't stop you cracking your games, it won't really stop you doing anything.

See Wikipedia and this article.


Comment by Daniel, on 14-MAR-2007 09:59

Argh, I can never get my comments right when it involves HTML!

Wikipedia article: http://en.wikipedia.org/wiki/Windows_vista#Criticism

Paul Smith's Blog


Comment by Vista, on 14-MAR-2007 10:49

This is the best tool EVER! ... if you're in need to try it out find the torrent Vista Valentines. It's only 600Mb.


Comment by Steve, on 15-MAR-2007 15:23

Re Microsoft -given I saw a URL shortcut to "Working BIOS driver crack" on a MS employee's laptop desktop (got to love those widescreen projectors) at yesterdays Tech briefing in Wellington, I'm betting this is not going to last long...


Author's note by juha, on 15-MAR-2007 15:34

Heh. Maybe he'd run out of product keys for the demo installations?


Comment by Khan, on 11-MAY-2007 02:37

Paradox crack is NOT working . I performed all the steps but the computer properties still shows the grace period required to activate windows.


Comment by khan, on 11-MAY-2007 05:15

Paradox crack is not working any more. Computer properties still shows the few days left to activate Windows.


Comment by vivek sharma, on 15-JUL-2007 14:47

this patch is not working after 10 times of worthy try.im getting BSOD


Comment by stephen, on 6-MAR-2008 06:40

i have used this patch for the lats 8 months it has worked flawlessly UNTILL KB940510 it detects the patch and wants you to reactivate. dont click the check box saying "i have read or something" just turn off the computer (via power button) and dont install that patch


Comment by someone, on 14-JUN-2008 14:21

This is the activator for vista and vista sp1. It works!

http://rapidshare.com/files/122291714/Vistany_Version_Activ.rar


Add a comment

Please note: comments that are inappropriate or promotional in nature will be deleted. E-mail addresses are not displayed, but you must enter a valid e-mail address to confirm your comments.

Are you a registered Geekzone user? Login to have the fields below automatically filled in for you and to enable links in comments. If you have (or qualify to have) a Geekzone Blog then your comment will be automatically confirmed and shown in this blog post.

Your name:

Your e-mail:

Your webpage:





Links to stories I've written:

Google News search for me
PC World New Zealand
Computerworld NZ
PC World and Computerworld Australia
PC World US
Computerworld US
Infoworld
NZ Herald
Virus Bulletin
PC World NZ Blog

Content copyright © Juha Saarinen. If you wish to use the content of my blog on your site, please contact me for details. I'm usually happy to share my stuff, as long as it's not for spamblogs and what have you. Attribution with a link back to the blog is always appreciated. If you wish to advertise on my blog, please drop me an email to discuss the details.

Comments policy
All comments posted on this blog are the copyright and responsibility of the submitters in question. Comments commercial and promotional in nature are not allowed. Please ensure that your comments are on topic and refrain from making personal remarks.




    follow me on Twitter





    Add to Netvibes



    Latest comments

    Bill Bennett on Trade Me, the behemoth on NZ’s Internet: Which begs the question, does TradeMe make more money from advertising than it m...

    juha on Trade Me, the behemoth on NZ’s Internet: @Edmund Yeah, page impressions are but one measure :)...

    Edmund Good on Trade Me, the behemoth on NZ’s Internet: All well and good to serve up that many pages - is anyone actually buying??...

    freitasm on Trade Me, the behemoth on NZ’s Internet: And with that they suck dry all the online advertising budget and no one else ge...

    lotech on Losers in the Apple iPad launch: Microsims are just smaller shaped SIMs - other than the size of the plastic it i...

    juha on Losers in the Apple iPad launch: @dacraka Vodafone NZ says it has MicroSIMs - I'd imagine Telecom has them too. C...

    dacraka on Losers in the Apple iPad launch: If NZ wants the 3G functionality, our mobile operators will need to come out wit...

    Foo on Losers in the Apple iPad launch: Great article Juha.@Jason - 60 days until release? Won't it be longer for NZ (Ju...

    Bnsofts on Losers in the Apple iPad launch: Ohh this is great thanks for sharing....

    freitasm on Losers in the Apple iPad launch: Phreek... Vodafone 3G network is 2100MHz only in the main centres. Everywhere th...



    Top Ten Techsplodings

    Telecom New Zealand's local lo...
    (28-APR-2006 17:32, 179241 views)
    Join New Zealand Internet blac...
    (16-FEB-2009 09:26, 132559 views)
    iTunes 7 bugs: doesn't Apple t...
    (14-SEP-2006 12:34, 91972 views)
    Working BIOS driver crack for ...
    (13-MAR-2007 16:14, 50969 views)
    The spoofed Telecom commercial...
    (19-MAY-2006 15:59, 45223 views)
    What did Materazzi say to Zida...
    (11-JUL-2006 08:20, 38976 views)
    Windows Vista problem solving ...
    (24-FEB-2007 18:16, 37381 views)
    Firefox 2.0 and Windows Vista ...
    (3-DEC-2006 12:23, 33810 views)
    Gutmann Reloaded and My Vista ...
    (26-JAN-2007 15:35, 32544 views)
    The Saddam Snuff Movie...
    (31-DEC-2006 11:25, 31237 views)




    Subscribe to RSS headline updates from: http://feeds.feedburner.com/Technozone
    Powered by FeedBurner



    Add to Google Subscribe in NewsGator Online Click here to add this RSS feed to Feedster Click here to add this RSS feed to My MSN Click here to add this RSS feed to AvantGo Click here to add this RSS feed to My Yahoo!

    Linkorama

    Modern Drunkard Magazine
    Centre for Citizen Media
    The Assimilated Negro
    The Raw Feed
    Object Dart
    Copyblogger
    Neil Sanderson's blog
    The Opinionated Diner
    Griffin's Gadgets
    Dion Hinchcliffe
    InternetNZ blog (Colin Jackson)
    Spareroom
    Off the record
    Rawiri Blundell
    KhooSuyinKhoo
    ReadWriteWeb
    Frankarr
    Tim Haines
    Darren Rowse - Problogger
    Daniel McKenzie
    The Hivelogic Narrative
    Fraser Talk
    Leaf Salon
    Bad Science
    Wanda Harland
    Kiwi Herald
    Mauricio Freitas
    Hard News
    The Geekzoner
    Mr Cokemaster
    Commercial Archive
    Kiwiblog
    Jama
    Chiefie's blog
    Generation X Y
    Not the South China Morning Post
    Nic often Wise
    Loosewire (Jeremy Wagstaff of WSJ)
    SunnyO
    BlackMagic NZ Film Blog
    Nigel Parker's MSDN blog