Some Sony CD's Install Root Kits New DRM method "goes too far"
#1
Posted 02 November 2005 - 04:21 PM
http://www.f-secure.com/weblog/archives/archive-112005.html - Details
http://blogs.zdnet.com/BTL/?p=2092 - Fix
If you don't have BlackLight Rootkit program I advice you get it. Its a very good program that will assist in picking up malware that the usual programs you use to scan your PC for Spyware/Adware/Malware will not. These rootkit trojans are designed to infect and place themself on your system so it can't be detected however BlackLight will pick it up.
Very curious that Sony would purposely implement a Trojan in the CDs, anyhow have read.
#2
Posted 02 November 2005 - 04:37 PM
Quote
The current F-Secure BlackLight beta does not work on Windows NT, 95, 98, ME, or 64-bit Windows.
...some do, some don't; some will, some won't (WR)
#3
Posted 02 November 2005 - 09:44 PM
Quote
Also:
http://www.f-secure.com/weblog/archives/ar...5.html#00000691
Quote
I strongly suggest everyone read Mark's article/blog entry about this:
http://www.sysinternals.com/blog/2005/10/s...tal-rights.html
Let's not cause a panic. And anyone who doesn't understand what Mark is talking about should in no way try to fix this root kit.
Root kits are not an infection or a trojan in and of themselves. They are often used by trojans to conceal their presence. That's all. Sony is using this as a means of concealing the presence of copyright protection software/files and to prevent it's removal by the somewhat technically savvy. It is a piece of crap installed surreptitiously and everyone has a right to be mad at Sony's draconian tactics, but the files the rootkit hides are not controlled by some remote hacker or used to steal sensitive information or display unwanted ads/popups.
I agree for the most part with Russinovich's level-headed conclusion:
Quote
I'm not sure if I believe in the media industry’s "right" to use copy protection mechanisms, but a boycott of Sony products is not a bad idea in my book.
BTW, Koan, root kits only work on 32-bit NT-based (2000, XP, 2003) systems with NTSF formatting. I.E., files are not hidden (or not hidden in the same way, not sure about this) on Win9X, 64-bit systems, or NT-based systems with Fat32 formatting. So there is no need for detection software such as F-Secure's BlackLight and sysinternals' RootkitRevealer.
RootkitRevealer is a detection tool only. BlackLight deals with the root kit by renaming it. It should also be pointed out that BlackLight is a time limited Beta that will no longer be available for free download after the first of the year. Read the disclaimer on the site--another reason for newbies to be careful with it as betas are still in the testing stage and could still be unstable.
Every love every ending
Or maybe there's no obligations now,
Maybe I've a reason to believe
We all will be received
In Graceland--Paul Simon
#5
Posted 03 November 2005 - 07:15 PM
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook
#9
Posted 10 November 2005 - 11:53 AM
If I've helped you, please consider donating to the Multiple Sclerosis Society (UK)
#10
Posted 10 November 2005 - 12:36 PM
Quote
By Nate Mook, BetaNews
November 10, 2005, 11:36 AM
What security experts have warned about Sony's DRM has come to pass, with a new trojan horse attempting to hide itself using techniques enabled by the company's anti-piracy software. Dubbed "Troj/Stinx-E" by Sophos, the application copies itself to a file called: $sys$drv.exe, which is hidden by Sony's copy protection.
betanews.com

Member of UNITE, Unified Network of Instructors and Trusted Eliminators
#11
Posted 10 November 2005 - 06:47 PM
Hmmm, a class action suit, maybe?
Become a BleepingComputer fan: Facebook
#12
Posted 10 November 2005 - 09:32 PM
~~~~~~
#13
Posted 11 November 2005 - 05:21 AM
http://news.bbc.co.uk/2/hi/technology/4424254.stm
If I've helped you, please consider donating to the Multiple Sclerosis Society (UK)
#14
Posted 11 November 2005 - 10:33 AM
~~~~~~
#15
Posted 11 November 2005 - 04:59 PM
Staying Updated Calendar of Updates.
For the time will come when men will not put up with sound doctrine. Instead, to suit their own desires, they will gather around them a great number of teachers to say what their itching ears want to hear....
Become a BleepingComputer fan: Facebook

Help



Back to top















