Trojan Horse Hides Using Sony Rootkit

By Nate Mook | Published November 10, 2005, 11:36 AM

What security experts have warned about Sony's DRM has come to pass, with a new trojan horse attempting to hide itself using techniques enabled by the company's anti-piracy software. Dubbed "Troj/Stinx-E" by Sophos, the application copies itself to a file called: $sys$drv.exe, which is hidden by Sony's copy protection.

F-Secure has named the malware "Breplibot.b," but says a code mistake will limit its damage. "Luckily, the bot has a design flaw. If the Sony DRM rootkit is active (hiding) in the system during infection, the bot will not run at all. Moreover, the bot cannot survive a reboot because of a programming error," explained F-Secure's Mika Pehkonen in a blog posting.

Comments

View comments by with a score of at least

Wait, so...to not get hit with this trojan I need to not remove Sony's rootkit?

Hmm... :/

Score: 0

|

Probaly just a script kiddy with sloppy code the real virus/trojan writes are probaly looking at sonys code and coming up with ways to turn it into a real virus/trojan.

I wonder how long before websites become infected and inject Sonys rootkit into people systems theres more than enough idiots out there not running up to date antivirus/firewall software out there i say about a week if that.

Score: 0

|

I knew it was only a matter of time.. -_-

Score: 0

|

ok i dont support what sony has done.
But hoping that more hacker will abuse sonys drm and making other people pay for sonys mistake seems very bad.

The hacker dont do it to get sony mad they are doing it to destroy for the consumer.

eye for an eye isnt suited for modern thinking .

Score: 0

|

Actually, given that not the flaw is not so wide spread, i wouldnt be surprised if the person who developed this Trojan actually did it to get the medias attention on Sony. I mean if you think about it, it does make some sense.

Score: 0

|

One only hopes that the retards at Sony have their own copy-protection installed and some enterprising virus writer can make one to target specific IPs.

Did I say that......naughty ;)

Score: 0

|

DoS on sony.com would be fitting...

Score: 0

|

HaHaHa... this would be quite amusing!

Score: 0

|

Oh what poetic justice!

Score: 0

|

Sshh...

Be careful what you wish for. Especially on a public forum with knowledgable(?) programmers.

Wouldn't want to be considered as promoting felonious behaviour, ya know.

Score: 0

|

Yeah you're right. I should be more careful, and in reality doing that would do more harm than good. Just a thought in the back of my head...like somebody else said, making a trojan to hurt others for Sony's mistake is a bad thing, and DoS sucks bandwidth from the zombie machines too (duh)

Score: 0

|

I hope they keep writting trojans and viruses for this flaw.

Sony as to pay for their ineptitude, and their freaking CEOs arrogance.

Score: 0

|

To people that want to record Sony music with DRM

AnyDVD tackles Sony DRM Rootkit Virus
-------------------------------------

Since March 2005, Sony BMG is using a rootkit-based DRM system
on some newer audio CDs. This DRM system is a serious hazard
to each Windows based PC. Well known websites like F-Secure.com
and SysInternals.com (URLs below) are confirming this exposure.

If AnyDVD is installed and active on a PC, this new so-called
"Sony DRM Rootkit Virus" has no access to the operating system
and the affected audio CD appears unprotected regardless!

"What the heck Sony thought to themselves," SlySoft's CEO
Giancarlo Bettini was kidding, "maybe they wanna build their
own bot net?".

This "anti rootkit protection" is not a new function of AnyDVD,
rather it is the nature of AnyDVD to filter all undesired stuff
between a CD/DVD drive and the operating system. It is just one
example, how well AnyDVD's option to "Remove CD Digital Audio
Protection" is working.

AnyDVD v5.5.1.1
New: Added functionality to remove invalid VOBUs from a title set to the option to remove "Protection based on unreadable Sectors". This fixes the error message "Out of memory" from DVDShrink with some DVDs, which suffer from a certain mastering error.
Fix: The option to remove "Protection based on unreadable Sectors" could cause DVDShrink to abort with an "invalid Navigation structure" error with some DVDs, which suffer from a certain mastering error.
Fix: Setup program did not delete obsolete RegCheck.exe file from previous installations
Fix: Undesired high CPU use for several minutes when checking for program update via internet connection

http://www.bitburners.co..._Sony_DRM_Rootkit_Virus/

Score: 0

|

This really makes you wonder what the virus author's intentions are. Let's face it, there have been "20 or so" cds that have this form of copy protection that may have sold a few hundred thousand copies. In order to get this virus, you'd need to recieve an infected email, and a few hundred thousand copies of the Sony DRM software versus the infinite possibilities of email addresses makes you wonder just how many people will actually be infected.

Don't get me wrong, virus writing and distribution is inexcusable in all forms, but it's like somebody's trying to prove something. Trying to open the doors to litigation against Sony.

I doubt it'll ever be a "successful" virus from the point of view of havoc, destruction and data loss - infection rates would be far too low, but the sheer fact that Sony will be held responsible for a virus AS WELL AS dodgy DRM software... it might be "successful" in a completely different way!

Score: 0

|

We can only hope.

Score: 0

|

Most AV proggies should already have this pegged. If not, update or switch programs.

Score: 0

|

One word.....GOOD!

Score: 0

|

Wow, beautiful. Nice going Sony.

The worst part is that Sony will soon start complaining that their drop in CD sales is due to P2P pirating...

Score: 0

|

Well, at least there's a little good news in this article.

Score: 0

|

After telling US to mind its own business, Kroes slaps caps on Rambus royalties

The holder of many patents worldwide pertaining to DDR memory offered to reduce its royalty stake in that technology, and today the EU said yes.

Why Apple succeeds, and always will

The company consistently plays by different rules, literally like David did in his battle against Goliath.

EC's Kroes to US senators: Mind your own business on Oracle + Sun

UPDATED The EU's antitrust chief told the United States Senate Tuesday that any merger that takes place in the world is more her affair than theirs.

Betanews Podcast: Rupert Murdoch and the buying stuff online problem

We'll have a more difficult time paying for online news if the underlying protocol for online payment has a big gaping hole in it.

In a peace offering to newspapers, Google offers a new news format

It's probably not a solution to the woes of major news publishers, but Living Stories may gather a few of those publishers together in search of one.

Google Maps doesn't prevent car accidents, only search accidents

This week, Google updated Maps for Android 3.3.1, adding topography, nearby points of interest, and error reporting.

DOJ: Microsoft interop docs are now 'substantially complete'

A major milestone in the US Government's oversight of Microsoft is passed, as the Justice Dept. is now saying the company's protocol documents make sense.

The $1 DVD rental debate: LA group says Redbox will lose movie makers $1B

A report from the Los Angeles Economic Development Corporation says cheap Redbox DVD rentals could seriously damage the movie business.

First impressions of Droid: Easy, breezy, friendly, if a little fat

Though it's not quite as well-polished as Apple's iPhone OS, the version of Android that Motorola's Droid phone sports is still a breeze to use.

Windows fix for TLS security bug still forthcoming, won't be Tuesday

Anyone looking for a fix for last month's discovery of a potentially serious security hole in TLS and SSL may have to wait until everyone is ready to act together.

Not the first, not the last, technology predictions for 2010

Carmi Levy | Wide Angle Zoom: The real truth is probably that what went around in 2009, will come around to haunt us next year.