Trojan Horse Hides Using Sony Rootkit
by Nate Mook
What security experts have warned about Sony's DRM has come to pass, with a new trojan horse attempting to hide itself using techniques enabled by the company's anti-piracy software. Dubbed "Troj/Stinx-E" by Sophos, the application copies itself to a file called: $sys$drv.exe, which is hidden by Sony's copy protection.
F-Secure has named the malware "Breplibot.b," but says a code mistake will limit its damage. "Luckily, the bot has a design flaw. If the Sony DRM rootkit is active (hiding) in the system during infection, the bot will not run at all. Moreover, the bot cannot survive a reboot because of a programming error," explained F-Secure's Mika Pehkonen in a blog posting.
Wait, so...to not get hit with this trojan I need to not remove Sony's rootkit?
Hmm... :/
Score: 0
Probaly just a script kiddy with sloppy code the real virus/trojan writes are probaly looking at sonys code and coming up with ways to turn it into a real virus/trojan.
I wonder how long before websites become infected and inject Sonys rootkit into people systems theres more than enough idiots out there not running up to date antivirus/firewall software out there i say about a week if that.
Score: 0
I knew it was only a matter of time.. -_-
Score: 0
ok i dont support what sony has done.
But hoping that more hacker will abuse sonys drm and making other people pay for sonys mistake seems very bad.
The hacker dont do it to get sony mad they are doing it to destroy for the consumer.
eye for an eye isnt suited for modern thinking .
Score: 0
Actually, given that not the flaw is not so wide spread, i wouldnt be surprised if the person who developed this Trojan actually did it to get the medias attention on Sony. I mean if you think about it, it does make some sense.
Score: 0
One only hopes that the retards at Sony have their own copy-protection installed and some enterprising virus writer can make one to target specific IPs.
Did I say that......naughty ;)
Score: 0
DoS on sony.com would be fitting...
Score: 0
HaHaHa... this would be quite amusing!
Score: 0
Oh what poetic justice!
Score: 0
Sshh...
Be careful what you wish for. Especially on a public forum with knowledgable(?) programmers.
Wouldn't want to be considered as promoting felonious behaviour, ya know.
Score: 0
Yeah you're right. I should be more careful, and in reality doing that would do more harm than good. Just a thought in the back of my head...like somebody else said, making a trojan to hurt others for Sony's mistake is a bad thing, and DoS sucks bandwidth from the zombie machines too (duh)
Score: 0
I hope they keep writting trojans and viruses for this flaw.
Sony as to pay for their ineptitude, and their freaking CEOs arrogance.
Score: 0
To people that want to record Sony music with DRM
AnyDVD tackles Sony DRM Rootkit Virus
-------------------------------------
Since March 2005, Sony BMG is using a rootkit-based DRM system
on some newer audio CDs. This DRM system is a serious hazard
to each Windows based PC. Well known websites like F-Secure.com
and SysInternals.com (URLs below) are confirming this exposure.
If AnyDVD is installed and active on a PC, this new so-called
"Sony DRM Rootkit Virus" has no access to the operating system
and the affected audio CD appears unprotected regardless!
"What the heck Sony thought to themselves," SlySoft's CEO
Giancarlo Bettini was kidding, "maybe they wanna build their
own bot net?".
This "anti rootkit protection" is not a new function of AnyDVD,
rather it is the nature of AnyDVD to filter all undesired stuff
between a CD/DVD drive and the operating system. It is just one
example, how well AnyDVD's option to "Remove CD Digital Audio
Protection" is working.
AnyDVD v5.5.1.1
New: Added functionality to remove invalid VOBUs from a title set to the option to remove "Protection based on unreadable Sectors". This fixes the error message "Out of memory" from DVDShrink with some DVDs, which suffer from a certain mastering error.
Fix: The option to remove "Protection based on unreadable Sectors" could cause DVDShrink to abort with an "invalid Navigation structure" error with some DVDs, which suffer from a certain mastering error.
Fix: Setup program did not delete obsolete RegCheck.exe file from previous installations
Fix: Undesired high CPU use for several minutes when checking for program update via internet connection
http://www.bitburners.co..._Sony_DRM_Rootkit_Virus/
Score: 0
This really makes you wonder what the virus author's intentions are. Let's face it, there have been "20 or so" cds that have this form of copy protection that may have sold a few hundred thousand copies. In order to get this virus, you'd need to recieve an infected email, and a few hundred thousand copies of the Sony DRM software versus the infinite possibilities of email addresses makes you wonder just how many people will actually be infected.
Don't get me wrong, virus writing and distribution is inexcusable in all forms, but it's like somebody's trying to prove something. Trying to open the doors to litigation against Sony.
I doubt it'll ever be a "successful" virus from the point of view of havoc, destruction and data loss - infection rates would be far too low, but the sheer fact that Sony will be held responsible for a virus AS WELL AS dodgy DRM software... it might be "successful" in a completely different way!
Score: 0
We can only hope.
Score: 0
Most AV proggies should already have this pegged. If not, update or switch programs.
Score: 0
One word.....GOOD!
Score: 0
Wow, beautiful. Nice going Sony.
The worst part is that Sony will soon start complaining that their drop in CD sales is due to P2P pirating...
Score: 0
Well, at least there's a little good news in this article.
Score: 0