PDA

View Full Version : Sony BMG Rootkit


naiku
11-03-2005, 06:18 PM
Sony's DRM Protected CD's require the listener to install a player on their pc. In doing so it will attach a rootkit onto your machine. If you don't know what a root kit is. It simplely attaches itself to your OS kernel and tells it some things. In this case says hide all files starting with $sys$.

If you use a rootkit remover like the one @ sysinternals.com it will remove these files but in doing so you will no longer have a CD rom drive and you will be forced to reinstall windows. I hear there is different ways to remove it, its worth looking into.

http://www.securityfocus.com/brief/34

Since if you are infected with this rootkit you can name a file $sys$ and it will become hidden from the OS. The url I posted is how WoW Botters are hidding their programs from the "Warden" (Their version of gameguard). Interesting... gg sony. Install a rootkit on machines so any moron script kiddie can hide their files by naming them $sys$. Thats good DRM protection.

megalomaniac
11-04-2005, 02:00 PM
yeah, it's really ridiculous - but as long as I see which CDs are DRM-enabled/copy protected, I won't bother because I simply refuse to buy such crap. Still crazy, again it's the people who actually buy the stuff that are the ones who get fucked. No file-sharer has to put up with a rootkit (well, at least not by default) cloaked as DRM protected media...

BTW, Warden works a lot different than GG - it scans window titles of active processes every 15 seconds, creates a hash to compare with a blacklist of known cheats. AFAIK it only reads and doesn't fuck further with your system