Original URL: http://www.theregister.co.uk/2005/11/10/sony_drm_trojan/
Virus writers have begun taking advantage of Sony-BMG's use of rootkit technology in DRM software bundled with its music CDs.
Sony-BMG's rootkit DRM technology masks files whose filenames start with "$sys$". A newly-discovered variant of of the Breplibot Trojan takes advantage of this to drop the file "$sys$drv.exe" in the Windows system directory.
"This means, that for systems infected by the Sony DRM rootkit technology, the dropped file is entirely invisible to the user. It will not be found in any process and file listing. Only rootkit scanners, such as the free utility RootkitRevealer, can unmask the culprit," warns Ivan Macalintal, a senior threat analyst at security firm Trend Micro
The malware arrives attached in an email, which pretends to come from a reputable business magazine, asking the businessman to verify his/her "picture" to be used for the December issue. If the malicious payload contained in this email is executed then the Trojan installs an IRC backdoor on affected Windows systems.
Romanian anti-virus firm BitDefender confirms that the malware is in the wild but a full technical analysis of the Trojan is yet to be completed. The response of anti-virus firms, some of which have only promised to flag up rather than block system changes made by Sony-BMG's rootkit, remains unclear. ®
Sony to exorcise 'rootkit' from USB drives (4 September 2007)
http://www.theregister.co.uk/2007/09/04/sony_fingerprint_rootkit_update/
Sony bundles rootkit-like software on USB drive (29 August 2007)
http://www.theregister.co.uk/2007/08/29/sony_rootkit_controversy/
How fat is my DRM? (20 December 2006)
http://www.theregister.co.uk/2006/12/20/sony_rootkit_drm_settlement/
Police hold three in spam Trojan bust (27 June 2006)
http://www.theregister.co.uk/2006/06/27/spam_trojan_arrests/
Researcher: Sony BMG rootkit still widespread (16 January 2006)
http://www.theregister.co.uk/2006/01/16/sony_bmg_rootkit_still_widespread/
Sony BMG 'diligently re-evaluates' CD anti-piracy tech (12 December 2005)
http://www.theregister.co.uk/2005/12/12/sony_anti-piracy_review/
SonyBMG backtracks on buggy bug fix (9 December 2005)
http://www.theregister.co.uk/2005/12/09/sony_mediamax_problems/
Security threats soar in 2005 (7 December 2005)
http://www.theregister.co.uk/2005/12/07/sophos_2005_security_survey/
Sony opens up over another CD security hole (7 December 2005)
http://www.theregister.co.uk/2005/12/07/sony_cd_security/
Sony unsinged by rootkit CD fiasco (22 November 2005)
http://www.theregister.co.uk/2005/11/22/analysis/
Gaffer tape defeats Sony DRM rootkit (21 November 2005)
http://www.theregister.co.uk/2005/11/21/gaffer_tape_trips_up_sony_drm/
Sony DRM uninstaller 'worse than rootkit' (17 November 2005)
http://www.theregister.co.uk/2005/11/17/sony_drm_uninstaller_peril/
Sony pulls rootkit DRM CDs (16 November 2005)
http://www.theregister.co.uk/2005/11/16/sony_withdraws_xcp_cds/
Sony rootkit DRM: how many infected titles? (15 November 2005)
http://www.theregister.co.uk/2005/11/15/sony_bmg_bodycount/
Sony suspends rootkit DRM (12 November 2005)
http://www.theregister.co.uk/2005/11/12/sony_suspends_rootkit_drm/
Sony BMG faces digital-rights seige (11 November 2005)
http://www.theregister.co.uk/2005/11/11/secfocus_sony_analysis/
Mac anti-rip code surfaces on Sony BMG CD (11 November 2005)
http://www.theregister.co.uk/2005/11/11/sony_bmg_mac_drm/
Sophos develops Sony DRM unmasking tool (10 November 2005)
http://www.theregister.co.uk/2005/11/10/sony_drm_unmasked/
Give us digital rights for digital consumers (10 November 2005)
http://www.theregister.co.uk/2005/11/10/digital_rights_online/
Sony hit by lawsuits over root kit (10 November 2005)
http://www.theregister.co.uk/2005/11/10/sony_sued_for_rootkit/
Sony digital boss - rootkit ignorance is bliss (9 November 2005)
http://www.theregister.co.uk/2005/11/09/sony_drm_who_cares/
Hidden DRM code's legitimacy questioned (3 November 2005)
http://www.theregister.co.uk/2005/11/03/secfocus_drm/
Sony to offer patch for 'rootkit' DRM (3 November 2005)
http://www.theregister.co.uk/2005/11/03/sony_rootkit_drm/
Removing Sony's CD 'rootkit' kills Windows (1 November 2005)
http://www.theregister.co.uk/2005/11/01/sony_rootkit_drm/
© Copyright 2008