473,769 Members | 3,857 Online
Bytes | Software Development & Data Engineering Community
+ Post

Home Posts Topics Members FAQ

Caution SONY Music CDs have trojan Malware

Whether you are a web surfer or a C++ developer, if you use Windows be
cautioned about SONY music CDs. They contain 'viewer' type software that is
actually a trojan horse for a "rootkit". The licence agreement gives no
indication whatsoever that the 'viewer' software contains the implementation
of a nasty near-impossible to remove rootkit software.

http://www.sysinternals.com/blog/200...al-rights.html

http://www.techdirt.com/articles/200...514209_F.shtml

http://www.theregister.co.uk/2005/11/03/secfocus_drm/

--

Beware SONY Music CDs.
They contain "viewers" that are actually
rootkit viruses that are near impossible to
remove.
http://www.sysinternals.com/blog/200...al-rights.html
http://www.techdirt.com/articles/200...514209_F.shtml
Nov 3 '05
87 5352
Sony Music CDs install Malware wrote:
Dustin Cook wrote:
relic wrote:
Justin wrote:
Relic, would you care to disprove the SysInternals page if you are
going to insult the person warning others of this?
Following attributes is not your strong suit, is it. Re-check the
thread and see if you can locate my insulting "Sony Music CDs
install Malware" anywhere.

Now fuck off.

--
Come to us with a problem only if you want help solving it.
That's what we do. Sympathy is what your girlfriends are for.


I'm still wondering what problems your feeble little mind is possibly
capable of either solving or assisting in solving. You have got to be
one of the dumbest little shits I've ever come across on usenet. You
know, back in my Raid vx days; I didn't encounter people as mouthy
and ignorant at the same time as you've been the last few days. Not
even on irc. Even the fucking aolers had more brains then you.
Christ. When I get a chance to meet morons like you, it brings back
fond memories of vxing. Your such an ignorant shit. Callin me a liar,
tellin me I don't know shit about viruses. I've written many, I would
think I know a fucking thing or two about them. Whats the name of any
you've written, you dumb shit?

I've long since retired from vxing, and forgotten many of the
routines; But I still suspect what I forgot is more then you're ever
going to learn. Your not shit. Your never going to be shit. heh.. You
fuckin lamer. My God... And to think I spent days trying to defend
myself, to some stupid little blowhard like you. HAHAHA...

Regards,
Dustin Cook
http://bughunter.atspace.org


Justin:

Actually, Relic is right ['usually is]. I think you followed the
thread wrong.


And I just posted the reply to Justin wrong

--

Beware SONY Music CDs.
They contain "viewers" that are actually
rootkit like malware that are near impossible to
remove.
http://www.sysinternals.com/blog/200...al-rights.html
http://www.techdirt.com/articles/200...514209_F.shtml
Nov 4 '05 #21
Geo wrote:
Dustin Cook wrote:
To remove it is a matter of cleaning up the files, theirs really no
need to play cat and mouse with it if you don't boot the host OS.
bartpe is a nice time saver. Once the files are gone, you can run
regedit from bart and mount the software hive, remove the offending
keys, unmount the hive, and reboot to the host OS. Windows will reset
your cdrom access back to it's own default drivers. If you have
burning software, you may need to reinstall it to re-enable burning
features.


And you think this is 'straight forward and easy', I've got no idea
what you're talking about, I don't even know what a 'hive' is let
alone how to [un]mount it !!!!


Geo:

"hive" - He's making references to the Windows registry. "mount" means to
make available to the running software [usually an operating system] for
use. Windows usually detects and mounts harddisks etc. automatically. Some
systems require the user to specifically command that a disk etc. gets
mounted. A BART [Bootable Antivirus and Recovery Tools] CD, is a bootable CD
that enables you to make fixes to the system without booting it from
Windows. "keys" refers to Windows registry key. "host OS" is your Windows
operating system. "burning software" refers to software that burns [creates]
CD-R discs such as a roll-your-own music CDs or a copy of another CD.

--

Beware SONY Music CDs.
They contain "viewers" that are actually
rootkit like malware that are near impossible to
remove.
http://www.sysinternals.com/blog/200...al-rights.html
http://www.techdirt.com/articles/200...514209_F.shtml
Nov 4 '05 #22
Dustin Cook, <bu************ **@gmail.com>, the undesirable, stoloniferous
fraudster, and hermit and religious recluse, dripped:
relic wrote:
Justin wrote:
Relic, would you care to disprove the SysInternals page if you are
going to insult the person warning others of this?

Following attributes is not your strong suit, is it. Re-check the
thread and see if you can locate my insulting "Sony Music CDs
install Malware" anywhere.

Now fuck off.

--
Come to us with a problem only if you want help solving it.
That's what we do. Sympathy is what your girlfriends are for.


I'm still wondering what problems your feeble little mind is possibly
capable of either solving or assisting in solving. You have got to be
one of the dumbest little shits I've ever come across on usenet. You
know, back in my Raid vx days; I didn't encounter people as mouthy and
ignorant at the same time as you've been the last few days. Not even
on irc. Even the fucking aolers had more brains then you. Christ.
When I get a chance to meet morons like you, it brings back fond
memories of vxing. Your such an ignorant shit. Callin me a liar,
tellin me I don't know shit about viruses. I've written many, I would
think I know a fucking thing or two about them. Whats the name of any
you've written, you dumb shit?

I've long since retired from vxing, and forgotten many of the
routines; But I still suspect what I forgot is more then you're ever
going to learn. Your not shit. Your never going to be shit. heh.. You
fuckin lamer. My God... And to think I spent days trying to defend
myself, to some stupid little blowhard like you. HAHAHA...


What a frothing rant. Foam all over the fucking joint.
Regards,
Dustbin k0oK
http://bumhunter.atspace.org


--
DISCLAIMER: The content does not reflect the thoughts or opinions of either
my ISP, myself, my company or employer, my friends (if any,) my goldfish or
my neighbour's mad dog; don't quote me on that; don't quote me on anything;
all rights reserved; the post is distribution copyrighted to the extent that
you may distribute the post and all its associated parts freely but you may
not make a profit from it or include the post in commercial publications
without written permission from the Prime Minister of Hutt Province; other
copyright laws for specific posts apply wherever noted or not noted, either
deliberately, negligently, or otherwise; posts are subject to change without
notice; posts are slightly enlarged to show detail; any resemblance to
actual persons, living or dead, is unintentional and purely coincidental;
hand wash only, tumble dry on low heat; do not bend, fold, mutilate, or
spindle; do not pass go; do not collect $200; your mileage may vary; no
substitutions allowed; for a limited time only; the post is void where
prohibited, taxed, or otherwise restricted; the post is provided "as is"
without any warranties expressed or implied; user assumes full liabilities;
not liable for damages due to use or misuse; an equal opportunity abuse
employer; no shoes, no shirt; quantities are limited while supplies last; if
defects are discovered, do not attempt to fix them yourself but return to an
authorised post service centre; caveat emptor; read at your own risk;
parental advisory - explicit words; text may contain material some readers
may find objectionable, parental guidance is advised; not suitable for
children; not suitable for adults; not for human consumption; keep away from
sunlight, pets and small children; limit one-per-family; no money down; no
purchase necessary; to approved purchasers only; facsimiles are acceptable
in South Australia; you need not be present to read this post; some assembly
required; batteries not included; action figures sold separately; no
preservatives added; tools not included; safety goggles may be required
during use; sealed for your protection, do not use if the safety seal is
broken; call before you dig; for external use only; if a rash, redness,
irritation or swelling develops, discontinue use; use only with proper
ventilation; avoid extreme temperatures and store in a cool, dry place; keep
away from open flames, naked flames and old flames; avoid inhaling fumes;
avoid contact with mucous membranes; do not puncture, incinerate, or store
above 60 degrees Centigrade; do not place near flammable or magnetic source;
smoking the post may be hazardous to your health; the best safeguard, second
only to abstinence, is the use of a good laugh; text used on the post is
made from 100% recycled electrons and magnetic particles; no animals were
used to test the hilarity of this post other than Synapse Syndrome; no salt,
MSG, artificial colour or flavour added; may contain traces of replies to
peanuts; if ingested, do not induce vomiting, if symptoms persist, consult
your humourologist; post is ribbed for your pleasure; slippery when wet;
must be 18 to read; possible penalties for early withdrawal; post offer
valid only in participating newsgroups; slightly higher in South Australia;
allow four to six weeks for delivery; damage from hurricane, lightning,
tornado, tsunami, volcanic eruption, earthquake, flood, orgasm, misuse,
self-abuse, neglect, unauthorised repair, damage from improper installation,
broken antenna, marred cabinet, incorrect line voltage, missing or altered
serial numbers, sonic boom vibrations, electromagnetic radiation from
nuclear blasts or other Acts of God are not covered; incidents owing to
aeroplane crash, ship sinking, motor vehicle accidents, leaky roof, broken
glass, falling rocks, mud slides, forest fire, flying projectiles or
dropping the item are also excluded; other restrictions may apply. If
something offends you, lighten up, get a life, and move on. All conditions
apply. Not available in all stores. Facts have been changed to protect the
guilty.

Gzdgzcgjzgckacd cnatggathkgkuaz khtojalawtltwua z.Zookzwn,cecng keclceawgk
Pcazrgp,arbgh,b hpq,blirvgeplcd hc.Ygjcdmbgebdg qep,rbagqprazrp aepehbdpqb
Nov 4 '05 #23
On 4 Nov 2005 02:10:20 -0800, "Geo" <gg@remm.org> wrote:
And you think this is 'straight forward and easy', I've got no idea
what you're talking about, I don't even know what a 'hive' is let alone
how to [un]mount it !!!!


You can pick it up easily enough from regedit help which tells you the
locations of the registry hive files. Editing with (bartpe) regedit is
simply a matter of selecting one of the files and loading it to a
temporary name of your choice. Edit using regedit in the normal way to
make the changes and unmount it simply by clicking on
File->Unload_Hive.
Jim.

Nov 4 '05 #24
On Fri, 4 Nov 2005 07:15:43 -0500, "Sony Music CDs install Malware"
<trunk@.box.sui tcase> wrote:
Dustin is Wrong 1. That's not 'easy' removal DustinThat's skilled removal by
someone who knows the system and registry very well as well as some of the
tools that are available.
Actually, he did say "aside from a general end user not knowing how to
boot from a cd such as a bart disc, or knowing how to use the registry
editor" before saying it was easy. With those qualifications, it *is*
easy.

Dustin is Wrong 2. And it is an infestation if special tools are needed for
a removal.


You won't find many (if any) in acv agreeing with that definition of
malware "infestatio n".
Jim.

Nov 4 '05 #25

Towelie wrote:
Dustin - so don't buy Sony. Your choice. Why use the issue to try to
prove your perceived intellectual superiority over others? Inferiority
complex? Can't handle being contradicted?
What in the world are you talking about? I'm not trying to prove any
superiority, I'm simply wanting some individuals who should know
better, like the register, from reporting inaccurate information, thats
all.
Virus writers: idiots who think they're clever cos they can write 3
lines of javascript.
Virus writers who loudly claim "credit" for their supposed creations:
even bigger idiots.
javascript? Kiddo, Mine were exe/com infectors. I don't need to claim
credit, I'm already published by name in virusbulletin, damn near 6
years ago.
People who claim to be virus writers when they obviously are not, then
use this imaginary "skill" to present themselves as smarter than
everybody else: the biggest idiots of all.
When they are obviously not? Sigh. I don't know how to make this any
simpler for you, I am Raid; I am a former well known virus writer. Why
in the hell would anybody claim to be this individual of all people, if
they were not? If you were a coder, you could see for yourself.
BugHunter is a legitimate application, but all programmers like bomb
makers have a certain signature. You'd find the coding style used on
BugHunter matches the coding style used on viruses and other malware
(war dialers, etc) written by Raid (me).
Did I just hear a virus writer calling somebody "lamer"? Now that's
very funny indeed. Why do people stick with writing viruses? Because
its so ridiculously easy. Doesn't even require any coding skills or
understanding of programming techniques whatsoever. So obviously anyone
who trumpets his own virus-coding skills doesn't have any.
Indeed. If your writing scripts, like javascript. :) I don't.
Incidently, you don't read so well; I'm retired. Have been for a very
long time now. Aside from maintaining contact with some old friends on
both sides, I have nothing to do directly with the Vx scene. My
interests are in malware removal, not it's creation.
BTW anyone who thinks the Sony DRM thing is an issue needs to google
"NSA key".


I do not feel the sony thing is that big of an issue. It's sneaky, but
something similiar was already released on the new foo fighters. It
just didn't make such an effort to hide itself.

Regards,
Dustin Cook

Nov 4 '05 #26

James Egan wrote:
On Fri, 4 Nov 2005 07:15:43 -0500, "Sony Music CDs install Malware"
<trunk@.box.sui tcase> wrote:
Dustin is Wrong 1. That's not 'easy' removal DustinThat's skilled removal by
someone who knows the system and registry very well as well as some of the
tools that are available.


Actually, he did say "aside from a general end user not knowing how to
boot from a cd such as a bart disc, or knowing how to use the registry
editor" before saying it was easy. With those qualifications, it *is*
easy.


heh. Hi James. Long time. :)

Dustin is Wrong 2. And it is an infestation if special tools are needed for
a removal.


You won't find many (if any) in acv agreeing with that definition of
malware "infestatio n".


Nope.. He sure won't. Laugh Laugh. Poor slob doesn't know what a virus
even is. Nor a rootkit, nor a worm. Sony's amusing little program
doesn't meet the criteria of any of them.

Regards,
Dustin Cook
http://bughunter.atspace.org

Nov 4 '05 #27
REH

Would you please remove your cross-posts to comp.lang.c++ from your
discussion?

Nov 4 '05 #28
Art
On 4 Nov 2005 07:49:39 -0800, "Dustin Cook"
<bu************ **@gmail.com> wrote:
I do not feel the sony thing is that big of an issue. It's sneaky, but
something similiar was already released on the new foo fighters. It
just didn't make such an effort to hide itself.


I thought it was the lack of a uninstall that was the big issue. Has
that been fixed? If a typical consumer/user is faced with having to
pay a expensive repair bill to have (possibly buggy) sw removed from
his PC, I'd say it's a big deal indeed.

Other issues such as continual added overhead (cpu/RAM useage) are
perhaps minor issues which most wouldn't consider a big deal nowdays
.... providing they are minor.

Art

http://home.epix.net/~artnpeg

Nov 4 '05 #29
On that special day, Dustin Cook, (bu************ **@gmail.com) said...
Nor a rootkit, nor a worm. Sony's amusing little program
doesn't meet the criteria of any of them.


I've seen it being named "rootkit" (behaviour) on a reputable German
site, the heise newsticker (something like register for Germans). They
used this term a bit loosely, because the original version was meant to
hide all processes and threads from the system, that begin with $sys$

That isn't exact science, of course, just meant to alert the readers
about this scumware.
Gabriele Neukam

Ga************* ************@t-online.de
--
Ah, Information. A property, too valuable these days, to give it away,
just so, at no cost.
Nov 4 '05 #30

This thread has been closed and replies have been disabled. Please start a new discussion.

By using Bytes.com and it's services, you agree to our Privacy Policy and Terms of Use.

To disable or enable advertisements and analytics tracking please visit the manage ads & tracking page.