Beware Sony CDs on your PCs


From a buddy:

There have been some threads about this on Audio Asylum and the Washington Post has an excellent article on this abomination. It's serious; Sony CDs install a poorly written piece of malware on your computer without telling you (the incompetent jackass who seems to have written it, one Ceri Coburn of First4Internet, had to ask for help from a Windows programming email list last year). The DRM malware uses CPU resources all the time even when you're
not playing the Sony CD, and it cloaks itself so deep in Windows that anti - virus software can't find it. Even worse, the trick it uses to hide itself opens up an avenue for viruses to hide from anti - virus tools too. One post
on CNet sums up the issue this way: "Highly invasive software that can corrupt Windows was installed by Sony without the user's knowledge or permission. The software is hidden, extremely low level, and impossible to remove by any malware tools. Normal use of the computer can cause Windows' devices to become inaccessible, forcing the user to reformat and reinstall Windows." Sony's "fix" is merely a patch that uncloaks the DRM code so it shows up in your registry, but doesn't remove the damn thing or fix its defects. And the DRM code blows up the beta test version of the next generation of Windows. Its completely unconscionable for Sony to have done this.
128x128nsgarch

Showing 4 responses by edesilva

They have offered a "fix," but here's what one commenter said about the patch:

The update is more than 3.5 megabytes in size, and it appears to contain new versions of almost all the files included in the initial installation of the entire DRM system, as well as creating some new files. In short, they’re not just taking away the rootkit-like function — they’re almost certainly adding things to the system as well. And once again, they’re not disclosing what they’re doing.

See http://www.freedom-to-tinker.com/?p=921
Apparently it is fairly recent. From my quick read, it only installs if you use the media player on the CD. If you look at the CD listing on Amazon, it should say [Copy Protected Content] under the main title. Here's more info:

http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html
Firefox is good, but the other answer is never executing something you don't trust. I've never trusted the content companies, so I have never executed any of the CD extra material on the discs I've gotten.
More follow up, including a response purportedly from F4I, the creators of the rootkit. And possible legal actions.

http://www.sysinternals.com/blog/2005/11/more-on-sony-dangerous-decloaking.html

Apparently this DRM has been around a while. I ran RKR on my computer and came up clean, a recommended step if you run Windows...