Skip to content

Sony Installs Rootkits to Enforce DRM

If you’ve inserted the Switchfoot CD Nothing Is Sound into your Windows PC, you more than likely have a Sony authored rootkit installed. Using the same stealth techniques that spyware/trojan/virus authors use to hide their programs on the PCs they have invaded, Sony’s DRM enforcement application similarly burrows itself deep into the operating system to avoid detection.

I encourage everyone that opposes DRM to let Sony know where you stand. Use their web form to request rootkit removal help and let them know that you won’t be giving Sony any more of your money until they clean up their act.

More Information:

F-Secure Blog
SysInternals Blog

15 Comments

  1. Couple that with http://www.engadget.com/entry/1234000500066081/ and it seems to me like Sony has lost every bit of consumer savvy they ever had. The laurels of the walkman just don’t look so perky anymore.

    Posted on 01-Nov-05 at 11:16 am | Permalink
  2. If you write Sony at the aforementioned web form, they will reply with a case number and a new web page you are supposed to visit. Here’s the address:

    http://cp.sonybmg.com/xcp/english/form9.html

    Notice how it tries to install a mystery ActiveX with no explanation of what this component does. What’s up with that?

    Posted on 01-Nov-05 at 11:20 am | Permalink
  3. Not to mention this:

    http://bigpicture.typepad.com/comments/2005/10/drm_crippled_cd.html

    Posted on 01-Nov-05 at 11:25 am | Permalink
  4. More unsettling news:

    http://www.theregister.co.uk/2005/11/01/sony_rootkit_drm/

    Posted on 01-Nov-05 at 12:13 pm | Permalink
  5. I knew the record co’s would eventually get around to this sort of thing. It’s quite disturbing.

    Posted on 02-Nov-05 at 10:56 am | Permalink
  6. Apparently Sony is using this on a bunch of their CDs.

    Wired on Sony’s rootkit: The Cover-Up Is the Crime

    http://www.wired.com/news/rants/0,2350,69467,00.html

    Posted on 02-Nov-05 at 6:39 pm | Permalink
  7. Another update on the Sony DRM madness:

    http://www.sysinternals.com/blog/2005/11/more-on-sony-dangerous-decloaking.html

    Posted on 04-Nov-05 at 12:32 pm | Permalink
  8. ttp://blogs.download.com/Spyware-Hunt/post.php?p=808

    Quote from Sony executive Thomas Hesse:

    “Most people, I think, don’t even know what a rootkit is, so why should they care about it?”

    Posted on 08-Nov-05 at 10:23 am | Permalink
  9. EMI wants you to know they don’t use rootkits:

    http://news.com.com/EMI+We+dont+use+rootkits/2100-1029_3-5937108.html?part=rss&tag=5937108&subj=news

    Posted on 08-Nov-05 at 2:01 pm | Permalink
  10. Make sure your audio CDs don’t automagically install software on your computer when you insert them. Here’s how to disable autoplay in Windows XP Pro:

    http://chris.webdevlab.com/blog/?p=63

    Posted on 09-Nov-05 at 10:40 am | Permalink
  11. And here’s a partial list of Sony CD’s with the rootkit:

    http://www.eff.org/deeplinks/archives/004144.php

    Posted on 09-Nov-05 at 11:41 am | Permalink
  12. Sony announced they will temporarily stop manufacturing CDs with this rootkit technology:

    http://www.securityfocus.com/print/brief/45

    And the A/V industry is actually going to start removing the rootkit when detected:

    http://blogs.technet.com/antimalware/archive/2005/11/12/414299.aspx

    Posted on 14-Nov-05 at 10:26 am | Permalink
  13. 1) Is their a utility to identify whether or not ones PC has been infected with this Sony rootkit?

    2) Is it possible to be infected by downloading songs via a P2P from a computer that is infected with this rootkit or perhaps the file that originally came with the Sony infected CD?

    Posted on 17-Nov-05 at 3:02 pm | Permalink
  14. Here’s Sony official “apology” and their announcement of a CD replacement program:

    http://cp.sonybmg.com/xcp/

    And as to your questions, John, yes, there are ways to detect if your PC has this Sony rootkit. For example, McAfee’s anti-virus product will detect and remove it:

    http://vil.nai.com/vil/content/v_136855.htm

    As to your second question, no, you can’t get this particular rootkit by downloading an MP3 via P2P.

    Now downloading porn… that’s a different story…

    j/k

    Made you nervous, didn’t I? :)

    Posted on 19-Nov-05 at 1:34 am | Permalink
  15. Scotch Tape Stymies Sony Copy Protection:

    http://informationweek.com/story/showArticle.jhtml?articleID=174400748

    Posted on 22-Nov-05 at 11:19 am | Permalink

Post a Comment

Your email is never published nor shared. Required fields are marked *
*
*