Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » First Virus found that uses Sony Rootkit...
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
FTC Shuts Down Adware/Spyware Vendor »
« spybot search and destory bug  
AuthorAll Replies


BQuick

join:2003-11-05
Italy

reply to sharpy merc
Re: First Virus found that uses Sony Rootkit...

And same news from Kaspersky Newsletter:

1. New backdoor program uses Sony rootkit

Kaspersky Lab, a leading developer of secure content management
solutions that protect against viruses, Trojans, worms, spyware, hacker
attacks and spam announces that a new backdoor program has been
detected. This is the first malicious program to use Sony rootkit
technology to hide its presence in the system.

The media has already written extensively about how Sony BMG applied
rootkit technology to hide and protect DRM components used to prevent
disks from being copied. One highly unfortunate effect of Sony's
decision to use this rootkit was the possibility that malicious programs
might implement the same technology. Kaspersky Lab virus analysts can
confirm that this has now happened.

Today a backdoor program which utilizes the rootkit technology was
detected. Kaspersky Lab classifies the program as
Backdoor.Win32.Breplibot.b. The backdoor was mass mailed using spamming
technologies, and attached to a message which uses classic social
engineering techniques to entice the recipient into launching the
attachment. The attachment allegedly contains a photograph. Once the
user launches the attached file, the backdoor code will penetrate the
victim machine.

Breplibot.b is a file 10240 bytes in size, packed using UPX. When
launching, the backdoor copies itself to the Windows system directory as
$SYS$DRV.EXE. Using this name makes it possible for the Sony rootkit
technology to be used to hide the activity of the malicious program. Of
course, the backdoor's activity will only be hidden if DRM protection,
as used on some Sony Audio CDs, functions on the victim machine.

As usual, Kaspersky Lab warns users to be careful, and not to open email
from unknown senders, or open attachments to suspicious messages.
------------

Great job Sony!Thank you!
Forums » Up and Running » Security » SecurityFTC Shuts Down Adware/Spyware Vendor »
« spybot search and destory bug  


Wednesday, 11-Nov 01:16:43 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.republican-creole
page compression OFF
Most commented news this week
· [125] Moto Sold About 100,000 Droids
· [95] Verizon Keeps Swinging At AT&T
· [86] VoIP Over 3G Still Not Working For iPhone
· [68] Government Will Release Some Telco Wiretap Lobbying Documents
· [62] Verizon's Hanging Up On Rural America
· [50] Verizon's Higher ETFs Annoy Senator
· [34] Bill Would Force ISPs To Block Financial Scams
· [32] Sprint Announces Job Cuts
· [24] Mediacom Hints At 50, 100 Mbps Speeds
· [24] Google Offers Free Holiday Airport Wi-Fi
Most people now reading
· Google Has Acquired Gizmo5 [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· Slow speed lately? [TekSavvy]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Telus supports CRTC's NN and UBB [TekSavvy]
· RG Firmware update to VDSL2 this morning [AT&T U-verse]
· 3.x Feral Druid - Bear Tanking Guide [World of Warcraft]
· Opening a file download dialog from a JavaScript function. [Webmasters and Developers]
· DSL Deployment - How hard w\Verizon as the ILEC? [Wireless Service Providers]