Search:  

 
 
   All ForumsHot TopicsGallery






how-to block ads


 
Forums » Up and Running » Security » Security » First Virus found that uses Sony Rootkit...
Search Topic:
Share Topic:
RSS topic:
toggle:
flat / full
normal / watch
Posting:
Post a:
Post a:
FTC Shuts Down Adware/Spyware Vendor »
« spybot search and destory bug  
AuthorAll Replies


BQuick

join:2003-11-05
Italy

reply to sharpy merc
Re: First Virus found that uses Sony Rootkit...

And same news from Kaspersky Newsletter:

1. New backdoor program uses Sony rootkit

Kaspersky Lab, a leading developer of secure content management
solutions that protect against viruses, Trojans, worms, spyware, hacker
attacks and spam announces that a new backdoor program has been
detected. This is the first malicious program to use Sony rootkit
technology to hide its presence in the system.

The media has already written extensively about how Sony BMG applied
rootkit technology to hide and protect DRM components used to prevent
disks from being copied. One highly unfortunate effect of Sony's
decision to use this rootkit was the possibility that malicious programs
might implement the same technology. Kaspersky Lab virus analysts can
confirm that this has now happened.

Today a backdoor program which utilizes the rootkit technology was
detected. Kaspersky Lab classifies the program as
Backdoor.Win32.Breplibot.b. The backdoor was mass mailed using spamming
technologies, and attached to a message which uses classic social
engineering techniques to entice the recipient into launching the
attachment. The attachment allegedly contains a photograph. Once the
user launches the attached file, the backdoor code will penetrate the
victim machine.

Breplibot.b is a file 10240 bytes in size, packed using UPX. When
launching, the backdoor copies itself to the Windows system directory as
$SYS$DRV.EXE. Using this name makes it possible for the Sony rootkit
technology to be used to hide the activity of the malicious program. Of
course, the backdoor's activity will only be hidden if DRM protection,
as used on some Sony Audio CDs, functions on the victim machine.

As usual, Kaspersky Lab warns users to be careful, and not to open email
from unknown senders, or open attachments to suspicious messages.
------------

Great job Sony!Thank you!
Forums » Up and Running » Security » SecurityFTC Shuts Down Adware/Spyware Vendor »
« spybot search and destory bug  


Sunday, 06-Dec 08:10:38 Terms of Use | Privacy Policy | Hosting by www.nac.net - DSL,Hosting & Co-lo | feedback | contact
over 10 years online! © 1999-2009 dslreports.com.
page compression OFF
Most commented news this week
· [163] Comcast Releasing Promised Usage Meter
· [147] Avast Antivirus Has Gone Mad
· [128] Comcast Makes NBC Universal Acquisition Official
· [125] The Bandwidth Hog Does Not Exist
· [105] Graduate Student Unveils Sprint's GPS Sharing With Feds
· [101] Google Invades ISP, OpenDNS Turf With Google Public DNS
· [85] FCC Ponders Moving From PSTN To IP Voice
· [82] Latest Consumer Reports Survey Not Kind To AT&T
· [81] New Bill Aims To Limit ETFs
· [75] Sprint Defuses GPS Privacy Media Bomb
Most people now reading
· False positive in Avast! or is it real? [Security]
· Wife might have to work in.... Iowa for a few months!!! [General Questions]
· Connecting to Google Voice Via SIP [VOIP Tech Chat]
· Windows 7 boot manager editing questions [Microsoft Help]
· [ PVP] 3.2 DK PvP D/W Spec... [World of Warcraft]
· Enhancement Shaman + Heirlooms, what to pick? [World of Warcraft]
· First commercial tool to crack BitLocker arrives (Updated) [Security]
· Is there any true cure for, or way to prevent, a hangover? [General Questions]
· [DNS] Google's public DNS... performance increases? [Comcast HSI]
· [Newsgroups] Newzleech down? [Filesharing Software]