Page 1 of 2

Update: fix released for Sony DRM rootkits

Posted: 2005-10-31 07:15pm
by Psycho Smiley
Linka

Summary: Sony's new DRMed CDs appear to be using a commercially available rootkit to prevent Windows users from uninstalling their DRM. This is not mentioned in the CD's EULA. Attempts to simply delete the DRM either fail or cripple the CD drive. Much mucking about in the registry, command-line only mode, and/or an alternate OS is required to fix the problem.

Solution: a) don't play Sony's DRMed CDs in your Windows box unless you have autorun disabled and know what you're doing.

b) An IE-only ActiveX cleanup program is hosted here

Posted: 2005-10-31 07:52pm
by Alyeska
That sounds very illegal. Infecting the users computer and all.

Posted: 2005-10-31 08:40pm
by BloodAngel
How does it manage to make only the local system account able to change the keys, when it initially runs as Administrator/Restricted user? :?

Not only is Sony installing malware, but they're potentially breaking through a Windows vulnerability.

Posted: 2005-10-31 08:54pm
by Braedley
I, through my ignorance (maybe stupidity), didn't disable autoplay when I first put the disk in my tray. Needless to say, I didn't like the results. The half-second to a second delay while the protected WMAs loaded the DRM keys wasn't what botthered me. No, what bothered me was the fact that my MP3 player wouldn't play them (it might have something to do with the fact that the firmware I have loaded on it goes against the DMCA (I love Canada)). So, I decided to delete the DRM folder that I happened to stumble apon, thinking thats all that was preventing me from ripping the cd the way I wanted. Boy was I wrong. Not only could I still not rip the CD, but I could no longer play the WMAs. All is good now, as I have gotten a friend to rip the CD for me (no thanks to Psycho here).

Anyways, this is still good news, but damn broken links means I can't find what I have to do!!! Ah, fixed...

Posted: 2005-10-31 09:34pm
by Admiral Valdemar
Boot in Linux, rip via FLAC, reboot into Windows, play in Winamp. V-sign Sony and corporate wankers screwing legit customers over.

Posted: 2005-10-31 09:44pm
by Braedley
Admiral Valdemar wrote:Boot in Linux, rip via FLAC, reboot into Windows, play in Winamp. V-sign Sony and corporate wankers screwing legit customers over.
Yeah, haven't gotten around to daul booting yet. Planning on it, but haven't had the time.

Posted: 2005-10-31 09:49pm
by Psycho Smiley
I believe in Braedley's case the solution was as simple as: use another computer, disable Autorun, don't install DRM, rip as per normal.

Braedley, please correct me if there was more to it.

Posted: 2005-10-31 10:15pm
by Braedley
No that was it. But niether you nor Moses_ were around whenever I wanted it ripped.
Oh, and even after reading the linked article, I still don't know how to get the shit off my computer. Any suggestions?

Posted: 2005-10-31 10:22pm
by Psycho Smiley
It looks like it takes much fucking around with debugging tools, and a strong knowledge of what you're doing.

Long story short, didn't you say Windows was getting slow again anyway? Format the right partition this time. :wink:

Posted: 2005-10-31 11:01pm
by Oline61
This is why you should download your music instead of legitimately buying it.

Just kidding, you should always obey the law :shock:

Posted: 2005-10-31 11:39pm
by Braedley
Canadians don't have to make that distinction. However, in my case, I really wanted the CD, partly so that I could good quality MP3s.

Posted: 2005-11-01 12:16am
by Spyder
That's fucking nasty. Firewall's that prevent program execution would stop it though wouldn't they?

Posted: 2005-11-01 12:39am
by Faram
Spyder wrote:That's fucking nasty. Firewall's that prevent program execution would stop it though wouldn't they?
Only from connecting to the internet.

But there is help to be found!

Process Guard

Used correctly this will take care of that crap.

Posted: 2005-11-01 01:26am
by Drooling Iguana
Makes me glad that I got into the habit of disabling autorun immediately after installation way back in the Win95 days. It was always just a nuissance, anyway.

DRM taken to extreams, Sony kills drives

Posted: 2005-11-01 01:18pm
by Ace Pace
Rootkits, DRM, filters killing your CD drive

This is too far.

Doh! double thread.

Posted: 2005-11-01 01:59pm
by Arthur_Tuxedo
Damn. I actually liked autorun. Oh well, it's disabled now, and after reading this I'll never use it again.

Posted: 2005-11-01 04:40pm
by Einhander Sn0m4n
The Register has it too.

Posted: 2005-11-01 04:57pm
by bilateralrope
I've tried a very quick look in the winXP home control pannel, can't find how to disable autorun. Since I haven't put any cds into the drive for weeks, and am likely to stay like that for weeks, I can't be bothered to look further.

Could someone tell me how to disable autorun ?

Posted: 2005-11-01 05:54pm
by General Zod
bilateralrope wrote:I've tried a very quick look in the winXP home control pannel, can't find how to disable autorun. Since I haven't put any cds into the drive for weeks, and am likely to stay like that for weeks, I can't be bothered to look further.

Could someone tell me how to disable autorun ?
Your Google-Fu is weak!

Posted: 2005-11-02 09:00pm
by Psycho Smiley
Update: a fix has been released. Check the OP.

Posted: 2005-11-02 10:08pm
by GuppyShark
Has there been any sort of backlash against Sony yet?

Posted: 2005-11-02 10:20pm
by Psycho Smiley
The fix is a direct response to the story being posted on many major tech sites. They probably wanted their asses covered before it hits a major news magazine or something.

EDIT: Slashdot says this may only make the shit visible, not remove it or keep it from hosing your system if you try to delete it. Braedley, have you tried this?

Posted: 2005-11-02 11:07pm
by Einhander Sn0m4n
I could get Mike Healan of Spywareinfo to test it on a Windows virtual machine...

Posted: 2005-11-03 01:09am
by Rogue 9
http://majorgeeks.com/Brute_Force_Unins ... d4714.html

Try that. It might not be able to respond to an attempt to use an unorthodox uninstallation method. It's not a sure bet, though.

Posted: 2005-11-03 01:19am
by Rogue 9
Psycho Smiley wrote:EDIT: Slashdot says this may only make the shit visible, not remove it or keep it from hosing your system if you try to delete it. Braedley, have you tried this?
Where does /. say this?