Showing posts sorted by relevance for query sony rootkit. Sort by date Show all posts
Showing posts sorted by relevance for query sony rootkit. Sort by date Show all posts

Thursday, August 30, 2007

Here we go Again, with Sony Rootkits!

Remember the Sony rootkit saga? yes the music cd's with hidden programs. You would think that someone will learn from his/her mistakes but I think Sony has utter disregard for us or is the corporation is filled with dumb nuts. Look at PS3, a great product, beaten by Wii and XBOX. Just to remind, when PS2 came out, I could not wait for it to come to USA, I got one from Japan! I still have not bought a PS3, But I do have Wii and a XBOX! My first digital camera was a Sony! Now I don't even look at Sony when it come to cameras. Canon and Olympus with Casio fills my camera racks. Believe me, there has been a few digital cameras since that first Sony! I think next time when I have to explain what is a moron is, I have a good candidate!
So what did Sony did this time?
F-Secure revealed on Monday;
"Hypothetical: Imagine that you visit your local mall and browse around for stuff to buy. And you decide to buy a new CD from your favorite artist and you also buy a brand new cool USB stick thingy on an impulse. You go home and stick the CD into your laptop's CD drive. It prompts you to install some software. You do so and while you are listening to the music, you open the USB stick package and start experimenting with your new toy. It has a fingerprint reader so you install the software for that as well. Guess what… you might have just installed, not one, but two different rootkit-like software on your laptop.

We received a report that our F-Secure DeepGuard HIPS system was warning about a USB stick software driver. The USB stick in question has a built-in fingerprint reader. The case seemed unusual so we ordered a couple of USB sticks with fingerprint authentication. We installed the software on a test machine and were quite surprised to see that after installation our F-Secure BlackLight (which I am running right now just to check, even though I have not bought this USB drive or any SONY CD's) rootkit detector was reporting hidden files on the system."
"T
his new rootkit (which can still be downloaded from sony.net) can be used by any malware author to hide any folder. We didn't want to go into the details about this in our public postings, but we suppose the cat's out of the bag now that our friends at McAfee blogged about this yesterday. If you simply extract one executable from the package and include it with malware, it will hide that malware's folder, no questions asked.

We still haven't received any kind of response from Sony International. Sony Sweden did however confirm in a public IDG story that the rootkit is indeed part of their software.
"

Friday, December 22, 2006

Sony pays up for rootkit saga, but it is a pittance

Today California / Texas and 39 other states have settled with Sony BMG for including a rootkit with their music CDs. I wrote a lot about this last year, one of the articles;
Geemodo: Sony DRM ROOTKIT, Suncomm, EFF new removal tool, yet the consumer problems don't go away.
The website created to pay the settlement says Sony did not collect any personal information, they only collected CD ID, Track ID and IP ADDRESS! If IP address is not personal information, or that it leads to your personal information, I don't know what it is. I think lawyers should get all the court records on this case. If SONY can say IP Address is not personal information, when MPAA and RIAA comes calling with IP address to point to you in the court, bring out the amo. Courts will not be able to accept the evidence both the ways for music industry. I think I will post on Groklaw about this piece.
Every user whose computer was damaged with the rootkit, will receive upto $175.00 for all the troubles user went through.Most likely it is $7.50! and some songs. Looks like they getting off for a song. I do not know how the court access the damage value for each user but Sony BMG must have really good lawyers.
Some news reports say that you need to have documented report in order get the settlement payment. The documented evidence seems to be using SONY tools to remove the rootkit! HAHA, it did not completely remove the rootkit or it left some information behind, if I recall the saga right.
Anyway you need to visit the special website created to make your claim. Follow the links provided below. To make it difficult as possible the site is a mess. So follow the links as described and may be you will be able to recover your damages.

Links;
Notice to class members with a list of CDs.
Go here to file a claim

Friday, December 09, 2005

Sony DRM ROOTKIT, Suncomm, EFF new removal tool, yet the consumer problems don't go away.



After writing about Sony rootkit stuff, here, here, here, and here, the first post, I thought I could forget about writing about it and continue doing my normal stuff. But the gadgets, gizmos and toys have to wait it seems.
After all the court cases, theories of breaking IPOD and Itunes, Sony problems still linger. Now their patches are requiring patches. These products should not have been there in the first place and now consumers have to go on patching their computers, just to get some work done!
By the way Sony has released a rootkit uninstaller, you don't have to use the web based uninstaller they earlier offered. But with the trust I have in Sony, let researchers do their work first before trying to use it.

Well, windows updates, spyware updates, virus updates and now add sony patches update to your list. How about other music publishers? I think these researchers will continue to watch for these rootkits. And I will continue writing about them.
By the way in the form of boycotting Sony, I have guided myself to get an Olympus Digital camera (Review coming soon) instead of a Sony cybershots, HP computer for my friend, instead of Sony PC, Samsung DVR in place of Sony. So Sony, start counting, these small numbers add up.

Saturday, November 12, 2005

Sometimes Answers comes as soon as you ask them! Microsoft responds to Sony rootkit.

My post geemodo: Sony Stops production of rootkit CD's, I asked what Microsoft is doing about this.
Well I read this article, Microsoft Zapping Sony DRM 'Rootkit' which brought answer to my questions.
Microsoft Corp. will start deleting the rootkit component of the controversial DRM scheme used by Sony BMG Music Entertainment.
The software giant's Windows AntiSpyware application will be updated to add a detection and removal signature for the rootkit features used in the XCP digital rights management technology.

According to Jason Garms, group product manager in Microsoft's Anti-Malware Technology Team, the rootkit removal signature will be pushed out at Windows users through the anti-spyware application's weekly signature update process.

Detection and removal of the XCP rootkit will also appear in Windows Defender, the next version of Windows AntiSpyware when that makeover ships.

Tuesday, November 08, 2005

Sony’s Rootkit Saga Continues! And Sony/First4 claim innocence!!

Mark has got response from SONY/First4 and does not look as if they understand nor admits what they have done.
excerpt from Mark's Blog;
An email address is required in order to send the consumer the uninstall utility. The wording on the web site is the standard Sony BMG corporate privacy policy that is put on all Sony web sites. Sony BMG does nothing with the customer service data (email addresses) other than use them to respond to the consumer.

The Sony privacy policy the comment refers to clearly states that Sony may add a user’s email address to their marketing lists:

Except on sites devoted to particular recording artists, we may share the information we collect from you with our affiliates or send you e-mail promotions and special offers from reputable third parties in whose products and services we think you may have an interest. We may also share your information with reputable third-parties who may contact you directly.

Again, the fact is that most users of Sony’s DRM won’t realize that they even have software that can be uninstalled. Also, the comment does not explain why Sony won’t simply make the uninstaller available as a freely accessible download like they do the patch, nor why users have to submit two requests for the uninstaller and then wait for further instructions to be emailed (I still have not received the uninstaller). The only motivation I can see for this is that Sony hopes you’ll give up somewhere in the process and leave their DRM software on your system. I’ve seen similar strategies used by adware programs that make it difficult, but not impossible, for you to remove them.

Instead of admitting fault for installing a rootkit and installing it without proper disclosure, both Sony and First 4 Internet claim innocence. By not coming clean they are making clear to any potential customers that they are a not only technically incompetent, but also dishonest.

Well I wonder if these software come pre installed on sony computers?

Wednesday, July 25, 2007

Sony Rootkit Saga continues!

If you thought Sony Rootkit (Geemodo: Sony pays up for rootkit saga, but it is a pittance) saga is over, you are wrong! Now this time, we even get to laugh a little.
Sony BMG is suing the Amergence (formerly SunnComm) that sold it spyware-based DRM for its music CDs. The DRM company made a piece of spyware called MediaMax that infected your computer even if you declined its license "agreement." The program spied on your music listening habits, installed itself in a way calculated to make it hard to uninstall, and phoned home with information about your computer. An uninstaller the company eventually released didn't really uninstall the software, but did create security vulnerabilities on your PC. It was a whole lot of trouble for Sony. I have not bought a single Sony product since them.
I got the first Aibo, the first Paly station, the play station 2 from Japan and numerous entertainment products and Cameras. But not any more. I have not got PS3.

I got the information from Hollywood reporter via BoingBoing.

Friday, September 01, 2006

Sophos anti rootkit software! It is free to download

I have been following the rootkit problem since the Sony DRM rootkit issue mentioned in an earlier post, Geemodo: Sony DRM ROOTKIT, Suncomm, EFF new removal tool, yet the consumer problems don't go away..
Lately I found that Sophos has released a anti-rootkit and downloaded it. I did not test against known root kits but I did check my computers. Alas did not find any valid root kits, that is because I have been vigilant. Not a fault of Sophos anti rootkit. I advise that anyone careful about their computer to download and scan the computers for rootkits as it is gaining popularity in the malware and virus scene.
The user manual is here if you want to read before downloading.


From the read me file that states some feature and other issues;
1. Key features
---------------

* Scans running processes, windows registry and local hard drives for
rootkits.

* Identifies known rootkits and selects, by default, files for removal
which will remove the rootkit component of the malware without
compromising OS integrity.

* Allows users to remove unidentified hidden files, but does not allow
removal of essential system files when hidden by an identified
rootkit.

* Once the user has run a scan, the screen prompts the user through
the necessary steps until every rootkit has been removed.

* Users can switch between the GUI and command-line functionality.

* Both context sensitive and command-line help are available.


2. Known issues
---------------

* Sophos Anti-Rootkit will work on a Terminal Services or Remote Desktop
environment but may produce this warning which can be ignored:
'Unable to flush drive C: (already open by another process)'.

* If the scan is performed while the computer is in use, false positives
may appear in the scan results. This is caused by files or registry
entries being deleted, including temporary files being deleted
automatically. We suggest you close non-essential applications and
re-run the scan.

* It may not be possible to clean up files on a removable drive or USB key.
This is because the clean up component runs before the device drivers
are loaded in the boot sequence. If this occurs, remove the removable
drive or USB key. Next, restart the computer, plug the key back in,
and scan with anti-virus software, such as Sophos Anti-Virus.

* When specifying the location of the clean up log on the command line
(sarcli -cleanlog=...), it must be on a local drive rather than a network
share. This is because the clean up component runs before the network
drivers are loaded in the boot sequence.

* The sarscan.log is cumulative and each entry is timestamped. The
sarclean.log only contains the results of the last cleanup operation
and there is no timestamp apart from the one on the file itself.

* If rootkit components are found on a drive which uses NTFS compression,
it may not be possible for SAR to identify them. In this case they will
be reported as "Unknown hidden file". This situation is not currently
supported by the product.

* Unidentified hidden files cannot be removed via the command line.
Please run the graphical user interface (sargui.exe) and refer to
section 3 of the Sophos Anti-Rootkit User Manual.

Wednesday, November 16, 2005

A train of Sony Flaws and an Owl Hoots!

Hello World, I just let Sony stuff pass for a day and Boom. So much news! I just finished reading Brian Krebs' writings and man, he is a busy one. So is "Freedom to Tinker" There are a bunch of must read articles. Brian is a google news featured guy! Thanks Brian. Then there is an Owl who muttered about me! Thanks Owlish!
now to Sony Saga, there seems to be a bunch of security flaws introduced by This bad bad rootkit. I see them Here,here here here...
What ever you do the Sony Uninstaller Hole seem to Stay Open.
According to Felten (whose research was informed by a discovery from a Finnish researcher known as "Muzzy"), "the root of the problem is a serious design flaw in SonyÂ’s web-based uninstaller. When you first fill out Sony'’s form to request a copy of the uninstaller, the request form downloads and installs a program -- an ActiveX control created by the [digital rights management software] vendor, First4Internet -- called CodeSupport.

"CodeSupport remains on your system after you leave SonyÂ’s site, and it is marked as safe for scripting, so any Web page can ask CodeSupport to do things. One thing CodeSupport can be told to do is download and install code from an Internet site.

"Unfortunately, CodeSupport doesnÂ’t verify that the downloaded code actually came from Sony or First4Internet. This means any web page can make CodeSupport download and install code from any URL without asking the userÂ’s permission."

Another researcher, Kaminsky has done more work, Kaminsky said he's not sure yet how many individual computers inside of those 560,000 networks actually have the Sony software installed on them, but noted that "at the end of the day, it only takes an average of two machines per network and we are easily talking about millions of machines here."
His simple explanation on his Plotting is;
Sony has a rootkit.

The rootkit phones home.

Phoning home requires a DNS query.

DNS queries are cached.

Caches are externally testable


Viola! A Map.


Kaminsky tied the addresses to geographic locations by using his access to a commercial geolocation database. He has since posted a software tool on his site that renders a very cool three-dimensional look at where the largest concentrations of installs are located
I could go on, But I think you have a bunch to read for now.
Have a good day!

Saturday, November 12, 2005

Sony Stops production of rootkit CD's

"As a precautionary measure, Sony BMG is temporarily suspending the manufacture of CDs containing XCP technology," it said in a statement.
But this is after, denying, ignoring, and even president of Sony BMG saying, "Most people I think don't even know what a rootkit is, so why should they care about it? The software is designed to protect our CDs from unauthorized copying and ripping,"
Well scores of security experts, Windows System experts and even the government officials, bringing out the facts may have lead Sony to stop production.
I have read many a article regarding this issues. But yet to see the best Windows experts, Microsoft, doing or saying anything about this.
But virus makers, bot makers are happy to issue their versions of software that piggyback on sony's rootkit.
Visit Brian Krebs site, he covers this better than I do.
Sophos, which is based in the United Kingdom, said it would issue a tool later today to detect the existence of Sony's DRM copy-protection on Windows computers, disable it, and prevent it from re-installing

Friday, November 18, 2005

Today;s Sony related advise, How to get a rootkit array!

Lame Sony (more on the lame matter later!) Has a way for you to distribute 200 rootkits at once!
Vaio, I used to like the, and as I said before, I gave my Sony Vaio away! I explained the situation, got the latest drivers for the notebook, without visiting sony site, Pointed Sony.com to timbaktu, My firewall blocks all known sony sites, out going!
Anyway I have a Brand new Toshiba notebook and a Brand New Compaq notebook all under $1400. But they are good, one a 64 bit AMD with 1.2GB memory and a 60GB drive, CD/DVD burner. The other is a mobile Pentium 4 with 764MB memory and 80GB Drive also with a CD/DVD burner. Both have Bright screen 15.4 inch screens. I love this country! Where else would you get deals like this, Both from Compusa!
This is from a guy, always had sony notebook! Eat this Sony! I will harp to everyone that I know, about what you did.
I work in the computer field, I already turned away two possible Sony sales to other vendors. Apology from you will be accepted, if made in pulic to every one you hurt.

Back to headline, Sony has a gadget that can burn 200 disks at once! No not industrial, it is a consumer device. It comes with a dual layer capable 200 DVD/CD burner, If you want a life time of rootkits, go find this one and some sony CD's!

Tuesday, November 22, 2005

Sony get your Blues Music and start playing, Dark Clouds are Circling you!

If computer security researcher Dan Kaminsky, is right and assuming all the cases are here in USA, Texas has about 7.6% of the US population And Dan's number is 560000 cases. So at $100000 a case sony might have to pay about 4 billion dollars. This is in addition to the lawyer and court fees. Add that to California, New York and EFF cases.
Well Sony, and other RIAA members and RIAA, don't feel bad, you make about $10 per CD, after paying the artists! So if you can go after grandmothers with $3000 stick, I will be laughing when sentence is delivered. Don't worry about me either, I don't download your music. In fact I buy my music, currently I have over 250 CDs. The music I buy is what I love. But lately I don't love music. I hope you,RIAA, understand what you are doing to music industry. I will stick to my gadgets and Gizmos. And I will listen to my old CDs. I have not bought a new CD in about two years now. I get my music now in second hand store, if I have to have a CD.

"Sony has engaged in a technological version of cloak and dagger deceit against consumers by hiding secret files on their computers," says Greg Abbott, the attorney general for Texas, and he is following through with a law suite, alleging that its controversial (and now recalled) "XCP" anti-piracy software violates the state's anti-spyware and consumer protection laws. You can read the press release here.Abbott's suit seeks civil penalties of $100,000 for each violation of the law, attorneys'’ fees and investigative costs.
Brian Kerbs at Security Fix has spoken to Abbott, today and has records about EFF and possible Massachusetts case. Read about better estimates on the fines on his site.
My other hero over at Freedom to Tinker is explaining about the copyright violations that Sony has done while trying to protect it's Digital Rights. Sony has used open source software to construct parts of this software. Read Matti Nikkiaccountt that explains thedissectionn of root kit. I don'tbelievee Sony when it say it is innocent, According to Matti, The project has been developed in a directory called "XCP Player Code\Sony ActiveX Player\XCPPlayerControl\". Sebastian Porst has also uncovered another bunch of violations. I am getting really sick of you Sony!
Please read Ed Felten's article to fully understand the extend of violations. He nicely mentions how mainstream media do not see this to be part of the case. Mainstream media did not see any beforeuntill they could not ignore.Forbess, do you still think blogs are junk factories?

UPDATE
Groklaw, the site covering the SCO/IBM and other items such as patents, have started a section devoted to Sony DRM/rootkit saga. All the legal documents will be filed and preserved!

Sunday, November 13, 2005

It seems I can't stop writing about this Sony DRM Saga!

I thought, I could go look for gadgets and gizmos to replace all the Sony stuff I have, and may be share the comparisons that I make available on this site. But now I have to write about this DRM again.
Again as many a experts warned, virus writes and mulware writers have their gadgets out and riding on the Sony protection. Read more about it here.
Remember the article geemodo: Sony rootkit survival kit, What? Here I go again., yes the same source, Freedom to tinker, has another article, describing another version of similar DRM protection from Sony.
This time it is from company called Suncomm. Apparently FTT (freedom to tinker) has been writing about this in 2003.
So if you have Any Sony CD's throw them away. Get yours from other source. Check the label before you buy.
As I said I am replacing My Sony Stuff. I don't play music on my computer because I prefer the big sound from a proper sound source. For portable music, I will use IPOD.
My Advice is to have a good firewall, I use Zonealarm. And a network firewall, I have one too since I have a few computers here.
Anyway these morons are relying on ignorance of people to do these type of work. I think we should thank all these people like mark, ftt and many others who brought this to light. Today if you look, you will see major media carrying the news, I will write about my first Sony replacement soon.

Wednesday, November 09, 2005

Californians (lawyers) Hit back Sony!

Sorry about skipping on gadgets and continuing on the Sony DRM Saga.(previous posts Sony Saga1, Sony Saga 2). I just read here that California class action lawsuit has been filled on behalf of the California consumers. A second, lawsuit is expected to be filed against Sony in a New York court on Wednesday.
This is regarding the rootkit installed by some 20 odd Music CD's released by SONY/BMG.
CA Lawsuit requests to prohibit any further sales of CD's with rootkit and of course monitory damages. Thank you Sony, another lawyer get rich (if he wins), at consumers expense.
Scott Kamber, an attorney in New York, aims to file the new York suit today.

Sunday, November 13, 2005

Get your Hard-fi (MP3 gadget) here and not worry about Sony DRM

Cambridge University physics graduate, Martin Brennan, founder of , has developed and now marketing a hard-FI gizmo in this HI-FI world of today.

What is Hard-Fi?

Hard-Fi is a Hi-fi with a hard disk that talks to your Phone, iPod or MP3 player. 3GA put the power of a PC into a stereo to create a product that breathes life into your MP3 phone, Ringtones and iPods.

There are 1.3 billion mobile telephone subscribers. By 2008 there will be 350 million MP3 handsets made each year. Far more people own and will own more handsets than computers. The MP3 player market is $6.9 billion. The ringtone business is $3 billion. music business is another place that I don't want to go. With all the Sony DRM stuff I have written,
geemodo: No Sony Gadgets, Gizmo's or anything related to Sony on this site!
geemodo: SonyÂ’s Rootkit Saga Continues! And Sony/First4 claim innocence!!
geemodo: Californians (lawyers) Hit back Sony!
geemodo: Wahington Cast eyes on Sony like DRM practices.
May be this is the Solution, But how long before Martin joins big boys and practice their trade?
The Other thing is if your MP3 player is in the loo, geemodo: MP3 Set LOOs you cannot take loo to the computer so Hard-Fi to your rescue.
Hard-Fi is quite simply the easiest way to get music into a phone or mp3 player.
Features of Hard-Fi gadget, if you call it that;
With Hard-Fi you can:
All this in box that i’s as easy to use as your car radio.
The power of a PC with the simplicity of a stereo.
* Store all your music
* Find tracks instantly
* Mix like a DJ
* Plug in your MP3 player or phone, press a button and the track that is playing is sent to the player or phone - done!
* Segue mode blends one track seamlessly into the next. Its like hearing your music for the first time. YouÂ’ll never want to go back.
* IDE hard disk stores 700 albums on 40Gb.
* Rapid 15x copy from CD to hard disk means you can load your CD collection very quickly and its simple - put the CD in the drawer and press OK.
* Built-in upgradeable database with 1.7million albums labels CD tracks as they are loaded.
* Instant track search on a key by key basis finds matching tracks in seconds - as simple as sending a txt message.
* Burn audio CDs from playlists.
* Background MP3 compression hidden from user.
* Reverberation, pitch shifting, tone control and other effects.
* Microphone & line in, loudspeaker & line out.
* Low cost DSP - flexible & just five ICs. Already in manufacture. New products possible in months.
* Suitable for all audio formats including micro-system, in-car, boombox, hi-fi separate even clock-radio.
His reasons for the Hard-Fi; And why he developed HaFE-FI.
MP3 compresses music by a factor of ten, and Hard disks of 20Gb - were big enough for an entire music collection. Low cost DSPs had 100 million instructions per second - enough for MP3.
Of course you could do all this on a PC but Martin knew that to be a mass market successor to the gramophone, the wireless, the record player, the transistor radio and the CD player the product needed spontaneity and simplicity. Not what comes to mind when you think of a PC.
Martin said "We have developed a successor to the home stereo but the most rewarding thing about the project is that when I hear my music on Hard-Fi - it surprises me - its like hearing it for the first time."
If you are technically interest in the gadgets inards, here is a block diagram of the system;

More info at Hardfi site.

Monday, November 14, 2005

Sony-BMG EULA! Laugh, Cry and Thrash!

Another installment on Sony DRM saga!
If you thought XCP "rootkit" copy-protection on Sony-BMG CDs was bad, perhaps you'd better read the 3,000 word (!) end-user license agreement (aka "EULA") that comes with all these CDs.
If you are unable to find it read the tasty bits EFF site.
Now the Legalese Rootkit: Sony-BMG's EULA
Yuo will see things like;
# If your house gets burgled, you have to delete all your music from your laptop when you get home. That's because the EULA says that your rights to any copies terminate as soon as you no longer possess the original CD.

# You can't keep your music on any computers at work. The EULA only gives you the right to put copies on a "personal home computer system owned by you."

# If you move out of the country, you have to delete all your music. The EULA specifically forbids "export" outside the country where you reside.

Friday, November 11, 2005

Sony rootkit survival kit, What? Here I go again.

A fellow blogger Ed Felten of Freedom to Tinker has published an article giving you enough information to survive and listen to your music. If have not bought any of the 20 odd CD's, stay clear, Don't buy Sony!
He starts with "HereÂ’s a handy bag of tricks for people whose computers are (or might be) infected by the SonyBMG/First4Internet rootkit DRM. The instructions here draw heavily from research by Alex Halderman and Mark Russinovich.". Go read.

Wednesday, July 19, 2006

Winternals no more!

When I first saw the blog post by Dwight Silverman and Jim Thompson at techblog, I was surprised and let a long sigh! Just what we need in this buggy windows world. Hope there are more Marks in the crowd!
Remember the Sony root kit saga! That we posted while ago? Yes Mark Russinovich, who discovered that root kit is now a Microsoft technical fellow!Vi
Here is his own words;
" I'm very pleased to announce that Microsoft has acquired Winternals Software and Sysinternals. Bryce Cogswell and I founded both Winternals and Sysinternals (originally NTInternals) back in 1996 with the goal of developing advanced technologies for Windows. We've had an incredible amount of fun over the last ten years working on a wide range of diverse products such as Winternals Administrator's pack, Protection Manager, Defrag Manager, and Recovery Manager, and the dozens of Sysinternals tools, including Filemon, Regmon and Process Explorer, that millions of people use every day for systems troubleshooting and management. There's nothing more satisfying for me than to see our ideas and their implementation have a positive impact.

That's what makes being acquired by Microsoft especially exciting and rewarding. I'm joining Microsoft as a technical fellow in the Platform and Services Division, which is the division that includes the Core Operating Systems Division, Windows Client and Windows Live, and Windows Server and Tools. I'll therefore be working on challenging projects that span the entire Windows product line and directly influence subsequent generations of the most important operating system on the planet. From security to virtualization to performance to a more manageable application model, there's no end of interesting areas to explore and innovate."

Well Sony root kit is not the only thing that Mark discovered, he discovered many a windows problems and provided us with many a tools to fix them. From Administrator's Pak, which I used extensively to autoruns to find and manage the place where most malware and rootkits begin their process.

I was wondering why Mark was so quite after he revealed the Sony rootkit. May be he was busy talking to Microsoft. Anyway I hope that Microsoft bought him out, not to silence him but to improve windows with his abilities. Get all the tools while you can at Systernals, you are going to need them. But will they work with Vista?

Tuesday, November 22, 2005

Root of Sony rootkit revelation!


Mark Russinovich is shown in his office with his Van Zandt CD from Sony BMG Music Entertainment, in which he discovered that the company had added a copy protection technology called XCP to his computer that this gadget blog has spoken so much about (one of the articles), Friday, Nov. 18, 2005, in Austin, Texas. Russinovich posted his findings to his blog which generated serious attention, and eventually forced Sony BMG to recall 50 different discs this week. Some 4.7 million had been made and 2.1 million sold (Photo and data from AP)My first article was published on 7th November.

Wednesday, October 11, 2006

PDF spammers giving you Haxdoor rootkit

Malware being spammed as PDF from retail stores by ZDNet's Suzi Turner -- Reports surfaced today of spam purporting to be from Dell, Walmart, Circuit City or Sony confirming an order for a Sony Vaio computer with a PDF attachment, but the attachment is, in fact, a very nasty piece of malware named Haxdoor. Text of email: Subject: Order ID : 37679041 Dear Customer, Thank you for ordering from our internet shop. If [...]


What ever you do if you get an email from above sources, do not hesitate, you know you did not order it, so delete it immediately.

Wednesday, June 06, 2007

Mark Russinovich's WinHec Keynote is online

Mark Russinovich of Systernals is now at M$ since M$ acquired the Systernals. I think it is good break for Mark and Bryce Cogswell. After providing us with tools to deal with all those (&*(&( on and in windows and finding things like Sony rootkit (have people already forgotten that!). But they are busy as ever. I had the chance to see Mark's presentation, Windows Server Platform Internals, as the WinHec keynote. As always it was a pleasure.
But I noticed at Microsoft technet Systernal site that a quite few videos of Mark is available for viewing.
1. •

Mark's WinHec keynote (Windows Server Platform Internals) is now available on-demand. This is an excellent session which covers many of the new technologies built into Windows Server 2008. In addition to a deep dive into these features there are pertinent demos as well.

2.•

Mark talks about life at Microsoft and working on Windows in this 5 minute interview taped at WinHEC.

Also you will find usual systernals info and tools.