The Mudcat Café TM
Thread #86040   Message #1607986
Posted By: JohnInKansas
18-Nov-05 - 06:09 AM
Thread Name: Tech: Sony Audio CDs INFECTED
Subject: RE: Tech: Sony Audio CDs INFECTED
Robin -

I haven't seen anything that indicates that any different Windows versions are unaffected.

One of the pros who's commented has indicated that the Sony uninstaller puts a different piece of shitware on your machine before the uninstall runs, and the "replacement" continues to attempt concealment and may in fact make the security and stability of your machine worse than with the original Sony rootkit.

Its also been reported that to get the Sony "uninstaller" you have to agree to their EULA that includes authorization for them to send you information about all future releases of new CDs.

The Sony uninstall runs a "getver" to see what version is on the machine before it installs the replacement crud, so it must be assumed that it's set up to adapt to whatever version you have.

The rootkit itself primarily just hides all the crap that Sony installs. The other crud replaces or modifies your CD/DVD drivers, and presumedly could load new drivers to work with any Windows version; so it must be assumed that Sony intended this to go on all Windows Versions that attempt to play the disks.

Some comment says that it goes on all Mac OS as well, and potentially causes greater OS instability there. There have been comments implying that it affects Linux also, although I haven't seen anyone specifically say so.

As released on the affected CDs, the Sony intention was if they couldn't fuck up your system, the disk simply couldn't be played on it since the disks are encoded to force you to use their playback program - which installs from the CD.

One AV maker has announced that their AntiVirus will (soon?) incorporate detection and removal for it, but I haven't seen whether it's an all-OS program. Microsoft says that removal will be incorporated "about Dec 1" in their AntiSpyware (still beta) program, but of course that's only available for WinXP.

Microsoft also says that detection and removal will be incorporated on their web AV/AS scanner, but I don't know whether that service is limited to current versions. For older, and unsupported, OS versions, it may come down to one of the few cases where you actually have to reformat and reinstall - but I'd hold off until there's more definite advice.

Several users have stated that they attempted to remove it manually, and lost all CD/DVD drive function. At least one fellow reported he bought a new drive because it looked like the drive itself had failed. We doubt that Sony will reimburse him.

John