Sony DRM uses black-hat rootkits

Steve sez, "A technical dissection by the mighty Mark Russinovich of Sony's rootkit-based DRM. Sony uses genuine black-hat techniques to install a rootkit, even choosing a Windows-sounding name for a service just like your favourite backdoor, and about as easy to detect or remove. Basically, Sony puts the sort of malware on its customers' PCs that the rest of the world spends alot of money fighting."

Last week when I was testing the latest version of RootkitRevealer (RKR) I ran a scan on one of my systems and was shocked to see evidence of a rootkit. Rootkits are cloaking technologies that hide files, Registry keys, and other system objects from diagnostic and security software, and they are usually employed by malware attempting to keep their implementation hidden (see my "Unearthing Rootkits" article from the June issue of Windows IT Pro Magazine for more information on rootkits). The RKR results window reported a hidden directory, several hidden device drivers, and a hidden application…

Link

(Thanks, Steve!)