Welcome,
Guest
. Please
login
or
register
.
November 26, 2024, 12:20:13 AM
News:
tastyspleen.net discord server:
http://discord.tastyspleen.net
Home
Forum
Help
TinyPortal
Search
Calendar
Login
Register
tastyspleen::quake 2 community
»
Forum
»
The Tech Junkie Boards
»
Tech Junkie Lounge
»
sony rootkit
« previous
next »
Print
Pages: [
1
]
Go Down
Author
Topic: sony rootkit (Read 2965 times)
reaper
Opulent Member
Posts: 2872
Nice night for a walk, eh? - Nice night for a walk
Rated:
sony rootkit
«
on:
June 01, 2009, 03:25:39 PM »
a friend's cdrom stopped working. it looks like sony's rootkit hooks into the normal cdrom driver.
this cdrom doesn't show in windows, and the driver says it has an error. so I copy all new .sys files over from a recovery partion, and there is still an error. looking further in the registry someone these keys "upperfilter" and "lowerfilter" actually somehow load code that somehow hooks into the cdrom driver. so I delete all this $sys$ files, and fake services, then I remove all the $sys$ stuff from the registry and it still comes back. I will be trying again tonight.
http://www.privsoft.com/archive/psc-drm.html
wow, sony owes me some money for this bullshit after fucking with it for about 4 hours. I hope Sony pays dearly for this.
Logged
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy
QwazyWabbit
Carpal Tunnel Member
Posts: 1373
Rated:
Re: sony rootkit
«
Reply #1 on:
June 01, 2009, 06:50:33 PM »
Sony rootkit is very old news (2005). Windows was patched long ago (internet time) to eliminate the vulnerability it exploited. Your friend wasn't patching windows or running the MS tools needed to prevent exploitation.
Microsoft MSRT detects and removes Sony rootkit automatically.
http://www.microsoft.com/security/malwareremove/default.mspx
MSAS also alerts when the kit attempts action to install itself.
«
Last Edit: June 01, 2009, 06:56:26 PM by QwazyWabbit
»
Logged
reaper
Opulent Member
Posts: 2872
Nice night for a walk, eh? - Nice night for a walk
Rated:
Re: sony rootkit
«
Reply #2 on:
June 01, 2009, 07:11:33 PM »
I'm sure my friends wasn't patching windows as he knows nothing about computers. One of the first things I did was run a removal tool, it was from symantec, but I did see the sony removal tool (didn't try it, I read it leaves files behind and actually is malware..), and I haven't tried the microsoft one. Possibly the semantic removal tool didn't work because the malware was half removed as the machine already had been taken over, and I removed all the bs services and crap running.
I went to sony's site and I cannot claim any money for fixing the computer because it's passed 2007, but they owe me some money regardless. I hope they fail miserably.
Logged
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy
QwazyWabbit
Carpal Tunnel Member
Posts: 1373
Rated:
Re: sony rootkit
«
Reply #3 on:
June 02, 2009, 02:21:48 AM »
Turn on automatic Windows updates it's designed for novice computer users and will keep him patched same as a Mac, install the MSRT and MSAS and Windows firewall. Get rid of Symantec AV, it's junk. I used to recommend Norton AV but Symantec has turned it into bloatware. Have him get NOD32 instead. Even AVG free edition is better than Symantec. MSRT must be manually run and is a post-infection tool but it knows how to remove all the major threats, including the sony rootkit.
Logged
reaper
Opulent Member
Posts: 2872
Nice night for a walk, eh? - Nice night for a walk
Rated:
Re: sony rootkit
«
Reply #4 on:
June 04, 2009, 08:42:46 AM »
Looks like the computer has been automatically patching and running MSRT for some time. Looking at the MSRT log it found nothing for a while.
The Microsoft online virus scan detected the rootkit and removed some files, however the cd rom still does not show. Looking for $sys$ files anywhere, they are finally all gone, even entries in the registry.
My guess is the registry is corrupted so the windows CD rom configuration is broke so it doesn't show. Not exactly sure how to fix that, but I'll have to do some research and mess with it this weekend.
good job sony!
Logged
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy
Whirlingdervish
Super ShortBus Extravaganza
Illimitable Sesquipedalian Member
Posts: 6384
Rated:
Re: sony rootkit
«
Reply #5 on:
June 04, 2009, 10:33:54 AM »
hrm, something very similar to that happened on a rig here at work and I haven't had time to fix it yet.
I think I'll check it out with the rootkit tool just in case.
Logged
QwazyWabbit
Carpal Tunnel Member
Posts: 1373
Rated:
Re: sony rootkit
«
Reply #6 on:
June 04, 2009, 02:30:38 PM »
MSRT does not scan automatically and it is not pro-active. It doesn't work like an A-V tool and must be manually run retroactively to eliminate malware but it does remove the rootkit. Fingering the registry before running MSRT may cause it to not detect some elements.
Rootkit Revealer will also detect the sony rootkit but it requires some expertise.
Logged
reaper
Opulent Member
Posts: 2872
Nice night for a walk, eh? - Nice night for a walk
Rated:
Re: sony rootkit
«
Reply #7 on:
June 04, 2009, 03:54:07 PM »
I know MSRT didn't get the rootkit because its logs go back months and months long before anyone touched the registry. It is run every so often, after being patched. It logs to a file and tells you what it's detected and removed.
AVG and the symantec removal tool did not find the rootkit, however microsoft onine virus scan did. It's just that the cdrom registry is corrupt, after I remove the upper filter and lower filter registry entries for the cdrom and reinstall the driver it should be fine.
Logged
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy
reaper
Opulent Member
Posts: 2872
Nice night for a walk, eh? - Nice night for a walk
Rated:
Re: sony rootkit
«
Reply #8 on:
June 04, 2009, 07:42:44 PM »
yes finally working.
the registry entry for upperfilters under the cdrom section still passed through gear...sys which was breaking the driver for some reason. sony root kit done.
Logged
VaeVictus "reaper is a lying sack of shit and ragequit then had, probably slugs, come alias and beat me, wasnt even the same person playing OBVIOUSLY, accuracies basicly doubled, and strategy
Print
Pages: [
1
]
Go Up
« previous
next »
tastyspleen::quake 2 community
»
Forum
»
The Tech Junkie Boards
»
Tech Junkie Lounge
»
sony rootkit
El Box de Shoutamente
Last 10 Shouts:
Costigan_Q2
November 11, 2024, 06:41:06 AM
"Stay cozy folks.
Everything is gonna be fine."
There'll be no excuses for having TDS after January 20th, there'll be no excuses AT ALL!!!
|iR|Focalor
November 06, 2024, 03:28:50 AM
RailWolf
November 05, 2024, 03:13:44 PM
Nice
Tom Servo
November 04, 2024, 05:05:24 PM
The Joe Rogan Experience episode 223 that dropped a couple hours ago with Musk, they're talking about Quake lol.
Costigan_Q2
November 04, 2024, 03:37:55 PM
Stay cozy folks.
Everything is gonna be fine.
|iR|Focalor
October 31, 2024, 08:56:37 PM
Costigan_Q2
October 17, 2024, 06:31:53 PM
Not activated your account yet?
Activate it now! join in the fun!
Tom Servo
October 11, 2024, 03:35:36 PM
HAHAHAHAHAHA
|iR|Focalor
October 10, 2024, 12:19:41 PM
I don't worship the devil. Jesus is Lord, friend. He died for your sins. He will forgive you if you just ask.
rikwad
October 09, 2024, 07:57:21 PM
Sorry, I couldn't resist my inner asshole.
Show 50 latest
User
Welcome,
Guest
. Please
login
or
register
.
November 26, 2024, 12:20:13 AM
1 Hour
1 Day
1 Week
1 Month
Forever
Login with username, password and session length
Search
Advanced search