Analysis: Sony BMG copy protection may be stealthy, but is it a "rootkit?"

Austin (TX) - When security software engineer Mark Russinovich was testing last week one of his programs called RootkitRevealer, on a system he normally expects to be free of malicious code, he noticed that it revealed a hidden directory, and several hidden files. Inside were what appeared to be device drivers, with .SYS and .DLL extensions, and one hidden executable .EXE file. These weren't hidden by the normal means - for instance, setting the old DOS "Hidden" attribute - but by cleverly diverting system calls used to identify themselves to Windows.

This started Russinovich on a search through his system for what was doing the diversion, which for him was a trivial matter to accomplish. What he found was a driver embedded in his system's memory, which was diverting all system calls to identify a directory whose listing began with the characters $sys$. Inside that directory - which he could easily open, even though Windows couldn't see it - were files that identified themselves as part of a package published by a company called First 4 Internet, Ltd. With a little bit of research, he discovered that this company produced digital rights management software for Sony BMG.

Latest Videos FromTom's Hardware