Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software
photo of Mary Landesman

Mary's Antivirus Software Blog

By Mary Landesman, About.com Guide to Antivirus Software since 2000

Trojan Exploiting Sony Rootkit Flawed

Thursday November 10, 2005
It seems the newly discovered Stinx.E Trojan is as buggy as the Sony rootkit it attempts to exploit. The question being asked by some security professionals is whether these are indeed flaws, or whether it's a deliberate attempt by the Trojan author to bring attention to the Sony rootkit problem while avoiding harming users.

The Sony rootkit, developed by First 4 Internet, contains a design flaw that allows any specially named file to be enveloped by the rootkit, thereby masking its presence on the system.

The first Trojan to exploit this flaw, Stinx.E, doesn't properly decrypt the registry keys needed to allow the Trojan to load when Windows is restarted. The Stinx.E Trojan also fails to load if the Sony DRM cloaking technology is active, despite its deliberate attempts to exploit it. Additionally, the IP addresses used to connect to the IRC server are invalid. In effect, the Sony Stinx Trojan is impotent.

Also see:

Comments

No comments yet. Leave a Comment

Leave a Comment

Line and paragraph breaks are automatic. Some HTML allowed: <a href="" title="">, <b>, <i>, <strike>

Discuss

Community Forum

Explore Antivirus Software

About.com Special Features

Build Your Own Website

Step-by-step advice on how to do everything from choosing a Web host to promoting your content. More >

Connect Your Home Computers

Easy ways to connect two computers for networking purposes. More >

Antivirus Software

  1. Home
  2. Computing & Technology
  3. Antivirus Software

©2009 About.com, a part of The New York Times Company.

All rights reserved.