XCP.Sony.Rootkit is one way for Sony to reach its goal to control the ripping and distribution of music. XCP.Sony.Rootkit installs a DRM executable as a Windows service, but employs a technique commonly used by malware authors to fool everyday users into believing this is a part of Windows. This service very frequently queries the primary executables associated with all processes running on the machine, resulting in nearly continuous read attempts on the hard drive, which has been shown to shorten the drive’s lifespan.
XCP.Sony.Rootkit loads a system filter driver which hijacks all calls for process, directory or registry listings, even those unrelated to the Sony BMG application. This rootkit driver modifies what information is visible to the operating system in order to cloak the Sony BMG software. This rootkit hides every file, process, or registry key beginning with $sys$. This represents a vulnerability, which has already been exploited to hide World of Warcraft RING0 hacks, and could potentially hide an attacker’s files and processes once access to an infected system had been gained.
How to Get Rid of XCP.Sony.Rootkit?
There are several ways to detect and remove XCP.Sony.Rootkit. The method you choose should be based on your own comfort and computer skill level. You can evaluate the methods below and choose which suits you best. Learn more on XCP.Sony.Rootkit Manual Removal Instructions.
