The aries.sys driver in Sony First4Internet XCP DRM software hides any file, registry key, or process with a name that starts with "$sys$", which allows attackers to hide activities on a system that uses XCP.
Link | Tags |
---|---|
http://www.osvdb.org/20435 | vdb entry |
http://secunia.com/advisories/17408 | third party advisory vendor advisory |
http://securitytracker.com/id?1015145 | vdb entry |
http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html |