EmailEmail
PrintPrint
Worry Watch: Compact discs are playing with fire
Saturday, November 26, 2005

 
 

WEEKLY REPORTS

Security updates

Top 10 Threats

   
 

Last year, in an attempt to thwart illegal duplication, Sony BMG began protecting some music CDs by including extended copyright protection (XCP) software that downloads when the CD runs on a computer.

Once the software downloads onto your system it prevents you from making more than two copies of the CD. Upon closer inspection of the program, experts have discovered that it buries itself deep into your Windows system and uses a cloaking tool, making it invisible to both the user and anti-virus programs. Detected on over half a million networks in 165 countries, this Sony backdoor has already been taken advantage of by computer threats -- like the Stinx.E Trojan -- hiding themselves in Sony's cloaking program.

Uninstalling the XCP software yourself could lead to the deletion of important software connected to your CD-ROM and could cause your system to crash. Some anti-virus companies also warn against using the patch released by Sony since it may leave an even bigger security hole on your system. Plus, the CD that you paid for still won't be playable on your PC.

Sony has released a complete list of CDs that include the XCP software. Since Sony plans to re-release these titles without the software, be sure to compare the item number listed with the item number that appears on the spine of your CD.

 

Artist

Title

Item Number

UPC code

1.

A Static Lullaby

Faso Latido

CK92772

827969277225

2.

Acceptance

Phantoms

CK89016

696998901629

3.

Amerie

Touch

CK90763

827969076323

4.

Art Blakey

Drum Suit

CK93637

827969363720

5.

The Bad Plus

Suspicious Activity?

CK94740

827969474020

6.

Bette Midler

Sings the Peggy Lee Songbook

CK95107
CK74815

827969510728
828767481524

7.

Billy Holiday

The Great American Songbook

CK94294

827969429426

8.

Bob Brookmeyer

Bob Brookmeyer & Friends

CK94292

827969429228

9.

Buddy Jewell

Times Like These

CK92873

827969287323

10.

Burt Bacharach

At This Time

CK97734

827969773420

11.

Celine Dion

On Ne Change Pas

E2K97736

827969773628

12.

Chayanne

Cautivo

LAK96819
LAK96818
LAK95886

037629681921
037629681822
037629588626

13.

Chris Botti

To Love Again

CK94823

827969482322

14.

The Coral

The Invisible Invasion

CK94747

827969474723

15.

Cyndi Lauper

The Body Acoustic

EK94569

827969456927

16.

The Dead 60's

The Dead 60's

EK94453

827969445327

17.

Deniece Williams

This Is Niecy

CK93814

827969381427

18.

Dextor Gordon

Manhattan Symphonie

CK93581

827969358122

19.

Dion

The Essential Dion

CK92670

827969267028

20.

Earl Scruggs

I Saw The Light With Some Help From My Friends

CK92793

827969279328

21.

Elkland

Golden

CK92036

827969203620

22.

Emma Roberts

Unfabulous And More: Emma Roberts

CK93950
CK97684

827969395028
827969768426

23.

Flatt & Scruggs

Foggy Mountain Jamboree

CK92801

827969280126

24.

Frank Sinatra

The Great American Songbook

CK94291

827969429129

25.

G3

Live In Tokyo

E2K97685

827969768525

26.

George Jones

My Very Special Guests

E2K92562

827969256220

27.

Gerry Mulligan

Jeru

CK65498

074646549827

28.

Horace Silver

Silver's Blue

CK93856

827969385623

29.

Jane Monheit

The Season

EK97721

827969772126

30.

Jon Randall

Walking Among The Living

EK92083

827969208328

31.

Life Of Agony

Broken Valley

EK93515

827969351529

32.

Louis Armstrong

The Great American Songbook

CK94295

827969429525

33.

Mary Mary

Mary Mary

CK94812
CK92948

000768353721
827969294826

34.

Montgomery Gentry

Something To Be Proud Of: The Best of 1999-2005

CK75324
CK94982

828767532424
827969498224

35.

Natasha Bedingfield

Unwritten

EK93988

827969398821

36.

Neil Diamond

12 Songs

CK94776
CK97811

827969477625
827969781128

37.

Nivea

Complicated

82876671562

828766715620

38.

Our Lady Peace

Healthy In Paranoid Times

CK94777

827969477724

39.

Patty Loveless

Dreamin' My Dreams

EK94481

827969448120

40.

Pete Seeger

The Essential Pete Seeger

CK92835

827969283523

41.

Ray Charles

Friendship

CK94564

827969456422

42.

Rosanne Cash

Interiors  

CK93655

827969365526

43.

Rosanne Cash

King's Record Shop

CK86994

696998699427

44.

Rosanne Cash

Seven Year Ache

CK86997

696998699724

45.

Shel Silverstein

The Best Of Shel Silverstein

CK94722

827969472224

46.

Shelly Fairchild

Ride

CK90355

827969035528

47.

Susie Suh

Susie Suh

EK92443

827969244326

48.

Switchfoot

Nothing Is Sound

CK96534
CK96437
CK94581

827969653425
827969643723
827969458129

49.

Teena Marie

Robbery

EK93817

827969381724

50.

Trey Anastacio

Shine

CK96428

827969642825

51.

Van Zant

Get Right With The Man

CK93500

827969350027

52.

Vivian Green

Vivian

CK90761

827969076125


Worry Watch Plus Online only:

Information, Protection and Prevention -- More about XCP, Sony, and the threats that exploit them
Sophos' Stinx.E information

US-Cert's suggestions for handling XCP

Panda Software's XCP definition

Doxpara's XCP research

Sony's FAQ about XCP


Latest Security Updates:

Anti-Spyware Product

Latest update

Find Downloads

Ad-Aware SE

SE1R75 15.11.2005 (Definitions updated November 15, 2005)

Download site

Spybot Search and Destroy

Version 1.4 (Definitions updated November 11, 2005)

Download site

Go back

* Reading: Solutions, Prevention & Remedies
Additional summary information related to a specific type of solution or prevention that you should be considering. Depending upon the week, this section may have:
• Recent Windows security releases from Microsoft
• Recent updates to widely used anti-spyware programs
• Recent updates to widely used anti-virus programs
• Recent updates to other security programs & devices (ex: Firewalls, routers)
• Recent updates to various applications in wide use


Top 10 Threats:

Name

Type

Affects

Alert Level

Sdbot.ftp

Worm

Windows 95, 98, 2000, ME, NT, XP

Medium

Netsky.P

Worm

Windows 95, 98, 2000, ME, NT, XP*

Severe

Gaobot.gen

Worm

Windows 2000, NT, XP*

Medium

Qhost.gen

Trojan

Windows 2000, NT, XP*

Low

Mitglieder.FK

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Mhtredir.gen

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Low

Netsky.D

Worm

Windows 95, 98, 2000, ME, NT, XP*

Low

Alcan.worm

Worm

Windows 95, 98, 2000, ME, NT, XP

Low

Parite.B 

Virus

Windows 95, 98, 2000, ME, NT, XP*

Low

Mitglieder.FO

Trojan

Windows 95, 98, 2000, ME, NT, XP*

Medium

Go back

Read: Top Threats
These are viruses that are currently on the watch lists of major anti-virus software companies.

Name
What the threat is called. We use the name given each virus by Panda Software. Sometimes other anti-virus companies give the same threat a different name. Usually they use similar names.

Type
There are different characteristics associated with different types of threats.
• Virus - has the ability to replicate or infect computers or other programs
• Trojan Horse (or Trojan) - appear to be harmless programs when you get them. They unleash their payload when you double-click, open, or execute them.
• Phishing - a Web site or e-maill message posing as another company - usually one you know to fool you into giving the sender personal information.
• Worm - self replicates onto additional disks, computers or networks
• Spyware - installs on your system to collect information about your activity, preferences or interests
• Hoax - false messages sent by e-maill to mislead the recipient
• Backdoors - opens a security hole that allows outsiders to take control of your computer
• Dialer - uses your telephone to dial an outside number - sometimes a number that costs you money when dialed

Affects
Not all viruses affect all types of systems. Some, for example may affect only Windows 98 and 95, but not Windows XP or NT. Others affect all Windows systems, but not Macintosh. In this column, we show you the consumer systems that the threat is known to affect. We don't always include the servers that operate in your company's backroom.

Alert level
The level of awareness that anti-virus vendors suggest you need to have for each threat listed.
For each threat listed, we'll post a corresponding link here, so you can get more information to help you recognize, diagnose, prevent, and repair the problem.

First published on November 26, 2005 at 12:00 am
Worry Watch is compiled by David Radin & Jes Scherder using data and reports from Microsoft, CERT, Panda, and other sources. To contact the compilers of Worry Watch, go to http://www.megabyteminute.com/contactdavid.html.