| View previous topic :: View next topic |
| Author |
Message |
sam1980
Cadet

 Joined: Oct 09, 2005 Posts: 1 Location: USA
|
Posted: Sun Oct 09, 2005 10:48 pm Post subject: |
|
|
The drivers & services you are seeing are a "trojan" copy protection. This can be disabled so you can copy your Audio CD, removing everything is a pain and I couldn't begin to tell you how to do that.
As was posted on CD Freaks this week: http://club.cdfreaks.com/showthread.php?t=151461
How to remove CDS-300 (MacroVision) & XCP (First 4 Internet) Drivers
--------------------------------------------------------------------------------
It's very sad how greedy record companies are now using these "trojan" based copy protections to stop you from copying your Audio CDs and preventing freedom w/ iPod etc.. Like Alex Halderman proved nothing is 100%.
I know all you CD Freaks know how to disable the MediaMax drivers. The purpose of these instructions is meant to disable the other (less known) trojans being used on Audio CDs.
As always if autorun is turned off there is no need for these instructions, however when it isn't - these drivers will infect your PC and then you need to either reformat or simply remove them as stated below:
HOW TO REMOVE CD AUDIO PROTECTION DRIVERS FROM PC
CDS-300 (MacroVision) http://www.macrovision.com
How to identify: There will be a directory in the root called “CDS300” and multiple files with “CDS” in the name.
Win98/ME: No protection
Win XP/2K: On windows partition (where Windows is installed default is C:/ drive) search for file called “sdcplh.sys” and delete it. You must restart the computer & now copy protection is now permanently disabled.
The default path is C:\WINDOWS\system32\drivers
XCP2 (First 4 Internet) http://www.xcp-aurora.com/
How to identify: There will be a file called “VERSION.DAT” if this is opened with Note Pad it will say something like “VERSION=XCP2, Version 1.7”
Win98/ME/2K & XP
Step 1. Press F8 during startup to boot into safe mode.
Step 2: On windows partition (where Windows is installed default is C:/ drive) Search for a file called “$sys$caj.dll” and delete it.
The default path is C:\WINDOWS\system32\$sys$caj.dll
Step 2: Reboot PC and go to “Device Manager” and uninstall all CD/DVD drives and then rescan for hardware changes.
Now the XCP protection is permanently disabled.
If you are looking for info on SunnComm's MediaMax CD3 see: http://www.cs.princeton.edu/~jhalderm/cd3/
|
|
| Back to top |
|
 |
kerashi
Cadet

 Joined: Nov 01, 2005 Posts: 1 Location: USA
|
|
| Back to top |
|
 |
wng_z3r0
MRU Teacher
 Joined: Mar 21, 2005 Posts: 1248
|
Posted: Wed Nov 02, 2005 5:40 am Post subject: |
|
|
That blog also tells you how to get your Cd drive back... _________________ Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
|
|
| Back to top |
|
 |
wawadave
Special Response Team Special Response Team
 Joined: Nov 22, 2002 Posts: 21503 Location: Installing Vista http://tinyurl.com/2l9qyd
|
|
| Back to top |
|
 |
MINz
Cadet

 Joined: Nov 16, 2005 Posts: 2 Location: USA
|
Posted: Wed Nov 16, 2005 4:20 pm Post subject: |
|
|
If you still need to remove this infection let me know and I'll post the instructions. I have most of the removal automated via batch files, but there are a few registry keys that need manually deleted.
MINz
|
|
| Back to top |
|
 |
jgk4cfc
Cadet

 Joined: Aug 12, 2005 Posts: 4 Location: USA
|
Posted: Wed Nov 16, 2005 7:27 pm Post subject: Missed my 15 minutes of fame :-{ |
|
|
I guess I missed my opportunity to make big news back in August when I first surfaced this...have you seen all the press that Mark Russinovich from SysInternals has gotten for making this public on his blog? (http://www.sysinternals.com/Blog/2005/11/victory.html)
Well, Mark put more time and more skill (yeah, a lot!) than I did or could have, but, it is sort of weird to feel like I did the initial detective work.
I must admit, I used several of the SysInternals tools (RootKitRevealer, Process Explorer, AutoRuns) in my early diagnostics of the problem. It was really RKR that uncovered the hidden directory.
Some related stories
- http://www.cnet.com/4520-6033_1-6376177.html
- http://www.theregister.co.uk/2005/11/15/sony_bmg_bodycount/
- http://www.infoworld.com/article/05/11/04/HNsonydrm_1.html
- http://www.eweek.com/article2/0,1895,1880543,00.asp?login=1&r=0
and there's lots more.
Cheers!
JGK
=============
"Blue is the color, Chelsea is the name!"
ChelseaFC - 1955, 2005 EPL Champs
Is 2006 our year in Europe?
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
Paul
CastleCops Founder
 Joined: Feb 22, 2002 Posts: 27351
|
|
| Back to top |
|
 |
IP: 82.35.*.*
Guest
|
Posted: Wed Jun 28, 2006 10:15 pm Post subject: Re: Rootkits = bad news |
|
|
| TelepathyCrimewave wrote: | Kav probably wont help if those are genuine rootkits.
If those are actually rootkits you wont like the news. From all available sources on the subject if there arent specific removal instructions for your specific rootkits or their variants, you may be looking at a reformat. Try Blacklight Beta as it at least allows you to try and rename the files in question if it finds what Rootkit Revealer did.
I'm looking at a nasty right now that was laying dormant on my C drive for god knows how long, glitches and ghost processes spooked me enough to investigate further until i found it. Both RR and BB both found it and there is no news on the net at all about it (sccfg.sys) and have yet to remove it. Everytime i rename it in BB and reboot the original file is recreated. Being that its hidden from the API i cant simply DEL C:\sccfg.sys either because it of course isnt seen by Windows. I even found the hook.log file in the C drive with no real evidence inside to locate anyhing else but i thought that was a bit brash on the part of the intruder. I'll probably be reformatting soon and when i do ill be sure to have many more security layers in place. IE: Primary Response, Diamond CS ProcessGuard, System Sentry, Zone Alarm Suite and AntiVirusKit, 1st Security Agent, and of course my trusty NetGear router; all of that coupled with ridiculously paranoid system settings, and that should ward off the biggest salvo of next generation nasties. |
|
|
| Back to top |
|
 |
IP: 144.134.*.*
Guest
|
Posted: Sun Aug 06, 2006 12:27 pm Post subject: Re: Rootkits = bad news |
|
|
| TelepathyCrimewave wrote: | Kav probably wont help if those are genuine rootkits.
If those are actually rootkits you wont like the news. From all available sources on the subject if there arent specific removal instructions for your specific rootkits or their variants, you may be looking at a reformat. Try Blacklight Beta as it at least allows you to try and rename the files in question if it finds what Rootkit Revealer did.
I'm looking at a nasty right now that was laying dormant on my C drive for god knows how long, glitches and ghost processes spooked me enough to investigate further until i found it. Both RR and BB both found it and there is no news on the net at all about it (sccfg.sys) and have yet to remove it. Everytime i rename it in BB and reboot the original file is recreated. Being that its hidden from the API i cant simply DEL C:\sccfg.sys either because it of course isnt seen by Windows. I even found the hook.log file in the C drive with no real evidence inside to locate anyhing else but i thought that was a bit brash on the part of the intruder. I'll probably be reformatting soon and when i do ill be sure to have many more security layers in place. IE: Primary Response, Diamond CS ProcessGuard, System Sentry, Zone Alarm Suite and AntiVirusKit, 1st Security Agent, and of course my trusty NetGear router; all of that coupled with ridiculously paranoid system settings, and that should ward off the biggest salvo of next generation nasties. |
I gave U similar details for this bug and removal of it 3 times...but stuppid image ver cleared it..im not writting it again..grr
|
|
| Back to top |
|
 |
KEPierre Currently banned Trooper

 Joined: Aug 22, 2006 Posts: 17 Location: USA
|
Posted: Tue Aug 22, 2006 4:05 pm Post subject: |
|
|
[spammer banned by Paul ]
|
|
| Back to top |
|
 |
SCCFG.SYS Cure
Guest IP: 216.194.*.*
|
Posted: Sun Jun 10, 2007 2:00 pm Post subject: Use AVG Anti-Rootkit |
|
|
To permanently remove sccfg.sys use AVG Anti-Rootkit , it is free and works perfectly ! When it asks you if you want to remove this file , just say yes . Your computer will be back to normal in no time , trust me , IT WORKS ! Heres a link to it : http://free.grisoft.com/doc/avg-anti-rootkit-free/lng/us/tpl/v5 
|
|
| Back to top |
|
 |
|
|