CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 949
Comments: 28
block bottom
spacer spacer

Hidden files and directories - DRM or trojan?
Goto page Previous  1, 2
 
Post new topic   Reply to topic       All -> FavForums -> Security [del.icio.us!] [digg it!] [reddit!]
View previous topic :: View next topic  
Author Message
sam1980

Cadet
Cadet


Joined: Oct 09, 2005
Posts: 1
Location: USA

PostPosted: Sun Oct 09, 2005 10:48 pm    Post subject:
Reply with quote

The drivers & services you are seeing are a "trojan" copy protection. This can be disabled so you can copy your Audio CD, removing everything is a pain and I couldn't begin to tell you how to do that.

As was posted on CD Freaks this week: http://club.cdfreaks.com/showthread.php?t=151461

How to remove CDS-300 (MacroVision) & XCP (First 4 Internet) Drivers

--------------------------------------------------------------------------------

It's very sad how greedy record companies are now using these "trojan" based copy protections to stop you from copying your Audio CDs and preventing freedom w/ iPod etc.. Like Alex Halderman proved nothing is 100%.

I know all you CD Freaks know how to disable the MediaMax drivers. The purpose of these instructions is meant to disable the other (less known) trojans being used on Audio CDs.

As always if autorun is turned off there is no need for these instructions, however when it isn't - these drivers will infect your PC and then you need to either reformat or simply remove them as stated below:

HOW TO REMOVE CD AUDIO PROTECTION DRIVERS FROM PC

CDS-300 (MacroVision) http://www.macrovision.com

How to identify: There will be a directory in the root called “CDS300” and multiple files with “CDS” in the name.

Win98/ME: No protection

Win XP/2K: On windows partition (where Windows is installed default is C:/ drive) search for file called “sdcplh.sys” and delete it. You must restart the computer & now copy protection is now permanently disabled.

The default path is C:\WINDOWS\system32\drivers

XCP2 (First 4 Internet) http://www.xcp-aurora.com/

How to identify: There will be a file called “VERSION.DAT” if this is opened with Note Pad it will say something like “VERSION=XCP2, Version 1.7”

Win98/ME/2K & XP

Step 1. Press F8 during startup to boot into safe mode.

Step 2: On windows partition (where Windows is installed default is C:/ drive) Search for a file called “$sys$caj.dll” and delete it.

The default path is C:\WINDOWS\system32\$sys$caj.dll

Step 2: Reboot PC and go to “Device Manager” and uninstall all CD/DVD drives and then rescan for hardware changes.

Now the XCP protection is permanently disabled.

If you are looking for info on SunnComm's MediaMax CD3 see: http://www.cs.princeton.edu/~jhalderm/cd3/

Back to top
View users profile Send private message
kerashi

Cadet
Cadet


Joined: Nov 01, 2005
Posts: 1
Location: USA

PostPosted: Tue Nov 01, 2005 5:07 am    Post subject:
Reply with quote

This was just posted on SysInternals and Slashdotted in case anyone missed it.

http://www.sysinternals.com/blog/2005/10/sony-rootkits-and-digital-rights.html

This is indeed a rootkit installed as DRM software from Sony. Further details in the article.

Back to top
View users profile Send private message
wng_z3r0

MRU Teacher


Joined: Mar 21, 2005
Posts: 1248

1st Responders MVP RootKit Detection Hosts Rootkit Experts Team F@H

PostPosted: Wed Nov 02, 2005 5:40 am    Post subject:
Reply with quote

That blog also tells you how to get your Cd drive back...


_________________
Proud member of Alliance of Security Analysis Professionals since 2005
Microsoft MVP-2006
Back to top
View users profile Send private message Visit posters website
wawadave

Special Response Team
Special Response Team

Joined: Nov 22, 2002
Posts: 21503
Location: Installing Vista http://tinyurl.com/2l9qyd
Premium RootKit Detection Hosts Rootkit Responders SRT

PostPosted: Wed Nov 02, 2005 6:07 pm    Post subject:
Reply with quote

hello read these links on this
http://www.sysinternals.com/Blog/
http://blogs.guardian.co.uk/technology/archives/2005/11/01/sony_rootkits_and_drm_gone_too_far.html
http://www.theregister.co.uk/2005/11/01/sony_rootkit_drm/
CastleCops Link/t137305-Safemode_rootkit_amp_DRM.html
http://carmainc.org/forums/index.php?showtopic=4064&st=0&p=2280181&#entry2280181


_________________
Brycetechs new tut dvd http://tinyurl.com/2u7rpk
The Pixel Palladium
Bryce Newby help and tuts, d/l,s How 2s Updated 18 Apr 2008
Back to top
View users profile Send private message Send email Visit posters website
MINz

Cadet
Cadet


Joined: Nov 16, 2005
Posts: 2
Location: USA

PostPosted: Wed Nov 16, 2005 4:20 pm    Post subject:
Reply with quote

If you still need to remove this infection let me know and I'll post the instructions. I have most of the removal automated via batch files, but there are a few registry keys that need manually deleted.

MINz

Back to top
View users profile Send private message
jgk4cfc

Cadet
Cadet


Joined: Aug 12, 2005
Posts: 4
Location: USA

PostPosted: Wed Nov 16, 2005 7:27 pm    Post subject: Missed my 15 minutes of fame :-{
Reply with quote

I guess I missed my opportunity to make big news back in August when I first surfaced this...have you seen all the press that Mark Russinovich from SysInternals has gotten for making this public on his blog? (http://www.sysinternals.com/Blog/2005/11/victory.html)
Confused
Well, Mark put more time and more skill (yeah, a lot!) than I did or could have, but, it is sort of weird to feel like I did the initial detective work.

I must admit, I used several of the SysInternals tools (RootKitRevealer, Process Explorer, AutoRuns) in my early diagnostics of the problem. It was really RKR that uncovered the hidden directory.

Some related stories
- http://www.cnet.com/4520-6033_1-6376177.html
- http://www.theregister.co.uk/2005/11/15/sony_bmg_bodycount/
- http://www.infoworld.com/article/05/11/04/HNsonydrm_1.html
- http://www.eweek.com/article2/0,1895,1880543,00.asp?login=1&r=0
and there's lots more.

Cheers!

JGK

=============
"Blue is the color, Chelsea is the name!"
ChelseaFC - 1955, 2005 EPL Champs
Is 2006 our year in Europe?

Back to top
View users profile Send private message
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Wed Nov 16, 2005 7:53 pm    Post subject:
Reply with quote

@jgk4cfc I did notice kudos to you thanks to this thread on several locations out there. So there is a movement in recognizing your initial work. Gold Cup


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
Paul

CastleCops Founder


Joined: Feb 22, 2002
Posts: 27351

Administrators Firetrust Forums Admin MIRT Moderators MVP Phishing Squad Premium Team CC Committee

PostPosted: Tue Nov 22, 2005 1:27 am    Post subject:
Reply with quote

@jgk4cfc, Bruce Schneier has linked to the story. Although both links point to this second page, here is the link to the work you did on page one for readers before Russinovich posted about it:

CastleCops Link/postx130470-0-0.html


_________________
Paul Laudanski - http://www.laudanski.com
http://www.linkedin.com/pub/1/49a/17b
Back to top
View users profile Send private message Send email Visit posters website
IP: 82.35.*.*

Guest






PostPosted: Wed Jun 28, 2006 10:15 pm    Post subject: Re: Rootkits = bad news
Reply with quote

TelepathyCrimewave wrote:
Kav probably wont help if those are genuine rootkits.
If those are actually rootkits you wont like the news. From all available sources on the subject if there arent specific removal instructions for your specific rootkits or their variants, you may be looking at a reformat. Try Blacklight Beta as it at least allows you to try and rename the files in question if it finds what Rootkit Revealer did.

I'm looking at a nasty right now that was laying dormant on my C drive for god knows how long, glitches and ghost processes spooked me enough to investigate further until i found it. Both RR and BB both found it and there is no news on the net at all about it (sccfg.sys) and have yet to remove it. Everytime i rename it in BB and reboot the original file is recreated. Being that its hidden from the API i cant simply DEL C:\sccfg.sys either because it of course isnt seen by Windows. I even found the hook.log file in the C drive with no real evidence inside to locate anyhing else but i thought that was a bit brash on the part of the intruder. I'll probably be reformatting soon and when i do ill be sure to have many more security layers in place. IE: Primary Response, Diamond CS ProcessGuard, System Sentry, Zone Alarm Suite and AntiVirusKit, 1st Security Agent, and of course my trusty NetGear router; all of that coupled with ridiculously paranoid system settings, and that should ward off the biggest salvo of next generation nasties.

Back to top
IP: 144.134.*.*

Guest






PostPosted: Sun Aug 06, 2006 12:27 pm    Post subject: Re: Rootkits = bad news
Reply with quote

TelepathyCrimewave wrote:
Kav probably wont help if those are genuine rootkits.
If those are actually rootkits you wont like the news. From all available sources on the subject if there arent specific removal instructions for your specific rootkits or their variants, you may be looking at a reformat. Try Blacklight Beta as it at least allows you to try and rename the files in question if it finds what Rootkit Revealer did.

I'm looking at a nasty right now that was laying dormant on my C drive for god knows how long, glitches and ghost processes spooked me enough to investigate further until i found it. Both RR and BB both found it and there is no news on the net at all about it (sccfg.sys) and have yet to remove it. Everytime i rename it in BB and reboot the original file is recreated. Being that its hidden from the API i cant simply DEL C:\sccfg.sys either because it of course isnt seen by Windows. I even found the hook.log file in the C drive with no real evidence inside to locate anyhing else but i thought that was a bit brash on the part of the intruder. I'll probably be reformatting soon and when i do ill be sure to have many more security layers in place. IE: Primary Response, Diamond CS ProcessGuard, System Sentry, Zone Alarm Suite and AntiVirusKit, 1st Security Agent, and of course my trusty NetGear router; all of that coupled with ridiculously paranoid system settings, and that should ward off the biggest salvo of next generation nasties.

I gave U similar details for this bug and removal of it 3 times...but stuppid image ver cleared it..im not writting it again..grr

Back to top
KEPierre
Currently banned

Trooper
Trooper


Joined: Aug 22, 2006
Posts: 17
Location: USA

PostPosted: Tue Aug 22, 2006 4:05 pm    Post subject:
Reply with quote

[spammer banned by Paul ]

Back to top
View users profile Send private message
SCCFG.SYS Cure

Guest
IP: 216.194.*.*






PostPosted: Sun Jun 10, 2007 2:00 pm    Post subject: Use AVG Anti-Rootkit
Reply with quote

To permanently remove sccfg.sys use AVG Anti-Rootkit , it is free and works perfectly ! When it asks you if you want to remove this file , just say yes . Your computer will be back to normal in no time , trust me , IT WORKS ! Heres a link to it : http://free.grisoft.com/doc/avg-anti-rootkit-free/lng/us/tpl/v5 Very Happy

Back to top
Display posts from previous:   
Post new topic   Reply to topic       All -> FavForums -> Security All times are GMT
Goto page Previous  1, 2
Page 2 of 2

 
Quick Reply:
Username: 

Quote the last message
Attach signature (signatures can be changed in profile)
 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum
You cannot attach files in this forum
You can download files in this forum


Powered by phpBB © 2001 phpBB Group
spacer spacer