How can I get rid of $sys$DRMServer.exe

Can anyone tell me how to get rid of this Sony DRM Root Kit that leaves a service named $sys$DRMServer.exe running.  
alan_hornAsked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

johnb6767Commented:
MG| Free Download - GMER 1.0.12.12086
http://www.majorgeeks.com/GMER_d5198.html

Sophos Anti-Rootkit
http://www.sophos.com/products/free-tools/sophos-anti-rootkit.html

Try these 2....
0
johnb6767Commented:
Malicious Software Removal Tool
http://www.microsoft.com/security/malwareremove/default.mspx

MS's tool is supposed to be updated soon to remove this, but I dont know if it has been released to do this yet....Might check Window Updates....

Netcraft: Microsoft Update Will Remove Sony DRM Rootkits
http://news.netcraft.com/archives/2005/11/13/microsoft_update_will_remove_sony_drm_rootkit.html
0
TolomirAdministratorCommented:
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
Acronis True Image 2019 just released!

Create a reliable backup. Make sure you always have dependable copies of your data so you can restore your entire system or individual files.

rpggamergirlCommented:
I second Tolomir's good advice. Removing Sony rootkit properly is important so as not to screw up your drive.

Grinler has an in-depth tutorial about Sony DRM rootkit:
http://www.bleepingcomputer.com/forums/topic34904.html

If the Sony rootkit service is now showing(also shows in hijackthis log) then the rootkit is no longer active.
O23 - Service: Plug and Play Device Manager ($sys$DRMServer) - First 4 Internet Ltd - C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe

The rootkit hides all files and services that start with $sys$. So If "$sys$DRMServer.exe" service is showing that means that the rootkit is no longer active and its okay to leave it installed.

Or: you could delete the service:
Start > Run > type in
cmd
press Enter, and run these commands and press Enter after each:
sc stop $sys$DRMServer
sc delete $sys$DRMServer

then make sure to delete the file it's pointing to --> C:\WINDOWS\system32\$sys$filesystem\$sys$DRMServer.exe
0
TolomirAdministratorCommented:
If you are in the U.S. you can even get a DRM free CD from your dealer. Just exchange the DRM protected one.

http://www.theinternetpatrol.com/instructions-for-exchanging-your-sony-bmg-cds-with-rootkit-for-safe-cds
Summary: Instructions for exchanging Sony BMG CDs with XCP for Sony BMG CDs without the Rootkit

This is also interesting: http://sonybmg.com/copy_protection_settlement2.html

Tolomir
0
TolomirAdministratorCommented:
Thank you.

Tolomir
0
alan_hornAuthor Commented:
Exactly what I needed,  Thank You
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows XP

From novice to tech pro — start learning today.