vdo_307c-6968.sys rootkit

This is a beautiful rootkit that is extremely evasive. I have tried using AVG’s anti-rootkit software to no avail.

I will keep this post updated as soon as I figure something out.

I ended up removing the rootkit with this program: http://rku.nm.ru/rkunhooker_v3/RkU3.7.300.502.zip

Use it at your own risk!  I just did a scan, found the offending file, click on unhook selected (there were a few files) and once that was done, I went into the C:\Windows\system32 directory and deleted the file.  I ran the AVG anti-rootkit and it didn’t find anything so I think it’s safe to say I got rid of it.

Comments are closed.