Just ran into this little nasty here at work that is resisting all efforts to remove it. The file is located in the Windows/System 32 folder and goes by the name dgockd.dll.
I first tried to boot to a live CD, namely Ultimate Boot CD 4, and delete the little bugger. Access denied !!??!!??? Whaaa ... ???
OK, so that's a first. Any live CD is able to remove ANY file from the boot drive, so now I'm stuck. I tried changing the file attributes from a CMD window, but its locked on a system level, not a file permission level, so its hooked into something, either winlogon.exe or explorer.exe at this point.
I then booted into Windows Safe Mode to take a look at the file using ProcessExplorer, and it appears to be polymorphic, as the file by that name above is now gone from the PC.
Running MalwareBytes in Safe Mode right now, but if that doesn't fix it, we nuke it from orbit and wipe it out. Rootkits are the worst of the worst, and its debatable whether you can even 100% guarantee that a PC will be clean after you have dealt with the rootkit.
I have only dealt with a handful of rootkits myself, but I'm curious to see what you guys have run into in your PC repair travels.
I first tried to boot to a live CD, namely Ultimate Boot CD 4, and delete the little bugger. Access denied !!??!!??? Whaaa ... ???
OK, so that's a first. Any live CD is able to remove ANY file from the boot drive, so now I'm stuck. I tried changing the file attributes from a CMD window, but its locked on a system level, not a file permission level, so its hooked into something, either winlogon.exe or explorer.exe at this point.
I then booted into Windows Safe Mode to take a look at the file using ProcessExplorer, and it appears to be polymorphic, as the file by that name above is now gone from the PC.
Running MalwareBytes in Safe Mode right now, but if that doesn't fix it, we nuke it from orbit and wipe it out. Rootkits are the worst of the worst, and its debatable whether you can even 100% guarantee that a PC will be clean after you have dealt with the rootkit.
I have only dealt with a handful of rootkits myself, but I'm curious to see what you guys have run into in your PC repair travels.
Comment