Saturday, August 04, 2007

Navipromo reloaded!

Came across a new variant of Navipromo rootkit, which is almost undetected. Only CAT-QuickHeal was able to flag the file, that too heuristically. Navipromo hooks APIs in Ntdll.dll to hide its presence. More information about this new variant can be found here. However, Navilog1 tool can remove this infection.


Post a Comment

<< Home