March 20, 2010

2/16: NTRootkit-AB a .SYS File That Terminates Antivirus Processes

NTRootkit-AB is a .SYS file that installs as a device driver that attempts to terminate antivirus processes.

The rootkit is primarily dropped by W32/Sality.ae parasite file infector.

More information can be found at this McAfee page.

1
IT Offers

Partners