1) This is rootkit driver which come packaged in malware. Main reason of this malware is to destroy AV which cannot be finished from user mode usually. When Rootkit.Indag.A gets loaded on PC then it registers as device in name \\Device\\GanDiao. Now user mode application able to utilize this driver to destroy any process.



Reply With Quote

Copyright Techfuels
Bookmarks