This is how InternetGameBox client looks like:

Here's a screen shot of hidden process:

Files and Registry keys hidden by Navipromo:


Surprisingly, the hidden executable is barely detected by AVs. Here's a screen shot of Virus.org Malware Scanner showing the scan result of the executable. It can be seen that only ArcaVir was able to detect it heuristically:

InternetGameBox' Navipromo rootkit can be completely removed using the Navilog1 tool. A tutorial to use the Navilog1 tool to remove Navipromo can be found at CastleCops Wiki.
0 comments:
Post a Comment