A small generic rootkit driver can be bundled in any malware. Its purpose is to kill any antivirus that cant be killed in user-mode (that have a self-protection driver) The rootkit is a driver, which is loaded as a device under the name GanDiao Any user mode application can kill any process when this driver is loaded. It will launch Global.exe every time the drive Is accessed, if the autorun feature is enabled.”]
Source: https://www.bitdefender.com/blog/hotforsecurity/bitdefender-weekly-review-msn-spreading-batch-worm/