• About Us
  • Search
  • Compatibility
  • Forums
  • Archive
  • Channels
  • Home
To take full advantage of all features you need to login or register. Registration is completely free and takes only a few seconds.
Warp2Search.net » News » November 2007 » Gromozon Rootkit Removal Tool

Gromozon Rootkit Removal Tool

Posted by: Tim Tibbetts on: 11/07/2007 05:50 PM [ Print | 0 comment(s) ] · 2138 views

Remove Gromozon, an attack designed to bypass traditional anti-malware tools.



What is Gromozon and how did it manage to bypass my current security tools?

Unfortunately Gromozon is not a single infection, but a blended attack designed to bypass traditional anti-malware tools. The end result meaning that the machine is not only infected by several well known Trojans but also a highly dangerous Rootkit. Traditional AV vendors are at the moment dealing with the known infections but overlooking the rootkit.

The path of infection is thus:

• On visiting an infected website an obfuscated JavaScript is run.

• The user is forwarded to another site which contains a further obfuscated JavaScript. This connects to a network of websites which are used to launch the infection routine. These websites are constantly changing and since May 2006 have become considerably more numerous

• A server side script is run to analyse the user agent (web browser) under which the user is visiting. Different attack methods are then launched depending on whether the user is running Opera, Firefox or Internet Explorer.

For Internet Explorer, the victim is presented with the option to install an ActiveX control called FreeAccess.ocx This is actually copied into the Windows system32 folder as a randomly named DLL.

Firefox and Opera undergo a very clever piece of social engineering. What appears to be a link to www.google.com is presented to the victim. This unfortunately is not a hyperlink but in fact a cleverly hidden .com file. Once accepted and run, a randomly named DLL is again installed to the windows system32 folder.

• Once the DLL agent is installed, various pieces of Adware are downloaded and installed onto the machine. Examples are the Bravesentry and LinkOptimizer Trojans. The real payload is then downloaded to the victim's computer. Both a Rootkit and service component are installed along with a hidden windows user account. The main purpose of this is to enable the Adware which was previously installed to be hidden from any Anti-malware tools installed on the machine

>> Gromozon Rootkit Removal Tool



Digg it! Del.icio.us Technorati Furl Google Bookmarks

« BitComet 0.96 · Gromozon Rootkit Removal Tool · DivX for Windows 6.7.0.17 »

Warp2Search.net » News » November 2007 » Gromozon Rootkit Removal Tool

Latest News

· Recuva (Slim) 1.33.451
· ZipGenius 6.2.0.2003
· AMP 4GB USB Drives Review
· Trend Micro RootkitBuster 2.80.1077
· OCZ DDR3 PC3-15000 Platinum Series 4GB Memory Kit Review
· NZXT Gamma Gaming Case Review
· Google Chrome OS Preview
· ASUS Radeon EAH5850 Review
· Seagate FreeAgent Theater+ HD Media Player Review
· Prolimatech Megahalems Rev.B LGA1156 Review
· Zowie Gear Hammer e-Sports Headset Review
· Patriot Viper Series DDR3-1600 8-8-8-24 XMP Ready Triple Channel Memory Kit Review
· Mackie MR8 Reference Monitors Review
· Apple Announces Black Friday 2009 Sale
· Antec Two Hundred Mid Tower Case Review
· Real Temp 3.46
· Opera 10.10 Final
· NZXT Guardian 921 PC Case Review

Community Forum

· S.T.A.L.K.E.R.: Call of Pripyat Benchmark
Posted by Regeneration

· Thermaltake BlacX Duet Dual Hard Drive Docking Station Review @ Tweaknews
Posted by Tweaknews

· Noctua NH-D14 Premium CPU Cooler Review @ Clunk.org.uk
Posted by Clunk

· HIS Radeon HD4850 iCooler 1GB Videocard Review @ Tweaknews
Posted by Tweaknews

· Building An Ultimate Gaming Machine!
Posted by ezone


Nodes To Friends





Online Users

There are currently 760 user(s) online:
Ask Jeeves, Cuil, Google, Live Search, MSN, Yahoo

© 2007-2009 Esselbach Internet Solutions
All products mentioned are registered trademarks or trademarks of their respective owners.
Read our disclaimer over here and our Privacy Policy over here
Managed with Contentteller(R) Business Edition, (C) 2002 - 2009 Esselbach Internet Solutions