Gromozon Rootkit Removal Tool icon

Gromozon Rootkit Removal Tool

1.3/5 7
Certified 100% CLEAN Freeware   

A small utility that can rapidly detect and remove the Gromozon rootkit. #Rootkit Removal  #Remove Gromozon  #Rootkit Scan  #Gromozon  #Removal  #Rootkit  

Description

Free Download

Unfortunately the Gromozon Rootkit isn't a single infection, but a blended attack designed to bypass traditional antimalware security applications.

The end result meaning that the machine is not only infected by several well known Trojans but also a highly dangerous Rootkit. Traditional AV vendors are at the moment dealing with the known infections, but overlooking the rootkit.

Here is how you could get infected with the Gromozon rootkit: ■ Upon visiting an infected webpage an obfuscated JavaScript is run. ■ The user is forwarded to another website which of course contains a further obfuscated JavaScript. This connects to a network of websites which are used to launch the infection routine. These websites are constantly changing and since May 2006 have become considerably more numerous ■ A server side script will be run to analyse the user agent (web browser) under which the user is visiting. Different attack methods are then launched depending on whether the user is running Opera, Firefox or Internet Explorer. ■ For Internet Explorer, the victim is presented with the option to install an ActiveX control called FreeAccess.ocx This is actually copied into the Microsoft Windows system32 folder as a randomly named DLL. ■ Firefox and Opera undergo a very clever piece of social engineering. What appears to be a link to www.google.com is presented to the victim. This unfortunately is not a hyperlink but in fact a cleverly hidden .com file. Once accepted and run, a randomly named DLL is again installed to the windows system32 folder. ■ Once the DLL agent is installed, various pieces of Adware are downloaded and installed onto the machine. Examples are the Bravesentry and LinkOptimizer Trojans. The real payload is then downloaded to the victim's computer. Both a Rootkit and service component are installed along with a hidden windows user account. The main purpose of this is to enable the Adware which was previously installed to be hidden from any Anti-malware tools installed on the machine

User Comments
This enables Disqus, Inc. to process some of your data. Disqus privacy policy
add to watchlist add to download basket send us an update REPORT
  runs on:
Windows All
  file size:
720 KB
  filename:
F758A9C.exe
  1 screenshot:
Gromozon Rootkit Removal Tool - screenshot #1
  main category:
Antivirus
  developer:
  visit homepage