Jump to content

Build Theme!
  • Infected?


Hey there! :wub: Looks like you're enjoying the discussion, but you're not signed up for an account. When you create an account, we remember exactly what you've read, so you always come right back where you left off. You also get notifications, here and via email, whenever new posts are made. You can like posts to share the love. :D Join 92047 other members! Anybody can ask, anybody can answer. Consistently helpful members may be invited to become staff. Here's how it works. Virus cleanup? Start here -> Malware Removal Forum.

Try What the Tech -- It's free!


Gromozon Rootkit: The Mutha Of All Rootkits

  • Please log in to reply
1 reply to this topic

#1 TeMerc



  • Visiting Fellow
  • PipPipPipPip
  • 626 posts

Posted 24 August 2006 - 10:21 AM

Well it seems the scum who craft malware for a living have out done themselves.

This rootkit, in some cases linked to LinkOptimizer, in many instances prevents the running of the following rootkit tools:
Rootkit Revealer
Ice Sword

Now this is not very consistent as it seems each DL found by researchers tends to change a little bit. Experts have been working on this thing since about August 12. 22 pages of forum analysis, commentary and attempted killing and so forth.

There is a complete write up by one of the research experts at Prevx. It can be read here.(PDF) I urge all with the slightest interest in malware and how they work to read this.

Some experts are recommending a reformat of a compromised system. Based on what I have seen and read, I tend to agree.

Just be sure to back up all your data before doing so. And of course be sure you're actually infected before panicking.

Most AV companies have not formulated any removal method, the instructions in the above PDF are the best so far and not 100% effective in every case.

I'll update as things progress.


Register to Remove

#2 Micah_6:8


    Evilware Emancipator

  • Authentic Member
  • PipPipPipPipPipPipPip
  • 10,060 posts
  • Interests:Web (Perl, PHP, JavaScript, HTML) programming, CNC programming, Squashing spyware!

Posted 14 September 2006 - 07:17 AM

Gromozon Removal Tool

Worked here: Click Me
Micah 6:8 He hath shewed thee, O man, what is good; and what doth the LORD require of thee, but to do justly, and to love mercy, and to walk humbly with thy God?

The help you receive here is free.
If you wish to show your appreciation, then you may donate to help keep us online.

Want to help others? Join the ClassRoom and learn how.

Download Hijack This! My Website: UnSpyMe!

Related Topics

0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users