Gromozon mystery clearing

Cleaner tool aims to remove sophisticated attack.

The shadowy blended threat known as Gromozon has slowly been gaining notoriety in recent weeks, particularly after some in-depth analysis was made public. Now anti-malware company PrevX has released a free, dedicated remover tool to combat the problem.

VB100

The threat has spread from an Italian website over several months, and uses a variety of highly sophisticated methods of infection, including various social engineering techniques and exploit attempts, which vary depending on the browser used to access the site, as well as obfuscated code to hamper analysis. It installs diallers, downloaders and adware on infected machines, all heavily stealthed by the accompanying rootkit technology.

The PrevX removal tool can be downloaded here. Read a blog entry on the threat from Symantec's Eric Chien here, and check the latest version of Marco Giuliani's analysis (in PDF format) here.

5 September 2006

Tags:    del.icio.us  digg this! digg this

Quick Links



Poll

When do you install software updates?
As soon as they are released
As soon as I have some time
I take my time, but I always install them eventually
Only when I feel it is absolutely necessary
Never
Leave a comment
View 12 comments

Jobs Career Sidebar

Twitter Feed

virusbtn: RT @emailsecmatters: The typical spam message has sources as diverse as the spam lunch meat: http://ht.ly/2yucd
2 hours ago


virusbtn: Can anyone write a rap about our RAP tests (http://bit.ly/255ySQ) and submit it to the Symantec competition http://bit.ly/bOJg8r
6 hours ago


Malware Prevalence

Autorun |########|
Conficker/Downadup |######|
VB |#####|
Agent |#####|
FakeAlert/Renos |####|
 View this month's full report
Virus Bulletin currently has 208,224 registered users.