Gromozon tries to drops its file through a JavaScript. Most of the times, it drops a file named www.google.com. Note that, the file is not a HTML web-link, instead it’s an executable file with .COM extension! When this file downloaded, it downloads more malware components and installs into the PC. Here's a screenshot showing the Gromozon trying to drop its installer.

Prevx has released a removal tool which successfully detects and removes the Gromozon rootkit. You can download it here.
More information regarding the Gromozon can be obtained at CastleCops Wiki and in this excellent PDF document by Prevx researcher Marco Guiliani.
0 comments:
Post a Comment