CastleCops, Internet Crime Fighters
Need help? Click here to register for free! Absolutely zero advertisements on this site!

$9736.22 of $21422.68
left sidedonated so farneed $11686.46 donated to reach our goalright side, our goal
Help CastleCops serve the community on new servers, Donate Here to reach our goal.

Donation/Premium
spacer
block bottom
Security Central
spacer
· Home
· PIRT/Fried Phish
· MIRT
· SIRT
· Deutsch
· Wiki
· Newsletter
· O16/ActiveX
· CLSID List
· Contest2007
· Downloads
· Feedback (send)
· Forums
· HijackThis
· Hijacktrend
· LSPs
· My Downloads
· O18
· O20
· O21
· O22
· O23
· O9
· Premium
· Private Messages
· Proxomitron
· Reviews
· Search
· StartupList
· Stories Archive
· Submit News
· WsIRT
· Your Account
· Acceptable Use Policy
block bottom
Survey
spacer
Was 2007 a good year?

Yes it was a wonderful year
Yes, but there is always room for improvement
Status quo
It was a challenge
Other (leave comment)



Results
Polls

Votes: 940
Comments: 25
block bottom
spacer spacer
image The Gromozon Rootkit - Detection and Removal image
CastleCops
The Gromozon Rootkit is a user mode rootkit that installs a variant of LinkOptimizer adware and occasionally the rogue antispyware program called Brave Sentry, a desktop hijacker. It is named after the site which distributes the threat. This threat pulls out all the tricks including random file naming, file morphing, file encryption (EFS), hiding in the AppInit_DLLs value of the Windows Registry key, using Windows reserved file names, using Alternate Data Streams (ADS) to hide in the system32 folder on NTFS file systems, and disabling rootkit and system analysis tools. The good thing is that Prevx came out with a removal tool for this beast, which you can find a link to after you read the following symptoms discussion.

From an operational point of view, one of the biggest symptoms is an inability to run most security programs. The Gromozon coders have done this to seriously curtail your chances of removing the threat. The following are symptoms of the Gromozon Rootkit in a HijackThis Log, but please be aware that they are not always present:

  • R0 - HKCU/Software/Microsoft/Internet Explorer/Main,Local Page =
  • R0 - HKLM/Software/Microsoft/Internet Explorer/Main,Local Page =
  • R3 - Default URLSearchHook is missing
  • O2 - BHO: Class - {1A06B098-0011-88C0-89F1-281F7413084A} - C:/WINDOWS/krctv1.dll (file missing)



  • Negster22, one of our own CastleCops staff who has also co-authored a book on "Rootkits for Dummies" out on Amazon has authored the bulk of our Wiki article highlight: "The Gromozon Rootkit - Detection and Removal". This article has also been maintained by other Wiki participants -- Thank you!

    To read the detection and removal of the Gromozon Rootkit in full detail, visit the wiki page.
    Posted on Tuesday, 23 January 2007 @ 19:21:08 UTC by Paul (2021 reads)
    [ Trackback ]
    image

    "The Gromozon Rootkit - Detection and Removal" | Login/Create an Account | 0 comments
    Threshold
    The comments are owned by the poster. We aren't responsible for their content.

    No Comments Allowed for Anonymous, please register
     
    Login
    spacer
    Nickname

    Password

    Security Code: Type Security Code: Usage signifies AUP acceptance
    · New User? · Click here to create a registered account.
    block bottom
    Related Links
    spacer
    · del.icio.us!
    · digg it!
    · reddit!
    · TrackBack (0)
    · Microsoft
    · Microsoft
    · HotScripts
    · W3 Consortium
    · Amazon.com
    · CastleCops
    · More about CastleCops
    · News by Paul


    Most read story about CastleCops:
    Acceptable Use Policy

    block bottom
    Article Rating
    spacer
    Average Score: 5
    Votes: 1


    Please take a second and vote for this article:

    Bad
    Regular
    Good
    Very Good
    Excellent


    block bottom
    Options
    spacer

    Printer Friendly Page  Printer Friendly Page

    block bottom
    spacer spacer