Remove Gromozon. Description and removal instructions

 
Title: Gromozon

Type: Trojans
Severity scale:Gromozon severity is 80  (80 / 100)
 
Gromozon is an extremely dangerous trojan illegally installed to victim computers by malicious web sites through sophisticated exploits. This parasite is a hard to get rid of threat that integrates downloader trojans, rootkits, adware and other dangerous pests. Once installed, Gromozon secretly downloads from the Internet and drops numerous malware parasites that serve unsolicited commercial advertisements, change essential system settings, severely degrade system performance, decrease Internet connection throughput, create malicious system services, etc. They can also crash the compromised computer and corrupt the entire system. Gromozon uses advanced rootkit techniques to hide its files, registry keys and related objects. It also injects malicious code into running software and system processes in order to make its removal as much difficult as possible. The parasite is able to prevent some anti-rootkit tools from running. Gromozon runs on every Windows startup.

It should be noted that web sites distributing Gromozon are hosting exploits targeting all popular web browsers (Microsoft Internet Explorer, Mozilla Firefox, Opera).

Gromozon and LinkOptimizer Removal Guide


Related files: xyz.exe, [X]1.exe, www.google.com, jvaa.dll, freeaccess.ocx, img.tif, com4.igp, [X1]1.exe, linkoptimizer.dll, [X]aa.dll, [X1]1.dll, [X1]aa.dll

Gromozon properties:
• Changes browser settings
• Shows commercial adverts
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Gromozon removal:

remover for Gromozon

Gromozon manual removal:

Kill processes:
xyz.exe, [X1]1.exe
Delete registry values:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[X1]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=[filename]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\[X2]
Delete files:
xyz.exe, [X1]1.exe, www.google.com, jvaa.dll, linkoptimizer.dll, [X1]aa.dll, [X1]1.dll, freeaccess.ocx, img.tif, com4.igp
Delete directories:
C:\Program Files\LinkOptimizer
Misc:
[X1] is a combination of random characters.
[X2] is a random CLSID.

Gromozon uses a lot of randomly named files that reside in different locations. The files provided are only basic, known parts of the parasite. Deleting them usually does not eliminate the infection. That's why an advanced removal software should be used.

Exact file location:
xyz.exe - C:\Program Files
[X1]1.dll - C:\Windows or C:\Winnt
linkoptimizer.dll - C:\Program Files\LinkOptimizer
com4.igp - C:; C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
jvaa.dll, [X]aa.dll - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
[X1]1.exe - C:\Windows\Temp or C:\Winnt\Temp; C:\Documents and Settings\[Current User]\Local Settings\Temp

Other programs to remove Gromozon:

• SUPERAntiSpyware - Review - Download
• CounterSpy - Review - Download
• Windows Defender - Review - Download

Information added: 24/08/06
Information updated: 01/09/06

Additional resources related to Gromozon:

Attention: If you know or you have a website or page about Gromozon removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Gromozon parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:


Comments from visitors:


1. by Guest. 2006-09-01 15:09:53
Just to note that the above link points to a press release regarding the first automatic removal tool for Gromozon.


Related news:
Similar parasites:
Related discussions: