Gromozon manual removal:
Kill processes:
xyz.exe, [X1]1.exe
Delete registry values:HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\[X1]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows\AppInit_DLLs=[filename]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\[X2]
Delete files:xyz.exe, [X1]1.exe, www.google.com, jvaa.dll, linkoptimizer.dll, [X1]aa.dll, [X1]1.dll, freeaccess.ocx, img.tif, com4.igp
Delete directories:C:\Program Files\LinkOptimizer
Misc:[X1] is a combination of random characters.
[X2] is a random CLSID.
Gromozon uses a lot of randomly named files that reside in different locations. The files provided are only basic, known parts of the parasite. Deleting them usually does not eliminate the infection. That's why an advanced removal software should be used.
Exact file location:
xyz.exe - C:\Program Files
[X1]1.dll - C:\Windows or C:\Winnt
linkoptimizer.dll - C:\Program Files\LinkOptimizer
com4.igp - C:; C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
jvaa.dll, [X]aa.dll - C:\Windows\System, C:\Windows\System32 or C:\Winnt\System32
[X1]1.exe - C:\Windows\Temp or C:\Winnt\Temp; C:\Documents and Settings\[Current User]\Local Settings\Temp
Post Comment: