You're in: Panda Security > Home Users > security-info > about-malware > encyclopedia > overview
Active Scan. Scan your PC free
Panda Security Product Line 2012

Virus Encyclopedia

Welcome to the Virus Encyclopedia of Panda Security.

Encyclopedia GetVirusCard True 0

Gronev.A

 
Threat LevelLow threatDamageHighDistributionNot widespread
Common name:Gronev.A
Technical name:W32/Gronev.A.worm
Threat level:Medium
Type:Worm
Effects:  

It plays a song with the Windows Media Player and closes the Internet Explorer browser when it detects the word Search in the address bar. It spreads via mapped drives.

Affected platforms:

Windows 2003/XP/2000/NT/ME/98/95

First detected on:June 25, 2007
Detection updated on:June 25, 2007
StatisticsNo
Yes, using TruPrevent Technologies

Brief Description 

    

Gronev.A is a worm that closes the Internet Explorer browser whenever it detects the word Search in the address bar.

Additionally, when it is run, the Windows Media Player is opened and a song called Lagu is played. Moreover, when the CMD shell is accessed, a window is displayed and a username with a pasword is created. This way, it could remotely control the affected computer.

Gronev.A spreads via mapped drives. In order to do so, it checks if the infected computer is connected to a network. And if so, it makes an inventory of all mapped drives and creates a copy of itself in each of them.

Visible Symptoms 

    

Gronev.A is easy to recognize, as when it is run, the Windows Media Player is run and a song called Lagu is played.

Additionally, when the CMD shell is run, a window like the following is displayed:

Message displayed by Gronev.A