Gronev.A is a worm that closes the Internet Explorer browser whenever it detects the word Search in the address bar.

Additionally, when it is run, the Windows Media Player is opened and a song called Lagu is played. Moreover, when the CMD shell is accessed, a window is displayed and a username with a pasword is created. This way, it could remotely control the affected computer.

Gronev.A spreads via mapped drives. In order to do so, it checks if the infected computer is connected to a network. And if so, it makes an inventory of all mapped drives and creates a copy of itself in each of them.


Technical details can be found at this Panda Software page.