1. Symantec/
  2. Security Response/
  3. W32.Dronzho

W32.Dronzho

Risk Level 2: Low

Discovered:
December 4, 2007
Updated:
December 4, 2007 6:41:32 PM
Type:
Worm
Infection Length:
82,432 bytes; 40,960 bytes; 32,768 bytes; 22,1184 bytes; 9,842 bytes; 65,536 bytes
Systems Affected:
Windows
W32.Dronzho is a worm that spreads through removable storage devices. It records keystrokes and replaces the file userinit.exe with a copy of itself.

Note: Compromised computers may experience problems logging in after restart. Please see the Removal Instructions for the specific instructions to remove this threat.

Antivirus Protection Dates

  • Initial Rapid Release version December 4, 2007 revision 002
  • Latest Rapid Release version August 8, 2016 revision 023
  • Initial Daily Certified version December 4, 2007 revision 003
  • Latest Daily Certified version August 9, 2016 revision 001
  • Initial Weekly Certified release date December 5, 2007
Click here for a more detailed description of Rapid Release and Daily Certified virus definitions.
Writeup By: Masaki Suenaga and Mircea Ciubotariu

Search Threats

Search by name
Example: W32.Beagle.AG@mm
STAR Antimalware Protection Technologies
2016 Internet Security Threat Report, Volume 21
  • Twitter
  • Facebook
  • LinkedIn
  • Google+
  • YouTube