Summary

Summary
Action
More Information
| How it spreads |
|
|---|---|
| Affected operating systems | Windows |
| Characteristics |
|
| Protection available since | 12 February 2005 16:18:42 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
More Information
W32/Bropia-H is a worm for the Windows platform.
When first run, W32/Bropia-H copies itself to the root folder using one of the
following filenames:
LOL.scr
Webcam.pif
hahahaha.pif
naked_drunk.pif
sister.pif
The worm monitors the status of MSN Messenger and sends a copy of itself to
Messenger contacts.
W32/Bropia-H disables the right mouse button to prevent context menus from
appearing. The worm also prevents the Windows Task Manager (taskmgr.exe) and
command prompts (cmd.exe) from being run.
The worm drops a file to the Windows system folder named svchosts.exe which
is detected by Sophos Anti-Virus as W32/Rbot-AIZ.
