Sophos

W32/Bropia-M

Category
Type
What to do
Prevalence low high

Summary

 
How it spreads
  • Chat programs
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 11 February 2005 21:38:35 (GMT)
Detected by All Sophos products
  • Endpoint Security and Control 9.0
  • Small business solutions 4.0

Action

More Information

W32/Bropia-M is a worm for the Windows platform.

When first run, W32/Bropia-M copies itself to the root folder using the following filenames:

Beautiful Ass.pif
Isass.exe
John Kerry as Super Chicken.scr
Kool.pif
Me & you pic!.pif
Me Pissed!.pif
sexy.pif
she's fuckin fit.pif
She Could Fit her Ass in a Teacup.pif
titanic2.jpg.pif

W32/Bropia-M sets the following registry entries in order to run each time a user logs on:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
NvMsnW
<Path to worm copy>

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices\
NvMsnW
<Path to worm copy>

The worm monitors the status of MSN Messenger and sends a copy of itself to Messenger contacts.

W32/Bropia-M disables the right mouse button to prevent context menus from appearing. The worm also prevents the Windows Task Manager (taskmgr.exe) and the registry editor (regedit.exe) from being run.

The worm may attempt to download files from remote sites and may open and display images in Internet Explorer.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer