News
[PSUs]| Monday 24th January 2005 |
Known as Bropia.A, the worm waits on an infected system until the Messenger window is opened and then sends a copy of itself to contacts, using filenames adaware.exe, VB6.EXE, lexplore.exe and Win32.exe.
If a contact accepts the file and runs it, it checks to see if any of the previously mentioned files are present, and if not, places a file called oms.exe on the computer and runs it.
This is a variant of Rbot, which installs a backdoor on the system and gives an attacker a way of accessing and controlling the infected system remotely.
Bropia.A may also disable the right mouse button that would normally bring up context-sensitive options. It also changes the Windows mixer volume settings, giving its victims some idea as to its presence.
Antivirus companies picked up the worm on Thursday, so anyone with up to date antivirus software will be protected. Infection levels are currently low.
Submit to: Digg | Slashdot | Del.icio.us | Technorati


