Free Republic
Browse · Search
News/Activism
Topics · Post Article

Skip to comments.

Bropia worm spreads on the back of MSN Messenger
Computer Buyer ^ | Monday 24th January 2005 | Matt Whipp

Posted on 02/03/2005 8:12:50 AM PST by PeterFinn

Bropia worm spreads on the back of MSN Messenger 5:04PM A new virus is using the MSN Messenger system to spread. Known as Bropia.A, the worm waits on an infected system until the Messenger window is opened and then sends a copy of itself to contacts, using filenames adaware.exe, VB6.EXE, lexplore.exe and Win32.exe.

If a contact accepts the file and runs it, it checks to see if any of the previously mentioned files are present, and if not, places a file called oms.exe on the computer and runs it.

This is a variant of Rbot, which installs a backdoor on the system and gives an attacker a way of accessing and controlling the infected system remotely.

Bropia.A may also disable the right mouse button that would normally bring up context-sensitive options. It also changes the Windows mixer volume settings, giving its victims some idea as to its presence.

Antivirus companies picked up the worm on Thursday, so anyone with up to date antivirus software will be protected. Infection levels are currently low.

Matt Whipp


TOPICS: Miscellaneous; News/Current Events; Technical; Unclassified
KEYWORDS: computersecurity; getamac; hacker; hackers; internetexploiter; lookoutexpress; lowqualitycrap; messenger; microsoft; msn; securityflaw; virus; windows; worm
Update your anti-virus dats...NOW!!!!
1 posted on 02/03/2005 8:12:51 AM PST by PeterFinn
[ Post Reply | Private Reply | View Replies]

To: PeterFinn

My daughter uses Messenger on oher iBook. Can this worm go there? (Computer clueless here, so be kind.)


2 posted on 02/03/2005 8:16:22 AM PST by sarasota
[ Post Reply | Private Reply | To 1 | View Replies]

To: sarasota

Anything connected to the internet running Messenger.


3 posted on 02/03/2005 8:17:42 AM PST by JohnnyZ ("Thought I was having trouble with my adding. It's all right now." - Clint Eastwood)
[ Post Reply | Private Reply | To 2 | View Replies]

To: PeterFinn
Thanks PeterFinn. I use Trillian so that I can IM/IRC/ICQ with folks from multiple services, including MSN, AOL, Yahoo and more. I suppose if the payload is sent as a file, someone would have to actually "ACCEPT" the download, and somewhat knowingly put themselves at risk. Alas, P.T. Barnum was right though.
4 posted on 02/03/2005 8:20:06 AM PST by Nice50BMG (AB 50 outlaws the use of this tagline in California.)
[ Post Reply | Private Reply | To 1 | View Replies]

To: PeterFinn

Messenger shutdown commencing in 3, 2, 1.....


5 posted on 02/03/2005 8:22:24 AM PST by Recovering Hermit
[ Post Reply | Private Reply | To 1 | View Replies]

To: PeterFinn
Here are some handy instructions for disabling MSN Messenger altogether.
6 posted on 02/03/2005 8:24:44 AM PST by Semolina Pilchard
[ Post Reply | Private Reply | To 1 | View Replies]

To: PeterFinn

http://amsn.sourceforge.net/ Good clone that runs on Linux/Win/OSX and others that isn't made by microsoft. :)


7 posted on 02/03/2005 8:26:46 AM PST by Brian328i
[ Post Reply | Private Reply | To 1 | View Replies]

To: PeterFinn
Update your anti-virus dats...NOW!!!!

Macintosh users can ignore this thread. :-)

8 posted on 02/03/2005 8:44:29 AM PST by 1LongTimeLurker
[ Post Reply | Private Reply | To 1 | View Replies]

To: sarasota
My daughter uses Messenger on oher iBook. Can this worm go there? (Computer clueless here, so be kind.)

She might be able to pass it along to others, but the virus won't work on a Mac so she is safe.

9 posted on 02/03/2005 8:45:36 AM PST by 1LongTimeLurker
[ Post Reply | Private Reply | To 2 | View Replies]

To: PeterFinn

Bookmarking.


10 posted on 02/03/2005 8:53:13 AM PST by TruthNtegrity
[ Post Reply | Private Reply | To 1 | View Replies]

To: 1LongTimeLurker

Thank you.


11 posted on 02/03/2005 8:55:17 AM PST by sarasota
[ Post Reply | Private Reply | To 9 | View Replies]

To: sarasota
My daughter uses Messenger on oher iBook. Can this worm go there? (Computer clueless here, so be kind.)

No. Macs are immune to PC diseases.

12 posted on 02/03/2005 1:35:27 PM PST by Swordmaker (Tagline now open, please ring bell.)
[ Post Reply | Private Reply | To 2 | View Replies]

To: 1LongTimeLurker
Macintosh users can ignore this thread. :-)

That's one of the few advantages of having nominal market share.

13 posted on 02/03/2005 1:39:45 PM PST by Labyrinthos
[ Post Reply | Private Reply | To 8 | View Replies]

To: sarasota

Not on an iBook ... the files it is trying to infect/install are all PC-only files.


14 posted on 02/03/2005 1:42:08 PM PST by spodefly (Yo, homey ... Is that my briefcase?)
[ Post Reply | Private Reply | To 2 | View Replies]

To: Nice50BMG
I suppose if the payload is sent as a file, someone would have to actually "ACCEPT" the download, and somewhat knowingly put themselves at risk. Alas, P.T. Barnum was right though.

Well, heck, they promised me the HOTTEST PORN PICTURE OF BRITANNY SPEARS EVER!!!!

I just had to see.

15 posted on 02/03/2005 1:43:29 PM PST by Lazamataz (Proudly Posting Without Reading the Article Since 1999!)
[ Post Reply | Private Reply | To 4 | View Replies]

Disclaimer: Opinions posted on Free Republic are those of the individual posters and do not necessarily represent the opinion of Free Republic or its management. All materials posted herein are protected by copyright law and the exemption for fair use of copyrighted works.

Free Republic
Browse · Search
News/Activism
Topics · Post Article

FreeRepublic, LLC, PO BOX 9771, FRESNO, CA 93794
FreeRepublic.com is powered by software copyright 2000-2008 John Robinson