Home > Support > Global Security Advisor 

Virus Detail

Win32.Bropia.A

Date Published:
20 Jan 2005

Last Updated:
27 Jan 2005

Threat Assessment

Overall Risk:   Low
Wild:  Low
Destructiveness:  Medium
Pervasiveness:  Medium

Characteristics

Type : Worm

Category : Win32

Also known as:  W32.Bropia (Symantec), W32/Bropia.worm (McAfee)

Immediate Protection Info

 
SignatureProductRemoval Instructions
28.68.06
eTrust Antivirus v7/8* (InoculateIT Engine)
11.x/8881
eTrust Antivirus v7/8* (Vet Engine)
6.1x/6021
eTrust EZ Antivirus 6.1x
6.2x/8881
eTrust EZ Antivirus 6.2x
6.3x/8881
eTrust EZ Antivirus 6.3x
6.4x/8881
eTrust EZ Antivirus 6.4x
7.x/8881
eTrust EZ Antivirus 7.x
10.6x/8881
Vet Anti-Virus 10.6x
 
 
 

Description

Win32.Bropia.A is a worm that spreads via MSN Messenger. It may also be able to spread using Windows Messenger. It drops a variant of the Rbot worm family, Win32/Rbot.BMB.

Back to top

Method of Infection

When run, Bropia.A creates two files in the root directory of the current drive (usually c:\). The first file is a copy of the worm itself, using one of the following file names:


Drunk_lol.pif
Webcam_004.pif
sexy_bedroom.pif
naked_party.pif
love_me.pif


The second file is called "oms.exe", and is a variant of the Rbot worm family, called Win32/Rbot.BMB. For more information on Win32/Rbot, please see elsewhere in our encyclopedia.


Bropia.A does not install itself in any other way; it will not run automatically when Windows is restarted.


Back to top

Method of Distribution

Via MSN Messenger

Bropia.A spreads by sending itself to contacts using MSN Messenger. We have received reports that it can spread using either MSN Messenger or Windows Messenger, both on internal networks and the Microsoft .NET Messenger service.


It sends itself using one of the following names:


Drunk_lol.pif
Webcam_004.pif
sexy_bedroom.pif
naked_party.pif
love_me.pif


Back to top

Payload

Installs Additional Malware

Bropia.A drops and executes a file called "oms.exe", which is a worm and IRC bot called Win32/Rbot.BMB. If any of the following files exist, however, it will not drop Rbot.BMB:


  • %System%\adaware.exe
  • %System%\VB6.EXE
  • %System%\lexplore.exe
  • %System%\Win32.exe
Modifies System Settings

Bropia.A also attempts to stop the user from running several programs, such as Windows Task Manager. It disables the right mouse button, and the 'ctrl-alt-delete' key combination. It also opens the files %System%\cmd.exe and %System%\taskmgr.exe and locks them, so they can not be executed.


The worm also sets the audio volume to zero.


Analysis by Hamish O'Dea


Back to top

CA Global Security Advisor

Current threat condition: Low
Low
Find Threats
Viruses Spyware
Vulnerabilities All

Security Resources

 
 
Page Tools