Welcome to P2PNET.net - The original daily p2p and digital news site. Always First!
Register | Login
RIAA News
Cool Stuff
MPAA News
Games / Consoles
News
Music
Movies
TV
Open Source
Mobiles
Advertising
Product News
P2P
Off Topic
Freedom
Politics
Interviews
Security
DRM
Links
Kids and Kartels
Search: 
Search
 
Web P2PNET   
Search: 
Search
Torrent Site Tracker
MP3rocket
 
Add real-time p2pnet headlines to YOUR site ! Click here to download our newsfeed code
p2pnet - rss feed: http://p2pnet.net/p2p.rss | p2pnet celebrities: http://p2pnet.net/celeb.rss | Mobile? http://p2pnet.net/index-wml.php

MSN Messenger Bropia F worm

p2pnet.net News:- Bropia F, a minor variant of Bropia.A, is the latest worm to catch the public eye, and this principally because it uses MSN Messenger to get around.

When it’s run, it copies itself as “msnus.exe” in the Windows system directory and then looks for winhost.exe, winis.exe and dnsserv.exe.

If it doesn’t find them, says F-Secure, it drops “cz.exe” and executes it to copy ‘winhost.exe’ in the Windows system directory adding the registry keys:

[HKLMSoftwareMicrosoftWindowsCurrentVersionRun]
“win32″ = “%SysDir%winhost.exe”

“This ensures that it will be executed at next system startup,” says F-Secure. “The bot can be used as a backdoor, collecting system information, logging keystrokes, relaying spam and for various other purposes.”

But it looks worse than it is because as Mikko Hypponen, the company’s director of antivirus research observes, “Do note this is not an automatic network worm; it still needs the recipients to accept the incoming file and run it.”

Bropia F also likes to display a Nekked Chicken with grill-lines and named SEXY.JPG. So if you see one such …

Something you think we should know? tips[at]p2pnet.net

===================

See:-
nekked chicken - F-Secure Virus Descriptions : Bropia.F, February 3, 2005

HOME

Leave a Reply

    Advertisments
Teksavvy