| ALIAS: | IM-Worm.Win32.Bropia.g |
[HKLM\System\CurrentControlSet\Services] [HKLM\Software\Microsoft\Windows\CurrentVersion\Run] [HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce] [HKCU\Software\Microsoft\Windows\CurrentVersion\Run] [HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce] "NvCplScan" = "%SystemDir%\nvsc32.exe"The bot can be used as a backdoor, collecting system information, logging keystrokes, relaying spam and for various other purposes. Brobia.G also drops a file "pic.jpg" and opens it. On default installation of Windows, the program associated with jpg-extension is usually Internet Explorer. This file presents a woman in handcuffs.
LOOK! <URL to worm> :-O wtf....<URL to worm> :D OMFG! <URL to worm> :P LMFAO! <URL to worm> :PWhere <URL to worm> is a http-link to worm's file. The link is static address. At the time of this writing, the file has been removed from the server.
Technical Details: Jarkko Turkulainen, Feb 16rd, 2005; F-Secure Corporation