got this in email this morning
Dear Trend Micro customer,
As of February 2, 2005, 6:55 PM (GMT - 08:00), TrendLabs has declared a Medium
Risk Virus Alert to control the spread of WORM_BROPIA.F.
TrendLabs has received numerous infection reports indicating that this malware
is spreading in the Bolivia, U.S., Korea, Taiwan, Mexico, and China.
This is a memory-resident worm that drops a copy of itself in the root folder
using different interesting file names with a PIF extension.
It attempts to propagate by sending copies of itself to all MSN Messenger
contacts.
It also drops the file WINHOST.EXE in the Windows system folder. Trend Micro
detects the said file as WORM_AGOBOT.AJC.
It has an anti-debugging technique, which enables it not to run if any of the
following debugging applications are present on the affected system:
? NT-ice
? Softice
It also drops and displays an image file, named SEXY.JPG.
TrendLabs will be releasing the following EPS deliverables:
TMCM Outbreak Prevention Policy 144
Official Pattern Release 2.390.00
Damage Cleanup Template 505