TrendLabs has declared a Medium-Risk alert to control the spread of this new WORM_BROPIA variant that is spreading via MSN Messenger in Korea, China, Taiwan, and the United States.
Upon execution, Bropia.F, a variant of Bropia.A drops a copy of itself in the Windows system folder, and then tries to propagate to other MSN Messenger users by sending a copy of itself under filenames like Bedroom-thongs.pif, Hot.pif, Naked_drunk.pif, Underware. Pif, LOL.scr, LMAO.pif, New_webcam.pif, ROFL.pif and Webcam.pif.
The worm is particularly damaging. It seeks out Windows identity keys and certain application activation codes and feeds the information to the sender via IRC.