Always glad to help where i can Bill,W32.Bropia.M was
doing the rounds on msn messenger last week and sending
itself as a whole host of names,
(Titanic2.jpg,sexy,me&you pic,Me pis*ed!,she's fuc*ing
fit) just to name a few and ive had to sort a few pcs
infected with this,Its easy to deal with though,Just by
choosing show all files and folders under the search
option and then typing in sass shows if you are infected.
As you know lsass it a legitimate windows file (approx
12kb and says LSA Export Version) but the Bropia saves
itself under the same system 32 folder as Isass (approx
30 to 32kb) and adds it self to the start up processes,If
you people can find both then just go msconfig if its not
blocked by the worm and disable any Isass.exe then reboot
and remove the files from system 32 folder plus the pics
that come with them all 30kb then restore the registry
using SFC /SCANNOW And windows disk.
Theres also some back door trojans that like to play with
the mouse too like Backdoor.Futro(Norton) also called
Backdoor.Delf.mz [Kaspersky] but again they are easy
enough to deal with and like you say its nice of the
writers to give us a clue what they are
Regards Andy