Browaf, also known as Browsesafe, is a worm that spreads through instant messages and online chats. Once executed, the parasite displays certain messages and installs itself to the system. Then it runs a spreading routine. Browaf uses Yahoo! Instant Messenger and mIRC programs to send links to the worm’s installation file to user contacts. The worm can also change the Internet Explorer default home page and receive certain commands from the remote attacker. Browaf runs on every Windows startup.