This indicates possible detection of the W32/Bropia.F-net worm passing through the network on TCP ports 6891 through 6900 using the MSNFTP protocol.
W32/Bropia is a worm that spreads through the internet via MSN Messenger. The worm carries an embedded copy of a W32/Agobot.AJC-tr variant. Affected systems will spread the worm by sending it to the contacts listed in MS Messenger.
Microsoft Windows Operating Systems.
System compromise: worm infection.
The default action has been set to pass. If this signature is not triggered by legitimate traffic in your network environment, change its action to "reset session", and disinfect the system which received/sent the packets. Check the main screen using the web interface for your FortiGate unit to ensure that the latest AV/NIDS database has been downloaded and installed on your system - if required, enable the "Allow Push Update" option.