W32/Opaserv-G

Category: Viruses and Spyware Protection available since:19 Mar 2003 00:00:00 (GMT)
Type: Win32 worm Last Updated:19 Jun 2003 00:00:00 (GMT)
Prevalence: Several Reports

Download Download our free Virus Removal Tool - Find and remove threats your antivirus missed

W32/Opaserv-G is a worm which spreads by copying itself to the Windows folder on drive C: and to network shares as INSTIT.BAT. The worm then adds an entry to WIN.INI on the shared drive so that INSTIT.BAT is run when Windows is started.

On the infected computer W32/Opaserv-G copies itself to the Windows folder as INSTIT.BAT and adds an entry to the registry at:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm is run when Windows is started.

W32/Opaserv-G may also attempt to contact several websites in Brazil.

download Try Sophos products for free
Download now