Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Read instructions on how to remove the W32/Opaserv-G worm and ensure your system is not vulnerable to reinfection.
More Information
W32/Opaserv-G is a worm which spreads by copying itself to the Windows folder on drive C: and to network shares as INSTIT.BAT. The worm then adds an entry to WIN.INI on the shared drive so that INSTIT.BAT is run when Windows is started.
On the infected computer W32/Opaserv-G copies itself to the Windows folder as INSTIT.BAT and adds an entry to the registry at:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm is run when Windows is started.
W32/Opaserv-G may also attempt to contact several websites in Brazil.
