Summary

Summary
Action
More Information
| Detected by | All Sophos products |
|---|---|
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Read instructions on how to remove the W32/Opaserv-I worm and ensure your system is not vulnerable to reinfection.
More Information
W32/Opaserv-I is a network-aware worm. W32/Opaserv-I tries to locate Windows network shares on computers which are accessible across the internet. It then copies itself to those computers, placing itself in the Windows folder in a file called mqbkup.exe.
W32/Opaserv-I creates the registry entry:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
mqbkup =<Windows folder>\mqbkup.exe
This automatically launches the worm every time you log on.
The worm also adds the line run=<Windows folder>\mqbkup.exe to your WIN.INI file. This is intended to launch the worm every time you start Windows.
W32/Opaserv-I drops Qzap-248.
