Sophos

W32/Opaserv-I

Aliases
  • Trojan.Win32.KillWin.m
  • W95/Opaserv.worm.F
  • W32/Opaserv.worm.m
  • W32.Opaserv.K.Worm
  • TROJ_WINKILL.A
Category
Type
What to do
Prevalence low high

Summary

 
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Read instructions on how to remove the W32/Opaserv-I worm and ensure your system is not vulnerable to reinfection.

More Information

W32/Opaserv-I is a network-aware worm. W32/Opaserv-I tries to locate Windows network shares on computers which are accessible across the internet. It then copies itself to those computers, placing itself in the Windows folder in a file called mqbkup.exe.

W32/Opaserv-I creates the registry entry:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
mqbkup =<Windows folder>\mqbkup.exe

This automatically launches the worm every time you log on.

The worm also adds the line run=<Windows folder>\mqbkup.exe to your WIN.INI file. This is intended to launch the worm every time you start Windows.

W32/Opaserv-I drops Qzap-248.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer