Sophos

W32/Opaserv-V

Category
Type
What to do
Prevalence low high

Summary

 
Protection available since 17 November 2003 05:45:22 (GMT)
Last updated 24 June 2005 18:09:23 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Please read the instructions on how to remove the W32/Opaserv-V worm and ensure your system is not vulnerable to reinfection.

More Information

W32/Opaserv-V is a worm which spreads by copying itself to network shares.

The worm drops copies of itself to the Windows folder as Banda!, Podre!! and speedy.pif, then adds an entry to the registry at

HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Spees3

to run itself on system restart.

The worm attempts to copy itself to the Windows folder on networked computers with open shared drives. The worm then modifies the win.ini on the remote machine to ensure it will be run on system restart.

W32/Opaserv-V also attempts to update itself periodically from a pre-configured website.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer