Summary

Summary
Action
More Information
| Protection available since | 17 November 2003 05:45:22 (GMT) |
|---|---|
| Last updated | 24 June 2005 18:09:23 (GMT) |
| Detected by | All Sophos products |
- Free virus, spyware, and adware scan
- Test your existing anti-virus protection
- Find threats your anti-virus missed
Action

Summary
Action
More Information
Please follow the instructions for removing worms.
Please read the instructions on how to remove the W32/Opaserv-V worm and ensure your system is not vulnerable to reinfection.
More Information
W32/Opaserv-V is a worm which spreads by copying itself to network shares.
The worm drops copies of itself to the Windows folder as Banda!, Podre!! and speedy.pif, then adds an entry to the registry at
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\Spees3
to run itself on system restart.
The worm attempts to copy itself to the Windows folder on networked computers with open shared drives. The worm then modifies the win.ini on the remote machine to ensure it will be run on system restart.
W32/Opaserv-V also attempts to update itself periodically from a pre-configured website.
