Sophos

W32/Opaserv-G

Aliases
  • Worm.Win32.Opasoft
Category
Type
What to do
Prevalence low high

Summary

 
Included in our products from January 2003 (3.65)
Detected by All Sophos products

Action

Please follow the instructions for removing worms.

Read instructions on how to remove the W32/Opaserv-G worm and ensure your system is not vulnerable to reinfection.

More Information

W32/Opaserv-G is a worm which spreads by copying itself to the Windows folder on drive C: and to network shares as INSTIT.BAT. The worm then adds an entry to WIN.INI on the shared drive so that INSTIT.BAT is run when Windows is started.

On the infected computer W32/Opaserv-G copies itself to the Windows folder as INSTIT.BAT and adds an entry to the registry at:

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

so that the worm is run when Windows is started.

W32/Opaserv-G may also attempt to contact several websites in Brazil.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer