Summary

Summary
Action
More Information
| Included in our products from | January 2003 (3.65) |
|---|---|
| Detected by | All Sophos products |
Action

Summary
Action
More Information
Read instructions on how to remove the W32/Opaserv-G worm and ensure your system is not vulnerable to reinfection.
More Information
W32/Opaserv-G is a worm which spreads by copying itself to the Windows folder on drive C: and to network shares as INSTIT.BAT. The worm then adds an entry to WIN.INI on the shared drive so that INSTIT.BAT is run when Windows is started.
On the infected computer W32/Opaserv-G copies itself to the Windows folder as INSTIT.BAT and adds an entry to the registry at:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
so that the worm is run when Windows is started.
W32/Opaserv-G may also attempt to contact several websites in Brazil.
