Computing.Net > Forums > Security and Virus > opaserv worm

Computer Problems? Computing.Net has over 1,000,000 posts about all things technology related! Over 90% answered within 24 hours! Click here to start participating now! Also, be sure to check out the New User Guide.

opaserv worm

Reply to Message Icon

Name: cmitcham
Date: January 2, 2003 at 07:31:17 Pacific
OS: win98
CPU/Ram: PII450/128Mb
Comment:

all the fixes i can find for this worm assume i can edit registry settings and delete files. is there any fix once the worm locks my machine with the "...violation of the digital millinium copyright..." screen?

the mcafee site talks about damage to the cmos. is this why although i can set it to boot cdrom first, it wont??

thanks for any help. it's my wife's pc, and i'm in deep doodoo.



Sponsored Link
Ads by Google

Response Number 1
Name: Tom41
Date: January 2, 2003 at 07:56:50 Pacific
Reply:

If you got that message, everything on your machine is gone...

You will have to enter Setup and restore all the CMOS settings then format and re-install Windows

http://securityresponse.symantec.com/avcenter/venc/data/w32.opaserv.k.worm.html


0

Response Number 2
Name: cmitcham
Date: January 2, 2003 at 08:51:23 Pacific
Reply:

thanks for the quick reply, allbeit bad news.

2 questions, if i might:

1. not that it matters now, but do you know how it decides when to switch from annoying worm with brasil, alevir, scrscv (i found them all on my other computer) to destructive (with mslicenf)? apparently, at least on my surviving machine, the worm's edit of the win.ini isn't exact with the syntax, so i have been seeing messages on boot about "mising c:\windows\brasil.pif as specified in the win.ini file" for weeks.

2. i admit i give NO attention to security, but i thought i was kinda safe by binding by network card to MS file and print sharing, as well as client for ms networks, but making sure my dial-up adapter was not. obviously, i was wrong.


0

Response Number 3
Name: capt
Date: January 2, 2003 at 09:45:03 Pacific
Reply:

Do a search at the top of the page using security section and there are all kinds of information about opaserve. Brad Peterson has done a lot of research and provided the most helpfull information. Just a few entries down is another request for help dealing with the new destructive version that you unfortunetly picked up. Brasil files are a sure sign of the worm, and you probably have gone to Symantec/Trend Micro and seen that it must be deleted. You must use your firewall to prevent reinfection. Be sure to check and if necessary clean out all your shared printing files. Each computer must be isolated from the other computers in the network to clean it. It is a very persistant pest, and is searching for any computer that still has part of the worm so it can spread! Take care and all the best!


0

Response Number 4
Name: Brad Peterson
Date: January 2, 2003 at 12:31:20 Pacific
Reply:

For a really nice Opaserv.K description, check out this post

http://www.computing.net/security/wwwboard/forum/3784.html

For a even better Opaserv writeup, that will answer all your questions, including the "how does Opaserv pick which variant to use" question, check out this post.

http://www.computing.net/security/wwwboard/forum/3289.html

You need to check out that last one for sure. You MUST protect yourself from getting reinfected so that this doesn't happen again

Brad Peterson
b_peterson@yahoo.com


0

Response Number 5
Name: cmitcham
Date: January 3, 2003 at 07:26:49 Pacific
Reply:

var people_thanking_brad += ;


0

Related Posts

See More



Response Number 6
Name: TOm
Date: January 3, 2003 at 11:49:49 Pacific
Reply:

Hello when i got read of the yaha virus all my documents wre deleted
how can i restre all of them
pl people tell me how can i restore them


0

Sponsored Link
Ads by Google
Reply to Message Icon






Post Locked

This post is quite old and has been locked from receiving new replies. Please create a new posting instead.


Go to Security and Virus Forum Home


Sponsored links

Ads by Google


Results for: opaserv worm

Solving The OPASERV.WORM www.computing.net/answers/security/solving-the-opaservworm/2897.html

Opaserv.worm scrsvr.exe virus fix www.computing.net/answers/security/opaservworm-scrsvrexe-virus-fix/2548.html

W32.Opaserv.Worm virus (scrsvr.exe) www.computing.net/answers/security/w32opaservworm-virus-scrsvrexe/2816.html