Virus-Alert Category 3

Devilfrank

Sehr aktiv
Symantec gibt Viren-Alarm der Stufe 3 heraus!
W32.Opaserv.Worm is a network-aware worm that attempts to replicate across open network shares. It copies itself to the remote computer as a file named Scrsvr.exe. This worm also attempts to download updates from wvv.opasoft.com, although the site may have already been shut down. Indicators of infection include:

The existence of the files Scrsin.dat and Scrsout.dat in the root of drive C. This indicates a local infection (that is, the worm was executed on the local computer).
The existence of the Tmp.ini file in the root of drive C. This indicates a remote infection (that is, the computer was infected by a remote host).
The registry key HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\Current Version\Run contains the string value ScrSvr or ScrSvrOld, which is set to c:\tmp.ini.


The complete Site here:
http://securityresponse.symantec.com/avcenter/venc/data/w32.opaserv.worm.html


Gruss Frank
 
Zurück
Oben