Threat Encyclopedia

Selected viruses, spyware, and other threats: sorted alphabetically

Win32/Opaserv.AF

Worm.Win32.Opasoft

Win32/Opaserv.AF is a variant of the worm Win32/Opaserv.A. It acts in Windows operating systems. It is represented by an executable file of PE format having length of 24064 bytes. The file is compressed by UPX utility. After it is decompressed, its length is 61 KB.

Note: In following text a symbolic inscription %windir% is used instead of the name of directory in which Windows operating system is installed. Of course, this may differ from installation to installation. The subdirectory System or System32 placed in %windir% has a name %system%.

It installs itself into the %windir% directory as a file speedy.bat. It assures its activation using system registry creating the item Spees2 with the value of %windir%\Speedy.bat in HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\Run.

There is following freely visible text string at the beginning of the body of the worm:

Telefonica ganhe menos e faca mais!!

NOD32 detects the worm Win32/Opaserv.AF using extended heuristics without upgrading. The detection using sample is added from version 1.518.

© 1992-2004 Eset s.r.o. All rights reserved. No part of this Encyclopedia may be reproduced, transmitted or used in any other way in any form or by any means without the prior permission.