DESCRIPTION:
The Opaserv-A is a Win32 worm that will spread through network shares.
A file called Scrsvr.Exe or Alevir.Exe will be created in the Windows
subdirectory (folder) once the worm is executed.
REMOVAL INSTRUCTIONS
- Run REGEDIT and delete the entries:
- HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
ScrSvr=C:\WINDOWS\ScrSvr.exe
-
HKLM\Software\Microsoft\Windows\CurrentVersion\Run\
alevir=C:\WINDOWS\alevir.exe
- For Windows 95, 98 or ME you will also have to edit WIN.INI.
For Windows ME run "SYSEDIT" to edit WIN.INI.
Type "Start" click "Run" and type:
EDIT C:\WINDOWS\WIN.INI
Look for:
run= c:\ScrSvr.exe
run= c:\temp.ini
or similar and delete the line. Save WIN.INI before exiting.
- Run VBUSTER.EXE and use it to delete all occurances of the worm.
Other Strains of the Opaserv Worm
Removal instructions of other strains of the Opaserv Worm are similar except that the active infected file in the Windows subdirectory has a different name. Follow the same instructions listed above but substitute the name of the file with the new name.