PDA

View Full Version : vicious worm



Miromiric
10-10-2004, 11:10 PM
i get the process srv32.exe opened, which takes 99% of my processor. i found that this process is linked with opaserv worm, but removal tool for it doesnt affect it. i tried with like 5 different antiviruses.
does anyone have any experience with this?

jesus
11-10-2004, 12:04 AM
seems to be a cunt to remove. get the latest windows update if you havent already. could be this one http://www.microsoft.com/technet/security/bulletin/MS00-072.mspx

try avg if you havent http://free.grisoft.com/freeweb.php/doc/2/lng/us/tpl/v5


"If you are on a network, or have a full time connection to the Internet such as DSL or Cable modem, you must disconnect the computer from the network and the Internet. Disable sharing before reconnecting computers to the network or to the internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, you must remove all shares, clean all computers on the network, patch all systems, and update definitions on all computers before you reconnect to the network or reenable shares. If you are on a network, or have a full time connection to the Internet such as DSL or Cable modem, you must disconnect the computer from the network and the Internet. Disable sharing before reconnecting computers to the network or to the internet. Because this worm spreads by using shared folders on networked computers, to ensure that the worm does not reinfect the computer after it has been removed, you must remove all shares, clean all computers on the network, patch all systems, and update definitions on all computers before you reconnect to the network or reenable shares. " http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2000091415173339

try http://housecall.antivirus.com/housecall/start_corp.asp to use the online scanner which should be able to disinfect the system. these too http://www.avast.com/eng/download/progr...eaner.html or Stinger from http://vil.nai.com/vil/averttools.asp (free tools).

another removal tool - ftp://ftp.europe.f-secure.com/anti-virus/tools/opastool.zip + instructions - ftp://ftp.europe.f-secure.com/anti-virus/tools/opastool.txt

hopefully you havent tryed all these

jesus
11-10-2004, 12:08 AM
or this http://www.sophos.com/support/cleaners/opasegui.com

Miromiric
11-10-2004, 08:19 AM
thank you jesus, your love truly enlightens my soul. thank you for our everyday bread and wine, but this doesnt help. if you can solve this for me i promise i will go to church every sunday and i wont be doin that in my bathroom anymore.

dan the acid man
11-10-2004, 09:08 AM
thank you jesus, your love truly enlightens my soul. thank you for our everyday bread and wine, but this doesnt help. if you can solve this for me i promise i will go to church every sunday and i wont be doin that in my bathroom anymore.

hahaha :lol: :lol:

im out of ideas, sorry, i'll have a look around at work today, see if i can find any info out

jesus
11-10-2004, 07:34 PM
find out what variant it is using some virus scanner then search for that in google. try this too - http://www.trendmicro.com/vinfo/virusencyclo/default5.asp?VName=WORM_OPASERV.S. or get hijackthis http://www.spychecker.com/download/download_hijackthis.html
save the log and post it here - http://castlecops.com/forum67.html someone can usually help.

278d7e64a374de26f==