TrendLabs Malware Blog
Glossary
TrendWatch
TrendLabs Twitter
WORM_OPASERV.M
Overview

Malware type: Worm

Aliases: Trojan.Win32.OpaKill.a (Kaspersky), W32.Opaserv.K.Worm (Symantec), Worm/OpaSoft.G (Avira), W32/Opaserv-I (Sophos),

In the wild: No

Destructive: Yes

Language: English

Platform: Windows 95, 98, ME, NT, 2000, XP, Server 2003

Encrypted: No

Overall risk rating:


Reported infections:

Damage potential:

High

Distribution potential:

High

Infection Channel 1 : Propagates via network shares


Infection Channel 2 : Propagates via software vulnerabilities


Description: 

This destructive, memory-resident worm, a member of the OPASERV family of worms, propagates via shared network drives by taking advantage of the Share Level Password vulnerability. This vulnerability enables malicious users to access shared drives, as discussed in Microsoft Security Bulletin MS00-072.

This worm deletes files, overwrites the boot sector, and destroys the CMOS, a critical system element which holds hardware configuration and initialization settings. These payloads leave affected systems practically unusable.

Its destructive payloads are executed when the system date is between December 24 to 31 or when the year is greater than 2002.

For additional information about this threat, see:
Solution
Technical Details

Description created: Jan. 2, 2003 3:01:22 PM GMT -0800

Search a new malware

Tell us how we did. Take our quick survey.