Forum Home
Press F1
 
Thread ID: 32510 2003-04-21 00:15:00 W32Opaserve fatpat (3639) Press F1
Post ID Timestamp Content User
137377 2003-04-21 00:15:00 My computer was infected with the W32 Opaserve virus and in desparation used the Symantec online help A$119 to remove the virus.
Virus has returned and is not in the previous locations. Only returns when i am connected and to date only corrupts the printer file.
Starts with brasil, then marcos, then sscrree, then WIN.INI file.
Have used the Microsoft fix and the Symantec removal tool and still it comes.
Any suggestions.
fatpat (3639)
137378 2003-04-21 00:19:00 I had this problem at work on 1 PC. I went into the registry and searched for opaserve and brasil, and deleted them all. Nortons removal instructions had not worked for me either. wotz (335)
137379 2003-04-21 00:22:00 $119 ouch!

see here (www.symantec.com).

clean it out, update your antivirus protection and fix the holes so you don't get it again.
tweak'e (174)
137380 2003-04-21 01:32:00 Follow the manual removal steps and make sure your unplugged from any network or the internet.

Then go to here (service1.symantec.com) to stop reinfection.
PoWa (203)
137381 2003-04-21 04:32:00 www.trendmicro.com

HTH

Murray P
Murray P (44)
137382 2003-04-21 04:41:00 Two things...1/ turn off system restore if xp/2k/ME, clean then turn restore back on and make a restore point. NOTE when system restore is turned off, it deletes all restore points.
2/ Visit online virus check/clean at http://housecall.trendmicro.com/
Pheonix (280)
137383 2003-04-22 09:11:00 I have downloaded the Microsoft fix and installed it. I have downloaded the Symantec fix and removal tool and run the tool in safe mode and in ordinary mode. I have disconnected the other computer in the network. I have the latest virus updates and run Norton 2002 every night.
The virus only comes when i am connected to the internet.
I have searched HKEY_local_machine looking for indication of the infection and gone into the registry to search the run command everything is as it should be.
If it is hiding in my temporary files why is Norton not finding it?
fatpat (3639)
137384 2003-04-22 10:38:00 this may seem like a barstard question buts theres a method in my madness (or is that maddness in my method ??) ........

>The virus only comes when i am connected to the internet

How do you know your infected? details please. :)
tweak'e (174)
137385 2003-04-22 10:40:00 do you have a firewall???? stu140103 (137)
137386 2003-04-22 11:02:00 Hi

The worm has a back door component, block it with your firewall. It may be updating itself by calling "home".

Had a similar virus/worm recently. It took several attempts to clean it off a win98 machine. In the end I deleted the temp folder in DOS and while still in DOS ran the TrendMicro cleaner for the particular nasty. I think you need the exact cleaner program so you need to be specific re version of virus/worm.

In my case I found I had been infected by 2 varients of the thing and the file name of the files it dropped into the temp folder changed at random. Just a guess but, I think the 2nd varient was called up (if thats the right term) by the first, either as a dorment file brought to life or downloaded. So at first I was try to clean one without knowing that the 2nd was working away.

HTH & wish u success

Murray P
Murray P (44)
1