Download TrojanHunter Now
Free 30-day trial!
Latest TrojanHunter Version:
TrojanHunter 5.0
Order Now
License file delivered within minutes.
Welcome, Guest. Please Login or Register.
Dec 1st, 2008, 8:31pm
   Mischel Internet Security Forum
   Malware
   Trojans
(Moderators: Helena, Gavin_Coe, Magnus)
   Opaserv.Y
« Previous topic | Next topic »
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print
   Author  Topic: Opaserv.Y  (Read 393 times)
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Opaserv.Y
« on: Sep 23rd, 2003, 9:07pm »
Quote Quote  Modify Modify

Opaserv.Y spreads directly through the Internet by looking for computers to infect. In order to do this, it checks if port 137 is open and unprotected. If it is, Opaserv.Y gets into the computer through port 139 and copies itself in the C:\Windows directory under the name Speedy.scr.
 
At the same time, it generates several entries in the Windows Registry in order to ensure that it is run whenever the computer is started up. If the infected computer is connected to a network, Opaserv.Y will exploit the Windows vulnerability known as Share Level Password - based on an inconsistency in the protection of network shares in the operating systems Windows Me/98/95- in order to spread to the rest of the computers in the network.
 
Up until now, PandaLabs has detected two versions of Opaserv.Y. The difference between the two is the compression utility they are packed with. Another characteristic of this malicious code is that if the user runs the file carrying the worm from an MS-DOS window, instead of displaying the following message: "This program requires MS Windows", one of the following three will be displayed:
 
- Telefonica ganhe menos e faca mais!!
- Queremos melhores servicos da SPEEDY
- Melhorem o servico Speed seus FDPS!!  

Best upgrade stuff now...
IP Logged

... but crap arrives pretty much straight away.
claire
Stole All the Forum Stars
********



carpe diem

   


Gender: female
Posts: 3479
Re: Opaserv.Y
« Reply #1 on: Sep 23rd, 2003, 9:32pm »
Quote Quote  Modify Modify

Many thanks Ian for your infos about the various nasties Smiley
IP Logged

Claire
Ian
Stole All the Forum Stars
********



Good things come to those who wait ...

   


Posts: 2913
Re: Opaserv.Y
« Reply #2 on: Sep 23rd, 2003, 10:19pm »
Quote Quote  Modify Modify

Forewarned is forearmed, as they say...
IP Logged

... but crap arrives pretty much straight away.
Pages: 1  Reply Reply  Notify of replies Notify of replies   Send Topic Send Topic   Print Print

« Previous topic | Next topic »
Search
Members
Login
Register