New worm, Opasoft, targets Windows systems

A new worm that targets machines running Microsoft Corp.'s Windows 95, 98, and ME operating systems is spreading, according to virus alerts posted by several leading antivirus software makers. Named "Opasoft", "W32/Opasoft" or "Opaserv," the new virus takes advantage of a common Windows application program interface (API) and loose security practices to spread over local and wide-area networks.

Unlike other worms that spread from computer to computer over the Internet by way of infected e-mail messages, Opasoft takes advantage of the Network Basic Input/Output System (NETBIOS), an API containing functions used to send and receive data over Microsoft networks, according to the announcements.

Once it hits a machine, Opasoft scans the infected computer's network for other machines to attack. When a vulnerable machine is located, the worm checks to see if the C: drive of that machine has been shared with other network computers and can be accessed, according to the alerts.

If it can access the C: drive, Opasoft places a copy of itself on that machine, then alters the win.ini file so that the worm is run the next time the machine is restarted.

If the shared directory on the computer is password-protected, the Opasoft worm will attempt to enter that folder by trying single-character passwords.

Office and home computer networks that are using any of the affected Windows operating systems, and that have enabled file sharing between machines on the network are particularly vulnerable to infection by Opasoft. This is especially true if passwords have not been established to protect access to shared directories on the network, according to a statement by security company Kaspersky Labs Ltd.

Although it is not known whether or not the Opasoft worm damages any files on the machines it infects, the worm does open a back door from the machine to a Web site, www.opasoft.com, from which updated versions of the worm and other script files are downloaded.

The Opasoft Web page was not accessible as of Friday afternoon.

For computers infected with the worm, users are instructed to delete the worm and make necessary modifications to the win.ini file.

All users are asked to install "strong" passwords for any shared folders on their computer -- combinations of three or more letters, numbers, and special characters.

Join the newsletter!

Or
Error: Please check your email address.
Rocket to Success - Your 10 Tips for Smarter ERP System Selection
Keep up with the latest tech news, reviews and previews by subscribing to the Good Gear Guide newsletter.

Paul Roberts

PC World
Show Comments

Brand Post

Most Popular Reviews

Latest Articles

Resources

PCW Evaluation Team

Andrew Teoh

Brother MFC-L9570CDW Multifunction Printer

Touch screen visibility and operation was great and easy to navigate. Each menu and sub-menu was in an understandable order and category

Louise Coady

Brother MFC-L9570CDW Multifunction Printer

The printer was convenient, produced clear and vibrant images and was very easy to use

Edwina Hargreaves

WD My Cloud Home

I would recommend this device for families and small businesses who want one safe place to store all their important digital content and a way to easily share it with friends, family, business partners, or customers.

Walid Mikhael

Brother QL-820NWB Professional Label Printer

It’s easy to set up, it’s compact and quiet when printing and to top if off, the print quality is excellent. This is hands down the best printer I’ve used for printing labels.

Ben Ramsden

Sharp PN-40TC1 Huddle Board

Brainstorming, innovation, problem solving, and negotiation have all become much more productive and valuable if people can easily collaborate in real time with minimal friction.

Sarah Ieroianni

Brother QL-820NWB Professional Label Printer

The print quality also does not disappoint, it’s clear, bold, doesn’t smudge and the text is perfectly sized.

Featured Content

Product Launch Showcase

Latest Jobs

Don’t have an account? Sign up here

Don't have an account? Sign up now

Forgot password?