Olmi details

  • Description

    Olmi is a rapidly spreading Internet worm that propagates through instant messages, IRC chats, file sharing networks, e-mails with malicious attachments, weakly protected network shares, malicious backdoors and by exploiting known system and software vulnerabilities. Once executed, the parasite secretly installs itself to the system and runs a spreading routine. Olmi sends copies of itself to contacts in the Windows Address Book and random, generated addresses. The worm searches for opened instant messages and sends replies containing malicious links. It uses Kazaa, eDonkey, LimeWire, Warez P2P, iMesh and Morpheus peer-to-peer applications to share infected files across popular file sharing networks. Furthermore, Olmi spreads through IRC chats, weakly protected network shares by picking common user names and passwords, and via backdoors left by some widely spread threats. The worm’s payload is comprised of several harmful functions. Olmi opens a back door providing the attacker with unauthorized remote access to the compromised computer. It allows the intruder to download arbitrary files, perform denial of service (DoS) attacks, uninstall or update the parasite. Olmi also terminates running antiviruses, firewalls and other security-related programs. It can also remove some installed parasites. Olmi runs on every Windows startup and every time the user runs an executable file.