Remove Olmi. Description and removal instructions

 
Title: Olmi

Type: Worms
Severity scale:Olmi severity is 68  (68 / 100)
 
Olmi is a rapidly spreading Internet worm that propagates through instant messages, IRC chats, file sharing networks, e-mails with malicious attachments, weakly protected network shares, malicious backdoors and by exploiting known system and software vulnerabilities.

Once executed, the parasite secretly installs itself to the system and runs a spreading routine. Olmi sends copies of itself to contacts in the Windows Address Book and random, generated addresses. The worm searches for opened instant messages and sends replies containing malicious links. It uses Kazaa, eDonkey, LimeWire, Warez P2P, iMesh and Morpheus peer-to-peer applications to share infected files across popular file sharing networks. Furthermore, Olmi spreads through IRC chats, weakly protected network shares by picking common user names and passwords, and via backdoors left by some widely spread threats.

The worm's payload is comprised of several harmful functions. Olmi opens a back door providing the attacker with unauthorized remote access to the compromised computer. It allows the intruder to download arbitrary files, perform denial of service (DoS) attacks, uninstall or update the parasite. Olmi also terminates running antiviruses, firewalls and other security-related programs. It can also remove some installed parasites.

Olmi runs on every Windows startup and every time the user runs an executable file.


Olmi properties:
• Allows remote user connection
• Connects itself to the internet
• Hides from the user
• Stays resident in background

Automatic Olmi removal:

remover for Olmi

Olmi manual removal:

Kill processes:
[X1].exe
Delete registry values:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run\[X2]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\[X2]
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Runservices\[X2]
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\Shell\Open\Command\(Default)=%Windir%\[X1].exe %1 %*
Delete files:
[X1].exe
Misc:
[X1] is a non-English character very similar to the C letter.
[X2] is a combination of meaningless characters.

The [X1].exe ("c.exe") file can be found in the main Windows folder C:\Windows or C:\Winnt.

Other programs to remove Olmi:

• Malwarebytes Anti Malware - Review - Download
• Malwarebytes Anti Malware - Review - Download
• Windows Defender - Review - Download

Information added: 27/04/06
Information updated: 27/04/06

Additional resources related to Olmi:

Attention: If you know or you have a website or page about Olmi removal, feel free to add a link to this list: add url




more resources

Post Comment:

Attention: Use this form only if you have additional information about Olmi parasite, its removal instructions, additional resources or behavior. By clicking "post comment" button you agree not to post any copyrighted, unlawful, harmful, threatening, abusive, harassing, defamatory, vulgar, obscene, profane, hateful, racially, ethnically or otherwise objectionable material of any kind.



Enter security code:

Latest spyware news:
Similar parasites: