Home Malware Programs Worms Imav

Imav

Posted: March 28, 2006

Imav is a worm that spreads through ICQ instant messages containing links to copies of the worm. Once the user follows such a link, Imav shows an image and installs itself to the computer. The worm disables essential services of installed antiviruses, firewalls and other security-related software, corrupts such software installations and removes related files. Imav lowers security settings by preventing installed antiviruses from running on computer startup. The spyware also blocks access to security-related Internet resources. It may download from the Internet and execute arbitrary files. Imav automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 __dwn_sp.exe
    2 _dwn.exe
    3 im_1.exe
    4 im_2.exe
    5 ~[X].exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSOFTWAREMicrosoftIMEFirstRun=1HKEY_CURRENT_USERSOFTWAREMicrosoftWindowsCurrentVersionRunim_autorn
Loading...