Home Malware Programs Worms Yimp

Yimp

Posted: March 28, 2006

Yimp is an Internet worm, which spreads through instant messages sent using the AIM or Yahoo! Messenger application. The victim receives a message containing a link to a malicious executable. Once he or she clicks on a link and runs a file, the worm immediately installs itself to the computer. It initiates a spreading routine sending bogus messages to all the user's contacts and runs a payload. Yimp downloads from the Internet and executes potenitally harmful files, disables several computer services and blocks access to popular antivirus and security-related web sites. The worm automatically runs on every Windows startup.

File System Modifications

  • The following files were created in the system:
    # File Name
    1 opengld.exe

Registry Modifications

  • The following newly produced Registry Values are:
    HKEY..\..\..\..{RegistryKeys}HKEY_CURRENT_USERSoftwareMicrosoftWindowsCurrentVersionRunopengldriversHKEY_LOCAL_MACHINESOFTWAREMicrosoftWindowsCurrentVersionRunopengldriversHKEY_LOCAL_MACHINESYSTEMCurrentControlSetServicesSharedAccessStart=4HKEY_LOCAL_MACHINESYSTEMCurrentControlSetServiceswuauservStart=4

Related Posts

Loading...