Symantec.com > Security Response > Threats and Risks > W32.Mypics.Worm.36352

W32.Mypics.Worm.36352 - Removal

Risk Level 1: Very Low

Printer Friendly Page

Discovered: May 8, 2000
Updated: February 13, 2007 11:56:25 AM
Also Known As: W32.Mypics.Worm
Type: Worm


To remove this worm:
  1. End the Pictures.exe task by pressing Ctrl+Alt+Delete once. In the list, select "Pictures" and then click End Task.
  2. Remove the following registry entries:

    HKEY_LOCAL_MACHINE\Software\Microsoft\Windows\CurrentVersion\RunServices= C:\Pictures.exe
    HKEY_LOCAL_MACHINE\Software\Microsoft\WindowsNT\Windows\RunServices= C:\Pictures.exe

  3. Check whether the Autoexec.bat file has been modified (this will only occur if the computer's system clock is set to year 2000). If so, delete Autoexec.bat and restore an original copy from backup.
  4. Check whether the Cbios.com file exists (this file will only exist if the computers system clock is set to year 2000). If so, delete the Cbios.com file.
  5. In the root of C:, look for the Picture.exe file and delete it.
  6. The worm alters the home page in the Microsoft Internet Explorer browser. You will need to restore the original home page.


Writeup By: Edric Ta
Search by name
Example: W32.Beagle.AG@mm
Windows 7
Windows Vista Security