Sophos

W32/LameYear-A

Category
Type
What to do
Prevalence low high

Summary

 
Affected operating systems Windows
Characteristics
  • Installs itself in the registry
Protection available since 15 June 2005 21:12:09 (GMT)
Last updated 18 January 2006 13:31:23 (GMT)
Detected by All Sophos products
  • Free virus, spyware, and adware scan
  • Test your existing anti-virus protection
  • Find threats your anti-virus missed

Action

Please follow the instructions for removing worms.

Windows NT/2000/XP/2003

In Windows NT/2000/XP/2003 you will also need to edit the following registry entry. The removal of this entry is optional in Windows 95/98/Me. Please read the warning about editing the registry.

At the taskbar, click Start|Run. Type 'Regedit' and press Return. The registry editor opens.

Before you edit the registry, you should make a backup. On the 'Registry' menu, click 'Export Registry File'. In the 'Export range' panel, click 'All', then save your registry as Backup.

Locate the HKEY_LOCAL_MACHINE entry:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Load
<Windows system folder>\MyGame.exe

and delete it if it exists.

Close the registry editor.

More Information

W32/LameYear-A is a worm for the Windows platform.

When run, W32/LameYear-A copies itself to the following locations:

A:\GameOfTheYear.exe
C:\GameOfTheYear.exe
<Windows system folder>\MyGame.exe

The worm sets the following registry entry in order to run each time a user logs on:

HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Load
<Windows system folder>\MyGame.exe

W32/LameYear-A waits a random number of seconds and then attempts to restore the worm copies and registry entries.

The worm searches the hard disk for files with the EXE file extension and creates worm copies in altername locations using the filenames found - easily leading to worm copies being run where utilities were intended.

RSS|Atom
Get reports about the latest virus and spyware threats delivered to your computer