Discovered: May 21, 2001
Updated: February 13, 2007 11:46:11 AM
Also Known As: Trojan.Win32.Eurosol
Type: Trojan Horse
To remove this Trojan, attempt to repair files detected as Trojan.Eurosol, restore the shell= line, and delete the keys that it added to the registry.
To scan with Norton AntiVirus:
- Run LiveUpdate to make sure that you have the most recent virus definitions.
- Start Norton AntiVirus (NAV), and then run a full system scan, making sure that NAV is set to scan all files.
- If any files are detected as Trojan.Eurosol, choose Repair. If any files cannot be repaired, choose Delete.
To edit the System.ini file:
- Click Start, and click Run.
- Type the following and then click OK.
edit c:\windows\system.ini
The MS-DOS Editor opens.
NOTE: If you have installed Windows to a different location, make the appropriate substitution.
- In the [boot] section of the file, look for an entry similar to the following:
shell=Explorer.exe <additional text added by Trojan>
- Delete all text (on the shell=Explorer.exe line only) that is to the right of Explorer.exe. When you are done, the line should read:
shell=Explorer.exe
- Click File, click Exit, and then click Yes when prompted to save the changes.
To edit the registry:
If ATGuard is installed on your system, you will need to reverse the registry modifications made by the Trojan horse.
CAUTION: We strongly recommend that you back up the system registry before making any changes. Incorrect changes to the registry could result in permanent data loss or corrupted files. Please make sure you modify only the keys specified. Please see the document
How to back up the Windows registry before proceeding.
- Click Start, and click Run. The Run dialog box appears.
- Type regedit and then click OK. The Registry Editor opens.
- Navigate to and delete the following keys:
HKEY_LOCAL_MACHINE\Software\WRQ\IAM\FirewallObjects\Applications\NETBIO32.EXE
HKEY_LOCAL_MACHINE\Software\WRQ\IAM\FirewallObjects\IPHosts\ftp.hotbox.ru
HKEY_LOCAL_MACHINE\Software\WRQ\IAM\FirewallObjects\IPFilterRules\Rule#
(where Rule# is the Rule key which refers to the information related to ftp.hotbox.ru.)
- Click Registry, and then click Exit to save the changes.
Writeup By: Brian Ewell