Discovered: January 29, 2002
Updated: February 13, 2007 11:51:29 AM
Type: Virus
To remove this virus, repair files that are detected as W32.HLLP.Gosusub, remove the value that the virus added to the registry, and remove the text that it added to the System.ini file.
To remove the virus:
- Run LiveUpdate to make sure that you have the most recent virus definitions.
- Start Norton AntiVirus (NAV), and make sure that NAV is configured to scan all files. For instructions on how to do this, read the document How to configure Norton AntiVirus to scan all files.
- Run a full system scan.
- If any files are detected as infected by W32.HLLP.Gosusub, click Repair. Files that cannot be repaired, or that no longer function after you try to repair them, should be replaced from a clean backup or reinstalled.
To edit the registry:
CAUTION: We strongly recommend that you back up the registry before you make any changes to it. Incorrect changes to the registry can result in permanent data loss or corrupted files. Modify only the keys that are specified. Read the document
How to back up the Windows registry for instructions.
- Click Start, and click Run. The Run dialog box appears.
- Type regedit and then click OK. The Registry Editor opens.
- Navigate to the following key:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
- In the right pane, delete the following value:
win386 C:\WINDOWS\win386.exe
- Click Registry, and then click Exit
To edit the System.ini file:
Follow these steps only if you are running Windows 95/98/Me.
- Click Start, and click Run.
- Type the following, and then click OK:
edit c:\windows\system.ini
The MS-DOS Editor opens.
NOTE: If Windows is installed in a different location, make the appropriate path substitution.
- Locate the line that begins with shell=explorer.exe
- Position the cursor immediately to the right of the ".exe" in "explorer.exe"
- Delete the text win386.exe
The line should now look like:
shell=explorer.exe
NOTE: Some computers may have an entry other than Explorer.exe after shell=. If this is the case and you are running an alternative Windows shell, then change this line to shell=explorer.exe for now. You can change it back to your preferred shell after you have finished this procedure.
- Click File, click Exit, and then click Yes when you are prompted to save the changes.
Writeup By: Atli Gudmundsson