Eurosol 6.0
(Trojan.Win32.Eurosol.60)

by -=WMP=-

Made in Russia






Server:
dropped file:
c:\WINDOWS\Netbios32.exe 

size: 216 KB

port: 1033, 14100 TCP

startup:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run "SysTray32" 
c:\windows\system.ini, [boot] "shell" 


Added:
c:\WINDOWS\sttask.dat 
c:\WINDOWS\sttl.dat 
c:\WINDOWS\stup.dat 

MegaSecurity