Found a virus - not sure of importance of infected file....

dlk9s

Junior Member
Jun 22, 2001
7
0
0
I just ran Norton Antivirus and it found a virus which it could not clean in the file "removeit.hta" in the root directory on C:. It has quarantined it, so it looks to be safe for now, but I am not sure what this file is for. Anyone out there know? I suppose I should probably delete it either way, since I can't clean it, but is it something I should figure out how to replace?

Thanks,
Dan
 

Allanv

Senior member
May 29, 2001
905
0
0
its the KAK worm virus look for it on symantic site or norton it will tell you how to remove also do you know how to find your email sygnature in outlook cus if its in there you are sending it to everyone in your address book


it hides in your win.ini file and yer startup as well ( i think) but check out symantic and do a search for kak worm

hope it helps i dont think you need to format for this one
 

dlk9s

Junior Member
Jun 22, 2001
7
0
0
Thanks for the response. I probably should've given a little more info about the virus that was found. Here is the exact wording from the log that Norton Antivirus created:

The file
C:\removeit.hta
is infected with the JS.Seeker virus.
This file was quarantined.

I'm not concerned about any problems with Outlook because I don't use it. I have it, I just don't use it (although I will check to be sure there's no one in the address book). This is the only instance of any virus that was found on my computer. I'm assuming win.ini is checked, too. It hasn't caused any problems and I'm guessing I can just remove the file. Just wanted to see if anyone with any more knowledge than me knew about this file and/or this virus.

...just looked at the file again and it appears to be an HTML application. I'm thinking that deleting the file is the best course of action.

--Dan
 

dlk9s

Junior Member
Jun 22, 2001
7
0
0
Allanv -

Thank you for reminding me to check Symantec's website. I just did that and it looks like this virus is pretty harmless. Here's a link if anyone is interested: http://www.symantec.com/avcenter/venc/data/js.seeker.html

Looks like it is something that changes your default home page and search pages of your web browser. I'm guessing it's from some porno site that mystically pops up when you're doing a search for something completely different. Like if you go to www.whitehouse.com instead of .gov. I hate how sometimes it takes me an hour to find the info I'm looking for online, but I can find porn in 10 seconds.

Thanks for the help.