This is a read-only archive. No new posts or registrations. Privacy Page
Spyware / Malware / Virus Removal

Help Jk.seeker Virus

4 min read

This thread's last reply is from . Advice, software, and links below may be out of date — treat specific steps and download links with caution.

Looking for the outcome? Ask AI

I've run Spybot, Adaware and Norton. Norton Finds but cannot fix, quarantine or delete. Trojan finds nothing. Just ran HJT. Any help would be appreciated.

HJT Log:

Logfile of HijackThis v1.97.7
Scan saved at 7:11:37 PM, on 6/7/2004
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\csrss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Program Files\Norton SystemWorks\Norton AntiVirus\navapsvc.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Norton SystemWorks\Norton Utilities\NPROTECT.EXE
C:\PROGRA~1\NORTON~1\SPEEDD~1\nopdb.exe
C:\WINDOWS\System32\rmctrl.exe
C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
C:\WINDOWS\System32\wuauclt.exe
C:\WINDOWS\System32\svchost.exe
C:\Documents and Settings\Marc McTizic\Desktop\HJT\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer,SearchURL = http://www.yyep.com/search/search05.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.yyep.com/search/search05.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.yyep.com/search/search05.html
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\WINDOWS\SYSTEM\blank.htm
O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O2 - BHO: (no name) - {0CF0B8EE-6596-11D5-A98E-0003470BB48E} - C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PRO\CCHELPER.DLL
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\Program Files\Spybot - Search & Destroy\SDHelper.dll
O2 - BHO: (no name) - {724d43a9-0d85-11d4-9908-00400523e39a} - C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O2 - BHO: NAV Helper - {BDF3E430-B101-42AD-A544-FADC6B084872} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O3 - Toolbar: &RoboForm - {724d43a0-0d85-11d4-9908-00400523e39a} - C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL
O3 - Toolbar: Pa&nicware Pop-Up Stopper Pro - {B1E741E7-1E77-40D4-9FD8-51949B9CCBD0} - C:\PROGRAM FILES\PANICWARE\POP-UP STOPPER PRO\POPUPPRO.DLL
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_12_0.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O3 - Toolbar: Norton AntiVirus - {42CDD1BF-3FFB-4238-8AD1-7859DF00B1D6} - C:\Program Files\Norton SystemWorks\Norton AntiVirus\NavShExt.dll
O4 - HKLM\..\Run: [SystemTray] SysTray.Exe
O4 - HKLM\..\Run: [NeroCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [RemoteControl] C:\WINDOWS\System32\rmctrl.exe
O4 - HKLM\..\Run: [NAV Agent] C:\PROGRA~1\NORTON~1\NORTON~1\navapw32.exe
O4 - HKLM\..\Run: [THGuard] "C:\Program Files\TrojanHunter 3.9\THGuard.exe"
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [Symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXE
O4 - HKLM\..\RunOnce: [0000 - C:\Documents and Settings\Marc McTizic\Start Menu\Programs\HP DeskJet 930C Series v2.1] C:\WINDOWS\command.com /c rmdir "C:\Documents and Settings\Marc McTizic\Start Menu\Programs\HP DeskJet 930C Series v2.1"
O4 - Global Startup: Microsoft Broadband Networking.lnk = C:\Program Files\Microsoft Broadband Networking\MSBNTray.exe
O4 - Global Startup: Encoder Agent.lnk = C:\Program Files\Windows Media Components\Encoder\WMENCAGT.EXE
O8 - Extra context menu item: &2 Customize Menu - res://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL/ComCustomIEMenu.html
O8 - Extra context menu item: &5 Fill from Identity - res://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL/ComFillIdent.html
O8 - Extra context menu item: &7 Fill Forms - res://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL/ComFillForms.html
O8 - Extra context menu item: &8 Save Forms - res://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL/ComSavePass.html
O8 - Extra context menu item: &9 Robo Toolbar - res://C:\PROGRAM FILES\SIBER SYSTEMS\AI ROBOFORM\ROBOFORM.DLL/ComShowToolbar.html
O9 - Extra button: Fill Forms (HKLM)
O9 - Extra 'Tools' menuitem: &7 Fill Forms (HKLM)
O9 - Extra button: Fill Ident (HKLM)
O9 - Extra 'Tools' menuitem: &5 Fill from Identity (HKLM)
O9 - Extra button: Fill Pass (HKLM)
O9 - Extra 'Tools' menuitem: &6 Fill from Passcard (HKLM)
O9 - Extra button: Save Pass (HKLM)
O9 - Extra 'Tools' menuitem: &8 Save Forms (HKLM)
O9 - Extra button: Go Fill (HKLM)
O9 - Extra 'Tools' menuitem: &A Go && Fill from Passcard (HKLM)
O9 - Extra button: Login (HKLM)
O9 - Extra 'Tools' menuitem: &B Login (Go, FIll, Submit) (HKLM)
O9 - Extra button: Identities (HKLM)
O9 - Extra 'Tools' menuitem: &3 Edit Identities (HKLM)
O9 - Extra button: Passcards (HKLM)
O9 - Extra 'Tools' menuitem: &4 Edit Passcards (HKLM)
O9 - Extra button: RF toolbar (HKLM)
O9 - Extra 'Tools' menuitem: &9 Robo Toolbar (HKLM)
O9 - Extra button: Yahoo! Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Yahoo! Messenger (HKLM)
O9 - Extra button: Messenger (HKLM)
O9 - Extra 'Tools' menuitem: Windows Messenger (HKLM)
O16 - DPF: {02BF25D5-8C17-4B23-BC80-D3488ABDDC6B} (QuickTime Object) - http://www.apple.com/qtactivex/qtplugin.cab
O16 - DPF: {072D3F2E-5FB6-11D3-B461-00C04FA35A21} (CFForm Runtime) - http://public.ornl.gov/CFIDE/classes/CFJava.cab
O16 - DPF: {30528230-99F7-4BB4-88D8-FA1D4F56A2AB} (YInstStarter Class) - http://us.dl1.yimg.com/download.yahoo.com/…s/yinst0401.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a224.g.akamai.net/7/224/52/20010419…meInstaller.exe
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://www.pandasoftware.com/activescan/as5/asinst.cab
O16 - DPF: {9F1C11AA-197B-4942-BA54-47A8489BB47F} (Update Class) - http://v4.windowsupdate.microsoft.com/CAB/…8037.5343981481
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://download.macromedia.com/pub/shockwa…ash/swflash.cab
Did you run Disk Cleanup on this one? The problem could be in your temporary files. If that doesn't solve the problem then try booting into safe mode and then running norton. If those steps do not clear it up, post the Norton log please. Your HijackThis! log looks ok.

Did you run Disk Cleanup on this one? The problem could be in your temporary files. If that doesn't solve the problem then try booting into safe mode and then running norton.

If those steps do not clear it up, post the Norton log please.

Your HijackThis! log looks ok.

Ran Disk Clean. Ran Norton. Ran Safe Mode. Ran Norton. JS.Seeker still present. This computer has Norton System Works. Not Norton Corporate Edition as the last one had. This is what I was able to extract from its report:

Date: 6/7/2004, Time: 0:53:52, on ABS
Virus scan started.

Date: 6/7/2004, Time: 0:53:52, on ABS
Virus scanning completed.
Master boot records:
Scanned: 0
Infected: 0
Repaired: 0
Boot records:
Scanned: 0
Infected: 0
Repaired: 0
Files:
Scanned: 1
Infected: 0
Repaired: 0
Quar'ed: 0
Deleted: 0

Date: 6/7/2004, Time: 0:56:28, on ABS
The file
C:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\sb.hta
is infected with the JS.Seeker virus.
Unable to repair this file.


Date: 6/7/2004, Time: 0:56:28, on ABS
The file
C:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\sb.hta
is infected with the JS.Seeker virus.
Access to the file was denied.


Date: 6/7/2004, Time: 9:35:42, on ABS
Virus scan started.

Date: 6/7/2004, Time: 9:35:56, on ABS
Virus scan canceled.

Date: 6/7/2004, Time: 9:46:02, on ABS
Virus scan started.

Date: 6/7/2004, Time: 11:55:18, on ABS
The file C:\WINDOWS\TEMP\tmk.js is infected with the VBS.Downloader.Trojan virus.
The file was quarantined.



Date: 6/7/2004, Time: 11:55:18, on ABS
The file C:\WINDOWS\sb.reg is infected with the JS.Seeker.H virus.
The file was quarantined.



Date: 6/7/2004, Time: 11:55:18, on ABS
The compressed file sb.hta within C:\undo\backup.cab is infected with the JS.Seeker virus.
Unable to delete the file.



Date: 6/7/2004, Time: 11:55:18, on ABS
The file C:\Documents and Settings\All Users\Start Menu\Programs\Disabled Startup Items\sb.hta is infected with the JS.Seeker virus.
The file was quarantined.



Date: 6/7/2004, Time: 11:55:18, on ABS
Virus scanning completed.
Master boot records:
Scanned: 2
Infected: 0
Repaired: 0
Boot records:
Scanned: 2
Infected: 0
Repaired: 0
Files:
Scanned: 95364
Infected: 4
Repaired: 0
Quar'ed: 3
Deleted: 0

Date: 6/7/2004, Time: 12:19:40, on ABS
Virus scan started.

Date: 6/7/2004, Time: 14:04:20, on ABS
The compressed file sb.hta within C:\undo\backup.cab is infected with the JS.Seeker virus.
Unable to delete the file.



Date: 6/7/2004, Time: 14:04:20, on ABS
Virus scanning completed.
Master boot records:
Scanned: 2
Infected: 0
Repaired: 0
Boot records:
Scanned: 2
Infected: 0
Repaired: 0
Files:
Scanned: 95467
Infected: 1
Repaired: 0
Quar'ed: 0
Deleted: 0

Date: 6/7/2004, Time: 14:17:18, on ABS
Virus scan started.

Date: 6/7/2004, Time: 14:17:20, on ABS
Virus scanning completed.
Master boot records:
Scanned: 0
Infected: 0
Repaired: 0
Boot records:
Scanned: 0
Infected: 0
Repaired: 0
Files:
Scanned: 6
Infected: 0
Repaired: 0
Quar'ed: 0
Deleted: 0

Date: 6/7/2004, Time: 19:26:42, on ABS
Virus scan started.

Date: 6/7/2004, Time: 19:26:44, on ABS
Virus scanning completed.
Master boot records:
Scanned: 0
Infected: 0
Repaired: 0
Boot records:
Scanned: 0
Infected: 0
Repaired: 0
Files:
Scanned: 11
Infected: 0
Repaired: 0
Quar'ed: 0
Deleted: 0

Date: 6/7/2004, Time: 20:36:12, on ABS
The file
C:\DOCUME~1\MARCMC~1\LOCALS~1\Temp\V5VC3Fa01176
is infected with the JS.Seeker virus.
Unable to repair this file.


Date: 6/7/2004, Time: 20:36:16, on ABS
The file
C:\DOCUME~1\MARCMC~1\LOCALS~1\Temp\V5VC3Fa01176
is infected with the JS.Seeker virus.
Access to the file was denied.


Date: 6/8/2004, Time: 12:39:16, on ABS
Virus scan started.

Date: 6/8/2004, Time: 14:13:38, on ABS
The compressed file sb.hta within C:\undo\backup.cab is infected with the JS.Seeker virus.
Unable to delete the file.



Date: 6/8/2004, Time: 14:13:40, on ABS
Virus scanning completed.
Master boot records:
Scanned: 2
Infected: 0
Repaired: 0
Boot records:
Scanned: 2
Infected: 0
Repaired: 0
Files:
Scanned: 82468
Infected: 1
Repaired: 0
Quar'ed: 0
Deleted: 0

Date: 6/8/2004, Time: 14:22:06, Administrator on ABS
Virus scan started.

Date: 6/8/2004, Time: 16:37:44, Administrator on ABS
The compressed file sb.hta within C:\undo\backup.cab is infected with the JS.Seeker virus.
Unable to delete the file.



Date: 6/8/2004, Time: 16:37:44, Administrator on ABS
Virus scanning completed.
Master boot records:
Scanned: 2
Infected: 0
Repaired: 0
Boot records:
Scanned: 2
Infected: 0
Repaired: 0
Files:
Scanned: 97506
Infected: 1
Repaired: 0
Quar'ed: 0
Deleted: 0
Ok, it looks like Norton is finding the virus in two location where is cannot remove it.

C:\DOCUME~1\MARCMC~1\LOCALS~1\Temp\V5VC3Fa01176
For the above entry, log onto the user name referenced (starts with MARCMC)
Go to start>run and paste this in the run box, then hit Enter
%userprofile%\LOCALS~1\Temp
Find V5VC3Fa01176 and see if you can delete it. If not, try renaming it, rebooting and then deleting it. Let us know how that works out..

C:\undo\backup.cab
Did you upgrade from windows 9x or ME to XP?

Ok, it looks like Norton is finding the virus in two location where is cannot remove it.

C:\DOCUME~1\MARCMC~1\LOCALS~1\Temp\V5VC3Fa01176
For the above entry, log onto the user name referenced (starts with MARCMC)
Go to start>run and paste this in the run box, then hit Enter
%userprofile%\LOCALS~1\Temp
Find V5VC3Fa01176 and see if you can delete it. If not, try renaming it, rebooting and then deleting it. Let us know how that works out..

C:\undo\backup.cab
Did you upgrade from windows 9x or ME to XP?

Cannot find V5VC3Fa01176 in that folder or any other.
backup.cab is the file made by windows installer when you upgraded. I don't have a copy to test this on but try the following.

Go to start>run and type cmd in the box
When the command prompt window ipens type cd c:\undo and hit Enter (there is one space between the d and the second c).
Now type attrib -s -r backup.cab with one space between the b and the first - and a space again between the s and the second - and a space between the r and the b, then hit Enter.

Scan the file with Norton now and see if it can clean it (hopefully you have the option to right click>scan with norton or perhaps you can set it up within the Norton control panel).

Cannot find V5VC3Fa01176 in that folder or any other.

Are you showing hidden files/folders?

How to show hidden files/folders
Go to Start>control panel>folder options>view tab
Check mark "display the contents of system folders"
Select "Show hidden files and folders"
Uncheck "Hide extensions for known file types"
Uncheck "Hide protected operating system files (Recommended)
Click the [ok] button.
still cannot locate V5VC3Fa01176 in that folder or any other. I did find the cab file it's a winzip file. I scanned it with norton and the virus came up. can I delete the winzip file in its entirety?
I see no harm in removing C:\undo\backup.cab as long as you have no plans of uninstalling XP and going back to ME. Did you try the attrib command I outlined on the file and then cleaning with Norton? Fixing it with Norton is the most elegant solution, better a fillet knife than a sledgehammer when possible. Rescan the complete system and see what you come up with, perhaps the V5VC3Fa01176 file (which was in a temp folder) is gone now.
did try running attrib all I got was c:undo everytime. norton is having a hell of a time fixing it. do you think installing corporate edition over systemworks could work? i also do not ever plan on switching back to me so if all else fails i could just delete and see if that works.
cd c:\undo
attrib -s -r backup.cab
If that is what your are doing then the file should be cleanable. As far as I know Norton can clean a zip archive.

did try running attrib all I got was c:undo everytime. norton is having a hell of a time fixing it. do you think installing corporate edition over systemworks could work?

AVG is an excellent free AntiVirus which works well alongside Norton.
Personally, I would not install Norton Corporate Edition over SystemWorks.
after i've typed in the command box do I close it? I've typed cmd which opens the command box. I get C:\Documents and Settings\Marc M> I type cd c:\undo following the > with no space and get c:\undo> then I type attrib -s -r backup.cab with no space following the > and I get c:\undo> Am I doing something wrong?

Ask AI

AI can make mistakes. Check the cited posts. Archived advice can be out-of-date

Don't include personal information. Questions and selected public posts go to OpenAI. About Ask AI