Taget fra:
http://www.symantec.com/avcenter/venc/data/js.seeker.b.htmlTechnical description:
When executed, this Trojan horse is usually copied to the Windows \\StartUp folder as the file run.hta. This insures that it runs when Windows starts.
It creates and then executes the registry import file C:\\Windows\\Homereg111.reg. When executed, it modifies Internet Explorer settings by making the following changes to the Windows registry:
In the key
HKEY_CURRENT_USER\\Software\\Microsoft\\
Internet Explorer\\Main\\
it modifies the values
Search Bar
Default_Search_URL
Search Page
so that they all point to a Web page that displays links to gambling, adult, and other sites.
In the key
HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\
Internet Explorer\\Search\\
it modifies the value
SearchAssistant
so that it points to the previously mentioned Web page.
The script also creates a \"favorite link\" titled \"Search The Web\" which links to the same Web page.
Removal instructions:
1. Run LiveUpdate to make sure that you have the most recent virus definitions.
2. Start Norton AntiVirus (NAV), and run a full system scan. Be sure that NAV is configured to scan all files.
3. Delete all files that are detected as JS.Seeker.B.
4. The modified Internet Explorer settings can be reconfigured from within Internet Explorer. To reconfigure the home page, click the Tools menu and click Options; to reconfigure search options, click the Search menu and click Customize.