knight.exe!!

Discussion in 'Malware Help (A Specialist Will Reply)' started by marysmail, Dec 21, 2007.

  1. marysmail

    marysmail Private E-2

    Hi. I'm trying to get rid of this "Knight.exe" ... Antivir says it's a Trojan, I think it's been around since the last "Windows Update" I authorized... every time I plug in any USB this "Disk Knight" thing popped-up saying USB drives could have viruses and blahblah, to which I just closed it and went on doing my thing.

    But today I tried to download some pics from my camera and Antivir went crazy.

    It's located in my C:/WINDOWS/Knight.exe and it won't let me delete it. (it says "knight.exe" is the trojan "TR/Autorun.acl")

    Any ideas? Thanks!! Mar.-
     
  2. abri

    abri MajorGeek

    Hi marysmail!
    Welcome to Major Geeks!

    Please go to the instructions in the READ & RUN ME FIRST , only in your case, go first to the link for your operating system (at the bottom of the page) and then look for Combofix before you do anything else. Install and run that first. Then go back and work through the above READ & RUN ME link in the normal order.

    When you finish all of that, you will be able to attach the Combofix, AVG-Antispyware and MGlogs.zip with your next post.

    abri
     
  3. marysmail

    marysmail Private E-2

    Hi, thanks for your reply! I've done everything on the "read & run me"... I think the knight.exe is gone...

    When I ran AVGantispy it didn't save a log, it wouldn't even give me the option to save it.. it found some tracking cookies (marked as medium) and a trojan (marked as high), which had a different root than the last one (the one from the knight.exe that showed up on AntiVir). Should I run it again and see if I can save the log this time?

    I'm attaching the MG zip and the log from combofix though.
     

    Attached Files:

  4. abri

    abri MajorGeek

    Hi marysmail!

    Your logs are clean. You can do the following things to make your computer safer from malware. Then please follow the instructions in the box for cleaning out the tools we had you install and to reset your restore points:


    Go to add/remove programs and uninstall the below:[/b]

    - J2SE Runtime Environment 5.0 Update 10
    - J2SE Runtime Environment 5.0 Update 11
    - J2SE Runtime Environment 5.0 Update 6
    - J2SE Runtime Environment 5.0 Update 9
    - Java(TM) 6 Update 2


    If you do not use Windows Messenger (not to be confused with MSN Messenger!!) I would like you to run Disable/Remove Windows Messenger


    abri
     
  5. marysmail

    marysmail Private E-2

    Great. Did everything it said on your last post and it went chocomilk smooth.

    Thank you so much for your help, Abri!! Oh, and Merry Xmas!

    Mar.-
     
  6. abri

    abri MajorGeek

    Thanks marysmail!

    Merry Christmas to you!

    abri
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds