Friday combatutto University have a virus that was beginning to circulate among the group of laptops that are often found in the same classroom (non) study. This trojan is the Disk Knight.
This nice little program infects all storage devices like USB flash-drive, MP3 players and so on. Moreover, once the device is inserted into a PC, by running the infected dell'autorun.
The main symptom of infection is the appearance of an icon that resembles the shield with the colors in the Windows tray bar. This icon allows you to launch, in that, some security programs: nothing further from the truth!
Once executed, the application is copied to the root folder of Windows and does so through the registry, to be invoked to perform any other application.
The keys to the registry to check are:
- HKEY_CLASSES_ROOT \\ exefile \\ shell \\ open \\ command : The correct default value is \u0026lt; "% 1"% * > while you may find \u0026lt; ; knight.exe "% 1"% * >. This line is used to ensure that every application by starting directly running the executable file (. Exe) to start the Trojan. Bring it back to original condition!
- HKEY_LOCAL_MACHINE \\ SOFTWARE \\ Microsoft \\ Windows \\ CurrentVersion \\ Run : here you should find a reference to the file \u0026lt; C: \\ Windows \\ Knight.exe >: delete it!
Finally, delete the file \u0026lt; C: \\ Windows \\ Knight.exe >. Now, your PC should be clean!
At present (November 26) the only virus that fails to recognize the trojan and delete it seems to be Nod32 .
Here is a step by step guide to remove the trojan .
I hope to be helpful! And remember: if you insert a pendrive that you're not 100% sure (even if it is yours and you have inserted another pc), pressing the SHIFT key prevents the execution dell'autorun. Windows Vista seems to be immune or otherwise to enable the Trojans really should mettercisi commitment.
0 comments:
Post a Comment