Disk Knight

Disk Knight is promoted as legitimate program that will block malicious programs to be run from USB and external memory devices. However, Disk Knight’s capability to propagate itself and be installed without user’s interaction put itself in the lists of rogue software or potentially unwanted application. The program will exploit certain security vulnerabilities to penetrate a system.

To avoid this virus, it is important to update all programs and install necessary patch for Windows operating system. Upgrading installed antivirus program is essential to obtain the latest database and avoid Disk Knight Infection.

Screen Shot Image:

Damage Level: Medium

Systems Affected: Windows 9x, 2000, XP, Windows Vista

Technical Details and Additional Information:

What Disk Knight can do?
- Copy itself to removable drives found on the compromised system.
- Modify registry to run itself during Windows start-up.

Malicious Files Added by Disk Knight
%Windìr%\Knight.exe
%Windìr%\recover.reg
%DriveLetter%\Knight.exe
%DriveLetter%\autorun.inf

Associated Windows Registry Entries:
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Current Version\Run\”Disk Knight” = “%Windìr%\Knight.exe”
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\exefile\shell\open \command\”(default)” = “Knight.exe %1 %*”

Disk Knight – Removal

Removing Disk Knight Manually:
1. If using Windows ME or XP, System Restore must be disabled to prevent the threat from restoring itself. [Windows XP System Restore]

2. Update the virus definitions.

3. Reboot Windows in SafeMode
- Press F8 on keyboard right after turning on the comptuer.
- Select Safe Mode from the menu.

4. Run a full system scan and clean/delete all infected file as stated above.

5. Delete/Modify any values added to the registry.
- For Windows 2000/XP: Go to Start > Run, type “regedit” on dialog box then press Enter on keyboard.
- For Windows Vista/7: Go to Start > Search Program and Files, type “regedit” and press Enter.

6. Exit registry editor and restart Windows.

Disk Knight Removal Tools

Manual removal provided on this page may or may not successfully remove Disk Knight. To completely get rid of the virus and other malicious software that may have been installed, we suggest running these tools.

In order to completely remove Disk Knight from a system, click here to download and run Malwarebytes Anti-Malware. Sometimes, Trojans will block the downloading and installation of MBAM. If this happens, download it from a clean PC and rename the executable file before executing on the infected machine.

Using Portable SuperAntiSpyware:
To thoroughly remove a virus, it is best to do a separate scan of another security program so that other infected files not detected by anti-virus application can be remove as well. Click here to download and run SAS Portable Scanner.

What to do next...