View Single Post
Old October 6th, 2008, 05:04 PM     #2 (permalink)
Spada
Senior Member
 
Join Date: Apr 2007
Posts: 664
It sounds like a hijacker, in fact like one I removed this morning identified as a worm. It was called knight.exe, not sure if this is the same, but it sounds like the appropriate type. check your hosts file in your system32 folder. C:\WINDOWS\system32\drivers\etc. This file is like a prefetch for IE (it will look here for ips of internet sites and redirect), so for instance if you see lots of ips down there, especially symantecs which is 128.242.186.225 according to Whois, there will be text to the side which is the redirect site. There should only be one in there which is localhost.
__________________
AMD 5200+ AM2 // 8800 GTS 320 // 2 GB PC 6400
We just won't talk about the MB for now.
Spada is offline   Reply With Quote