Computer Security & Viruses/Ahkntfs.exe

Advertisement


Question
 

Answer
Ahkntfs.exe is a rare variety of spyware. To remove it, first turn off System Restore. The reason for this is that it probably hides a copy of the infection.

How to disable or enable System Restore in Windows ME:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001012513122239?OpenDo...

How to disable or enable System Restore in Windows XP:
http://service1.symantec.com/SUPPORT/tsgeninfo.nsf/docid/2001111912274039?OpenDo...

Now open Task Manager (CTRL+ALT+DEL). Then click the processes tab, click on Ahkntfs.exe, then click End Process. Click Yes to confirm.

Next open a command prompt with Start --> Run, type command.com in the box and click OK. This will bring up a window where you can type commands. Type "del C:\WINNT\System32\?hkntfs.exe".

Your final task is to clean out the program from the Registry. Click Start --> Run and enter Regedit in the box, then hit OK.  This brings up the Registry editing progam. The easy way to find it is to click Edit --> Find. This will bring up a box where you can enter "?hkntfs.exe". Now make certain the boxes labeled keys, values and data are all checked. Click "Find Next." Anything it finds, highlight it and delete it.

Now it is safe to reenable System Restore.

Computer Security & Viruses

All Answers


Answers by Expert:


Ask Experts

Volunteer


Carolyn Meinel

Expertise

I cover Windows, Linux, TCP/IP and Ethernet security questions. I do not cover Mac, smart phones, or other networking issues.

Experience

Books by Carolyn Meinel: wrote a chapter for The Hacking of America book (see http://www.amazon.com/exec/obidos/ASIN/1567204600/happyhacker) My article Code Red for the Web for Scientific American was reprinted in the book Best American Science Writing 2002 (see http://www.amazon.com/exec/obidos/ASIN/0060936509/happyhacker). My book The Happy Hacker: A Guide to Mostly Harmless Hacking is now in 4th edition with a Japanese edition (see http://happyhacker.org/hhbook/).

Organizations
IEEE, AAAS

Publications
See a list with some online links at http://cmeinel.com

Education/Credentials
MS, Industrial Engineering, The University of Arizona Took a course in computer forensics at the University of Texas at Austin/

Past/Present Clients
DARPA, SAIC, Palmer Labs

©2012 About.com, a part of The New York Times Company. All rights reserved.