Had a user bring a desktop that was highly infected with spyware, and I wasn't able to work inside of windows, so slaved it up and began the trek of removal.
SuperAntiSpyware removed:
0 Memory
68 Files
4922 Registry
Malwarebytes:
52 Files.
Reattached the drive to the computer and booted up and was able to work again. Everything was definatley better, as first no sight of anything suspicious. So I installed SAS and MBAM on the computer because the guy has kids and told him I'd leave a couple of apps on it.
So normally I'd run through all the other apps AutoRuns, Hijackthis, etc. But decided to Run SAS again.
The results:
SAS finds an additional:
1 Memory
42 Files
165 registry
then MBAM found an additional:
20 registry
6 files
And this took about 4 hours of scanning time. Obviously when possible I'll install in windows and scan. BUT that being said, I am very very surprised that I'm needing to RESCAN once it's back in windows. Years of Antivirus scanning with slaved drives has always taken care of the problems completely.
In these cases, it's really going to extend the amount to fix, and HOPEFULLY everything comes out peachy cause if not, then your going into a reinstall and you've put way too many hours on it.
Any comments on this guys?
SuperAntiSpyware removed:
0 Memory
68 Files
4922 Registry
Malwarebytes:
52 Files.
Reattached the drive to the computer and booted up and was able to work again. Everything was definatley better, as first no sight of anything suspicious. So I installed SAS and MBAM on the computer because the guy has kids and told him I'd leave a couple of apps on it.
So normally I'd run through all the other apps AutoRuns, Hijackthis, etc. But decided to Run SAS again.
The results:
SAS finds an additional:
1 Memory
42 Files
165 registry
then MBAM found an additional:
20 registry
6 files
And this took about 4 hours of scanning time. Obviously when possible I'll install in windows and scan. BUT that being said, I am very very surprised that I'm needing to RESCAN once it's back in windows. Years of Antivirus scanning with slaved drives has always taken care of the problems completely.
In these cases, it's really going to extend the amount to fix, and HOPEFULLY everything comes out peachy cause if not, then your going into a reinstall and you've put way too many hours on it.
Any comments on this guys?