Hi All
A friend was caught by a "Microsoft Support" scam yesterday, they downloaded GoToAssist 3.1X on her HP Elitebook running Win7 Pro 64Bit on a Crucial MX300 SSD.
I rebooted into Safe Mode and deleted the GoToAssist, but when I rebooted into Windows the "Microsoft Alert" and chat window they used popped right back up on the Desktop, so I'm assuming there's a rootkit in the system.
The machine is currently off with Internet disabled.
Does anyone have any ideas of how to clean this out short of nuking the drive... there's stuff in there my friend would rather not lose if at all possible. (Yeah, she didn't back-up on a regular basis.)
A friend was caught by a "Microsoft Support" scam yesterday, they downloaded GoToAssist 3.1X on her HP Elitebook running Win7 Pro 64Bit on a Crucial MX300 SSD.
I rebooted into Safe Mode and deleted the GoToAssist, but when I rebooted into Windows the "Microsoft Alert" and chat window they used popped right back up on the Desktop, so I'm assuming there's a rootkit in the system.
The machine is currently off with Internet disabled.
Does anyone have any ideas of how to clean this out short of nuking the drive... there's stuff in there my friend would rather not lose if at all possible. (Yeah, she didn't back-up on a regular basis.)
My Computer
- OS
- Win7 Pro 64Bit
- CPU
- Intel Core 2 Duo E8400 3MHz
- Motherboard
- MSI P43-Neo3-F
- Memory
- 6GB Kingston DDR2 800
- Graphics Card(s)
- GeForce 8400 GS 512MB
- Sound Card
- SoundBlaster Audigy 24bit
- Monitor(s) Displays
- Samsung
- Hard Drives
- OCZ Vertex 60GB SSD (OS/Apps only)
1x WD 500GB 7200rpm (Data + Win7 Profile)
1x WD 1TB 7200rpm (Data only)
- PSU
- Apevia 500w
- Case
- Apevia Spyder full tower