Spybot Search & Destroy Screenshot
Results 1 to 4 of 4

Thread: Spybot Search & Destroy Screenshot

  1. #1
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103

    Spybot Search & Destroy Screenshot

    Yesterday I went out on a service call for a malware infected system. I started by installing Spybot and running a scan. After a few minutes I told the customer, "Mmm, I think this needs to go back to the office." I set it up to run a scan, went on another job and when I came back this is what I saw.




    I apologize for the quality of the photo, but I was trying to get it quickly because I was convinced the system would crash or explode. Anyway, the number of Win32.Agent.cmn infections is 29329. And that isn't a typo. You can use your browser's zoom feature to check it out.

    I clicked the fix button, then left again. When I returned, Spybot had locked up, but when I rescanned the system 100% of the Win32.Agent.cmn infections were gone, and the second scan (which took about 12 minutes) removed everything but the Win32.Agent.pz infections. ComboFix killed those. After I ran Eset's online scan (clean, BTW) I took it back home.
    Last edited by slgrieb; June 27th, 2008 at 05:28 PM.

  2. #2
    Registered User
    Join Date
    Nov 1998
    Location
    La Baie Quebec Canada
    Posts
    545
    and that thing would still boot and run?who says windows is not stable,lol

  3. #3
    Registered User slgrieb's Avatar
    Join Date
    Feb 2003
    Posts
    4,103
    I'm not sure "ran" is a good description. "Crawled" might be more like it. But yes, I'm confident that the machine was free of infection when I returned it. But I did have a really long chat with the owner about security.

    With only a couple of exceptions, all of the files infected with Win32.Agent.cmn were either fonts or DivX movies downloaded via LimeWire.

    Edit: One point that is frequently overlooked in discussions about infected systems isn't whether or not the system is clean after the removal/reformat or whatever, but whether the user's passwords and personal data may have been compromised. It's always safest to assume the worst, but it can be very hard to communicate to users the need to change all their critical login information on any banking or investment sites, and communicate their concerns to the relevant security departments.
    Last edited by slgrieb; June 27th, 2008 at 07:38 PM.

  4. #4
    Registered User Mags's Avatar
    Join Date
    Oct 2005
    Location
    England
    Posts
    614
    Ooh look at that!

    Would you like to come and do the vaa-aacing in my house, Slgrieb, it's overdue?

Similar Threads

  1. The Ugly Return of Virtumonde - The spyware that just keeps coming back
    By slgrieb in forum Spyware & Antivirus - Security
    Replies: 8
    Last Post: December 13th, 2011, 03:08 PM
  2. Spybot - Search & Destroy v1.5.1.15 Final
    By TechZ in forum Other Software Applications
    Replies: 2
    Last Post: September 4th, 2007, 10:20 AM
  3. NEWS: A Search Engine, Better Than Google
    By TechZ in forum Tech News
    Replies: 1
    Last Post: June 1st, 2007, 05:51 AM
  4. Replies: 0
    Last Post: September 12th, 2006, 09:30 AM
  5. DOWNLOAD: Spybot Search and Destroy 1.4 Final
    By TechZ in forum Other Software Applications
    Replies: 7
    Last Post: June 10th, 2005, 10:45 AM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •