Dec 18 2009
Ive ran into a spyware today, Security Center, that was difficult at first glance to remove, but turned out to be an easy fix. I got to the client and all .exe files would result in a “file “x” is infected” pop-up and it wouldnt allow the program to launch. It also hid the desktop icons which resulted in not being able to access “My Computer.” However, Control Panel was accessible, which allowed my to get to a point where I could type in C:\ and access the C: Drive. At that point I could do a search for files that had been modified that day, since the user knew the infection occurred at about 8am this morning. I found a file that was simply a bunch of numbers and had the same icon shortcut as the Spyware infection logo at pop-up. Although I couldnt delete the file, I was able to rename that file and at reboot it wouldnt activate.
As I suspected, that was the main file and by renaming it, it wasnt launched at startup. I was able to load a spyware scanner, which I used SuperAntiSpyware, and remove the other registry entries and sub-files.
It looked like a possible remove hard drive and scan that way, but it turned out to be a fairly easy removal.