ddrueding
Fixture
One of my better users got an e-mail claiming to be from AOL and requesting her username and password.
She knew this was probably a scam, deleted the message and went to Google. Did a Google search for AOL support and got a phone number. This is where the story gets a little foggy. She can't confirm exactly which number she dialed (old landline phone) or what website she was on (swears it was something.aol.com). But within a couple minutes the tech has remoted into her system and "done a bunch of stuff on the command line". At this point he says her system is infected with all kinds of stuff and that she should contact MS to have it cleaned. She thanks him, hangs up, unplugs her computer and calls me.
So here I am on the machine. Recovery Console has been installed, but NOD32 and MalwareBytes (part of my install, update automatically) haven't been run. To the best of my knowledge the system looks clean.
Thoughts?
She knew this was probably a scam, deleted the message and went to Google. Did a Google search for AOL support and got a phone number. This is where the story gets a little foggy. She can't confirm exactly which number she dialed (old landline phone) or what website she was on (swears it was something.aol.com). But within a couple minutes the tech has remoted into her system and "done a bunch of stuff on the command line". At this point he says her system is infected with all kinds of stuff and that she should contact MS to have it cleaned. She thanks him, hangs up, unplugs her computer and calls me.
So here I am on the machine. Recovery Console has been installed, but NOD32 and MalwareBytes (part of my install, update automatically) haven't been run. To the best of my knowledge the system looks clean.
Thoughts?