All seemed ok- MBAM ran (after rkill) and seemed to remove the malware. THen about a day afterl I returned his machine to him and he went back online, signs of infection showed up in his wife's User Account, now he's having all kinds of odd behavior (browser redirects using FireFox), very slow startup and shutdown, several program errors and programs not ending at shutdown, and IE will not start at all.
I'm worried that the machine is either still infected w. IS 2010 or something else. What can I do? Is there a good tool to determine whether something is still infecting this machine?
Edited by xingxang, 17 January 2010 - 09:33 PM.