You are viewing a single comment's thread.

view the rest of the comments →

willofthewarrior ago

How did you remove it? How did you detect it?

goatboy ago

They were remoted into my machine and actively sharing the screen in the middle of the night. I saw them using it and ended the network connection. Then I blocked all related ports on my router and reimaged the infected machine, making sure the new image didn't have any remote management client installed. I was lucky. A more sophisticated enemy might have disabled the monitor or used a simultaneous user log in.