Mr. Purple Cat Esq. - 2018-07-23
The operator was incredibly dumb enough to download and run an elevated exe.
In a callcentre type place, if the machines are not all virtual (using citrix or something) which would be surprising nowadays, they will have an image that can be built onto a machine from the network on boot. So if a machine is playing up u just re-image it. Takes a couple mins. Deleting system32 is not going to do shit.
This whole thing is kinda sad..
|