sorry, no chinese input, but here are the steps
所在版块:技术の宅 发贴时间:2005-09-01 09:47

用户信息
复制本帖HTML代码
高亮: 今天贴 X 昨天贴 X 前天贴 X 
download [process explorer] and [rootkit revealer] from sysinternals.com

you shouldn't see any suspicious processes from tool 1. for diagnosis, you can copy and paste the list of processing running on your computer here.

for the second tool, you might need to run it in safe mode. to do that, reboot and press F8 and select Safe Mode.

for more information, refer to

http://research.microsoft.com/rootkit/

http://www.sysinternals.com/utilities/rootkitrevealer.html
.
欢迎来到华新中文网,踊跃发帖是支持我们的最好方法!

War is peace.
Freedom is slavery.
Ignorance is strength.
 相关帖子 我要回复↙ ↗回到正文
极度痛苦中,求助于各位大师 poi   (726 bytes , 608reads )
遇到同样的问题,最后是重装系统,然后装SP2和trend officescan 山水   (39 bytes , 229reads )
感谢ING poi   (0 bytes , 179reads )
more info needed SmellsLikeTeenSpirit   (325 bytes , 256reads )
恕在下实在是菜鸟,弱弱的请求具体地说明. poi   (44 bytes , 268reads )
sorry, no chinese input, but here are the steps SmellsLikeTeenSpirit   (469 bytes , 227reads )
感谢斑主大师.贴上用process explorer得到的processing runing poi   (6347 bytes , 580reads )
嗯, SmellsLikeTeenSpirit   (252 bytes , 178reads )
再谢一次 poi   (0 bytes , 226reads )
哈哈,系统好象恢复正常了也. poi   (99 bytes , 203reads )
hehe, 其实到底是哪一步解决了问题? SmellsLikeTeenSpirit   (0 bytes , 206reads )
不太清楚.好象是kill掉BL515.EXE 1308 .目前一切正常. poi   (0 bytes , 232reads )
cool SmellsLikeTeenSpirit   (0 bytes , 120reads )
已经KILL了 poi   (367 bytes , 200reads )
some kernel mode rootkits can even hide from process explorer. 留名   (0 bytes , 204reads )
ya i agree SmellsLikeTeenSpirit   (27 bytes , 153reads )
各位大师,为什么只有看的,没有回的.请救我于水深火热之中. poi   (0 bytes , 158reads )