Am 01.09.2010 16:12, schrieb andy.ling@xxxxxxxxxxx: [snip]
The only way he finally got a hold of it was to use Process Explorer (rather than task manager). This allowed him to examine each process and suspend the threads without killing it. With all the threads of the malware processes suspended he could then start killing things off and use the "fixer" programs to clean his PC
Which is why we use a PE (boot-cd) to fix infected computers. Look for UBCD4Win or hiren boot-cd. Have fun... -- Martin Vethake Uffenkamp Computer Systeme snailmail: Uffenkamp Computer Systeme Gartenstr. 3 D-32130 Enger-Dreyen email : martinv@xxxxxx web : http://www.ucs.de/ voice : +49-5224-978075 fax : +49-5224-978076 To unsubscribe or subscribe goto: //www.freelists.org/list/davidpilling