, 21 2017 . 22:13
+
_
.
. .
. . , , – .
:" ".. . " ". :-" , .. . - , - , ".
.
.
1. F8
Windows.
2. - , .
3. regedit.exe
- Enter--- .
( . .
( ).
--
.
, ,
– . – ,
– .
, ).
4. : HKEY_LOCAL_MACHINE-SOFTWARE-
Microsoft-Windows NT-CurrentVersion-Winlogon.
UserInit Shell .
--Userinit - C:\Windows\system32\userinit.exe,
! !
--Shell - explorer.exe
:-- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows
NT\CurrentVersion\Windows\AppInit_DLLs - .
Winlogon, . Shell
explorer.exe ( Shell)
5. .
BIOS
, , , .
, . :
- Delete
- BIOS
-
-
-
- , .
,
, Windows, .
,
, .
, :
1. , ,
- - - .
2. , Windows.
3. .
4. , .
Windows 7 ,
F-8 ,
.
,
–
.
, F-8 ,
, Windows 7.
Windows 7.
Windows 7,
.
Windows 7 ,
,
.
LiveCD.
LiveCD Dr.Web. –
, .
LiveCD . .
. ,
. :
1. ;
2. - SCD Writer.
3. LiveCD.
4. SCD Writer, "",
" ".
LiveCD, .
,
, CD. BIOS
( Delete).
Boot ( ). ,
. .
, , .
, .
. ,
.
Dr.WebScanner, ""
. --"".
Windows
, .
. , . , , , "" .
.
AVZ
1. AVZ. .
- ( ,
). .
,
, AVZ.
Windows ,
, F8.
" ".
, .
AVZ .
--explorer "Enter".
" ", .
2. avz.exe.
3. " — — ".
, "" ""
4. " " , .
— " ".
-- "",
"", "".
" Infected".
5. " "--" "
-
6. " ". " "
" ",
" RootKit User-Mode"
"RootKit Kerner-Mode"
--
" SPI/LSP",
" TCP/UDP ", " ",
" ".
"" .
! , ( ), AVZPM ---"
". ""---"" .
, ...
P/S. , -- , ( ) . AVZ. \ . --" ", " ".
,
, ,
-- , , .
https://jumabai.blogspot.com/2016/07/blog-post.html