Archives for: March 2009

Mar 29
How to enable Task Manager and Registry Editor

Most modern malware has the bad habit of disabling basic system tools, to prevent the user from cleaning the system. In the previous article I described how a malicious program can disable safe mode, but there are two targets that are much more common than safe mode, they are the task manager and the registry editor.

If you can't start the task manager, you can't kill the process of the offensive program. If you can't start the registry editor you cannot edit the list of autorun programs and prevent the offensive program from starting next time Windows boots.

These tools can be disabled via the registry, the following key holds the values we need: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\policies\system

The question is - how to edit the registry if the registry editor is disabled? ;-)

Read more! »

Mar 27
Pentru cine?

Vote for nobody

Mar 23
How to make safe mode work again

As malware is getting more widespread, it is also getting nastier and it is more difficult to return a computer to a 100% clean state. Even after you remove all the infected files and malicious modules, some things still don't work well.

One such feature is safe mode - an infected (or post-infected) Windows boots fine in normal mode, but it cannot boot into safe mode, at one point you see a blue screen of death.

Your first guess is to re-install Windows, or use sfc.exe to recover some corrupt system files. A re-install will take time and it is an "ugly" solution, while using sfc.exe won't help in this case. In order to understand how to restore the safe mode functionality, we need to understand how safe mode works.

Read more! »

Mar 6
Inforail
Inforail logo

Since not that long ago I became a teacher. I have classes at the Technical University of Moldova - where I used to be a student no more than 3 (or 2?) years ago.

Inforail is a wiki created to enhance the academic experience, for both - my students and myself. You can visit the site by going to info.railean.net. If you go there you can see lists of keywords that refer to the things that were discussed in class, as well as keywords related to the assignments given in the labs.

Read more! »

Poll

I am

View Results

Who's Online?

  • Guest Users: 2

Syndicate this blog Subscriptions

Other stuff

Support the cause