APPENDIX A
The Bootup Process
The Windows Bootup Process
To better understand how malware autostarts in Windows, let’s take a quick look at how Windows boots up. Depending on whether the system is BIOS-based or EFI-based, the bootup process differs up to the point of passing control to the kernel (see Figure A-1).
image
image
Figure A-1   A simplistic view of the bootup process
BIOS-Based system
On a BIOS-based system, the bootup process begins with the BIOS. The BIOS code selects a boot device and loads that device’s Master Boot Record (MBR) into memory. ...

Get Malware, Rootkits & Botnets A Beginner's Guide now with the O’Reilly learning platform.

O’Reilly members experience books, live events, courses curated by job role, and more from O’Reilly and nearly 200 top publishers.