Wilders Security Forums  

Go Back   Wilders Security Forums > Software, Hardware and General Services > other software & services
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old December 18th, 2007, 05:51 PM
ronjor's Avatar
ronjor ronjor is offline
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,201
Default AutoRuns for Windows v9.0

Quote:
This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. You can configure Autoruns to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond the MSConfig utility bundled with Windows Me and XP.
Microsoft Sysinternals
  #2  
Old December 18th, 2007, 09:10 PM
HAN's Avatar
HAN HAN is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: USA
Posts: 1,718
Default Re: AutoRuns for Windows v9.0

Thanks Ron!
  #3  
Old December 19th, 2007, 03:10 AM
newbino newbino is offline
Frequent Poster
 
Join Date: Aug 2007
Posts: 270
Default Re: AutoRuns for Windows v9.0

From Windows Sysinternals Autoruns page
Quote:
Usage
See the November 2004 issue of Windows IT Pro Magazine for Mark's article that covers advanced usage of Autoruns
article
  #4  
Old December 19th, 2007, 04:15 AM
ErikAlbert ErikAlbert is offline
Incredibly Massive Poster
 
Join Date: Jun 2005
Posts: 9,456
Default Re: AutoRuns for Windows v9.0

I ran Autoruns immediately and it found this very suspicious object in my online and even off-line system partition under :

HKCU\SOFTWARE\Microsoft\Internet Explorer\Desktop\Components
Autorun Entry: 0
Description...: blank (very suspicous)
Publisher......: blank (very suspicious, unknown source)
Image Path...: File not found about:Home (very suspicious, completely hidden)

I was stupified, because that was in theory impossible.
Was this a sneaky rootkit or keylogger ?
Was this a malware that infected the firmware of all my hardware components ?
Was this an object caused by one of these "invisible" things of Joanna ?
Was I infected by Rustock A upto Z ?
Was this malware telling me I'm a zero as a bad joke ?
I don't know. After the first panic and taking a valium pill, I got my common sense back.

I have an image of WinXPproSP2 only, which has never been on-line, not even for activation.
If that image also contained this suspicious object, I was malware-free.

So I restored that image, ran Autoruns and this suspicious object appeared again in the Autoruns List, which means it was NOT a malicious object.
Case closed and back to normal.

This is typical M$ : scaring the user about nothing. This is the second time.
__________________
ErikAlbert
Security = WinXPproSP3 Firewall + Anti-Executable + DefenseWall HIPS * Recovery = ShadowProtect + FirstDefense-ISR
Malware Survival Rate = 0.00%, but each malware has my sympathy.

Last edited by ErikAlbert : December 19th, 2007 at 04:22 AM.
  #5  
Old December 19th, 2007, 05:40 AM
Longboard's Avatar
Longboard Longboard is offline
Massive Poster
 
Join Date: Oct 2004
Location: Sydney, Australia
Posts: 3,097
Default Re: AutoRuns for Windows v9.0

Ta
__________________
Don't confuse me with someone who actually knows what they are talking about.
Linux Registered user 469135
Please, support Medecins Sans Frontieres
  #6  
Old December 19th, 2007, 01:06 PM
appster's Avatar
appster appster is offline
Frequent Poster
 
Join Date: Jun 2007
Location: Paradise (Hawaii)
Posts: 430
Default Re: AutoRuns for Windows v9.0

@Erik, fwiw I have that also, so perhaps that provides additional reassurance that it actually is an MS entry.
  #7  
Old December 19th, 2007, 01:31 PM
twl845's Avatar
twl845 twl845 is online now
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: AutoRuns for Windows v9.0

Quote:
Originally Posted by ronjor
Thanks for the tip! I'm running Autoruns v8.6. can I install v9 over my v8.6 or do I have to uninstall v8.6 first? Thanks
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
  #8  
Old December 19th, 2007, 01:58 PM
HAN's Avatar
HAN HAN is offline
Very Frequent Poster
 
Join Date: Feb 2005
Location: USA
Posts: 1,718
Default Re: AutoRuns for Windows v9.0

I just replace all 4 existing files with the 4 new ones...
  #9  
Old December 19th, 2007, 01:59 PM
appster's Avatar
appster appster is offline
Frequent Poster
 
Join Date: Jun 2007
Location: Paradise (Hawaii)
Posts: 430
Default Re: AutoRuns for Windows v9.0

Quote:
Originally Posted by twl845
Thanks for the tip! I'm running Autoruns v8.6. can I install v9 over my v8.6 or do I have to uninstall v8.6 first? Thanks
There is no install (as such). Just replace the old exe with the new one.
  #10  
Old December 19th, 2007, 02:01 PM
bellgamin's Avatar
bellgamin bellgamin is offline
Very Frequent Poster
 
Join Date: Aug 2002
Location: Hawaii
Posts: 5,202
Default Re: AutoRuns for Windows v9.0

Quote:
Originally Posted by twl845
Thanks for the tip! I'm running Autoruns v8.6. can I install v9 over my v8.6 or do I have to uninstall v8.6 first? Thanks
I installed right over the old one. Works for me!

Ah Ron -- 10Q!
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender
  #11  
Old December 19th, 2007, 02:05 PM
twl845's Avatar
twl845 twl845 is online now
Massive Poster
 
Join Date: Apr 2005
Location: New York, USA
Posts: 3,331
Default Re: AutoRuns for Windows v9.0

Thanks all.
__________________
Now that I'm older, I seem to have more patience.
It turns out I just don't give a crap.

WIN 7 64x, Avast! PRO V8, Outpost FW Pro 8.x, MBAM Pro Real Time, Shadow Defender, Active@ Disk Image, Macrium Reflect Standard, AX64 Time Machine
  #12  
Old December 20th, 2007, 10:16 PM
lucas1985's Avatar
lucas1985 lucas1985 is offline
Global Moderator
 
Join Date: Nov 2006
Location: France, May 1968
Posts: 4,047
Default Re: AutoRuns for Windows v9.0

Quote:
Originally Posted by ErikAlbert
This is typical M$ : scaring the user about nothing. This is the second time.
Erik,
Autoruns isn't a blacklist scanner. It only informs you about certain system variables and it's up to you to verify/decide on them.
It's a forensic tool (like HijackThis, Runscanner, anti-rootkits, integrity checkers, etc) and it isn't targeted to "newbies", although you can learn how to use it without fear.
__________________
"Pouvoir à l'Imagination. Power to the imagination. La imaginación al poder".

"Perfect is the enemy of good enough". Voltaire.
 

Wilders Security Forums > Software, Hardware and General Services > other software & services « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 08:45 AM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums