Hi,
I am from the United States of America, I don't know how many times I have praised
Mark Russinovich and Bryce Cogswell which are both Awesome programmers.
They created what was once called System Internals (SysInternals)
They have moved to Microsoft at Technet circa 2004... http://technet.microsoft.com/en-us/sysinternals/bb545027.aspx
Microsoft hired Mark because they are TOP Notch Windows Programmers and have
made a great name for himself.
I was reading here about rootkit-gen virus and windows\system32\ files, I didn't
see the lock on the link until I was ready to respond to Chico44 about RootKit Revealer.
AutoRuns (500kb download), (#1) Is also a Must Have tool for ANY Microsoft Windows XP and higher user, I have used it on Windows 98 SE also.
Mark & Bryce are Number One in my book of programmers.
I hope the next time someone is told by an anti-virus software there is a ROOTKIT, that they
check out SysInternals.
--------------------A SLICE OF AUTORUNS Introduction ---------------------------
This utility, which has the most comprehensive knowledge of auto-starting locations of any startup monitor, shows you what programs are configured to run during system bootup or login, and shows you the entries in the order Windows processes them. These programs include ones in your startup folder, Run, RunOnce, and other Registry keys. You can configure Autoruns to show other locations, including Explorer shell extensions, toolbars, browser helper objects, Winlogon notifications, auto-start services, and much more. Autoruns goes way beyond the MSConfig utility bundled with Windows Me and XP.
Autoruns' Hide Signed Microsoft Entries option helps you to zoom in on third-party auto-starting images that have been added to your system and it has support for looking at the auto-starting images configured for other accounts configured on a system. Also included in the download package is a command-line equivalent that can output in CSV format, Autorunsc.
You'll probably be surprised at how many executables are launched automatically!
------------------------------------------------------------------------------------------
Peace.
#
