Runscanner : freeware startup analyzer
If you want free network inventory don't forget to visit Lansweeper : Freeware asset and software inventory
Welcome Guest Search | Active Topics | Members | Log In | Register

Possible new launch point to watch Options
TonyKlein
Posted: Sunday, December 09, 2007 5:25:50 PM

Rank: Newbie
Groups: Member

Joined: 11/22/2007
Posts: 4
Points: 12
Location: The Netherlands
Hi all. :)

Wouldn't we want to watch the following key as well?

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\AeDebug

I've noticed various malware writing to it specifying a rogue executable as debugger:

http://www.symantec.com/en/aa/norton/security_response/writeup.jsp?docid=2007-110915-3903-99&tabid=2
http://www.symantec.com/security_response/writeup.jsp?docid=2007-112815-0617-99&tabid=2
http://www.sophos.com/security/analyses/w32brontokbo.html


Cheers,

Tony CLSID List - A Collection of Autostart Locations
GeertM
Posted: Monday, December 10, 2007 9:31:21 AM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 141
Points: 192
Location: Belgium
Welcome to the forum Tony.

I'll add this to my todo list.



Lansweeper : free software and computer inventory
TonyKlein
Posted: Monday, December 10, 2007 10:08:17 AM

Rank: Newbie
Groups: Member

Joined: 11/22/2007
Posts: 4
Points: 12
Location: The Netherlands
Hi Geert, thanks, and you're welcome. :)

I've also added to the Sysinternals "Utility Manager" thread with this suggestion.

I haven't had the occasion to do any testing on this launch point myself, so let's wait and see what they say.

In any case, although it might be a rather unlikely launch point, it could very well 'lie dormant' for ages, at least provided the malware itself isn't detected in the meantime, and then launch the baddie in the event of a system crash.

Tony CLSID List - A Collection of Autostart Locations
TonyKlein
Posted: Monday, December 10, 2007 10:22:56 PM

Rank: Newbie
Groups: Member

Joined: 11/22/2007
Posts: 4
Points: 12
Location: The Netherlands
Andy has just added this launch point to his SilentRunners script. :d/

Tony CLSID List - A Collection of Autostart Locations
GeertM
Posted: Wednesday, December 12, 2007 12:21:10 AM

Rank: Administration
Groups: Administration

Joined: 2/16/2007
Posts: 141
Points: 192
Location: Belgium
If you really want surprises, I'll add two "undiscovered" launch points to the next version (1.6)
(I need to do some more testing with them first)

PM me for more info ;)

This is not included in the 2 "surprises", but missing in silentrunners and autoruns (and my current version)

174 HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon\VmApplet
http://www.microsoft.com/technet/prodtechnol/windows2000serv/reskit/regentry/12331.mspx?mfr=true



Lansweeper : free software and computer inventory
TonyKlein
Posted: Wednesday, December 12, 2007 9:28:24 AM

Rank: Newbie
Groups: Member

Joined: 11/22/2007
Posts: 4
Points: 12
Location: The Netherlands
VmApplet is already on my list though. ;)

... but you bet I'm interested in those two new ones :d/

Got to run right now, but I would indeed appreciate you PM'íng me with the gory details! ;)

Tony CLSID List - A Collection of Autostart Locations
LUSHER
Posted: Wednesday, December 12, 2007 3:46:15 PM
Rank: Member
Groups: Member

Joined: 3/2/2007
Posts: 53
Points: 159
TonyKlein wrote:
Andy has just added this launch point to his SilentRunners script. :d/


OMG, i'm abandoning runscanner for silentrunners!!!

That's the advantage of Silentrunners i guess more mobile.

Users browsing this topic
Guest


Forum Jump
You cannot post new topics in this forum.
You cannot reply to topics in this forum.
You cannot delete your posts in this forum.
You cannot edit your posts in this forum.
You cannot create polls in this forum.
You cannot vote in polls in this forum.

SoClean Theme Created by Jaben Cargman
Powered by YetAnotherforum.net
Copyright © 2003-2006 Yet Another Forum.net. All rights reserved.
This page was generated in 0.128 seconds.