Sysinternals Homepage
Forum Home Forum Home > Sysinternals Utilities > Autoruns
  New Posts New Posts RSS Feed: Autoruns fails to detect
  FAQ FAQ  Forum Search   Calendar   Register Register  Login Login

Autoruns fails to detect

 Post Reply Post Reply
Author
Message Reverse Sort Order
namrehto View Drop Down
Senior Member
Senior Member


Joined: 23 June 2005
Location: Scotland
Online Status: Offline
Posts: 3861
Post Options Post Options   Quote namrehto Quote  Post ReplyReply Direct Link To This Post Topic: Autoruns fails to detect
    Posted: 13 June 2007 at 12:42am
The issue here is that the primary exe rundll32.exe is signed. Autoruns doesn't check command line args.
Gil
Back to Top
Barfy View Drop Down
Newbie
Newbie


Joined: 12 June 2007
Online Status: Offline
Posts: 1
Post Options Post Options   Quote Barfy Quote  Post ReplyReply Direct Link To This Post Posted: 12 June 2007 at 11:09pm
Recently I got my computer infected in some strange way - each time I restart it, my Internet Explorer home page gets replaced.
Autoruns with a "hide signed Micrsoft modules" option turned on did not show anything suspicios.
 
Although, when I turned the option off, the following line, which appeared as a legitimate under autoruns took my attention:
 
rundll32.exe advpack.dll,LaunchINFSection gv_inst.inf, Section
 
the inf file contained a code to set a home page. It could also easily contain some instructions to copy and replace files etc.
 
Maybe the newer version of autoruns should filter those "signed" Microsoft entries.
Back to Top
 Post Reply Post Reply

Forum Jump Forum Permissions View Drop Down