More startup detectors.

| | Comments (1)

I've spent about 4-5 hours remote supporting someone trying to "untrojan" a server which was pretty badly infected. Personally I wouldn't have bothered, and just reinstalled but as usual in a business situation they need the box running NOW and can't wait for a proper fix. So I've spent some time clearing up most of the remote agents and gaping holes on the server. I don't think it will be long until they are infected again - the current stats I read last week was 20 minutes for an unprotected machine! Anyway, Mike had a link to a spyware detection page which in turn had a link to Sysinternals - Autoruns which has a nice gui interface to programs running on startup. One neat trick is the right click option to fire up the program into google.

1 Comments

Another really good Startup Editor type program is "Startup Organizer" by MetaProducts (http://www.metaproducts.com/mp/mpProducts_Detail.asp?id=9).

It's very simular to SysInternal's Autoruns with one very useful exception. If you leave it running in the background, it will pop up every time something trys to add something to any Startup entry in your computer. Registry, Startup folder, etc... It gives you the option to allow the modification to take place or stop it before it happens.

This can be very handy for catching those nasty programs before they even get a chance to get into your computer.

It's not free, but $25 is not that much to pay for a program that eagle-eye's your startup locations and lets you know if something is modifying it.

Categories

Pages

Powered by Movable Type 4.1

About this Entry

This page contains a single entry by published on August 23, 2004 3:41 PM.

BootBot for Windows 2003 was the previous entry in this blog.

Mcafee Webshield email scanning is pants is the next entry in this blog.

Find recent content on the main index or look in the archives to find all content.