The windows tool msconfig doesn't really tell us much about the programs that run at startup in Windows. Let's just compare it to autoruns for a moment.
Knowing how malware can install itself even as a print monitor, it's usually a good idea to rely on autoruns and not msconfig.
Since it can also verify drivers and file signatures, it can hide signed Microsoft programs and show unsigned or fake signature software, usually a sign of malware.
Monday, October 29, 2007
Using Sysinternals Autoruns to disable startup programs
Posted by cmihai at 8:45 AM
Labels: Digital Forensics, Microsoft, Security
Subscribe to:
Post Comments (Atom)
0 comments:
Post a Comment