Suspicious services - what to check first?

Hi malware fighters,

  1. Check menu start-> programs that ‘start up’ to find suspicious programs

  2. Check inside administrative tools → services whether suspicious services are started up and what services can be disabled.

  3. Check the registry at the following locations from programs to start up automatically in windows

=> Hkey_Local_Machine\Software\Microsoft\Windows\Run
=> Hkey_Current_User\Software\Microsoft\Windows\Run

Well that is for starters, folks,

polonus

Autoruns for Windows v9.38 facilitates the checking you recommend, and much, much more! :smiley:
http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx

Edit: Polonus, have you checked out “OSAM” (Online Solutions Autorun Manager)? Sounds like its thoroughness of checking might be interesting to you.

Hi Alan Baxter,

Sure will give this a try and you please try this and give it a swirl - StartDreck
Get it here: http://www.niksoft.at/download/startdreck.htm

polonus

StartDreck doesn’t look too appealing. It hasn’t been updated since 2004. I have second thoughts about OSAM too. According to its homepage, the last three versions are in Russian only.

Have you checked out Autoruns yet? Selecting the Logon tab and the Hide Microsoft and Windows entries option give a succinct list. Yup, there’s the Avast! service GUI. 8)

Hi Alan Baxter,

I had autoruns and a couple of other tools from sysinternals on my computer for a long time, it is in my forensic box,

pol

I’m not surprised you have Autoruns after all. It sure provides a lot of information though. I usually use the System Startup display in Spybot - Search & Destroy instead. Any changes are highlighted immediately.