BDPCR
New Member
- Reaction score
- 1
- Location
- South Florida
This has gotten me out of a few snags and figured id post the guide. Autoruns the latest version can check the registry of a slaved drive allowing the manipulation of services drivers and start-up apps in a nice easy to understand GUI. It is very simple to use just make sure you have the proper permissions for the sub-folders in windows/system32/config. This has worked well for machines that fail to boot past the splash or when one tracks down a BSOD causing program that loads.
http://computer-forensics.sans.org/blog/2010/06/28/autoruns-dead-forensics/

http://computer-forensics.sans.org/blog/2010/06/28/autoruns-dead-forensics/
