funsec mailing list archives

Silent Runners, a new tool I just found out about


From: "Richard M. Smith" <rms () computerbytesman com>
Date: Tue, 10 Jan 2006 10:22:52 -0500

FYI.  Check out http://www.silentrunners.org which is a tool for finding out
all of the sneaky ways that the adware, spyware, and malware vendors have
figured out to run their code on our computers.  It is similar to
HijackThis, but it looks like it is doing more checking.  The Notepad user
interface however could use some work. ;-)  I would like to see the tool
generate a nice looking HTML file instead.

Richard 

-----Original Message-----
From: Andrew Aronoff [mailto:ntbugtraq.sub () aaronoff com] 
Sent: Monday, January 09, 2006 2:20 PM
To: Silent_Runners_Users () aaronoff com
Subject: Silent Runners Update (R43)
Importance: High

Hello,

I waited three months before issuing R42. Five minutes after I did and
independently of the R42 release, I learned of a new launch point, which
necessitates R43. It is recommended that you download Silent Runners R43 and
delete earlier versions.

In Windows 2000 and Windows XP, if the following value exists:

HKLM\System\CurrentControlSet\Control\SafeBoot\Option\
"UseAlternateShell"=1

... the shell listed at this value:

HKLM\System\CurrentControlSet\Control\SafeBoot\AlternateShell

will be launched at boot instead of Windows Explorer.

Thanks to Tony K in the Netherlands for having brought this launch point to
my attention.

FYI, Silent Runners has been named "Tool of the Month" in the Februrary 2006
issue of "PC World" magazine. You can read the citation
here: http://tinyurl.com/at8pb

(If anyone has a copy of the print magazine, I'd be eager to buy it at the
newsstand price and refund all postage. PC World is not sold here. Please
contact me by e-mail.)

The launch points list on the web site has been updated.
http://www.silentrunners.org/sr_launchpoints.html

The updated script (R43) can be found here:
http://www.silentrunners.org/Silent%20Runners.vbs

A zipped version can be found here:
http://www.silentrunners.org/Silent%20Runners.zip

Thanks again to those users who have provided feedback for improve- ments.
If you ever have any problem with the script, please let me know.

To be removed from this distribution list, please request it via a reply to
this e-mail or use the Contact form on the web site.

regards, Andy
_______________________________________________
Fun and Misc security discussion for OT posts.
https://linuxbox.org/cgi-bin/mailman/listinfo/funsec
Note: funsec is a public and open mailing list.


Current thread: