Silent Runners has been updated to R36
 
  Tweaks.com
 Home    Members    Calendar    Who's On        Main Site
 




Silent Runners has been updated to R36Expand / Collapse
Author
Message
Posted 4/26/2005 8:46 AM


Forum Moderator

Forum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum ModeratorForum Moderator

Group: Moderators
Last Login: 8/8/2008 6:28 AM
Posts: 2,748, Visits: 7,025

Silent Runners has been updated to R36 and adds important functional improvements. If you use this program, it is recommended that you download the new version and delete earlier ones.

1. On NT4+ systems, the script now checks:
HKLM\System\CurrentControlSet\Services\Tcpip\Parameters\DataBasePath
to determine where the HOSTS file is located. If the default value has been changed, a "HIJACK WARNING!" appears. The script uses the location in this value to find the HOSTS file.

2. On NT4+ systems, the script now checks sub-keys (executable names) of:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\
for a value named "Debugger".

This is a very powerful launch point. Any program can be cited as a debugger and it will run in place of the executable name. There is one default value that serves as an example. If anything else is found, an "INFECTION WARNING!" appears.

3. The launch points list on the web site has been updated to this location

The updated script (R36) is here:

A zipped version can be found here:

NOTE: This tool is for advanced users who know how to read and use the log it generates.



__________________________________________

"THE BAD GUYS DON'T NEED A SEARCH WARRANT. ARE YOU PROTECTED?"





Microsoft MVP - Windows Security
Post #159366
« Prev Topic | Next Topic »


Reading This TopicExpand / Collapse

All times are GMT -6:00, Time now is 6:29am

Powered By InstantForum.NET v4.1.4 © 2008
Execution: 0.078. 9 queries. Compression Enabled.