Satyajit Menon: Today we’re going to discuss the use of a very useful Windows SysInternals tools named Autoruns that we can use to examine programs that start during the boot process or the login process. This comes in particularly useful when you start trying to dig around for potential malware as well as applications that are configured to auto-start that you had no idea were even running! So without further delay – let’s dive right in …
Most administrators are aware of the usual places to look for programs that are auto-starting – such as the Startup folder itself and the Run and RunOnce registry keys. Using MSCONFIG.EXE we can examine the components that execute from these locations.