Location: Regedit

Discussion: Forgot something guysReported This is a featured thread

Showing 2 posts

Cynical-Crow
Forgot something guys
Mar 27 2009, 7:22 AM EDT | Post edited: Mar 27 2009, 7:22 AM EDT
Alright, Crow here.
You guys forgot some nice lil tricks with regedit. Simply open regedit by clickong on run then typing in "Regedit" then, click on HKEY_CURRENT_USER, then click on software, then click on mircosoft, then to windows. From there, you'll find run. Click on it, that my friends, is the harder way to run programs on startup. You'll notice that if you have MSN, you'll see a value like so ""C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /background" that, runs messanger on startup, even if it isn't set to run on startup using other means. An example of manipulating this to your advantage would be to make a new string value, then to write say as an example "C:\WINDOWS\System32\notepad.exe" it would run notepad on startup. So if you're a complete lamer then I'll line it out for you, write the path of the file you want to run as a string value. Simple it runs on startup everytime you log on.

Another usefull thing you forgot, is removing MRU objects, which record your activities and encode them. For extra precaution it is good to delete these.
Go to the same place I mentioned earlier HKEY_CURRENT_USER/Software/mircosoft/windows then, find explorer, click on that then click on RUN MRU a couple entries will be in there. Delete the entries that have values of such. "A, B, C etc" then click on MRU list and remove the value, don't delete the entry, just remove the data.

I might write more in the future, your friend the Crow
1  out of 1 found this valuable. Do you?    
Keyword tags: None
Mason(pkk)
Mason(pkk)
1. RE: Forgot something guys
Mar 27 2009, 7:17 PM EDT | Post edited: Mar 27 2009, 7:17 PM EDT
please post in the new site only. www.3ethicalhackers.com Do you find this valuable?