RunScanner 1.0 released!

lusher

Member
Aug 17, 2007
86
0
0
RunScanner is a completely free windows system utility which scans your system for all configured running programs. You can use runscanner to detect autostart programs, spyware, adware, homepage hijackers, unverified drivers and other problems.

Very comprehensive autostart list

* Scanning of 80+ hijack locations, hosts file editor, process killer, online malware/whitelist analysis.
* Covers everything from Autoruns, HJT, Silentrunners and more.
* Malware will find it harder than ever to hide.
* Freeware.

For beginner and expert users

Beginner mode:
"Safe mode" : no changes can be made by the user.
Targetted at novice computer users that want support from a forum or from a malware specialist.
Beginners can upload or post a text of binary ".run" file. Experts can load it up into runscanner, examine it for malware and mark entries for removal and repost it. The beginner can reload the file and it will automatically make entries for removal.

Expert mode :
Targetted at expert users, this is the most powerful mode.
All delete, filter, export, lookup ... features are available.

Easier to use

* Online malware analysis of results. (optional, not required)
* Verification of authenticode signatures (Microsoft signed, signed by verified publisher, Whitelisted by online database )
* MD5 hash calculation of files + online file rating
* Online lookup of scanned entries. (Runscanner database + Google)
* RunScanner makes it easier to determine which entries are likely to be malicious.
* One executable, no installation required.
* Backup / restore of deleted items.

Log analysis made easy

* Saving and importing of text files to .run files (all information available)
* A user with problems can save the .run file, an expert can mark the items that need fixing and send the .run file back to the user
* Plain text file logging with only the items that need your attention.

Malware removal abilities and misc

* Powerful process killer
* Kill multiple processes at once
* Kill and rename
* Kill and delete
* Delete at next reboot
* Regedit jump
* Explorer jump
* Extended filters
* Marking of items.
 

redbeard1

Diamond Member
Dec 12, 2001
3,006
0
0
Interesting tool. I ran it on a system that I had cleaned of some nasty spyware, and it found old references for the two problem files I had removed then.

It takes a couple of minutes to run on an older system, but that would be related to how much it does check.

It does not appear to show a couple of spots that some new nasty hijackers have used recently.

These spots are:

Autorun entries from Registry:
HKCU\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

Autorun entries from Registry:
HKLM\Software\Microsoft\Windows\CurrentVersion\policies\Explorer\Run

These can be viewed if you use the misc tools feature of HijackThis (which is where I copied the text from). I have been looking for another tool that checks this spot.

Thanks for the heads up.
 

lusher

Member
Aug 17, 2007
86
0
0
Changelog 1.0.2
Fixed bug with "problem with shortcut , searching for file gui"
Fixed false positive warning with AVG antivirus
(Thanks to Lusher for reporting the bug)

Changelog 1.0.1 (Bugfix)
Fixed bug with AppInit_DLLs (Thanks to Lusher for reporting the bug)
 

lusher

Member
Aug 17, 2007
86
0
0
Updated to 1.0.3

http://www.runscanner.net/download.aspx

Changelog 1.0.3
Added trusted zones HKLM
Added HKCU\Software\Classes\Folder\Shellex\ColumnHandlers
Added HKCU\SOFTWARE\Microsoft\Active Setup\Installed Components
Added HKCU\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Added HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
Added 105 HKCU\Software\Microsoft\Internet Explorer\MenuExt
Fixed minor bug with incorrect filter
Fixed minor sorting bug in text log file
Changed behaviour with 068 -> download lsp-fix
Changed ctrl+c (copy) formatting
Google lookup now also searches for GUID, registry entry if no exename available.
 

bsobel

Moderator Emeritus<br>Elite Member
Dec 9, 2001
13,346
0
0
I'm always leary of a newbie posting about security software (especially one that has already had an AV product FP on it). But the site appears legit and the code actually is digitially signed from a small but known shareware producer.

FYI.
 

lusher

Member
Aug 17, 2007
86
0
0
Nah, you are right to be "leary". I have no creditability what so ever, for all you know I might be a bad guy trying to trick you...

so called Security programs are particularly good as trojans, because people always presume that because of their functions they are more likely to trigger FPs...

Most people wouldn't blink an eye if they find this so called security program (anti-rootkit or antivirus or whatever) requires administrative previlages to run...to install drivers and services... And Blam! They get hit!!!
 

lusher

Member
Aug 17, 2007
86
0
0
Changelog 1.6.3.0

MD5 calculation now uses the windows api for improved speed.
Added warning when access denied on reading/writing hosts file.
Fixed bug with copying MD5 hashes to clipboard.
Fixed bug with incorrect files not found.
Fixed bug when fixing some items, the items were fixed but not removed from the selection list
Fixed problem with invalid datatype for the internet explorer search page.
Added more safe publishers to the list.

Added Launch/hijack locations:

153 HKLM\Software\Microsoft\Windows NT\CurrentVersion\Drivers32\ Midi, Midi1 -> Midi9 (used by the silentbanker worm)
220 HKCU\Software\Classes\*\ShellEx\ContextMenuHandlers
221 HKLM\Software\Classes\*\ShellEx\ContextMenuHandlers
222 HKCU\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
223 HKLM\Software\Classes\AllFileSystemObjects\ShellEx\ContextMenuHandlers
224 HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers
225 HKCU\Software\Classes\Folder\ShellEx\ContextMenuHandlers
226 HKCU\Software\Classes\Directory\ShellEx\ContextMenuHandlers
227 HKLM\Software\Classes\Directory\ShellEx\ContextMenuHandlers
228 HKCU\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
229 HKLM\Software\Classes\Directory\Background\ShellEx\ContextMenuHandlers
230 HKCU\Software\Classes\Folder\Shellex\ColumnHandlers
231 HKLM\Software\Classes\Folder\Shellex\ColumnHandlers
240 HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
241 HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellIconOverlayIdentifiers
 
sale-70-410-exam    | Exam-200-125-pdf    | we-sale-70-410-exam    | hot-sale-70-410-exam    | Latest-exam-700-603-Dumps    | Dumps-98-363-exams-date    | Certs-200-125-date    | Dumps-300-075-exams-date    | hot-sale-book-C8010-726-book    | Hot-Sale-200-310-Exam    | Exam-Description-200-310-dumps?    | hot-sale-book-200-125-book    | Latest-Updated-300-209-Exam    | Dumps-210-260-exams-date    | Download-200-125-Exam-PDF    | Exam-Description-300-101-dumps    | Certs-300-101-date    | Hot-Sale-300-075-Exam    | Latest-exam-200-125-Dumps    | Exam-Description-200-125-dumps    | Latest-Updated-300-075-Exam    | hot-sale-book-210-260-book    | Dumps-200-901-exams-date    | Certs-200-901-date    | Latest-exam-1Z0-062-Dumps    | Hot-Sale-1Z0-062-Exam    | Certs-CSSLP-date    | 100%-Pass-70-383-Exams    | Latest-JN0-360-real-exam-questions    | 100%-Pass-4A0-100-Real-Exam-Questions    | Dumps-300-135-exams-date    | Passed-200-105-Tech-Exams    | Latest-Updated-200-310-Exam    | Download-300-070-Exam-PDF    | Hot-Sale-JN0-360-Exam    | 100%-Pass-JN0-360-Exams    | 100%-Pass-JN0-360-Real-Exam-Questions    | Dumps-JN0-360-exams-date    | Exam-Description-1Z0-876-dumps    | Latest-exam-1Z0-876-Dumps    | Dumps-HPE0-Y53-exams-date    | 2017-Latest-HPE0-Y53-Exam    | 100%-Pass-HPE0-Y53-Real-Exam-Questions    | Pass-4A0-100-Exam    | Latest-4A0-100-Questions    | Dumps-98-365-exams-date    | 2017-Latest-98-365-Exam    | 100%-Pass-VCS-254-Exams    | 2017-Latest-VCS-273-Exam    | Dumps-200-355-exams-date    | 2017-Latest-300-320-Exam    | Pass-300-101-Exam    | 100%-Pass-300-115-Exams    |
http://www.portvapes.co.uk/    | http://www.portvapes.co.uk/    |