AutorunCheck Forensic Edition
AutorunCheck Forensic Edition is a system diagnostic software tool designed to expedite the process of identifying and verifying persistence mechanisms in Microsoft Windows PCs. This tool was created to facilitate the jobs of system support professionals and malware forensics investigators and it offers all the product features available from the AutorunCheck Desktop Edition both on the local system and also through a mounted clone drive or acquired image from another PC.
Please note that all the features are available not only to the local system and but also from a remote cloned drive/image:
- Snapshot target: live system and any shadow copies of the local or remote system drive.
- Snapshot History: Changes in history that have been made to any Autorun entry and easier to detect unwanted changes made by potentially malicious software.
- Timline/History Search: Any suspicious Autorun entry can be traced to all the changed events of a system Snapshot history
Supported Windows Operating Systems:
- Microsoft® Windows® XP SP2/Vista/7/8/10 Technical Preview
Additional Requirements: Internet connection for evaluating Autorun entries with the Autorun Setting Repository Version Histories: Version 1.0.1 General Release