A forum for reverse engineering, OS internals and malware analysis 

Ask your beginner questions here.
 #4487  by Every1is=
 Sun Jan 16, 2011 3:14 pm
Jaxryley wrote:XP VM.

This one instigates a reboot and hotkeys won't work with it active.

Had to boot from a live cd and delete the exe or you can put RogueKiller in the Startup folder before executing the sample which will kill the trojan's process at restart.

xpiofrbtkzhr.exe - 18/43 - TR/Ransom
http://www.virustotal.com/file-scan/rep ... 1290435591
xpiofrbtkzhr.rar
Ah, good thing I came across your post!! Something I have wanted to know for a long long time.... What is the order in which windows loads startup items? Which ones and how the H*LL can you change the load order of those?
I mean... I know there are registry keys for drivers and startup items in the registry as well as the startup folder and the possibility to load services, of course. But your example is a perfect one: how do I make sure that a certain tool loads before another tool or driver? I have had some instances where I needed (well, wanted) to switch load order of drivers to troubleshoot a problem. I had found no information on this back then, and even up to now, only one tool that allows you to simply change the order. I forgot the name, sorry... but I do remember you could register at their site for platinum and/or gold licences for their software. My point being: it is possible and it is being done. Why couldn't I find anything useful about it? Or documentation to point me in the right direction? On top of that, I am no skilled programmer at all so delving into the MS windows developper documentation to write my own tool won't do me any good probably, I fear, since the things you guys do here just overshoot human abilities IMO. Any of you guys know what to do/where to look so I can switch load order of drivers/tools/services if necessary for troubleshooting a system when necessary?
 #4490  by EP_X0FF
 Sun Jan 16, 2011 3:20 pm
Hello,

check this tool from Bryce Cogswell

Regards.
 #4492  by Every1is=
 Sun Jan 16, 2011 3:59 pm
Sorry for the OT post in the other thread EP... and thanks for the link!!
I'll posts these Q's in this section in the future.