09.02.2014 Views

Windows sysinternals

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

Chapter 16 Error Messages 385<br />

FIGURE 16-3 Outlook’s current directory preventing a rename in that folder hierarchy.<br />

The Case of the Failed AV Update<br />

After “The Case of the Process Killing Malware” was solved (as discussed in Chapter 18,<br />

“Malware”), Aaron’s friend Paul went home and instructed his son to keep all his software<br />

patched and up to date. He then set a good example by doing the same on his own desktop.<br />

Unfortunately, the result was an unbootable computer.<br />

Software must be kept up to date, so Paul updated the free antivirus software on his<br />

Microsoft <strong>Windows</strong> XP computer. When he rebooted, the computer displayed the <strong>Windows</strong><br />

XP startup splash screen progress bar and then blue-screened. Subsequent restarts ended<br />

the same way.<br />

Naturally, Paul called Aaron, who changed into his well-worn “No, I will not fix your<br />

computer” t-shirt and came over. Aaron could probably have solved the problem in Safe<br />

Mode or with System Restore, but those options must have seemed too easy for him.<br />

(Actually, he wanted to ensure that the failing software did not load.) Instead, he booted<br />

the computer with an old <strong>Windows</strong> Preinstallation Environment (WinPE) CD. He then ran<br />

Autoruns, chose File | Analyze Offline System, pointing Autoruns to the C:\<strong>Windows</strong> folder on<br />

the hard drive and to one of the profiles in the C:\Documents and Settings folder.<br />

The old WinPE instance was not able to verify signatures, so Aaron chose to hide Microsoft<br />

and <strong>Windows</strong> entries without signature verification, simply trusting that in this case no<br />

modules on the system would falsely claim to be from Microsoft. In addition to the failing<br />

antivirus’ Autostart Extensibility Points (ASEPs), Autoruns revealed several other services and<br />

drivers that were no longer needed and were out of date. Aaron disabled all of them, as<br />

shown in Figure 16-4, and restarted the computer.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!