[Solved] Sysinternals Autoruns - No longer detected (Bug)
-
Sysinternals Autoruns was detected in the past but currently it is no longer detected.
Here you can see that Sysinternals Autoruns was detected in the past: https://vulndetect.org/topic/508/added-autoruns-app-requestNote
The Current Version displayed in Help -> About is 13.96.
So please use the field File Version String or Product Version String to get the correct version number.
Here the information extracted from the 64-Bit EXE file:
File name and path: D:\PortableApps\PortableApps\_WSCCPortable\Sysinternals Suite\Autoruns64.exe Product Name: Sysinternals autoruns Internal Name: Sysinternals Autoruns Original Filename: autoruns.exe File Description: Autostart program viewer Company: Sysinternals - www.sysinternals.com Legal Copyright: Copyright (C) 2002-2019 Mark Russinovich Legal Trademarks: Comments: File Version String: 13.96 File Version: 13.96.0.0 Product Version String: 13.96 Product Version: 13.96.0.0
Here the information extracted from the 32-Bit EXE file:
File name and path: D:\PortableApps\PortableApps\_WSCCPortable\Sysinternals Suite\Autoruns.exe Product Name: Sysinternals autoruns Internal Name: Sysinternals Autoruns Original Filename: autoruns.exe File Description: Autostart program viewer Company: Sysinternals - www.sysinternals.com Legal Copyright: Copyright (C) 2002-2019 Mark Russinovich Legal Trademarks: Comments: File Version String: 13.96 File Version: 13.96.0.0 Product Version String: 13.96 Product Version: 13.96.0.0
-
I think this is because it is bundled with WSSC, thus you can't see it, because you use a corporate account.
If you inspect the same host using your personal account, then you ought to see it. Including more Sysinternal utilities.
Beware that everything Sysinternals is in an intermediate stage for a few days, because we added a lot, and we still have a backlog of rules to add for many versions. And even the product name for a handful or so.
-
@Tom I looged in with my personal account, where I see Last Inspection 2 months ago.
But here I see that Sysinternal and Nirsoft are bundled with WSCC:So this issue is solved...