Guest User

Untitled

a guest
Sep 22nd, 2011
561
0
Never
Not a member of Pastebin yet? Sign Up, it unlocks many cool features!
  1. function format-autoruns () {
  2.  
  3. #Process each csv into an object
  4. #This is used to prevent errors when exporting to csv file
  5. #if any of the fields are null
  6.  
  7. $a = "Null"
  8. #Create Custom autorunsc object
  9. $objAutorunsc = New-Object System.Object
  10. $objAutorunsc | Add-Member -type NoteProperty -name entry -value $a
  11. $objAutorunsc | Add-Member -type Noteproperty -Name "image path" -Value $a
  12. $objAutorunsc | Add-Member -type NoteProperty -name Publisher -Value $a
  13. $objAutorunsc | Add-Member -type NoteProperty -name Enabled -Value $a
  14. $objAutorunsc | Add-Member -type NoteProperty -name Description -Value $a
  15. $objAutorunsc | Add-Member -type NoteProperty -name "Launch String" -Value $a
  16. $ObjAutorunsc | Add-Member -type Noteproperty -Name Category -Value $a
  17.  
  18.     if($_.entry -ne $Null){$objAutorunsc.entry = $_.entry}
  19.     if($_.publisher -ne $null){$objAutorunsc.publisher = $_.publisher}
  20.     if($_.enabled -ne $null){$objAutorunsc.enabled = $_.enabled}
  21.     if($_."Image path" -ne $null){$objAutorunsc."Image path" = $_."image path"}
  22.     if($_.description -ne $null){$objAutorunsc.description = $_.description}
  23.     if($_."launch string" -ne $null){$objAutorunsc."launch string" = $_."launch string"}
  24.     $objAutorunsc.Category = $_.Category
  25.  
  26. return $objAutorunsc
  27. }
  28.  
  29. function do-autorunsc () {
  30. ###############Check for non microsoft signed startup services or other other startup programs
  31.  
  32. #Call Sysinternals program AutorunsC(ommandLine) and output Non MS IE, Hijacked Images, StartPrograms and #Services
  33. #Output (via the '>') to a text file, the '-c' means data will be returned in csv format
  34. #'-v' means verify signatures, '-m' means hide Microsoft entries.  -'e' is for Internet Explore only
  35. #'-h' is for hijacked images only
  36.  
  37.  
  38. Set-Location <Autoruncs Location>  #Change this to a directory that contains autorunsc.exe
  39. autorunsc -c -e -m -v > .\autorunsIE.csv
  40. autorunsc -c -h -m -v > .\autorunsHijack.csv
  41. autorunsc -c -m -v > .\autorunsStart.csv
  42.  
  43. #import csv files into objects, filter only interesting fields
  44.  
  45. $Non_MS_IE_Addon = Import-Csv ".\autorunsIE.csv" | select entry,publisher,enabled,"image path",description,"launch string"
  46. $Non_Ms_Image_Hijacks = Import-Csv ".\autorunsHijack.csv" | select entry,publisher,enabled,"image path",description,"launch string"
  47. $Non_MS_Startup = Import-Csv "autorunsStart.csv" | select entry,publisher,enabled,"image path",description,"launch string"
  48.  
  49. #Create blank object to hold output from formatting function.
  50. $OutObj = @()
  51.  
  52. $Non_MS_IE_Addon | Add-Member -type noteproperty -Name Category -Value "IE"
  53. $OutObj = $OutObj + ($Non_MS_IE_Addon | % {$_ | format-autoruns})
  54. if($Non_Ms_Image_Hijacks -ne $Null){ #Hijacks are likely to be null, this will prevent an error if it is
  55.      $Non_Ms_Image_Hijacks | Add-Member -type noteproperty -Name Category -Value "Hijack"
  56.      $OutObj = $OutObj + ($Non_MS_Image_hijacks | % {$_ | format-autoruns})
  57. }
  58. $Non_MS_startup | Add-Member -type noteproperty -Name Category -Value "Startup"
  59. $OutObj = $OutObj + ($Non_MS_Startup | % {$_ | format-autoruns})
  60.  
  61. #Output formatted csv to file
  62. $OutObj | Export-Csv .\AutorunsLog.csv -force
  63.  
  64. #cleanup
  65. del -Force .\autorunstart.csv -ErrorAction SilentlyContinue | Out-Null #out null prevents writing to console
  66. del -Force .\autorunsIE.csv -ErrorAction SilentlyContinue | Out-Null
  67. del -Force .\autorunsHijack.csv -ErrorAction SilentlyContinue | out-null
  68. Pop-Location
  69.  
  70. }
Advertisement
Add Comment
Please, Sign In to add comment