Not a member of Pastebin yet?
Sign Up,
it unlocks many cool features!
- function format-autoruns () {
- #Process each csv into an object
- #This is used to prevent errors when exporting to csv file
- #if any of the fields are null
- $a = "Null"
- #Create Custom autorunsc object
- $objAutorunsc = New-Object System.Object
- $objAutorunsc | Add-Member -type NoteProperty -name entry -value $a
- $objAutorunsc | Add-Member -type Noteproperty -Name "image path" -Value $a
- $objAutorunsc | Add-Member -type NoteProperty -name Publisher -Value $a
- $objAutorunsc | Add-Member -type NoteProperty -name Enabled -Value $a
- $objAutorunsc | Add-Member -type NoteProperty -name Description -Value $a
- $objAutorunsc | Add-Member -type NoteProperty -name "Launch String" -Value $a
- $ObjAutorunsc | Add-Member -type Noteproperty -Name Category -Value $a
- if($_.entry -ne $Null){$objAutorunsc.entry = $_.entry}
- if($_.publisher -ne $null){$objAutorunsc.publisher = $_.publisher}
- if($_.enabled -ne $null){$objAutorunsc.enabled = $_.enabled}
- if($_."Image path" -ne $null){$objAutorunsc."Image path" = $_."image path"}
- if($_.description -ne $null){$objAutorunsc.description = $_.description}
- if($_."launch string" -ne $null){$objAutorunsc."launch string" = $_."launch string"}
- $objAutorunsc.Category = $_.Category
- return $objAutorunsc
- }
- function do-autorunsc () {
- ###############Check for non microsoft signed startup services or other other startup programs
- #Call Sysinternals program AutorunsC(ommandLine) and output Non MS IE, Hijacked Images, StartPrograms and #Services
- #Output (via the '>') to a text file, the '-c' means data will be returned in csv format
- #'-v' means verify signatures, '-m' means hide Microsoft entries. -'e' is for Internet Explore only
- #'-h' is for hijacked images only
- Set-Location <Autoruncs Location> #Change this to a directory that contains autorunsc.exe
- autorunsc -c -e -m -v > .\autorunsIE.csv
- autorunsc -c -h -m -v > .\autorunsHijack.csv
- autorunsc -c -m -v > .\autorunsStart.csv
- #import csv files into objects, filter only interesting fields
- $Non_MS_IE_Addon = Import-Csv ".\autorunsIE.csv" | select entry,publisher,enabled,"image path",description,"launch string"
- $Non_Ms_Image_Hijacks = Import-Csv ".\autorunsHijack.csv" | select entry,publisher,enabled,"image path",description,"launch string"
- $Non_MS_Startup = Import-Csv "autorunsStart.csv" | select entry,publisher,enabled,"image path",description,"launch string"
- #Create blank object to hold output from formatting function.
- $OutObj = @()
- $Non_MS_IE_Addon | Add-Member -type noteproperty -Name Category -Value "IE"
- $OutObj = $OutObj + ($Non_MS_IE_Addon | % {$_ | format-autoruns})
- if($Non_Ms_Image_Hijacks -ne $Null){ #Hijacks are likely to be null, this will prevent an error if it is
- $Non_Ms_Image_Hijacks | Add-Member -type noteproperty -Name Category -Value "Hijack"
- $OutObj = $OutObj + ($Non_MS_Image_hijacks | % {$_ | format-autoruns})
- }
- $Non_MS_startup | Add-Member -type noteproperty -Name Category -Value "Startup"
- $OutObj = $OutObj + ($Non_MS_Startup | % {$_ | format-autoruns})
- #Output formatted csv to file
- $OutObj | Export-Csv .\AutorunsLog.csv -force
- #cleanup
- del -Force .\autorunstart.csv -ErrorAction SilentlyContinue | Out-Null #out null prevents writing to console
- del -Force .\autorunsIE.csv -ErrorAction SilentlyContinue | Out-Null
- del -Force .\autorunsHijack.csv -ErrorAction SilentlyContinue | out-null
- Pop-Location
- }
Advertisement
Add Comment
Please, Sign In to add comment