It is currently Wed Jun 19, 2013 6:06 am

All times are UTC - 8 hours




Post new topic Reply to topic  [ 6 posts ] 
Author Message
 Post subject: AIMP3
PostPosted: Thu Feb 16, 2012 5:43 pm 
Offline

Joined: Sat Mar 26, 2011 2:31 am
Posts: 646
Personally, I disagree with qualify aimp as Not Stealth, as reflected in its entry, because:

1) Running AIMP3 on an account without Admin rights (which I suppose is the most common scenario): Stealth.
2) Running AIMP3 on an account with Admin rights: Not stealth.
Creates the following keys:
XP 32
Code:
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIMP.TDropTarget
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AIMP.TDropTarget\CLSID
HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0041494D-5033-4472-6F70-546172676574}
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0041494D-5033-4472-6F70-546172676574}\LocalServer32
      HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{0041494D-5033-4472-6F70-546172676574}\ProgID
HKEY_CLASSES_ROOT\AIMP.TDropTarget
      HKEY_CLASSES_ROOT\AIMP.TDropTarget\CLSID
HKEY_CLASSES_ROOT\CLSID\{0041494D-5033-4472-6F70-546172676574}
      HKEY_CLASSES_ROOT\CLSID\{0041494D-5033-4472-6F70-546172676574}\LocalServer32
      HKEY_CLASSES_ROOT\CLSID\{0041494D-5033-4472-6F70-546172676574}\ProgID

VISTA 64
Code:
HKEY_CLASSES_ROOT\CLSID\{0041494D-5033-4472-6F70-546172676574}
      HKEY_CLASSES_ROOT\CLSID\{0041494D-5033-4472-6F70-546172676574}\ProgID
      HKEY_CLASSES_ROOT\CLSID\{0041494D-5033-4472-6F70-546172676574}\LocalServer32
HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0041494D-5033-4472-6F70-546172676574}\
      HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0041494D-5033-4472-6F70-546172676574}\LocalServer32
      HKEY_CLASSES_ROOT\Wow6432Node\CLSID\{0041494D-5033-4472-6F70-546172676574}\ProgID
HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{0041494D-5033-4472-6F70-546172676574}
      HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{0041494D-5033-4472-6F70-546172676574}\ProgID
      HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Classes\CLSID\{0041494D-5033-4472-6F70-546172676574}\LocalServer32


3) Running AIMP3 on an Admin account with less privileges using the runas command: Stealth
For example, launching the program with a bat file with this content:
Code:
runas /trustlevel:0x20000 AIMP3.exe

or
Code:
runas /trustlevel:"Basic User" AIMP3.exe

All the functions of the program work well this way.

To find out the levels available in your system (assuming that you're using an administrator account), just open a prompt and type:
Code:
c:\>runas /showlevels


So I think that, at least, it deserves a mention about the fact of its "stealthness" when is the case.
(Thanks to SYSTEM and dany for opening my eyes) :wink:


Top
 Profile  
 
 Post subject: Re: AIMP3
PostPosted: Fri Feb 17, 2012 5:37 am 
Offline
User avatar

Joined: Sat Jul 31, 2010 1:19 am
Posts: 824
Location: Helsinki, Finland
I have added more information to the entry.

lautrepay wrote:
(Thanks to SYSTEM and dany for opening my eyes) :wink:


What do you mean? These comments?

(BTW, I have regshotted PhotoFiltre Portable after writing the comment there. See this thread.)

_________________
My YouTube channel | Release date of my fourth playlist: April 11, 2013


Top
 Profile  
 
 Post subject: Re: AIMP3
PostPosted: Fri Feb 17, 2012 5:50 am 
Offline
User avatar

Joined: Mon Aug 27, 2007 2:00 am
Posts: 3787
SYSTEM wrote:
I have added more information to the entry.
Thanks. I was going to ask what would be the best approach with this entry and what you did seems it.

_________________
Added 177 Applications: Portable and an AutoIt MVP
SoftwareSpot - Portable Apps


Top
 Profile  
 
 Post subject: Re: AIMP3
PostPosted: Fri Feb 17, 2012 9:19 am 
Offline
User avatar

Joined: Wed Jun 20, 2007 1:00 pm
Posts: 1098
Location: Ingolstadt [DE]
guinness wrote:
Thanks. I was going to ask what would be the best approach with this entry and what you did seems it.
Agree :!:
We should keep this entry as brief as possible and avoid the necessity of editing it with every update.

The only thing I had to change is "Start AIMP2.exe" into "Launch AIMP3.exe" ... I missed that (too) :oops:


Top
 Profile  
 
 Post subject: Re: AIMP3
PostPosted: Fri Feb 17, 2012 12:35 pm 
Offline

Joined: Wed Jul 18, 2007 5:45 pm
Posts: 618
That "runas" command is new to me!

I only have two trust levels on my XP com - "Disallowed" and "Unrestricted."
Will give the "Disallowed" one a try to see what happens.

Update:
"Disallowed" doesn't allow the program to run, which is appropriate! ;)
"Unrestricted" is basically the same as running the app regularly as an admin. (Not stealth)

_________________
is it stealth? ;)


Top
 Profile  
 
 Post subject: Re: AIMP3
PostPosted: Fri Feb 17, 2012 4:50 pm 
Offline
User avatar

Joined: Thu Aug 07, 2008 4:51 am
Posts: 2614
freakazoid wrote:
That "runas" command is new to me!


It should be in your Windows\System32 folder (runas.exe). Documentation at http://www.microsoft.com/resources/docu ... x?mfr=true

_________________
bəʊɡɪ bəəs


Top
 Profile  
 
Display posts from previous:  Sort by  
Post new topic Reply to topic  [ 6 posts ] 

All times are UTC - 8 hours


Who is online

Users browsing this forum: No registered users and 2 guests


You cannot post new topics in this forum
You cannot reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot post attachments in this forum

Search for:
Jump to:  

Protected by Anti-Spam ACP Powered by phpBB © 2000, 2002, 2005, 2007 phpBB Group