Forum Discussion

firepark32's avatar
firepark32
Copper Contributor
Aug 08, 2024

Issue with Autoruns v14.11 – Offline System Registry Hives Not Unmounted

 

When using the Analyze Offline System option leaves registry hives mounted, risking system corruption.

 

Steps to Reproduce:

  1. Open Autoruns v14.11.
  2. Use File > Analyze Offline System.
  3. Close AutoRuns.
  4. Observe that registry hives remain mounted after the process has terminated. (Regedit.exe > HKLM > autoruns.software / autoruns.system / autoruns.user)

Impact:

  1. Can render the offline system unbootable.
  2. Prevents you from using Analyze Offline System again as the HKLM\autoruns.* mountpoints are already in use.

 

Workaround: Use v13.100, which works correctly.

 

No RepliesBe the first to reply

Resources