“Analyze Offline System” Feature Added in Autoruns from Windows Sysinternals

Autoruns from Windows Sysinternals is a must-have tool for every troubleshooter, and it has always been in my toolkit (and kept updated regularly) for years. In v10.02 a new option "Analyze Offline System…" was added in Autoruns which enables you to inspect the startup configuration, services and other settings of an offline system.

You simply connect the subject PC’s hard disk as a slave drive to another system, or mount the drive/image which you want to analyze offline (for Malware / Rootkit removal, or for other purposes) in another system, and fire up Autoruns as Administrator (elevated). Mention the Windows directory and user profile locations of the offline system, and Autoruns will enumerate startup points and other settings from the system registry hives and NTUSER.DAT, from the relative directories of the mentioned paths.

  • System Registry Hives are located at \Windows\System32\Config
  • User Registry Hive NTUSER.DAT located at \Users\{username}

Autoruns and Dead Computer Forensics is a nice article written by Chad Tilbury – which you can go through for more information. Analyze Offline System feature in Autoruns would come in handy in situations where remote support/login to the problematic PC is not an option, or if the PC is in unbootable state especially in the aftermath of Malware / Rootkit attack or perhaps, due to other misconfiguration.

One small request: If you liked this post, please share this?

One "tiny" share from you would seriously help a lot with the growth of this blog. Some great suggestions:
  • Pin it!
  • Share it to your favorite blog + Facebook, Reddit
  • Tweet it!
So thank you so much for your support. It won't take more than 10 seconds of your time. The share buttons are right below. :)

Ramesh Srinivasan is passionate about Microsoft technologies and he has been a consecutive ten-time recipient of the Microsoft Most Valuable Professional award in the Windows Shell/Desktop Experience category, from 2003 to 2012. He loves to troubleshoot and write about Windows. Ramesh founded Winhelponline.com in 2005.

1 thought on ““Analyze Offline System” Feature Added in Autoruns from Windows Sysinternals”

  1. When using “Analyze offline system” after refreshing the ‘Autoruns” page the checked elements are unchecked again. How to make this permanent? Is this procedure read-only?


Leave a Reply