Notifications
Clear all

Registry changes

6 Posts
6 Users
0 Reactions
434 Views
(@toddtvc)
Active Member
Joined: 18 years ago
Posts: 13
Topic starter  

I have began to using a virtual machine for testing or validating software tools or researching registry changes with USB devices. Is there some type of software out there that will show registry changes? My main purpose for this is to have a clean install of XP in VM and then attach different devices or install software and see what changes are made in the registry. Thanks.


   
Quote
 dcso
(@dcso)
Eminent Member
Joined: 19 years ago
Posts: 31
 

Have a look at Procmon and InCtrl5.


   
ReplyQuote
keydet89
(@keydet89)
Famed Member
Joined: 21 years ago
Posts: 3568
 

I'd look at Regshot, too, as an option.

Todd, I applaud your approach and hope that you intend to share your results.

One caveat that caught some AV companies a while back…be sure to distinguish between changes made by the device or software you installed, and those made by the shell. This can be dependent upon the OS, of course (ie, XP vs. Win2K3), but it's a good thing to keep in mind.


   
ReplyQuote
(@minesh)
Trusted Member
Joined: 18 years ago
Posts: 75
 

I was thinking about this a lot this week… is there a site which is has such information on for a wide range of software?

Kind of like a central database, where you can search for software, and it displays what changes are made using that software?

Minesh


   
ReplyQuote
(@kovar)
Prominent Member
Joined: 18 years ago
Posts: 805
 

Sounds like you've got a project ….

-David


   
ReplyQuote
(@jonathan)
Prominent Member
Joined: 20 years ago
Posts: 878
 

Have a look at Procmon and InCtrl5.

Yes - Process Monitor (procmon.exe) which developed out of Sysinternal's excellent RegMon and FileMon would I think provide what you need. RegMon is still available too. These tools are all free.

"Regmon is a Registry monitoring utility that will show you which applications are accessing your Registry, which keys they are accessing, and the Registry data that they are reading and writing - all in real-time. This advanced utility takes you one step beyond what static Registry tools can do, to let you see and understand exactly how programs use the Registry. With static tools you might be able to see what Registry values and keys changed. With Regmon you'll see how the values and keys changed"


   
ReplyQuote
Share: