Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 07-23-2004, 21:45
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
Registry Monitoring, what's best?

I searched and found a thread about Registry Snapshots, but not real time registry monitoring under WinXP!

I use Regmon, but does it capture ALL activity from any dll's, ocx files etc, from the program you want to monitor?

I've installed a Macromedia projector prog but can't find where it stored the reg number using Regmon, tried Filemon to see if it was in a file, again no dice! This prog creates many temp files in my temp folder, but regmon/filemon never reports any of them are running, just the main app used to launch the prog.

I've also tried Active Registry Monitor to compare snapshots and a prog called MultiMon, but it kept giving Monitor failed error and never showed anything? Neither found where the reg number was being stored

Any suggestions (other than use Google you moron ) for an in depth registry monitor?
Reply With Quote
  #2  
Old 07-23-2004, 22:10
DARKER DARKER is offline
VIP
 
Join Date: Jul 2004
Location: Somewhere Over the Rainbow
Posts: 541
Rept. Given: 16
Rept. Rcvd 123 Times in 54 Posts
Thanks Given: 21
Thanks Rcvd at 1,038 Times in 262 Posts
DARKER Reputation: 100-199 DARKER Reputation: 100-199
Thumbs up Best one

The best one is by me Regmon (Good work Mark). But when you want use it in "Real world" i recommende change the window name and others things that can't be detected by other progies :-)
Reply With Quote
  #3  
Old 07-23-2004, 23:17
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
I remember a patch for an earlier version of Regmon/Filemon, but it's not been updated for newer versions!

I managed to sort it out eventually. Have Win98 on another partition, so booted it up, ran Active Registry Monitor before/after installing the prog and it found the reg key I was looking for

Would still like to see it 'real time' though!
Reply With Quote
  #4  
Old 07-23-2004, 23:48
bilbo bilbo is offline
Friend
 
Join Date: Jul 2004
Posts: 103
Rept. Given: 36
Rept. Rcvd 15 Times in 12 Posts
Thanks Given: 15
Thanks Rcvd at 17 Times in 11 Posts
bilbo Reputation: 15
I suggest you REGSHOT: less than 50 KB!

It simply do snapshots before and after installations, and then compares the two. It cannot be defeated. It does not need installation. It can do the same job to monitor directories...

Small is beautiful
bilbo
Reply With Quote
  #5  
Old 07-24-2004, 06:02
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
Thanks bilbo, just tried Regshot, does the job too! It's not as polished as Active Registry Monitor but for 43kb it's not surprising

Another tool for the collection!
Reply With Quote
  #6  
Old 07-26-2004, 02:27
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
Regshot runs under WinXP for me so can't see why it won't run under 2000!

Here's a link to it:

Code:
http://k3nny.wz.cz/regshot.1.7.2.zip
Reply With Quote
  #7  
Old 07-26-2004, 05:55
ak74
 
Posts: n/a
There's a Utility InCtr-5 [ In Control ] from Pc Mag which one can run before installing any program and again after install is done [ even after a reboot ] and which give a log of what the changes were made to the Registry.

The only problem is the is log is Megabyte size file to peruse !

Pc mag Uty's are no longer free . They charge $5.00 for any three. I have this one , but do not know how to send it ? If any body needs it to try .

Please leave a clear instruction . Thank you.
Reply With Quote
  #8  
Old 07-26-2004, 12:47
TheDutchJewel's Avatar
TheDutchJewel TheDutchJewel is offline
VIP
 
Join Date: Aug 2002
Posts: 716
Rept. Given: 27
Rept. Rcvd 464 Times in 267 Posts
Thanks Given: 20
Thanks Rcvd at 642 Times in 183 Posts
TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499 TheDutchJewel Reputation: 400-499
ak47, I'll up it for you.

This is the one I have:
Quote:
InCtrl5, Version 1.0
Copyright (c) 2000 Ziff Davis Media, Inc.
Written by Neil J. Rubenking
First Published in PC Magazine, US Edition, December 5, 2000, v19n21
http://www.pcmag.com/utilities/
Attached Files
File Type: rar InCtrl5 v1.0.rar (758.4 KB, 19 views)
__________________
thedutchjewel.freehostia.com
Reply With Quote
  #9  
Old 07-26-2004, 13:06
JMI JMI is offline
Leader
 
Join Date: Jan 2002
Posts: 1,627
Rept. Given: 5
Rept. Rcvd 199 Times in 99 Posts
Thanks Given: 0
Thanks Rcvd at 98 Times in 96 Posts
JMI Reputation: 100-199 JMI Reputation: 100-199
That file is nearly as old as I am. Well not quite, but my CD is gathering dust in the cabinet, and that's where it will stay. There are too many later, more functional versions of registry montoring devices to go back to some of the really old stuff. But hey, if it works for you, and you want to, use it. But all the other, newer ones are out there available for downloading on the net. And NO, don't ask me where, go search and yee shall find. And InCtrl5 is available everywhere on the net.

[Edit: hackmix, in an effort to get his first post, claimed the program could not be defeated and didn't even have to be installed. Since the program under discussion comes in a installer and does not, as described, include a standalone exe, hackmix's post has been removed.]

[Edit2: There is also a script available on the net to exclude the recording.of some things you might not want to record. This would be agumented. Search for: "inctrl5_exclusion.txt".]


Regards,
__________________
JMI
Reply With Quote
  #10  
Old 07-27-2004, 15:14
ssb ssb is offline
Friend
 
Join Date: Jul 2004
Location: Europe
Posts: 16
Rept. Given: 0
Rept. Rcvd 0 Times in 0 Posts
Thanks Given: 0
Thanks Rcvd at 0 Times in 0 Posts
ssb Reputation: 0
I use TotalUninstall for that kind of job. It can export file/registry mods in a text file with before/after fields. That's very helpful.
With TUN you always have the full uninstall option too
Reply With Quote
  #11  
Old 07-29-2004, 20:53
Paasan
 
Posts: n/a
you could try LockDown Millennium registry monitor and see if you like it. its not freeware though.

hxxp://lockdowncorp.com/manual/RegistrySettings.htm
Reply With Quote
  #12  
Old 07-29-2004, 22:39
deviljin
 
Posts: n/a
Why not give Advanced Registry Tracer a try? See for it and let us know

deviljin
Reply With Quote
  #13  
Old 07-29-2004, 23:22
robino
 
Posts: n/a
you can also try Resplendent Registrar, it seems to be good
Reply With Quote
  #14  
Old 08-08-2004, 00:55
JBG
 
Posts: n/a
System Mechanic also has a good one included. I have used it for years.
They call it Safe Installer. Shows before and after for your whole system.
Reply With Quote
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What tool for Monitoring Application Eugen General Discussion 18 10-10-2023 00:22
fibratus: A useful tool for cracking and monitoring Turkuaz General Discussion 0 10-05-2023 06:05


All times are GMT +8. The time now is 19:29.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )