Exetools  

Go Back   Exetools > General > General Discussion

Notices

Reply
 
Thread Tools Display Modes
  #1  
Old 07-23-2004, 21:45
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
Registry Monitoring, what's best?

I searched and found a thread about Registry Snapshots, but not real time registry monitoring under WinXP!

I use Regmon, but does it capture ALL activity from any dll's, ocx files etc, from the program you want to monitor?

I've installed a Macromedia projector prog but can't find where it stored the reg number using Regmon, tried Filemon to see if it was in a file, again no dice! This prog creates many temp files in my temp folder, but regmon/filemon never reports any of them are running, just the main app used to launch the prog.

I've also tried Active Registry Monitor to compare snapshots and a prog called MultiMon, but it kept giving Monitor failed error and never showed anything? Neither found where the reg number was being stored

Any suggestions (other than use Google you moron ) for an in depth registry monitor?
Reply With Quote
  #2  
Old 07-23-2004, 22:10
DARKER DARKER is offline
VIP
 
Join Date: Jul 2004
Location: Somewhere Over the Rainbow
Posts: 541
Rept. Given: 16
Rept. Rcvd 123 Times in 54 Posts
Thanks Given: 21
Thanks Rcvd at 1,038 Times in 262 Posts
DARKER Reputation: 100-199 DARKER Reputation: 100-199
Thumbs up Best one

The best one is by me Regmon (Good work Mark). But when you want use it in "Real world" i recommende change the window name and others things that can't be detected by other progies :-)
Reply With Quote
  #3  
Old 07-23-2004, 23:17
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
I remember a patch for an earlier version of Regmon/Filemon, but it's not been updated for newer versions!

I managed to sort it out eventually. Have Win98 on another partition, so booted it up, ran Active Registry Monitor before/after installing the prog and it found the reg key I was looking for

Would still like to see it 'real time' though!
Reply With Quote
  #4  
Old 07-23-2004, 23:48
bilbo bilbo is offline
Friend
 
Join Date: Jul 2004
Posts: 103
Rept. Given: 36
Rept. Rcvd 15 Times in 12 Posts
Thanks Given: 15
Thanks Rcvd at 17 Times in 11 Posts
bilbo Reputation: 15
I suggest you REGSHOT: less than 50 KB!

It simply do snapshots before and after installations, and then compares the two. It cannot be defeated. It does not need installation. It can do the same job to monitor directories...

Small is beautiful
bilbo
Reply With Quote
  #5  
Old 07-24-2004, 06:02
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
Thanks bilbo, just tried Regshot, does the job too! It's not as polished as Active Registry Monitor but for 43kb it's not surprising

Another tool for the collection!
Reply With Quote
  #6  
Old 07-26-2004, 02:27
Barry Barry is offline
Friend
 
Join Date: Dec 2003
Posts: 84
Rept. Given: 10
Rept. Rcvd 1 Time in 1 Post
Thanks Given: 0
Thanks Rcvd at 1 Time in 1 Post
Barry Reputation: 2
Regshot runs under WinXP for me so can't see why it won't run under 2000!

Here's a link to it:

Code:
http://k3nny.wz.cz/regshot.1.7.2.zip
Reply With Quote
  #7  
Old 08-08-2004, 00:55
JBG
 
Posts: n/a
System Mechanic also has a good one included. I have used it for years.
They call it Safe Installer. Shows before and after for your whole system.
Reply With Quote
Reply


Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
What tool for Monitoring Application Eugen General Discussion 18 10-10-2023 00:22
fibratus: A useful tool for cracking and monitoring Turkuaz General Discussion 0 10-05-2023 06:05


All times are GMT +8. The time now is 23:45.


Always Your Best Friend: Aaron, JMI, ahmadmansoor, ZeNiX, chessgod101
( Since 1998 )