+ Reply to Thread
Results 1 to 11 of 11

Thread: Registry watcher

  1. #1

    Join Date
    16.06.10
    P2P Client
    I can haz candy
    Posts
    590
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss590

    Question Registry watcher

    I'm looking for an application which watches all registry changes after OS install. If I install the trial version of Avast AntiVirus Internet Security, it ought to remove all registry changes made by that application. Meaning, if I installed the application again, the trial would start from 30 days.

    Please, don't recommend me Revo Uninstaller and the like. They don't cut it.
    Reply With QuoteReply With Quote
    Thanks

  2. #2
    Try Registrar Registry Manager. It's the best full-featured registry manager there is. Besides the obvious features, it also includes an activity monitor which is exactly what you are looking for. Can monitor specific operations such as: read, write, successful read, successful write and can monitor by specific application and/or by excluding several apps from search. And the results can be exported to a text file. The output is similar to this:

    Code:
    Date/time                    Action          Process        Status                                   Key                                                                                                                                                                    Not used   Value                                                                      Value type      Data   Size   Not used   Not used   HKEY   PID    ThreadID   CPU   
    -----------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------------
    9/6/2011 17:21:47.9581853    QueryKey        opera.exe      00000000  STATUS_SUCCESS                 HKEY_USERS\SANDBOX_RAZOR_OPERA\machine                                                                                                                                                                                                                                                                           64     3628   3632       0
    Reply With QuoteReply With Quote
    Thanks

  3. Who Said Thanks:

    sebota (10.09.11)

  4. #3

    Join Date
    16.06.10
    P2P Client
    I can haz candy
    Posts
    590
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss590
    SL mentioned that application. For my use, ought I monitor write and successful write or only successful write? Should I monitor more specific operations? Is the application able to monitor all successful write operations and monitor selected applications? I know it may be redundant, nevertheless I would find that useful.
    Reply With QuoteReply With Quote
    Thanks

  5. #4
    I think you may know about it, but I'll post it anyway,
    Process Monitor

    I don't know what specialities Master Razor's application have over this, but I tested it and It seems it can do the job well; monitor everything and then set a filter to look for Avast for example.


    I am cheatos

    Reply With QuoteReply With Quote
    Thanks

  6. #5
    I would say to monitor write and successful write. It's useful for users that modify settings in windows/specific applications and want to see which registry key corresponds to the setting. It wasn't intended for such installation activities but it will record all successful writes.
    Sorry if I couldn't be more helpful but I really haven't tested it on application install.
    It's still a lot safer than your average registry snapshot-install-compare. Those kind of applications capture everything (and chances are that they will capture a lot more than your application).
    Reply With QuoteReply With Quote
    Thanks

  7. #6

    Join Date
    16.06.10
    P2P Client
    I can haz candy
    Posts
    590
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss590
    When you say

    Quote Originally Posted by cheatos View Post
    set a filter to look for Avast
    what does that mean? Will it look for registry changes where it says "Avast" or is it more advanced?
    Reply With QuoteReply With Quote
    Thanks

  8. #7
    Reply With QuoteReply With Quote
    Thanks

  9. #8

    Join Date
    16.06.10
    P2P Client
    I can haz candy
    Posts
    590
    Activity Longevity
    0/20 17/20
    Today Posts
    0/5 ssssss590
    Quote Originally Posted by seldom View Post
    What about Regshot?
    Quote Originally Posted by Master Razor View Post
    Those kind of applications capture everything (and chances are that they will capture a lot more than your application).
    Seems like those applications aren't safe to rely on. Maybe it can be used in combination with Registrar Registry Manager.
    Reply With QuoteReply With Quote
    Thanks

  10. #9
    Quote Originally Posted by Gapo View Post
    When you say



    what does that mean? Will it look for registry changes where it says "Avast" or is it more advanced?
    Sorry for the late reply, (now I guess it's late, you must have already experimented with it ?)
    Anyway, I didn't try it much, but you can try it 'live' in a VM,
    install windows, install avast and this program,
    install avast while this program is monitoring, then save the log,
    later, open the log again, and select avast's exe or setup name as filter.

    It should work, howeve it's not tested.


    I am cheatos

    Reply With QuoteReply With Quote
    Thanks

  11. #10
    Quote Originally Posted by Gapo View Post
    Seems like those applications aren't safe to rely on. Maybe it can be used in combination with Registrar Registry Manager.
    The registry is constantly read and written to. Regshot takes a snapshot before and another after the changes have been made and only then it compares and outputs the changes. However, if between the snapshots a program is running in the background, say a virtual machine or utorrent or an antivirus then it will also be recorded but only if it writes to the registry. Which is something you can't be sure of. I'm not saying they are bad but you'll have to be careful.
    Reply With QuoteReply With Quote
    Thanks

  12. #11
    Retired Seal
    SealLion's Avatar
    Join Date
    03.05.08
    Location
    The Arctic--Believe it!!
    Posts
    2,079
    Activity Longevity
    0/20 19/20
    Today Posts
    0/5 sssss2079
    The thing that I have discovered in using Registrar Registry Manager is that it allows the user to multi-delete .reg entries as opposed to what Windows registry allows the user to do. That is to only individually delete unwanted .reg files making that process very time consuming.

    I've always found that after using the above named registry cleaner, which is in fact quite good for a number of reasons not to mention to see who the owner is of what-ever named registry and be able to change that ownership, is that it doesn't quite empty the registry of all unwanted registry entries (and many other very good inclusions that other registry cleaners don't offer are provided in this registry cleaner. You'll see once you begin using). Anyways, back on topic and I will tell you that no software on the market will completely and entirely clean out unwanted registry values. None will. You will always, always, and always have to go inside your own registry to take out unwanted registry entries. Revo??----forget it. It's useless. As are many other programs with the exception of a few.

    There is one other very, very good registry seeker and cleaner called Registry First Aid. Very good program. It will definitely clean out your registry but man, I tell ya..you better make some back-ups of registries that your unfamiliar with in using this program. I"ve had to bust my a$$ getting my registry back because I didn't make a back-up of .reg files that I knew I should have at at that time.

    CCleaner does'n't do enough of a good job. It only takes out 'safe' registry entries to delete without that deletion harming your system. PCCleaner??---forget that too.
    Last edited by SealLion; 10.09.11 at 05:54.
    "God, from the mount Sinai
    whose grey top shall tremble,
    He descending, will Himself,
    in thunder, lightning, and loud trumpet’s sound,
    ordain them laws".


    John Milton (1608-1674) in Paradise Lost


    Ripley's SealLion's Believe it or Not! ~ NASCAR car crashes and Windows have just one thing in common.
    Oh, oh. Better use LINUX.
    Reply With QuoteReply With Quote
    Thanks

+ Reply to Thread

Tags for this Thread

Posting Permissions

  • You may post new threads
  • You may post replies
  • You may not post attachments
  • You may not edit your posts
  •