View Full Version : Registry Compare
Rampage1329
02-14-2008, 01:36 PM
I have a windows xp vm machine. I am trying to load a virus to see what files and registry additions are being made. Our contract with trend is not solving the problem, is there a way I can see the registry entries and changes as they happen. I tried using teatimer by spybot but it isn't giving me enough information. Any help would be appreciative.
mattsaccount
02-14-2008, 01:42 PM
This tool may provide what you're looking for, but you'll have to filter the results to exclude all the normal registry changes that occur in the background as the system sits there.
http://www.microsoft.com/technet/sysinternals/processesandthreads/regmon.mspx
Edit: realized that's out-of-date now. Try this:
http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx
Rampage1329
02-14-2008, 04:52 PM
this looks like it might work. Does it list dlls?
SpaceHonkey
02-14-2008, 05:52 PM
I used to use a tool called regsnap. Looks like it's still out there. Not sure how long the demo lasts...
http://lastbit.com/regsnap/
vBulletin® v3.8.2, Copyright ©2000-2009, Jelsoft Enterprises Ltd.