Control Registry

ulair

Distinguished
Oct 22, 2006
3
0
18,510
Hi, im wondering if there is any possibility to see what programs do with the registry.
Is there a way to see what a program reads/adds/changes in the registry?

Is there a tool that can watch that?

Thx in advance for help
 

fattony

Distinguished
Oct 16, 2006
609
0
18,990
www.sysinternals.com

look for filemon and regmon, real-time logging of what reg keys get opened, closed, accessed, and enumerated, filemon also shows the files being used

use filtering options to make it a bit clearer, these things log access very heavily so you might get confused...turning off ur AV while monitoring the traces would help too
 

fattony

Distinguished
Oct 16, 2006
609
0
18,990
np...if u're having a particular issue with registry access, look for the access denied message in the .log files from regmon, they're very helpful