Logo Questions Linux Laravel Mysql Ubuntu Git Menu
 

How to log and compare Windows Registry data before and after any program installation?

I need to compare the windows registry data before and after install a program ?

like image 639
RicardoBalda Avatar asked Dec 16 '09 01:12

RicardoBalda


People also ask

How do I track Windows registry changes?

Launch Event Viewer, and browse to Event Viewer > Windows Logs > Security. You should see “Audit Success” events recording the date and time of your tweaks, and clicking these displays the name of the Registry key accessed, and the process responsible for the edit.

Which tool is used to Analyse the registry entries?

In order to extract Windows registry files from the computer, investigators have to use third-party software such as FTK Imager [3], EnCase Forensic [4] or similar tools. FTK Imager is oneo fthe most widely used tool for this task.

How do I monitor my registry activity?

Regshot Unicode is an Open-source Registry monitoring tool that monitors your computer's file system and Registry keys. A snapshot of the system registry is taken before and after the changes have been made. You will be able to see what changes have been made to your files by looking at that snapshot.


1 Answers

If you happen to have Total Commander, this is pretty easy:

  1. export the registry before the installation and after the installation (save with the same name in different folders)

  2. open both folders in Total Commander, highlight the file on one side, go to Files > Compare By Content... voilá:

enter image description here

Total Commander is shareware, try before you buy.

like image 68
Bulwersator Avatar answered Sep 25 '22 04:09

Bulwersator