Reglooks
|
ReglooksReglooks erstellt ein Verzeichnis aller Registry-Einträge von Windows.• Download zum Desktop reglooks.exe • Doppelklick reglooks.exe • Mach weiter nichts - warte bis sich ein Logfile öffnet • Kopiere den Inhalt des Berichts in den Thread (Sicherheitsforum)
• Reglooks erstellt ein Verzeichnis dieser Registry-Einträge: --- SSODL regkeys --- --- USERINIT regkey --- --- SHELL regkey --- --- SYSTEM regkey --- --- APPINIT_DLLS regkey --- --- NOTIFY regkeys --- --- BOOTEXECUTE regkey --- --- SHELLEXECUTEHOOKS regkey --- --- HKLM\Run regkeys --- --- HKLM\RunOnce regkeys --- --- HKLM\RunOnceEx regkeys --- --- HKLM\RunServices regkeys --- --- HKLM\RunServicesOnce regkeys --- --- HKCU\Run regkeys --- HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run "ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe" --- BROWSER HELPER OBJECTS regkeys --- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\ Explorer\Browser Helper Objects "{00C6482D-C502-44C8-8409-FCE54AD9C208}" FILE ="C:\\Program Files\\ TechSmith\\SnagIt 6\\SnagItBHO.dll" --- TOOLBAR regkeys --- HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar "{E915E62E-41DA-40D0-8106-3438B4D24394}" FILE ="C:\\Program Files\\ WinSweep\\SurfBar.dll" --- URLSEARCHHOOKS regkeys --- HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\ URLSearchHooks only standard regkeys found --- CONTEXTMENUHANDLERS regkeys --- HKEY_CLASSES_ROOT\*\shellex\ ContextMenuHandlers --- ALTERNATESHELL regkey --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Control\SafeBoot "AlternateShell"="cmd.exe" --- SERVICES --- HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\ Services\TSP "DisplayName"="TSP" \??\C:\WINDOWS\system32\drivers\klif.sys --- SECURITYPROVIDERS regkey --- --- SVCHOST regkey --- --- WOW-CMDLINE regkeys --- --- DNS SERVER regkeys --- --- STARTUP FOLDERS --- --- TASK SCHEDULER JOBS --- --- File associations --- .BAT files: ("%1" %*) .COM files: ("%1" %*) .EXE files: ("%1" %*) .HLP files: (%SystemRoot%\System32\winhlp32.exe %1) .INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1) .JS files: (%SystemRoot%\System32\WScript.exe "%1" %*) .PIF files: ("%1" %*) .REG files: (regedit.exe "%1") .SCR files: ("%1" /S) .TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1) .VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*) |