|
|
Topics
|
Reglooks
reglooks.exe
marcvn/tools/reglooks
Regslook
Download reglooks zum Desktop
Doppelklick reglooks.exe.
-
Mach weiter nichts - warte bis sich ein Logfile öffnet
-
Kopiere den Inhalt des Berichts in den Thread (Sicherheitsforum)
--- SSODL regkeys ---
--- USERINIT regkey ---
--- SHELL regkey ---
--- SYSTEM regkey ---
--- APPINIT_DLLS regkey ---
--- NOTIFY regkeys ---
--- BOOTEXECUTE regkey ---
--- SHELLEXECUTEHOOKS regkey ---
--- HKLM\Run regkeys ---
--- HKLM\RunOnce regkeys ---
--- HKLM\RunOnceEx regkeys ---
--- HKLM\RunServices regkeys ---
--- HKLM\RunServicesOnce regkeys ---
--- HKCU\Run regkeys ---
HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
"ctfmon.exe"="C:\\WINDOWS\\System32\\ctfmon.exe"
--- BROWSER HELPER OBJECTS regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\
Explorer\Browser Helper Objects
"{00C6482D-C502-44C8-8409-FCE54AD9C208}" FILE ="C:\\Program Files\\
TechSmith\\SnagIt 6\\SnagItBHO.dll"
--- TOOLBAR regkeys ---
HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Toolbar
"{E915E62E-41DA-40D0-8106-3438B4D24394}" FILE ="C:\\Program Files\\
WinSweep\\SurfBar.dll"
--- URLSEARCHHOOKS regkeys ---
HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\
URLSearchHooks
only standard regkeys found
--- CONTEXTMENUHANDLERS regkeys ---
HKEY_CLASSES_ROOT\*\shellex\
ContextMenuHandlers
--- ALTERNATESHELL regkey ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Control\SafeBoot
"AlternateShell"="cmd.exe"
--- SERVICES ---
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\
Services\TSP
"DisplayName"="TSP"
\??\C:\WINDOWS\system32\drivers\klif.sys
|
|
Suchbegriff eingeben:
--- SECURITYPROVIDERS regkey ---
--- SVCHOST regkey ---
--- WOW-CMDLINE regkeys ---
--- DNS SERVER regkeys ---
--- STARTUP FOLDERS ---
--- TASK SCHEDULER JOBS ---
--- File associations ---
.BAT files: ("%1" %*)
.COM files: ("%1" %*)
.EXE files: ("%1" %*)
.HLP files: (%SystemRoot%\System32\winhlp32.exe %1)
.INF files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.INI files: (%SystemRoot%\System32\NOTEPAD.EXE %1)
.JS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
.PIF files: ("%1" %*)
.REG files: (regedit.exe "%1")
.SCR files: ("%1" /S)
.TXT files: (%SystemRoot%\system32\NOTEPAD.EXE %1)
.VBS files: (%SystemRoot%\System32\WScript.exe "%1" %*)
|
|