How does RegRun work?
1. If you use Windows NT4/2000/XP/Vista:
When Windows starts, you can see the following files:
%SYSTEMROOT%\SYSTEM32\config.nt
%SYSTEMROOT%\SYSTEM32\autoexec.nt
Registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\RunEx
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Values: Shell, Run, Load
HKLM\Software\Microsoft\Active Setup\Installed Components
Additionally registry keys monitored by Registry Tracer:
HKCU\Software\Microsoft\Internet Explorer\Main, Start Page value
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs value
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, UserInit value
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, BootExecute value
The number of recommended to tracing registry keys increases every day.
Read the latest information at http://www.regrun.com.
File Extensions (on default):
pif, bat, com, exe.
Device drivers.
NT Services.
2. If you use Windows 95/98/ME.
When RegRun is started for the first time, it reads the following files:
· AUTOEXEC.BAT
· CONFIG.SYS
· WINSTART.BAT
· WIN.INI
· SYSTEM.INI
And the following registry keys:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices
HKCU\Software\Microsoft\Windows\CurrentVersion\Run
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx
HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce
HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce
HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce
Additionally registry keys monitored by Registry Tracer:
HKCU\Software\Microsoft\Internet Explorer\Main, Start Page value
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks
HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad
HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs value
HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, UserInit value
HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, BootExecute value
The number of recommended to tracing registry keys increases every day.
Read the latest information at http://www.regrun.com.
File Extensions (on default):
pif, bat, com, exe.
VXD and Device drivers.
Finally: STARTUP and COMMON STARTUP folders.
Whichever Windows you are using, RegRun remembers the entries in the registry and checks them every time you start. With each start, RegRun lists any changes found in a log file, which you can view at any time.
You may activate Secure Start. This has a unique function in that it allows the removal of programs before loading Windows!
Open RegRun Control Center, Options, Secure Start. Check "Secure Start DOS" (only for Windows 95/98) or "Secure Start Windows" box.
Secure Start is activated automatically if you selected "High" or "Ultra High" Security Level.
Read more about Secure Start.