How does RegRun work?

1. If you use Windows NT4/2000/XP/Vista:

When Windows starts, you can see the following files:

%SYSTEMROOT%\SYSTEM32\config.nt

%SYSTEMROOT%\SYSTEM32\autoexec.nt

Registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunEx

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

 

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKEY_LOCAL_MACHINE\Software\Microsoft\Windows NT\CurrentVersion\Winlogon

Values: Shell, Run, Load

HKLM\Software\Microsoft\Active Setup\Installed Components

 

Additionally registry keys monitored by Registry Tracer:

HKCU\Software\Microsoft\Internet Explorer\Main, Start Page value

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs value

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, UserInit value

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, BootExecute value

The number of recommended to tracing registry keys increases every day.

Read the latest information at http://www.regrun.com.

 

File Extensions (on default):

pif, bat, com, exe.

 

Device drivers.

NT Services.

 

2. If you use Windows 95/98/ME.

When RegRun is started for the first time, it reads the following files:

·      AUTOEXEC.BAT

·      CONFIG.SYS

·      WINSTART.BAT

·      WIN.INI

·      SYSTEM.INI

And the following registry keys:

HKLM\Software\Microsoft\Windows\CurrentVersion\RunEx

HKLM\Software\Microsoft\Windows\CurrentVersion\Run

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServices

HKCU\Software\Microsoft\Windows\CurrentVersion\Run

 

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnceEx

HKLM\Software\Microsoft\Windows\CurrentVersion\RunOnce

HKLM\Software\Microsoft\Windows\CurrentVersion\RunServicesOnce

HKCU\Software\Microsoft\Windows\CurrentVersion\RunOnce

 

HKLM\Software\Microsoft\Active Setup\Installed Components

 

Additionally registry keys monitored by Registry Tracer:

HKCU\Software\Microsoft\Internet Explorer\Main, Start Page value

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks

HKLM\Software\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Windows, AppInit_DLLs value

HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon, UserInit value

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager, BootExecute value

The number of recommended to tracing registry keys increases every day.

Read the latest information at http://www.regrun.com.

 

File Extensions (on default):

pif, bat, com, exe.

VXD and Device drivers.

 

Finally: STARTUP and COMMON STARTUP folders.

 

Whichever Windows you are using, RegRun remembers the entries in the registry and checks them every time you start. With each start, RegRun lists any changes found in a log file, which you can view at any time.

 

You may activate Secure Start. This has a unique function in that it allows the removal of programs before loading Windows!

Open RegRun Control Center, Options, Secure Start. Check "Secure Start DOS" (only for Windows 95/98) or "Secure Start Windows" box.

Secure Start is activated automatically if you selected "High" or "Ultra High" Security Level.

Read more about Secure Start.