Batch scripting "Scanreg.exe" on W2K platform

From: Iheagwara, Charles (
Date: 10/03/01

Message-ID: <E5B3448D642AD311A5F0009027848F76875209@MAIL>
From: "Iheagwara, Charles" <>
Subject: Batch scripting "Scanreg.exe" on W2K platform
Date: Wed, 3 Oct 2001 08:31:19 -0400 

Ladies and Gentlemen:

I want to come up with a batch script using "Scanreg.exe" that can search for any strings or rogue files that are left in the registry after an
attack. The two possibilities I have considered include

1. Coming up with a script that can detect strings that don't match the registry. For example, in the script below I am searching for a specific
string "windows"

scanreg /s windows /r \lm /kvde
scanreg /s windows /r \cu /kvde
scanreg /s windows /r \cr /kvde
scanreg /s windows /r \us /kvde

But in a Web production environment where the registry is constantly changing, this becomes a problem. It seems then that only a script that can
identify any string or filename that is incompatible with the registry will work.

2. Coming up with a script that will compare two registries: one standard, the other rogue. The problem here is how do I generate any of these

Please help.



Relevant Pages

  • Where are the strings in gc.get_objects?
    ... script to show the numbers of each different type of object. ... for key in keys: ... I get similar results on both Python 2.4 and Python 2.5. ... Can anyone explain were the strings are? ...
  • Python, MS SQL, and batch inserts
    ... com object, does a little formatting, and then inserts that data into ... ADODB.command objects for working with SQL. ... machine running the script. ... The overhead for recreating the strings was monster. ...
  • Re: buffer interface problem
    ... I have run into a problem running a Python script that is part of the ... The purpose of the script is to walk a directory tree, unzipping files, ... I get the message "expected an object with the buffer ... either Unicode strings or bytestrings, ...
  • ruby/tk and script encoding
    ... I have big problems with supporting the iso8859-2 characters in my ... The TixCombobox can be configured to callback a proc when the ... have inserted to the combobox earlier from my script (i.e., ... So, it seems, that on one machine, the strings from my script are ...
  • Session losing variables?
    ... I have a script start.php and a second script proceed.php ... <?PHP ... // Strings match, so open logfile, exit if this fails. ...