Re: Any Product Give Detailed Log of All Changed Files?



"MowGreen" <mowgreen@xxxxxxxxxxxxx> wrote in message
news:ijccld$h87$1@xxxxxxxxxxxxxxxxxxxx
W wrote:
Is there any user friendly product that would install a gadget in the
system
toolbar that would give you a complete log of all files and registry
objects
changed on the computer along with the processes that change them?

There are Sys Internals tools like RegMon, but these are too low level
and
very friendly. There is the EventViewer security log, but that is an
abomination and anything but user friendly.

Moreover, inevitably when you need something like RegMon it is not
running.
I just had a situation where I inserted a USB key and I believe it made
some
attempt to install something on the computer. Seeing the detail of
what
processes were attempting to move which files to what folders, at the
moment
it was happening, would have been useful.



RegMon is retired and no longer supported. Try Process Monitor -
http://technet.microsoft.com/en-us/sysinternals/bb896645

I want something that installs as a service and continuously gathers data.
I want the UI to be in the style of a personal firewall, always ready to
handout information when I need it.

Process Monitor is great for detailed process level interrogation, but it's
not the tool you leave running 24x7.

--
W


.



Relevant Pages

  • Re: Any Product Give Detailed Log of All Changed Files?
    ... There are Sys Internals tools like RegMon, but these are too low level and ... inevitably when you need something like RegMon it is not running. ... I know that there are some tools related to creating a custom MSI package that keep track of what changes on a system when you install software so that it can create the operations list required by an MSI package, but I haven't been involved in that directly to know what the software names would be:( ...
    (microsoft.public.security)
  • Re: Software-Deinstallation: Hinterlassen von Daten in der Registry/Filesystem
    ... Z.B. durch Protokolliern der Installation und ... Vor/Nachvergleich. ... RegMon: ... (oder auch den Process Monitor: ...
    (de.soc.recht.misc)
  • Re: Setting unchangeable IPs
    ... communication, booking, accounting, etc... ... Using process monitor to figure out what exactly ... RegMon for registry. ...
    (microsoft.public.windows.server.active_directory)