Protecting the Registry

Discussion in 'other security issues & news' started by WilliamP, May 23, 2004.

Thread Status:
Not open for further replies.
  1. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    I tried using the reg monitor in SSM and I didn't care for it much. I like SSM as an application firewall but I don't think the reg monitor is all that good. I have been searching for a good reg monitor for awhile now and couldn't find one I like.

    WilliamP I'm sure someone over at the PG forum when they get time. :)
     
  2. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Will,

    I think we've exhausted our options regarding finding new/better apps specifically designed to protect the registry. Again, let me know what you think about GRR. If resource usage is minimal, I may add it to my "portfolio". :D

    I saw your post on the PG forum. Good thinking. I'm heading that way too.
     
  3. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Notageek, hello!

    Have you tried using the DCS freebie called RegistryProt? If so, I would like to know what you think about it. If not, give it a try.
     
  4. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    I tried it. I liked it when I used it on my win98 computer but when I got XP it didn't work well on my xp so I dropped it. It froze my computer.
     
  5. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Let me put it this way. Maybe RegistryProt didn't play alone with another program I had running nat the time and the 2 programs go into a fight and froze my computer. But after I stopped using RegistryProt my computer didn't freeze again.
     
  6. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    Notageek, I had a similar problem while using Reg prot. I had to do a system restore and remove Regprot. The problem went away so I guess it was Reg prot. Check out Grr. Their web site is very informative. http://www.greyware.com/software/grr/
     
  7. FanJ

    FanJ Guest

    Hi,

    Just a strictly personal opinion ;)

    First of all, please note that I'm still on W 98 SE.
    So I cannot run programs like Process Guard or TinyTroyanTrap.
    Be assured that I would love to try using ProcessGuard from DiamondCS.
    From what I've understand, it is top.

    In the past I've used RegProt from DiamondCS.
    I'm really sorry to say it, but it gave me much too much problems.
    I went to RegRun Gold. An absolutely excellent program !!!
    I would recommand it to everyone.
    Use it (if you can) together with ProcessGuard and a file-integrity-checker (yeah, I know, it's me again LOL ;) ).
    I fully admit that I am not the greatest expert on the registry.
    There are here some experts on RegRun like for example Wizard, Mickey, and several others. I'll try to ask some of them to give you their opinion.
     
  8. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Thanks WilliamP. I'm on my way over to chack out Grr. I'll let you know how I like it. I have become really picky when it comes to using programs on my computer. :)
     
  9. strongarm

    strongarm Guest

  10. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    Strongarm ,a lot of people have recommended RegRun Gold, and I have looked at it. It is kind of expensive for what I am looking for. It seems to have a lot of features that I don't think I would use, or know how to use. o_O
     
  11. strongarm

    strongarm Guest

    Just tryin' to help m8. But GRR looks like a good app too if all yer lookin' 4 is reg protection. Hope it works out 4 ya.
     
  12. wizard

    wizard Registered Member

    Joined:
    Feb 9, 2002
    Posts:
    818
    Location:
    Europe - Germany - Duesseldorf
    I use RegRun since ages. The biggest advantage of RegRun compared to other programs is that you also can define additional registry keys to be monitored. This means once a new start-method is found in the registry you can update the program on your own.

    Also this gives some flexibility in monitoring the registry values for other security apps as well.

    Besides that RegRun covers all common start methods and some real exotic ones used by some backdoor trojans. Especially in regards to those exotic methods RegRun is IMHO one of the best programs available.

    wizard
     
  13. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    Hi Wizard, Thank you for your post. Regrun Gold looks like it is rather complicated and has a lot of features I wouldn't use. The program Grr also allows you to customize the files and such that you want to keep an eye on. I'm still not sure that I need the additional protection. o_O
     
  14. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    William - I agree. Still unsure if the extra app is needed. In the PG forum somone who seemed knowledgeable I believe implied it wasn't, unless the user allows PG to let malware run.
     
  15. Ruffian

    Ruffian Guest

    You can do that in SSM too. I'm amazed most other programs dont offer this.
     
  16. WilliamP

    WilliamP Registered Member

    Joined:
    Jun 1, 2003
    Posts:
    2,208
    Location:
    Fayetteville, Ga
    D and C, I read it the same way you do. I certainly hope they are correct. I seem to remember reading about some type of baddy that could get in , but I'm not sure. It would have to get to the registry with out executing. I don't know if that is possible! o_O
     
  17. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    I would sure feel better about DCS RegistryProt if I understood how it works. It always warns me when a program that is already running tries to write data to the registry, but it never warns me when I'm installing a new app.
     
  18. drdetroit

    drdetroit Guest

    The problem with Regprot is it stinks. It only monitors certain areas of the registry and doesn't work well against newer trojans. It's kinda like putting a band-aid on a broken arm.
     
  19. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    DrDetroit - Do you have any details to back up that broad claim? I've found DCS' other products to work very well, and I'm surprised to hear they would offer a product that's half-baked. What areas of the registry doesn't it protect? Why would they design it that way?
     
  20. drdetroit

    drdetroit Guest

    Here's what you need to do Dazed. Goto the Diamondcs homepage. Scroll down to the bottom of the page. Click on 'contact us' And you can then ask them why Regprot is so out of date. And why newer trojans are so easily able to bypass it. And which reg keys exactly it monitors. They will help you far greater than i ever could. Good luck.
     
  21. MickeyTheMan

    MickeyTheMan Security Expert

    Joined:
    Feb 9, 2002
    Posts:
    1,017
    RegRun is a must app as far as i'm concerned
     
  22. hojtsy

    hojtsy Registered Member

    Joined:
    Dec 28, 2003
    Posts:
    351
  23. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
  24. Dazed_and_Confused

    Dazed_and_Confused Registered Member

    Joined:
    Mar 4, 2004
    Posts:
    1,831
    Location:
    USA
    Just had to disable DCS RegProtect. Started causing problems on my PC, as others have posted here. Every time I installed protection, computer would run very slow. ProcessExplorer indicated that RP was constantly using large amounts of resources and CPU time. My CPU meter was constantly pegged at 100% Things back to normal after disabling. Very disappointed. Now only registry protection I have is DCS PG (if you want to call that registry protection). Not a happy camper today. :mad:
     
  25. notageek

    notageek Registered Member

    Joined:
    Jun 3, 2002
    Posts:
    1,601
    Location:
    Ohio
    Sorry to hear about that. I had problems with RegProt also on my XP. RegProt made my computer freeze up. So I stopped using it and now I don't use a reg monitoring program like RegProt any more. I use Startup Monitor and SSM (with the reg the reg monitor turned off). I know winsonar has a reg monitor built in but I don't how good it works.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.