RegistryReport
RegistryReport shows information about the operating system, installed software, the last user activity, the user settings and many other details from raw Windows NT 5 Registry files "SYSTEM", "SOFTWARE", "SAM" and "NTUSER.DAT" (Windows 2000/XP/2003/Vista).
You can configure the amount of information for each category in the settings dialog. Over the graphical user interface you can save, print and search the generated report. The report can be copied or saved as RTF or plain text.
RegistryReport doesn't process the Registry files of the running operating system.
Tip: To get information from the running system, you can use the application
SystemReport. With the application
RegistryViewer you can view raw Registry files like in the Windows Registry editor.
Download
| Version: | 1.3.9 |
| Last update: | 01.06.2010 |
| Installation: | None (portable) |
| License: | Freeware |
| Required: | Registry files from Windows NT 5 or higher for examination |
Zusätzliche Downloads
EnCase script: MultiFile Viewer
With this script for Guidance EnCase you can open multiple files at the same time with one of the installed EnCase file viewers. The file viewer must support the opening of multiple files.
EnCase script: RegistryReport Exporter
This script for Guidance EnCase search for Windows NT 5 Registry database files (Windows 2000, XP, Server 2003 and Vista) and shows it in a selection dialog. The selected files can be exported in an user defined folder. Additionally, these files can be opened with RegistryReport.
Languages
German
English
Chinese trad. v1.3.1
Japanese v1.3.9
Dutch v1.3
Russian v1.3.8
Screenshot
Professional Version
Some features of this application are available in the professional version only. A professional license is offered to selected translators and other persons that supported this application. If you have questions about the professional license please feel free to contact me per e-mail.
Features of the professional version:
- Automatically executed applications:
- Redirection of registred files (Registry Shell Spawning)
- The CLSID, the name and status (the classification) will be readed from the files BHOList.txt and ToolbarList.txt
- Modification time of the Registry keys
- Users and user groups:
- Date and time of the last logon, the last password change and the last invalid logon attempt
- Additional user account informations
- Operating system:
- Product ID and product key
- Setup and logon informations
- User profiles
- If the last access time for files on NTFS device are modified automatically
- Recently attached devices:
- Hardware ID and driver ID
- Creation and modification time
- Modification time of the mounted devices
- Network:
- Network adapters
- Last modification time of the Registry keys
- Recently used objects:
- The last modification time for each list
- Used network shares
- Used files of the Microsoft Management console
- Scanned background pictures
- Search assistant: Searched printers, computers and persons
- Explorer bar: Searched computers
- Installed software:
- Installation date of the application
- All installed updates can be included in the software list
- Modification time of the Registry keys
- System services:
- Service types:
- Unknown services
- Kernel device drivers
- Filesystem drivers
- Adapter arguments
- For each service:
- Dependencies
- Object (System user under wich the service is executed)
- Modification time of the Registry keys
- Windows updates:
- Update type
- Username of the installing user
- Installation date
- Modification time of the Registry keys
- Security:
- Windows Firewall
- uthorized applications
- Globally opened ports
- Version GUID and date of the MRT (Windows Malicious Software Removal Tool)
- Image File Execution Options (Debugger)
- Internet:
- Time zone settings of "Internet settings" / "Security"
- Misc informations:
- Modification time of the Windows Recycle Bin settings
- Settings:
- The colors for headlines and for the text can be configured.
Changelog
The changelog for this application is available in the German version of this page only.