PDA

View Full Version : RegAlyzer


iisjman07
10-26-2009, 10:07 AM
I use this on malware infested computers where regedit it blocked. It lets you have access to the registry and has lots of other pretty cool features. One particular feature I use alot is Bookmarks, where you can make a link to a particular place in the registry, like one mine I have is linked to "HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run" because I'm far too lazy to remember lots of different registry entries....

http://www.safer-networking.org/en/regalyzer/index.html

Methical
10-27-2009, 02:55 AM
RunAlyzer (http://www.safer-networking.org/en/runalyzer/index.html) looks like a good app as well.

Gives an overview over many relevant system settings, intended to replace the Tools section currently integrated into Spybot-S&D.

http://www.safer-networking.org/images/runalyzer/runalyzer-main-1.png

Methical
10-27-2009, 02:59 AM
One particular feature I use alot is Bookmarks, where you can make a link to a particular place in the registry

Care to share your bookmarks with the world? :D

Tweak
10-27-2009, 04:27 AM
Care to share your bookmarks with the world? :D

Although not EXACTLY what you asked for in that these are obviously not bookmarks it does serve as a reminder of some important locations and information as it pertains to the registry. (Multiple sources via Google for these paths and information) Hope this is useful. :cool:

HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Curr entVersion\Run

HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon

Windows NT-based operating systems

Windows NT-based systems store the registry in a binary hive format which is the same format that can be exported, loaded and unloaded by the Registry Editor in these operating systems. The following Registry files are stored in %SystemRoot%\System32\Config\:
Sam – HKEY_LOCAL_MACHINE\SAM
Security – HKEY_LOCAL_MACHINE\SECURITY
Software – HKEY_LOCAL_MACHINE\SOFTWARE
System – HKEY_LOCAL_MACHINE\SYSTEM
Default – HKEY_USERS\.DEFAULT
Userdiff – Not associated with a hive. Used only when upgrading operating systems.

The following files are stored in each user's profile folder:
%UserProfile%\Ntuser.dat – HKEY_USERS\<User SID> (linked to by HKEY_CURRENT_USER)
%UserProfile%\Local Settings\Application Data\Microsoft\Windows\Usrclass.dat (path is localized) – HKEY_USERS\<User SID>_Classes (HKEY_CURRENT_USER\Software\Classes)

Windows NT-based operating systems automatically create a backup of each hive (.BAK) in the %Windir%\System32\config folder. Any file can be restored from the Recovery Console.
System Restore can back up the registry and restore it as long as Windows is bootable, or from the Windows Recovery Environment starting with Windows Vista.
NTBackup can back up the registry as part of the System State and restore it.
On Windows NT-based systems, the Last Known Good Configuration option in startup menu relinks the HKLM\SYSTEM\CurrentControlSet key, which stores hardware and device driver information.
Windows 98 and Windows Me include command line (Scanreg.exe) and GUI (Scanregw.exe) registry checker tools to check and fix the integrity of the registry, create up to five automatic regular backups by default and restore them manually or whenever corruption is detected. The registry checker tool backs up the registry, by default, to %Windir%\Sysbckup Scanreg.exe can also run from MS-DOS.
The Windows 95 CD-ROM included an Emergency Recovery Utility (ERU.exe) and a Configuration Backup Tool (Cfgback.exe) to back up and restore the registry. Additionally Windows 95 backs up the registry to the files system.da0 and user.da0 on every successful boot.

rusty.nells
10-27-2009, 06:15 AM
Here are my Regedit bookmarks, in .reg format, and the file attached below.


**NOTE: Spaces were inserted after posting, do not copy-and-paste**

Windows Registry Editor Version 5.00

[HKEY_CURRENT_USER\Software\Microsoft\Windows\Curre ntVersion\Applets\Regedit\Favorites]
"TCPIP"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Services\\Tcpip\\Parameters"
"Winsock2"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Services\\WinSock2"
"Winsock2-Parameters"="Computer\\HKEY_LOCAL_MACHINE\\System\\CurrentContr olSet\\Services\\WinSock2\\Parameters"
"Uninstall"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Uninstall"
"Uninstall"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Uninstall"
"MSCONFIG"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Shared Tools\\MSConfig"
"Internet Zones"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Internet Settings\\Zones"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\Shell Folders"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Explorer\\Shell Folders"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\User Shell Folders"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Explorer\\User Shell Folders"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\explorer\\User Shell Folders"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\explorer\\User Shell Folders"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\explorer\\Shell Folders"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\explorer\\Shell Folders"
"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows NT\\CurrentVersion\\Windows"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Policies\\system"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Policies\\system"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Policies\\system"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Policies\\system"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\RunServices (95 98 ME)"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\RunServices"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\RunServicesOnce (95 98 ME)"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\RunServicesOnce"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Run"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Run"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\RunOnce"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\RunOnce"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Run"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Run"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\RunOnce"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\RunOnce"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\RunOnceEx"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\RunOnceEx"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Runonce"="Computer\\HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Runonce"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\RunonceEx"="Computer\\HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\RunonceEx"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Run"="Computer\\HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Run"
"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Runonce"="Computer\\HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Runonce"
"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\RunonceEx"="Computer\\HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\RunonceEx"
"HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Run"="Computer\\HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\Software\\Microsoft\\Windows\\Cur rentVersion\\Run"
"HKLM\\System\\CurrentControlSet\\Control\\Session Manager"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Control\\Session Manager"
"HKCR\\exefile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\exefile\\shell\\open\ \command"
"HKCR\\comfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\comfile\\shell\\open\ \command"
"HKCR\\cplfile\\shell\\cplopen\\command"="Computer\\HKEY_CLASSES_ROOT\\cplfile\\shell\\cplop en\\command"
"HKCR\\batfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\batfile\\shell\\open\ \command"
"HKCR\\htafile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\htafile\\shell\\open\ \command"
"HKCR\\http\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\http\\shell\\open\\co mmand"
"HKCR\\htmlfile\\shell\\opennew\\command"="Computer\\HKEY_CLASSES_ROOT\\htmlfile\\shell\\open new\\command"
"HKCR\\htmlfile\\shell\\print\\command"="Computer\\HKEY_CLASSES_ROOT\\htmlfile\\shell\\prin t\\command"
"HKCR\\inffile\\shell\\install\\command"="Computer\\HKEY_CLASSES_ROOT\\inffile\\shell\\insta ll\\command"
"HKCR\\InternetShortcut\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\InternetShortcut\\she ll\\open\\command"
"HKCR\\piffile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\piffile\\shell\\open\ \command"
"HKCR\\regfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\regfile\\shell\\open\ \command"
"HKCR\\regfile\\shell\\merge\\command"="Computer\\HKEY_CLASSES_ROOT\\regfile\\shell\\merge \\command"
"HKCR\\vbsfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\vbsfile\\shell\\open\ \command"
"HKCR\\vbefile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\vbefile\\shell\\open\ \command"
"HKCR\\jsfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\jsfile\\shell\\open\\ command"
"HKCR\\jsefile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\jsefile\\shell\\open\ \command"
"HKCR\\wshfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\wshfile\\shell\\open\ \command"
"HKCR\\wsffile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\wsffile\\shell\\open\ \command"
"HKCR\\scrfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\scrfile\\shell\\open\ \command"
"HKCR\\scrfile\\shell\\config\\command"="Computer\\HKEY_CLASSES_ROOT\\scrfile\\shell\\confi g\\command"
"HKCR\\txtfile\\shell\\open\\command"="Computer\\HKEY_CLASSES_ROOT\\txtfile\\shell\\open\ \command"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\FileExts"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Explorer\\FileExts"
"(ICQ) HKCU\\Software\\Mirabilis\\ICQ\\Agent\\Apps"="Computer\\HKEY_CURRENT_USER\\Software\\Mirabilis\\ ICQ\\Agent\\Apps"
"HKLM\\Software\\Microsoft\\Active Setup\\Installed Components"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Active Setup\\Installed Components"
"HKCU\\Software\\Microsoft\\Active Setup\\Installed Components"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Active Setup\\Installed Components"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Windows"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\RunOnce\\Setup"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\RunOnce\\Setup"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\RunOnce\\Setup"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\RunOnce\\Setup"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\ShellServiceObjectDelayLoad"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\ShellServiceObjectDelayLo ad"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\ShellServiceObjectDelayLoad"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\ShellServiceObjectDelayL oad"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\SharedTaskScheduler"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\SharedTaskSche duler"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\policies\\Explorer\\Run"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\policies\\Explorer\\Run"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Policies\\Explorer\\Run"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Policies\\Explorer\\Run"
"HKCR\\PROTOCOLS\\Filter"="Computer\\HKEY_CLASSES_ROOT\\PROTOCOLS\\Filter"
"HKLM\\System\\CurrentControlSet\\services\\VxD"="Computer\\HKEY_LOCAL_MACHINE\\System\\CurrentContr olSet\\services\\VxD"
"HKLM\\System\\CurrentControlSet\\Services"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Services"
"HKLM\\System\\CurrentControlSet\\Services\\WinSock 2\\Parameters\\Protocol_Catalog9\\Catalog_Entries"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Services\\WinSock2\\Parameters\\Protocol_Ca talog9\\Catalog_Entries"
"HKLM\\System\\CurrentControlSet\\Control\\WOW"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Control\\WOW"
"HKCU\\Control Panel\\Desktop"="Computer\\HKEY_CURRENT_USER\\Control Panel\\Desktop"
"HKLM\\System\\CurrentControlSet\\Control\\Session Manager"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Control\\Session Manager"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon\\Notify"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon\\Notify"
"HKLM\\Software\\Microsoft\\Command Processor"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Command Processor"
"HKCU\\Software\\Microsoft\\Command Processor"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Command Processor"
"HKLM\\Software\\Policies\\Microsoft\\Windows\\Syst em\\Scripts"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Policies\\ Microsoft\\Windows\\System\\Scripts"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\System\\CurrentControlSet\\Control\\MPRServi ces"="Computer\\HKEY_LOCAL_MACHINE\\System\\CurrentContr olSet\\Control\\MPRServices"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\Browser Helper Objects"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\Browser Helper Objects"
"HKLM\\Software\\Microsoft\\Internet Explorer\\Toolbar"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Internet Explorer\\Toolbar"
"HKCU\\Software\\Microsoft\\Internet Explorer\\Explorer Bars"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Internet Explorer\\Explorer Bars"
"HKLM\\Software\\Microsoft\\Internet Explorer\\Explorer Bars"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Internet Explorer\\Explorer Bars"
"HKCU\\Software\\Microsoft\\Internet Explorer\\UrlSearchHooks"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Internet Explorer\\UrlSearchHooks"
"HKCU\\Software\\Microsoft\\Internet Explorer\\Extensions"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Internet Explorer\\Extensions"
"HKLM\\Software\\Microsoft\\Internet Explorer\\Extensions"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Internet Explorer\\Extensions"
"HKLM\\Software\\Microsoft\\Internet Explorer\\Search"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Internet Explorer\\Search"
"HKLM\\Software\\Microsoft\\Internet Explorer\\Main"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Internet Explorer\\Main"
"HKU\\.DEFAULT\\Software\\Microsoft\\Internet Explorer\\Main"="Computer\\HKEY_USERS\\.DEFAULT\\Software\\Microsof t\\Internet Explorer\\Main"
"HKCU\\Software\\Microsoft\\Internet Explorer\\SearchUrl"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Internet Explorer\\SearchUrl"
"HKCU\\Software\\Microsoft\\Internet Explorer\\main"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Internet Explorer\\main"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Image File Execution Options"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Image File Execution Options"
"HKCR\\*\\shellex\\ContextMenuHandlers"="Computer\\HKEY_CLASSES_ROOT\\*\\shellex\\ContextMe nuHandlers"
"HKCR\\*\\shellex\\ContextMenuHandlers\\Open With"="Computer\\HKEY_CLASSES_ROOT\\*\\shellex\\ContextMe nuHandlers\\Open With"
"HKLM\\Software\\Classes\\AllFileSystemObjects\\She llEx\\ContextMenuHandlers"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Classes\\A llFileSystemObjects\\ShellEx\\ContextMenuHandlers"
"HKCU\\Software\\Classes\\AllFileSystemObjects\\She llEx\\ContextMenuHandlers"="Computer\\HKEY_CURRENT_USER\\Software\\Classes\\Al lFileSystemObjects\\ShellEx\\ContextMenuHandlers"
"HKLM\\Software\\Classes\\Folder\\ShellEx\\ContextM enuHandlers"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Classes\\F older\\ShellEx\\ContextMenuHandlers"
"HKCU\\Software\\Classes\\Folder\\ShellEx\\ContextM enuHandlers"="Computer\\HKEY_CURRENT_USER\\Software\\Classes\\Fo lder\\ShellEx\\ContextMenuHandlers"
"HKLM\\Software\\Classes\\Directory\\ShellEx\\Conte xtMenuHandlers"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Classes\\D irectory\\ShellEx\\ContextMenuHandlers"
"HKCU\\Software\\Classes\\Directory\\ShellEx\\Conte xtMenuHandlers"="Computer\\HKEY_CURRENT_USER\\Software\\Classes\\Di rectory\\ShellEx\\ContextMenuHandlers"
"HKLM\\Software\\Classes\\Directory\\Background\\Sh ellEx\\ContextMenuHandlers"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Classes\\D irectory\\Background\\ShellEx\\ContextMenuHandlers"
"HKCU\\Software\\Classes\\Directory\\Background\\Sh ellEx\\ContextMenuHandlers"="Computer\\HKEY_CURRENT_USER\\Software\\Classes\\Di rectory\\Background\\ShellEx\\ContextMenuHandlers"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\explorer\\ShellExecuteHooks"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\explorer\\ShellExecuteHo oks"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Utility Manager"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Accessibility\\Utility Manager"
"(Vista) HKCU\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Accessibility\\Configuration"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows NT\\CurrentVersion\\Accessibility\\Configuration"
"HKLM\\Software\\Classes\\Folder\\shellex\\ColumnHa ndlers"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Classes\\F older\\shellex\\ColumnHandlers"
"HKCU\\Software\\Classes\\Folder\\shellex\\ColumnHa ndlers"="Computer\\HKEY_CURRENT_USER\\Software\\Classes\\Fo lder\\shellex\\ColumnHandlers"
"HKLM\\system\\CurrentControlSet\\Control\\SafeBoot \\Option"="Computer\\HKEY_LOCAL_MACHINE\\system\\CurrentContr olSet\\Control\\SafeBoot\\Option"
"HKLM\\System\\CurrentControlSet\\Control\\Security Providers"="Computer\\HKEY_LOCAL_MACHINE\\System\\CurrentContr olSet\\Control\\SecurityProviders"
"(Win 9x, 2000) HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\MountPoints"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Explorer\\MountPoints"
"(XP) HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\MountPoints2"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Explorer\\MountPoints2"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\App Paths"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\App Paths"
"HKLM\\SYSTEM\\CurrentControlSet\\Control\\Print\\M onitors"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Control\\Print\\Monitors"
"HKLM\\system\\currentcontrolset\\control\\lsa"="Computer\\HKEY_LOCAL_MACHINE\\system\\currentcontr olset\\control\\lsa"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Winlogon"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Winlogon"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\AeDebug"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\AeDebug"
"HKLM\\System\\CurrentControlSet\\Control\\Session Manager\\SubSystems"="Computer\\HKEY_Local_Machine\\System\\CurrentContr olSet\\Control\\Session Manager\\SubSystems"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\ShellIconOverlayIdentifiers"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\ShellIconOverl ayIdentifiers"
"HKCU\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\ShellIconOverlayIdentifiers"="Computer\\HKEY_CURRENT_USER\\Software\\Microsoft\\ Windows\\CurrentVersion\\Explorer\\ShellIconOverla yIdentifiers"
"HKLM\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Drivers32"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows NT\\CurrentVersion\\Drivers32"
"HKLM\\SYSTEM\\CurrentControlSet\\Control\\BootVeri ficationProgram"="Computer\\HKEY_LOCAL_MACHINE\\SYSTEM\\CurrentContr olSet\\Control\\BootVerificationProgram"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\MyComputer\\BackupPath"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\MyComputer\\Ba ckupPath"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\MyComputer\\CHKDskPath"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\MyComputer\\CH KDskPath"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\MyComputer\\cleanuppath"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\MyComputer\\cl eanuppath"
"HKLM\\Software\\Microsoft\\Windows\\CurrentVersion \\Explorer\\MyComputer\\DefragPath"="Computer\\HKEY_LOCAL_MACHINE\\Software\\Microsoft\ \Windows\\CurrentVersion\\Explorer\\MyComputer\\De fragPath"

Methical
10-27-2009, 06:35 AM
Here are my Regedit bookmarks, in .reg format, and the file attached below.


**NOTE: Spaces were inserted after posting, do not copy-and-paste**

Thanks rusty.nells !