<?xml version="1.0"?>
<feed xmlns="http://www.w3.org/2005/Atom" xml:lang="en">
	<id>https://wiki.spybot.info/index.php?action=history&amp;feed=atom&amp;title=Importing_an_InCtrl5_log</id>
	<title>Importing an InCtrl5 log - Revision history</title>
	<link rel="self" type="application/atom+xml" href="https://wiki.spybot.info/index.php?action=history&amp;feed=atom&amp;title=Importing_an_InCtrl5_log"/>
	<link rel="alternate" type="text/html" href="https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;action=history"/>
	<updated>2026-05-02T05:53:59Z</updated>
	<subtitle>Revision history for this page on the wiki</subtitle>
	<generator>MediaWiki 1.39.15</generator>
	<entry>
		<id>https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;diff=850&amp;oldid=prev</id>
		<title>CCRDude: Made InCtrl5 a link</title>
		<link rel="alternate" type="text/html" href="https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;diff=850&amp;oldid=prev"/>
		<updated>2008-05-27T19:04:53Z</updated>

		<summary type="html">&lt;p&gt;Made InCtrl5 a link&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 19:04, 27 May 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l1&quot;&gt;Line 1:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 1:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Opensbieditlite-inctrl5-example-3721.png|thumb|300px|Import dialog]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Image:Opensbieditlite-inctrl5-example-3721.png|thumb|300px|Import dialog]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;−&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #ffe49c; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;InCtrl5 is a popular tool that monitors changes to the registry and file system and logs them to for example HTML files. [[OpenSBI Edit Lite]] is able to import such logs to give you a quick start into writing new SBI files.&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;[[&lt;/ins&gt;InCtrl5&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;]] &lt;/ins&gt;is a popular tool that monitors changes to the registry and file system and logs them to for example HTML files. [[OpenSBI Edit Lite]] is able to import such logs to give you a quick start into writing new SBI files.&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Quick Steps==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Quick Steps==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>CCRDude</name></author>
	</entry>
	<entry>
		<id>https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;diff=833&amp;oldid=prev</id>
		<title>CCRDude: /* Warning */ added limitations of InCtrl5</title>
		<link rel="alternate" type="text/html" href="https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;diff=833&amp;oldid=prev"/>
		<updated>2008-05-27T17:33:54Z</updated>

		<summary type="html">&lt;p&gt;&lt;span dir=&quot;auto&quot;&gt;&lt;span class=&quot;autocomment&quot;&gt;Warning: &lt;/span&gt; added limitations of InCtrl5&lt;/span&gt;&lt;/p&gt;
&lt;table style=&quot;background-color: #fff; color: #202122;&quot; data-mw=&quot;interface&quot;&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;col class=&quot;diff-marker&quot; /&gt;
				&lt;col class=&quot;diff-content&quot; /&gt;
				&lt;tr class=&quot;diff-title&quot; lang=&quot;en&quot;&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;← Older revision&lt;/td&gt;
				&lt;td colspan=&quot;2&quot; style=&quot;background-color: #fff; color: #202122; text-align: center;&quot;&gt;Revision as of 17:33, 27 May 2008&lt;/td&gt;
				&lt;/tr&gt;&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot; id=&quot;mw-diff-left-l25&quot;&gt;Line 25:&lt;/td&gt;
&lt;td colspan=&quot;2&quot; class=&quot;diff-lineno&quot;&gt;Line 25:&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Warning==&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;==Warning==&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Not all changes that happen while a malware is installed are associated with that malware. Windows itself does update MRU (Most Recently Used) lists in the registry, for example. Malware might also install legit third party libraries for it&amp;#039;s purposes. The InCtrl5 import allows rapid  detection prototyping, but you still need to pay a lot of attention to avoid [[False positive|false positives]].&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;Not all changes that happen while a malware is installed are associated with that malware. Windows itself does update MRU (Most Recently Used) lists in the registry, for example. Malware might also install legit third party libraries for it&amp;#039;s purposes. The InCtrl5 import allows rapid  detection prototyping, but you still need to pay a lot of attention to avoid [[False positive|false positives]].&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td colspan=&quot;2&quot; class=&quot;diff-side-deleted&quot;&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot; data-marker=&quot;+&quot;&gt;&lt;/td&gt;&lt;td style=&quot;color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #a3d3ff; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;&lt;ins style=&quot;font-weight: bold; text-decoration: none;&quot;&gt;InCtrl5 is also not a complete monitoring tool; it will probably not list a lot of rootkit activity, WMI changes are difficult to recognize if at all, and the same goes for various other API calls that update binary files, where you will notice only that the file has changed, not what exactly was changed.&lt;/ins&gt;&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;br/&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;tr&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Tutorials]]&lt;/div&gt;&lt;/td&gt;&lt;td class=&quot;diff-marker&quot;&gt;&lt;/td&gt;&lt;td style=&quot;background-color: #f8f9fa; color: #202122; font-size: 88%; border-style: solid; border-width: 1px 1px 1px 4px; border-radius: 0.33em; border-color: #eaecf0; vertical-align: top; white-space: pre-wrap;&quot;&gt;&lt;div&gt;[[Category:Tutorials]]&lt;/div&gt;&lt;/td&gt;&lt;/tr&gt;
&lt;/table&gt;</summary>
		<author><name>CCRDude</name></author>
	</entry>
	<entry>
		<id>https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;diff=831&amp;oldid=prev</id>
		<title>CCRDude: First draft</title>
		<link rel="alternate" type="text/html" href="https://wiki.spybot.info/index.php?title=Importing_an_InCtrl5_log&amp;diff=831&amp;oldid=prev"/>
		<updated>2008-05-27T17:30:13Z</updated>

		<summary type="html">&lt;p&gt;First draft&lt;/p&gt;
&lt;p&gt;&lt;b&gt;New page&lt;/b&gt;&lt;/p&gt;&lt;div&gt;[[Image:Opensbieditlite-inctrl5-example-3721.png|thumb|300px|Import dialog]]&lt;br /&gt;
InCtrl5 is a popular tool that monitors changes to the registry and file system and logs them to for example HTML files. [[OpenSBI Edit Lite]] is able to import such logs to give you a quick start into writing new SBI files.&lt;br /&gt;
&lt;br /&gt;
==Quick Steps==&lt;br /&gt;
* Run [[OpenSBI Edit Lite]].&lt;br /&gt;
* Start a new file (menu &amp;#039;&amp;#039;File: New&amp;#039;&amp;#039;).&lt;br /&gt;
* Open the import dialog (menu &amp;#039;&amp;#039;File: Import: Import InCtrl5 logs&amp;#039;&amp;#039;).&lt;br /&gt;
* Select one or more HTML log files as created by InCtrl5.&lt;br /&gt;
* Make your choice of changes to detect by selecting the checkboxes next to them.&lt;br /&gt;
* Finish by pressing the &amp;#039;&amp;#039;OK&amp;#039;&amp;#039; button.&lt;br /&gt;
* Add useful descriptions for files (see [[Description templates|description templates]]).&lt;br /&gt;
* Update the [[Advanced file parameters|advanced file parameters]] where required (see the tutorial [[Choosing advanced file parameters]]).&lt;br /&gt;
&lt;br /&gt;
==Details==&lt;br /&gt;
The import dialog will give you three tabs:&lt;br /&gt;
# The tab &amp;#039;&amp;#039;Items&amp;#039;&amp;#039; shows the contents in a structured view:&lt;br /&gt;
#* The root level of the structure will be root registry keys and drives that changes appeared on.&lt;br /&gt;
#* Levels in the structure that were not changed and are displayed for better viewing are displayed with grey icons and no checkboxes.&lt;br /&gt;
#* Where registry items and files are detected to be associated with one another, they share the same background color. As an example, this will combine a BHO, the associated CLSID, typelib, interface and file.&lt;br /&gt;
#* The toolbar at the bottom will show buttons that will filter the list to display only those items that belong to the selected group.&lt;br /&gt;
#* You can type in any term into the filter field to display only those items that include the filter term. Remove any text in the field to undo the filter.&lt;br /&gt;
# The one named &amp;#039;&amp;#039;Filtered&amp;#039;&amp;#039; will show you any items you&amp;#039;ve suppressed on the main view. If you right click any item here, you&amp;#039;ll be able to make it visible in the &amp;#039;&amp;#039;Items&amp;#039;&amp;#039; list again. Reasons for permanently suppressing items would for example be registry changes to various MRU lists that are not related to malware.&lt;br /&gt;
# The last tab, &amp;#039;&amp;#039;Preview&amp;#039;&amp;#039;, shows you how the OpenSBI code for the selected entries would look like. This is the same code that will be added to the file you&amp;#039;ve opened in the editor.&lt;br /&gt;
&lt;br /&gt;
==Warning==&lt;br /&gt;
Not all changes that happen while a malware is installed are associated with that malware. Windows itself does update MRU (Most Recently Used) lists in the registry, for example. Malware might also install legit third party libraries for it&amp;#039;s purposes. The InCtrl5 import allows rapid  detection prototyping, but you still need to pay a lot of attention to avoid [[False positive|false positives]].&lt;br /&gt;
&lt;br /&gt;
[[Category:Tutorials]]&lt;/div&gt;</summary>
		<author><name>CCRDude</name></author>
	</entry>
</feed>