Difference between revisions of "RegyKey"

From SpybotWiki
Jump to: navigation, search
m (Description: added adv build info)
m (info about HKCU)
 
(One intermediate revision by the same user not shown)
Line 5: Line 5:
 
|GROUP = Registry
 
|GROUP = Registry
 
|MINUPDATE = n/a
 
|MINUPDATE = n/a
|ADVFILEPARAMS = no
+
|ADVFILEPARAMS = yes (sixth)
 
|ADVREGPARAMS = yes (fifth)
 
|ADVREGPARAMS = yes (fifth)
 
|ADVBUILDPARAMS = yes (fifth)
 
|ADVBUILDPARAMS = yes (fifth)
Line 13: Line 13:
 
==Usage==
 
==Usage==
 
  RegyKey:<description(string)>,<rootkey(enum)>,<keypath(string)>,<key(string)>[[,advanced registry parameters][,advanced file parameters]]
 
  RegyKey:<description(string)>,<rootkey(enum)>,<keypath(string)>,<key(string)>[[,advanced registry parameters][,advanced file parameters]]
 +
 +
To flag any things located in HKEY_USERS, just add one rule with HKEY_CURRENT_USER as the root key. During a scan, rules for HKEY_CURRENT_USER will be applied to all detected users, not just the ''current'' one.
  
 
===Examples===
 
===Examples===

Latest revision as of 14:05, 29 May 2008

RegyKey
Group Registry
Main Application Version 0.95 or later
1.5.3 for adv. file
Required Update n/a
File Parameters yes (sixth)
Registry Parameters yes (fifth)
Build Parameters yes (fifth)
Special Parameters no

Searches for the defined registry key and adds it to the results list, if found.

Usage

RegyKey:<description(string)>,<rootkey(enum)>,<keypath(string)>,<key(string)>[[,advanced registry parameters][,advanced file parameters]]

To flag any things located in HKEY_USERS, just add one rule with HKEY_CURRENT_USER as the root key. During a scan, rules for HKEY_CURRENT_USER will be applied to all detected users, not just the current one.

Examples

RegyKey:"User settings",HKEY_CURRENT_USER,\SOFTWARE\,"Spyware"

Description

Detects a registry key and flags it for removal.

  1. First, a description. Using a description template instead of plain text is recommended so that the user will receive a localized version.
  2. The root key, where HKEY_CURRENT_USER stands for all users actually.
  3. The path to the value, starting with a backslash. This may not include the actual subkey you want to remove. PT
  4. The name of the key to detect. You may use a Algo-Prefix here. AP PT
  5. To refine detection, you can use advanced registry parameters to check the actual data of the value, as well as advanced build parameters. You may use Algo-Prefixes here. AP PT
  6. Starting with 1.5.3, advanced file parameters for Flow Control can be specified. PT

Scan Results

  • The identified registry key(s).

See also

Similar commands