Jump to content











Photo
- - - - -

offlinereg


  • Please log in to reply
33 replies to this topic

#26 erwan.l

erwan.l

    Gold Member

  • Developer
  • 1936 posts
  • Location:Nantes - France
  •  
    France

Posted 23 June 2013 - 07:07 PM

Offreg.dll comes from MS WDK.

i have included in the zip file both the 32bits version (offreg.dll) and 64bits version (offreg64.dll).

 

The 32bits should be fine in most systems (including 64bits ones) except on system where the 32bits subsystem is missing.

On a "64bits only" system offreg64.exe will load offreg64.dll and then use MS API's in that library.

 

So now either I am passing the wrong parameters in 64bits mode or the function names are different.

 

I am back to work tomorrow and there I'll have tons of 64 bits system to test on.

 

/Erwan



#27 erwan.l

erwan.l

    Gold Member

  • Developer
  • 1936 posts
  • Location:Nantes - France
  •  
    France

Posted 04 May 2014 - 04:10 PM

Updated to version 0.9.6.

 

Changelog since latest version.

 

added : exception handler
added : human error messages, next to int codes
added : nobackup parameter (last) to save to original file
added : deletekeys (and all its subkeys)
added : deletekeys will delete the top (empty) key
added : import function (from a reg file)
 
Import will parse a regedit reg file and create or modifies values found in the reg file.
 
This is based on a idea/suggestion from Wonko here.
 
/Erwan


#28 Wonko the Sane

Wonko the Sane

    The Finder

  • Advanced user
  • 13690 posts
  • Location:The Outside of the Asylum (gate is closed)
  •  
    Italy

Posted 04 May 2014 - 05:33 PM

 

Import will parse a regedit reg file and create or modifies values found in the reg file.

 
This is based on a idea/suggestion from Wonko here.

 

Well, to be fair :unsure:, I would say that the whole thingy:

http://reboot.pro/to...gistry-library/

http://reboot.pro/to...fline-registry/

derives from a successful implementation of the "Bait'nWait" technique by Wonko.  ;) and from your very graciously :thumbsup: falling for it :w00t:.

 

:lol:

 

:duff:

Wono



#29 erwan.l

erwan.l

    Gold Member

  • Developer
  • 1936 posts
  • Location:Nantes - France
  •  
    France

Posted 04 May 2014 - 06:33 PM

Well as long as an idea is good, I'll always consider the bait :)



#30 Biatu

Biatu

    Member

  • Members
  • 55 posts
  •  
    United Kingdom

Posted 11 May 2014 - 10:02 AM

Can we make a version of this that redirects registry from child processes? Like runscanner...but better, and x64?

Thanks, and good job.



#31 erwan.l

erwan.l

    Gold Member

  • Developer
  • 1936 posts
  • Location:Nantes - France
  •  
    France

Posted 11 May 2014 - 10:07 AM

Can we make a version of this that redirects registry from child processes? Like runscanner...but better, and x64?
Thanks, and good job.


You mean hooking api registry?
If so, it would be another project i guess.

#32 Biatu

Biatu

    Member

  • Members
  • 55 posts
  •  
    United Kingdom

Posted 08 November 2014 - 12:56 AM

You mean hooking api registry?
If so, it would be another project i guess.

yes, exactly. It would be very useful in WinPE as well.



#33 erwan.l

erwan.l

    Gold Member

  • Developer
  • 1936 posts
  • Location:Nantes - France
  •  
    France

Posted 01 February 2015 - 08:49 PM

A quick update to Offlinereg.

Next to the command line version, there is now a graphical front end which uses the same piece of code (delphi library) as the command line.

 

It has basic and limited functions for now but could evolve in the future.

it is is very lightweight so it should work on winpe as well.

 

WaZGnJ2.png



#34 Biatu

Biatu

    Member

  • Members
  • 55 posts
  •  
    United Kingdom

Posted 25 November 2015 - 11:06 PM

Can you implement a method of executing cmd, and/or child processes with redirection to the offline hive? like RunScanner? Another interesting feature would be to use the offline hive as a mirror or fallback, whereas if the entry does not exist in the live hive offlinereg would defer to the offline hive but all writes/updates goto the live hive.

WOuld be useful in WinPE when it comes to implementing specific functionality.

 

Edit:

Lol my fault, just realised I asked you before a long time ago :P


Edited by Biatu, 25 November 2015 - 11:06 PM.





0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users