Home / Other / Reviews and recommendations / Track changes in registry & filesystem
0 Members and 1 Guest are viewing this topic. « previous next »
Pages: [1] - (Bottom) Print
Author Topic: Track changes in registry & filesystem  (Read 1668 times)
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« on: October 04, 2009, 11:21:42 AM »

Some software come with hidden malware which goes undetected by many antivirus software. By analyzing the change made by the software installer to both your registry and file system, it can be much more easier to remove the hidden malware.

So how can you track the changes? So far there has been no straightforward tool, until today. TrackWinstall is a portable tool that creates a system snapshot, then launches the installer and finally shows you all the changes made by the installer.

It comes in two modes, One-Click Protocol and Two-Phase Mode.

    * One-Click Protocol(Simple Installs): Take snapshot of the system state, launches the specified installer, and then records the changes.
    * Two-Phase Mode(Complex Installs): Take snapshot of the system state, terminates, and records the changes on the next launch(after system restart).
If you want to exclude a add/exclude a certain file system, you can do so by going to Options. You can also skip Windows Update files to speed up the process.

once the system snapshot has been created, you don’t need to create it every time when installing applications. You can load it by clicking Load button on the main window.  you can download it here http://translate.google.com/translate?u=http%3A%2F%2Fwww.withopf.com%2Ftools%2Ftrackwinstall%2F&langpair=de%7Cen

[attachment deleted by admin]
IP logged
BC_Programmer
Mastermind


Thanked: 697
Posts: 15,881

Computer: Specs
Experience: Beginner
OS: Windows 7


Pinkie Pie is best pony

BC-Programming.com 1 1
« Reply #1 on: October 04, 2009, 02:01:28 PM »

the same effect could be achieved with regmon/Process monitor...
IP logged

My Blog

BASeBlock 2.3.0 (NOW WITH MACGUFFINS!)
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #2 on: October 04, 2009, 02:15:44 PM »

Or Total Uninstall...which has been around since Win98.
IP logged

   
"
All generalizations are false, including this one.  "
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #3 on: October 05, 2009, 02:37:46 AM »

yes ,but by running the installer through trackwinstall you are given a detailed view of what was files were added, what was modified and for example you installed a trial software you can identify certain registry keys that prevent you from reinstalling after the trial expired.i will post a screen of the report it gives.
IP logged
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #4 on: October 05, 2009, 07:57:23 AM »

Same with Total Uninstall...
IP logged

   
"
All generalizations are false, including this one.  "
BC_Programmer
Mastermind


Thanked: 697
Posts: 15,881

Computer: Specs
Experience: Beginner
OS: Windows 7


Pinkie Pie is best pony

BC-Programming.com 1 1
« Reply #5 on: October 05, 2009, 08:49:11 AM »

Same with Total Uninstall...

or registry monitor and file monitor or process monitor.

Of course regmon,filemon, and procmon don't have oversized buttons.


Additionally the idea of taking a "snapshot" is ridiculous, especially given that there are functions to monitor the registry for changes just as there are for files.
IP logged

My Blog

BASeBlock 2.3.0 (NOW WITH MACGUFFINS!)
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #6 on: October 05, 2009, 09:31:57 AM »

No over-sized buttons ? ?.......Darn !

 ;D
IP logged

   
"
All generalizations are false, including this one.  "
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #7 on: October 05, 2009, 09:53:26 AM »

sorry you did not like it, i thought it was cool :)
IP logged
BC_Programmer
Mastermind


Thanked: 697
Posts: 15,881

Computer: Specs
Experience: Beginner
OS: Windows 7


Pinkie Pie is best pony

BC-Programming.com 1 1
« Reply #8 on: October 05, 2009, 10:21:50 AM »

given the fact that some of your other "reviews" have ended up being infested and or triggering AV programs I think it's safe to say that perhaps you should be a tad more careful what you use?
IP logged

My Blog

BASeBlock 2.3.0 (NOW WITH MACGUFFINS!)
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #9 on: October 05, 2009, 03:50:12 PM »

B.C said-  ( Additionally the idea of taking a "snapshot" is ridiculous, especially given that there are functions to monitor the registry for changes just as there are for files.)   looking at total uninstalls help file it seems a "snapshot" is what it does so are you saying that it too is ridiculous?

[attachment deleted by admin]
IP logged
patio
Moderator
Genius



Thanked: 1069
Posts: 11,354

Experience: Beginner
OS: Windows 7


Maud' Dib

« Reply #10 on: October 05, 2009, 03:58:51 PM »

I'm not...

I've used it for many years.
IP logged

   
"
All generalizations are false, including this one.  "
BC_Programmer
Mastermind


Thanked: 697
Posts: 15,881

Computer: Specs
Experience: Beginner
OS: Windows 7


Pinkie Pie is best pony

BC-Programming.com 1 1
« Reply #11 on: October 05, 2009, 03:59:16 PM »

B.C said-  ( Additionally the idea of taking a "snapshot" is ridiculous, especially given that there are functions to monitor the registry for changes just as there are for files.)   looking at total uninstalls help file it seems a "snapshot" is what it does so are you saying that it too is ridiculous?

I never said I liked total uninstall...
IP logged

My Blog

BASeBlock 2.3.0 (NOW WITH MACGUFFINS!)
bobgar34
Topic Starter
Intermediate



Thanked: 3
Posts: 198

Experience: Experienced
OS: Windows XP

« Reply #12 on: October 07, 2009, 12:28:20 AM »

i had never heard of Total Uninstall until Patios post and i have to say i am very impressed.and @ B.C. filemon and regmon were both new to me and both are apps that now i can not go without. so thanks Patio and B.C
IP logged
BC_Programmer
Mastermind


Thanked: 697
Posts: 15,881

Computer: Specs
Experience: Beginner
OS: Windows 7


Pinkie Pie is best pony

BC-Programming.com 1 1
« Reply #13 on: October 07, 2009, 12:52:57 AM »

:)

actually, many of the tools you've found useful have pretty good Sysinternals equivalents. Some of them are a bit complicated, but they are more powerful (not as user friendly though- no "fit it now *censored*" buttons  ;D)
IP logged

My Blog

BASeBlock 2.3.0 (NOW WITH MACGUFFINS!)
Pages: [1] - (Top) Print 
Home / Other / Reviews and recommendations / Track changes in registry & filesystem « previous next »
 


Login with username, password and session length

Old Forum Search | Forum Rules
Copyright © 2010 Computer Hope ® All rights reserved.
Powered by SMF 2.0 RC3 | SMF © 2006–2010, Simple Machines LLC
Page created in 0.122 seconds with 21 queries.