home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
PCGUIA 127
/
PC Guia 127.iso
/
Software
/
Utils
/
Winpooch Watchdog
/
Winpooch-0.5.10.exe
/
{app}
/
README
< prev
next >
Wrap
Text File
|
2006-02-02
|
4KB
|
112 lines
Winpooch - Readme
*****************
Author Benoit Blanchon
Date 02/02/2006
Version 0.5.10
Web site http://www.winpooch.com/
About Winpooch
--------------
Winpooch is a watchdog for Windows. It watches running
programs and prevents them from doing dangerous operations.
This very simple program helps you to detect Trojans and
spywares. I can also detect virus : if ClamWin is installed on your
computer, you can tell Winpooch to scan each executable file before
allowing it to run.
Winpooch runs under 32-bits versions of Windows 2000,
Windows XP and Windows 2003. Support for 64-bits versions will come later.
About version 0.5.10
--------------------
It's been a very long time from the release date of the 0.5.9.
Many reasons to that : new job, new home, new computer... I was several
months without having a second to type a line of code. Anyway, the new
branch 0.6 is still under development.
What Winpooch watches ?
-----------------------
By default, Winpooch will not spy services, but this can be
activated by modifying the value "Use debug privilege" in the configuration
Window.
With default rules, Winpooch will ask the user before allowing
a program to write sensible files or registry keys. Default rule are
very rich, you may choose to reduce them or to change default action.
Don't hesitate to create you own filters, this new Winpooch is
highly customizable.
Which API function are hooked ?
-------------------------------
This section is intended to users with some knowledge of the Win32 API.
If you don't know about it, you can skip it.
- Functions in ntdll.dll :
+ NtSetValueKey
and so :
. RegSetValueExA
. RegSetValueA
. RegSetValueExW
. RegSetValueW
+ NtCreateFile and NtOpenFile
and so :
. CreateFileA
. CreateFileW
. CopyFileA
. CopyFileW
. CopyFileExA
. CopyFileExW
+ NtSetInformationFile
and so :
. MoveFileA
. MoveFileW
. MoveFileExA
. MoveFileExW
. MoveFileWithProgressA
. MoveFileWithProgressW
+ NtDeleteFile
and so :
. DeleteFileA
. DeleteFileW
- Functions in kernel32.dll :
+ CreateProcessA
+ CreateProcessW
- Functions in ws2_32.dll
+ connect
+ listen
Next evolutions
---------------
What you may expect for next versions :
- Wizard to help you configure filters
- Kernel-mode API hooking (planned for versions 0.6.x)
Please note that version 0.6.0 is keeping us very busy
so it's difficult to add new features into 0.5 branch. Thanks
for your comprehension.
About license
-------------
Winpooch comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under
certain conditions. For details, please read LICENSE text file.
This software uses the FreeImage open source image library.
See http://freeimage.sourceforge.net for details.
FreeImage is used under the GNU GPL, version 2.
Authors
-------
Benoit Blanchon.............. Programming
Sylvain Fajon................ Graphics and tests
Amaury Bertron-Besnier....... Web site
Seather...................... Dirs and keys to watch
Andrea Vezzali............... Original Italian translation
Moreno Monga................. Current Italian translation
Marcin "Angelo" Wawrzyniak... Polish translation
Mßrton Balßzs (documan)...... Hugarian translation
Andreas Ender................ German translation
Hakan Aktas.................. Turkish translation
Vitor Brock.................. Portuguese translation
Jochem Jean van de Groep..... Dutch translation