![]() |
|
#1
|
||||
|
||||
|
Tiny Watcher is a small program that reports changes in important system files at start up. Usually it gives you the option to either remove or confirm those changes, but today following a regular Windows Update restart, it's only giving me the 'Remove' option:
Quote:
My instinct would be to confirm the changes since the Windows update included updates to .Net Frameworks, but with Tiny Watcher that's not an option, so I'm thinking removing Tiny Watcher unless someone here happens to know that it's right in this case. Otherwise, any good (up-to-date) alternatives to Tiny Watcher?
__________________
Main machine: Samsung laptop, i7 QuadCore, 16GB RAM, SSD, USB3.0, Win7 Home Premium 64-bit (main), Mint 12.4 (linux newbie) Software: Comodo Internet Security, KeyScrambler, Keepass w/ Dropbox to sync, Sandboxie, Peerblock, Drive Snapshot, a2cmd, EasyBCD for custom boot, AutoHotkey. |
|
#2
|
||||
|
||||
|
I would confirm it too but if you want to keep TW then why not reset it?
__________________
once we only had ideals, today they are the only things we are missing Microsoft MVP, 2006 - 2013/14 |
|
#3
|
||||
|
||||
|
Quote:
not sure if i want to keep it anymore... i'd prefer a program that just reports the changes but leaves the deciding to the user (without hoop jumping).
__________________
Main machine: Samsung laptop, i7 QuadCore, 16GB RAM, SSD, USB3.0, Win7 Home Premium 64-bit (main), Mint 12.4 (linux newbie) Software: Comodo Internet Security, KeyScrambler, Keepass w/ Dropbox to sync, Sandboxie, Peerblock, Drive Snapshot, a2cmd, EasyBCD for custom boot, AutoHotkey. |
|
#4
|
||||
|
||||
|
winpatrol plus then
is for you to use buddy![]()
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#5
|
||||
|
||||
|
mscorsvw.exe is a notorious cpu-eater. I never see it because I killed it a long time ago. For me dot net works okay without it.
Do a Google search on mscorsvw.exe & you will get tons of hits such as THIS - which tells how to get rid of this Microsoft piece of crap. Quote:
Registry monitoring TW's registry list is largely based on research done by Kees1958, Tony Klein, & hojtsy. By the way -- these same superb sources also form one of the primary bases for registry watch lists used by Online Armor, MJ Registry Watcher, RegRun, et alia. System files monitoring TW's system files monitoring uses wild cards (*) that cause it to cover extremely critical system files with just a few entries as follows. . . Quote:
Because of TW's broad spectrum of monitored key files, I disabled TW's quick scan from startup & instead I run TW's deep scan daily at startup, called as follows . . . Quote:
Bottom Line Give up TW for some bit of Microsoft's intrusive, cpu-eating, ill-conceived mscorsvw.exe? NOT me! As for WinPat -- if someone wants to run a real-time HIPS, I recommend Malware Defender (it's free) or Online Armor-free. They cover MANY more threat behaviors than does WP.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender Last edited by bellgamin : September 4th, 2010 at 12:15 AM. |
|
#6
|
||||
|
||||
|
good explanation bell buddy
__________________
Anti-Executable Standard 5.20.1112.562/K9 Web Protection 4.4.268 |
|
#7
|
||||
|
||||
|
Take those areas watched by Tiny Watcher and import them to Winpatrol and your set.
I have a detection by TinyWatcher on my laptop with something similar. Quote:
I traced it to a service for HP Printers. I reported the false positive to the Tiny Watcher developer over 3 weeks ago and still not even a confirmation email saying that they have received it and are looking into it.
__________________
|Kaspersky Anti-Virus 2013|Private Firewall|HitmanPro|MBAM|Keriver Image|WinPatrol Plus|
Looking for volunteer authors to write articles, reviews, and How-Tos. If you think you have what it takes, contact me. |http://pc-babble.com/| |
|
#8
|
||||
|
||||
|
Quote:
![]()
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#9
|
||||
|
||||
|
Quote:
Doesnt exactly make one want to use a program. Especially when something has been reported numerous times, it hasnt been fixed, and the coder wont even respond to emails.
__________________
|Kaspersky Anti-Virus 2013|Private Firewall|HitmanPro|MBAM|Keriver Image|WinPatrol Plus|
Looking for volunteer authors to write articles, reviews, and How-Tos. If you think you have what it takes, contact me. |http://pc-babble.com/| |
|
#10
|
||||
|
||||
|
Quote:
(1) TW (free. Highly configurable) (2) Sentinel (free - not nearly as configurable as TW) (3) ADInf Pro ($14.95 - extremely powerful, interfaces nicely with several antivirus programs, equally as configurable as TW but a bit more complicated to learn. Concerning which, Wilders has a very detailed tutorial HERE.) In actuality integrity checkers need little or no updating IF & ONLY IF they are readily configurable. AFAIK their ONLY *major* weakness, as a security app, is that they are not self-protected. Thus, a malware can easily target them, to screw up their database or kill them altogether. I protect TW with my HIPS (any good HIPS can be configured to strongly protect any given app from mutilation or deletion or spoofing). Is an integrity checker worth the effort? My answer -- you will rarely find a commercially-based server that lacks one. Many ITs consider integrity checkers to be indispensable. So do I. This is especially true since my own philosophy of strong but non-intrusive layered security is heavily centered on an integrity checker plus imaging. I happen to prefer TW, but would switch to ADInf in a heartbeat if TW was no longer available.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#11
|
||||
|
||||
|
You can import the registry settings that TW watches into Winpatrol free or paid and have just as good of protection with more added features.
__________________
|Kaspersky Anti-Virus 2013|Private Firewall|HitmanPro|MBAM|Keriver Image|WinPatrol Plus|
Looking for volunteer authors to write articles, reviews, and How-Tos. If you think you have what it takes, contact me. |http://pc-babble.com/| |
|
#12
|
||||
|
||||
|
Quote:
Thanks for the details, I didnt know that there was specific software for this. There is also a command in windows that automatically checks the integrity of system files, is quite recommended to run it after malware cleaning: sfc /scannow If any file is not original the program automatically will replace the file with the original one from a backup or from the CD/DVD Last edited by lordraiden : September 7th, 2010 at 07:38 PM. |
|
#13
|
||||
|
||||
|
Quote:
Don't get me wrong. WP is a nice little HIPS. However, comparing WP to a file integrity checker is comparing apples to lawn mowers. They simply are not designed to do the same thing in the same way. ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Note 1: Since the subject of HIPS has been introduced into the discussion, I might add that WP is a narrow-spectrum HIPS-type app with zero capability for stopping kill apps & rootkits, AND (except for autoruns et alia) is not set-up or configurable to protect other types of files. For fewer cpu cycles than are needed to run WP, you can run any one of several broad-scope HIPS which are light-years more powerful than WP. Malware Defender is one example. D+ is another. OSSS is yet another; & the list goes on. However, I am OT. This thread is about TW vs mscorsvw.exe -- not about WP vs other HIPS.
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#14
|
||||
|
||||
|
Quote:
I decided to give Winpatrol a try. Can it be set to only run during start-up, or to only monitor the areas that Tiny Watcher monitors during start-up? And if so, how?
__________________
Main machine: Samsung laptop, i7 QuadCore, 16GB RAM, SSD, USB3.0, Win7 Home Premium 64-bit (main), Mint 12.4 (linux newbie) Software: Comodo Internet Security, KeyScrambler, Keepass w/ Dropbox to sync, Sandboxie, Peerblock, Drive Snapshot, a2cmd, EasyBCD for custom boot, AutoHotkey. |
|
#15
|
||||
|
||||
|
Quote:
|
|
#16
|
||||
|
||||
|
Quote:
__________________
Primo freebeez: TinyWatcher POP Peeper Kalender |
|
#17
|
||||
|
||||
|
ok, so suppose i let WinPatrol run in real time; how can I make it monitor the same registry keys that Tiny Watcher monitors? I mean, below is a picture of WinPatrols's "Registry Monitoring" tab, and it appears to require registry value and data names, as opposed to just registry key names... so how do I make WinPatrol Monitor the whole registry keys that Tiny Watcher monitors instead of just individual registry entry values/data?
__________________
Main machine: Samsung laptop, i7 QuadCore, 16GB RAM, SSD, USB3.0, Win7 Home Premium 64-bit (main), Mint 12.4 (linux newbie) Software: Comodo Internet Security, KeyScrambler, Keepass w/ Dropbox to sync, Sandboxie, Peerblock, Drive Snapshot, a2cmd, EasyBCD for custom boot, AutoHotkey. |
| « Previous Thread | Next Thread » |
| Thread Tools | Search this Thread |
|
|