Wilders Security Forums  

Go Back   Wilders Security Forums > Other Security Topics > other security issues & news
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old April 18th, 2012, 05:30 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Testing for changes made by software to your drive

Hi guys

Let's say that I would like to do some testing to find out how a certain piece of software affects my drive; what kind of new files appear on my disk after using the software, what files change, and as much similar information as possible.

Is there a way I could go about it without having to purchase special equipment? I would imagine this kind of analysis cannot be made on a Windows level as the OS itself might be making changes to the drive which would be difficult to distinguish from changes made by the software being tested. What I have available is my stationary PC, two laptops, and one external USB 2.0 200GB drive.

Specifically, I am looking to find out exactly what happens on my drive when using Google Chrome and certain instant messaging software, outside of a sandbox.

I realize that this might be difficult to do, but any input which could get me going in the right direction will be appreciated.
__________________
My setup
  #2  
Old April 18th, 2012, 06:10 PM
ronjor's Avatar
ronjor ronjor is online now
Global Moderator
 
Join Date: Jul 2003
Location: Texas
Posts: 46,202
Default Re: Testing for changes made by software to your drive

Several free tools here. https://blogs.technet.com/b/sysinter...edirected=true

Autoruns
  #3  
Old April 18th, 2012, 06:16 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Testing for changes made by software to your drive

Thanks for the link. Some interesting things there, particularly this:

http://blogs.technet.com/b/sysintern...edirected=true

However I was not able to find anything that would help me do what I am trying to do - most of the software/updates over there have to do with monitoring active processes and RAM-related issues, as opposed to analyzing changes on the hard drive. Perhaps I missed something?
__________________
My setup
  #4  
Old April 18th, 2012, 10:26 PM
FanJ FanJ is offline
Updates Team
 
Join Date: Feb 2002
Posts: 1,802
Default Re: Testing for changes made by software to your drive

ADinf32
http://www.adinf.com/
http://www.wilderssecurity.com/showthread.php?t=320057
http://www.wilderssecurity.com/showthread.php?t=72131


TinyWatcher
http://www.donationcoders.com/kubicl...her/index.html
http://www.wilderssecurity.com/showthread.php?t=319874
Ask bellgamin about it.


NIS File Check
No more available (as far as I know)

File Change Alarm
Maybe still available, not sure however
  #5  
Old April 18th, 2012, 10:43 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,454
Default Re: Testing for changes made by software to your drive

Process Monitor allows to track individual processes. It's helpful.

There are a few tools, including open-source, which I'm bad remembering the names , but they allow you to take snapshots of the system. Including of the registry.

You can then verify the changes. They will highlight them.

Is this what you're looking for?
  #6  
Old April 18th, 2012, 11:27 PM
EASTER's Avatar
EASTER EASTER is offline
Massive Poster
 
Join Date: Jul 2007
Location: U.S.A. (South)
Posts: 4,510
Default Re: Testing for changes made by software to your drive

Quote:
File Change Alarm
Maybe still available, not sure however

A very useful system change monitor in "real-time" complete with saved reports to review later if something of concern needs going over.

It goes in all my units no matter what. Feather-lite! but razor accurate!

I can post a link for it if need be.

Regards EASTER
__________________
★AX 64 Time MachineCurrent Version 1.1.0.996 ★
★Shadow Defender★| EQSecure v4.0 Beta3 |#Sandboxie 4.08 beta# |FirstDefense-ISR|★FileChangeAlarm★ |Reserve Space|
Maxthon 4 | X Iron 17.0 | Chromium 19.0 | CometBird 11

Microsoft Windows 8 64bit (UEFI/GPT) Secure Boot¶
¶Linux Mint 14 MATE¶
  #7  
Old April 18th, 2012, 11:37 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Testing for changes made by software to your drive

yes M00nbl00d, that's exactly what I'm looking for.

Thanks for the suggestions guys, I will take a look at everything that was mentioned (and the stuff that were only referenced, too! )
__________________
My setup
  #8  
Old April 19th, 2012, 10:40 AM
noone_particular noone_particular is offline
Very Frequent Poster
 
Join Date: Aug 2008
Posts: 1,876
Default Re: Testing for changes made by software to your drive

What you describe sounds like an install monitor. On XP and older systems, Inctrl5 would have done what you want. It took a snapshot of your system before the event, then took another after. Then it compared them and listed all registry changes and all new, modified, or deleted files and folders. Reports could be saved in multiple formats. It worked equally well on installs, config changes, and monitoring changes made my websites or apps. The only thing it didn't cover well is services. Install Spy is another. Not sure if it's still around or which OS it's compatible with.
__________________
Sitting in a bunker, here behind my wall, waiting for the worms to come.
  #9  
Old April 19th, 2012, 02:27 PM
BrandiCandi
 
Posts: n/a
Default Re: Testing for changes made by software to your drive

Sounds like you want to look for digital forensics tools that will compare pre and post hashes/ MD5sums. I haven't used them but it would do exactly what you want. None of them are particulary user friendly from what I understand.
  #10  
Old April 20th, 2012, 03:55 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Testing for changes made by software to your drive

I gave ADinf32 a try, and unfortunately it didn't deliver, although it's a really nice tool.

Here is what I did.

- Cleared my drive with CCleaner and a custom-made batch file.
- Created a drive "snapshot" using ADinf32
- Launched Chrome in non-incognito, non-sandboxed mode
- Browsed around for 10-15 minutes, visiting all the websites that leave tons of rubbish on your drive (facebook, cnn, yahoo, some local websites and a bunch of random stuff)
- Instructed ADinf32 to check my drive for changes. The only thing it was able to find was the change of a single file, that was related to some background services running.
- I ran CCleaner just to confirm - 20MB of temp files/cookies/various other stuff were detected.

This software appears to only check important windows files / folders / processes for changes, but doesn't monitor everything that happens on a hard drive (which makes sense given the purpose Adinf32 was created to serve.)

Let me stress again: I need to check for ALL changes that happen to my hard drive. I do not expect a single piece of software to do that for me (although that would be awesome), so I am prepared to do some work myself, if only I knew how to go about it.

Basically what I am trying to do: I want to see exactly what traces do various software leave on my hard drive, so I can update my custom batch file to always delete those artifacts after I am done working. Sandboxing could be a solution to this, but I cannot run everything inside of a sandbox, and definitely not always.

So I am still without a solution at the moment.
__________________
My setup

Last edited by syncmaster913n : April 20th, 2012 at 06:28 PM.
  #11  
Old April 20th, 2012, 09:32 PM
jdd58's Avatar
jdd58 jdd58 is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Iowa
Posts: 415
Default Re: Testing for changes made by software to your drive

Maybe directory monitor will work for you. -http://www.brutaldev.com/page/Directory-Monitor.aspx

If not go to -http://www.techsupportalert.com/content/probably-best-free-security-list-world.htm

and go to section 7.10.
  #12  
Old April 20th, 2012, 09:37 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,849
Lightbulb Re: Testing for changes made by software to your drive

Inctrl5 should do it, as noone_particular says If you search hard enough you can still get it

The other alternative i would have suggested is, using something like ShadowDefender/Returnil etc, but i see you already use VirtualBox !

I guess you are attempting to track who/what does what to your comp whilst online, rather than just drop all changes without knowing what they were etc

Hope you find it & can use it
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #13  
Old April 21st, 2012, 01:20 AM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Testing for changes made by software to your drive

Thanks guys, will try all of those today.

Quote:
Originally Posted by CloneRanger
I guess you are attempting to track who/what does what to your comp whilst online, rather than just drop all changes without knowing what they were etc

Yup, precisely This way I can apply what I learn to every machine I use, which doesn't always need to be configured for my particular taste. Plus it's fun!

EDIT: Inctrl5 definitely doesn't cut it, it can basically only monitor things strictly related to a particular installation file that you choose from your drive before the program takes it's snapshot. It doesn't offer the flexibility I would require.

http://www.brutaldev.com/page/Directory-Monitor.aspx - seems like it MIGHT be the right tool, but I can't for the life of me figure out how to view the logs showing changes. I can only see the words "xxx changes made" but no way to check what those changes are. I'll keep looking, but the programis so straightforward that I am not sure what I might have missed.
__________________
My setup

Last edited by syncmaster913n : April 21st, 2012 at 01:43 AM.
  #14  
Old April 21st, 2012, 02:04 AM
jdd58's Avatar
jdd58 jdd58 is offline
Frequent Poster
 
Join Date: Jan 2008
Location: Iowa
Posts: 415
Default Re: Testing for changes made by software to your drive

Try Moo0 File Monitor -http://www.moo0.com/?top=http://www.moo0.com/software/FileMonitor/
  #15  
Old April 21st, 2012, 05:16 AM
ichito's Avatar
ichito ichito is offline
Frequent Poster
 
Join Date: Jan 2011
Location: Poland - Cracow
Posts: 848
Default Re: Testing for changes made by software to your drive

TinyWatcher is very useful and nice app...but now I can recommend another app...it's System Explorer with nice feature in context of this thread
Quote:
Snapshots

Provides tool for making snapshot of file system and registry state. You can easily compare two snapshots and see differences made between capturing of snapshots. This tool is usefull for analyzing changes made in computer.
http://systemexplorer.net/onlinehelp.php?t=sections
__________________
"Who was not a rebel in his youth, this will be a pig in old age" - J. Piłsudski
SG.pl
  #16  
Old April 22nd, 2012, 10:19 AM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Testing for changes made by software to your drive

Quote:
Originally Posted by jdd58
Try Moo0 File Monitor -http://www.moo0.com/?top=http://www.moo0.com/software/FileMonitor/

Bingo! Thanks a lot.
__________________
My setup
  #17  
Old April 23rd, 2012, 01:10 PM
m00nbl00d m00nbl00d is offline
Incredibly Massive Poster
 
Join Date: Jan 2009
Posts: 6,454
Default Re: Testing for changes made by software to your drive

This one may also prove useful for this kind of monitoring.

-https://blogs.technet.com/b/askperf/archive/2010/01/12/an-introduction-to-the-windows-system-state-analyzer.aspx?Redirected=true
  #18  
Old April 23rd, 2012, 04:07 PM
syncmaster913n syncmaster913n is offline
Regular Poster
 
Join Date: Mar 2012
Posts: 153
Default Re: Testing for changes made by software to your drive

Nice, I'm actually looking for something that would monitor the registry in a reliable manner; most apps out there only take notice if entries are added or removed, but do not inform you if the value of any key is changed. Maybe this will deliver.

Thanks to Moo0 FileMonitor, I noticed something I do not understand today. I've described it here: http://www.wilderssecurity.com/showthread.php?t=322696

Overal, it's an excellent tool, extremely reliable and informs you of absolutely ANY change that happens to the harddrive. The only thing it lacks is an option to exclude certain directories from the monitoring process. But you can get used to its absence or simply close certain programs if they are particularly annoying and you need to focus.

Overal my impression is that when browsing in Chrome, the only folders to be worried about are AppData\Local\Google\Chrome\User Data\Default (I've set my batch file to clear that folder completely, excluding the Bookmarks and Preferences files) and AppData\Roaming\Microsoft\Windows\Recent (I clear this one completely). Some changes to Windows\Prefetch and the Temp folders as well. Other than that I haven't noticed anything unusual, at least for Chrome.

EDIT: Sysinternals Process Monitor is an awesome registry and HDD monitor.
__________________
My setup

Last edited by syncmaster913n : April 23rd, 2012 at 07:21 PM.
  #19  
Old April 25th, 2012, 07:08 PM
CloneRanger's Avatar
CloneRanger CloneRanger is offline
Massive Poster
 
Join Date: Jan 2006
Location: Home usually
Posts: 3,849
Default Re: Testing for changes made by software to your drive

@ jdd58

Thanks for reminding me about the Moo0 File Monitor

@ syncmaster913n

Yeah you're right about Inctrl5, my bad memory

A very good registry App is RegDefend by www.ghostsecurity.com I tried to visit them just now but it's not what i expected to see ? This is how it used to look http://web.archive.org/web/201010230....com/regdefend You can still download it from there, or for eg here http://www.brothersoft.com/regdefend-36038.html if you want to try it. Let us know if you do
__________________
.
Malware = You don't scare me

A different perspective https://rt.com - https://rt.com/on-air
  #20  
Old July 31st, 2012, 01:52 PM
Athletic's Avatar
Athletic Athletic is offline
Regular Poster
 
Join Date: Jan 2009
Posts: 88
Default Re: Testing for changes made by software to your drive

There is one more portable app that gives even more live info
FileMon 7.04

LINK:----http://www.softpedia.com/get/Programming/Other-Programming-Files/Filemon.shtml----

It is something like Moo0 FileMonitor 1.07
__________________
1.Firefox 2. Sandboxie 3. Shadow Defender 4. Acronis TI 5. FastStone 6.Micro Torrent 7.WinPatrol
 

Wilders Security Forums > Other Security Topics > other security issues & news « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 02:13 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums