WinPatrol v19

Discussion in 'other anti-malware software' started by Gobbler, Oct 1, 2010.

Thread Status:
Not open for further replies.
  1. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    yeah i dont see it yet but i see the real time is faster than before;) this is a good thing:cool:
     
  2. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    the realtime is very fast now..indeed. :thumb: :D
     
  3. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
  4. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Open notepad and save as HKCU.reg file (Ansi format) and all user space autostart entries are guarded as well. Double click the HKCU.reg file and allow (when you have the plus version)
    **** star after this line (first line is Windows Registry etc)

    Windows Registry Editor Version 5.00

    [HKEY_CURRENT_USER\Software\BillP Studios\WinPatrol\RegOptions]
    "HKEY_CURRENT_USER\\Software\\BillP Studios\\WinPatrol\\Options\\FileTypes"="1"
    "HKEY_CURRENT_USER\\Software\\BillP Studios\\WinPatrol\\Class\\exefile"="%1 %*"
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Download\\CheckExeSignatures"="yes"
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoTrayItemsDisplay"=dword:00000001
    "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SCRNSAVE.EXE"="C:\\Windows\\system32\\logon.scr"
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shell\\"=""
    "HKEY_CURRENT_USER\\Control Panel\\don't load\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\ColumnHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\CopyHookHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\PropertySheetHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\ColumnHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\ContextMenuHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\CopyHookHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\DragDropHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\PropertySheetHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\ColumnHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\CopyHookHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\DragDropHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\ContextMenuHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\ColumnHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\CopyHookHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\ColumnHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\ContextMenuHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\CopyHookHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Drive\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\exefile\\shell\\open\\command\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\Autorun"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Ctf\\LangBarAddin\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Group Policy\\"=""
    "HKEY_CURRENT_USER\\software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\"=""
    "HKEY_CURRENT_USER\\software\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\load"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Programs"="com exe bat pif cmd"
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Shell"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Notify"=""
    "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System\\Scripts\\Logoff\\"=""
    "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System\\Scripts\\Logon\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoTrayItemsDisplay"=""
    "HKEY_CURRENT_USER\\Control Panel\\Desktop\\SCRNSAVE.EXE"=""
    "HKEY_CURRENT_USER\\Control Panel\\Don't Load\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shell\\"=""
    "HKEY_CURRENT_USER\\Control Panel\\don't load\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\ColumnHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\CopyHookHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\*\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\ColumnHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\CopyHookHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\ColumnHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\CopyHookHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\AllFilesystemObjects\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\Background\\shellex\\ColumnHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\CopyHookHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Directory\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\ColumnHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\ContextMenuHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\CopyHookHandlers\\ \\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\DragDropHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Folder\\shellex\\PropertySheetHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\Drive\\shellex\\ContextMenuHandlers\\"=""
    "HKEY_CURRENT_USER\\Software\\Classes\\exefile\\shell\\open\\command\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Active Setup\\Installed Components\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Command Processor\\Autorun"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Ctf\\LangBarAddin\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Advanced\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\Shell Folders\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\User Shell Folders\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Group Policy\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\DisallowRun"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\NoRun"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\Run"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Policies\\Explorer\\RestrictRun"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Shell Extensions\\Approved\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\ShellServiceObjectDelayLoad\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Terminal Server\\Install\\"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\load"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Programs"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Shell"=""
    "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows NT\\CurrentVersion\\Windows\\Notify"=""
    "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System\\Scripts\\Logoff\\"=""
    "HKEY_CURRENT_USER\\Software\\Policies\\Microsoft\\Windows\\System\\Scripts\\Logon\\"=""
     
  5. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    Kees1985, are those additional registry protection you can add manually to Winpatrol Plus? I don't really get the post entirely. I managed to create a registry file, but I'm not sure how I make WinPatrol accept it. :)
     
  6. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    Heavy real-time protection -- totally unnecessary in the present era of imaging and snapshots. Simply do a daily scan with a file integrity checker (for example, Tiny Watcher), and *restore* if you find a nasty.

    Why motivate folks to slog through their surfing with WinPat dragging down their computers? Next thing we know, someone will be posting about the great deal that folks can get at <finally fast dot com>. :D
     
  7. CloneRanger

    CloneRanger Registered Member

    Joined:
    Jan 4, 2006
    Posts:
    4,978
    Hey everybody, you seen the great deals available at finallyfast.com ? :D
     
  8. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    i have no idea whats going on, on ur system, but ive never seen anyone claim that winpatrol has slowed their system down and i feel the same, my system doesnt get any impact from using winpatrol in realtime, disk IO usage almost 0 as well at 187 reads and 0 writes, with a CPU time of only 0:00:08, and altho RAM usage doesnt really matter, it still only uses 10mb of RAM...

    so i really cant see what ur definition of slow is...
     
  9. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    i think he may say that if one add all those reg entries provided by kees will probably slowed down system
     
  10. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    ANY app running in real time will eat cpu cycles. WinPat, with all those registry items to check, will have a voracious appetite. But never mind that -- in the present era of imaging & snapshots & sandboxes & VM, WinPat is simply an out-dated solution trying desperately to find a problem.
     
  11. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    i use it for its convenience with readily available info and no noticeable slowdown, and ur right ANY app will, so will the Tiny Watcher program u mentioned, anyways, idk what the increase in resource usage wuld be with those registry keys being covered, maybe someone can try them out then report on the usage.

    i find it not very practical to go straight to something as large scale as imaging and restoring images for small changes i like to see and know about, not really worth the time and effort of an image.
     
  12. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    i can testify that WinPatrol Plus really helps to protect the system,i tested againts rouges and fake antivirus(also trojans) and it is very light it really take a litle snapshot of the system and if some new suspicous programs wants to be added to ones system WiPatrol Plus will burk and Alert you to prevent changes;) it works very well againts rouges and fake programs,i think that Nod32 AntiVirus with WinPatrol Plus will provide a very solid and strong system protection:thumb: :thumb:
     
  13. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    TW runs only on-demand. I have it run at start-up while I make my cup of Jamaican Blue Mountain.

    If you are going to run a weak-side HIPS (namely WinPat) why not run a full HIPS (Malware Defender or - shudder - D+) for better protection costing fewer cpu cycles than WinPat uses?
     
  14. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    ill disagree with the last part since i have used D+, i used to use Outpost, ive used EQSecure and OA and not a single one of them is lighter on resources than winpatrol by quite a large margin, a full HIPS monitors many more areas of the systems than winpatrol, and winpatrol doesnt monitor all areas in realtime (only a select few, the rest get checked every so often)

    and it might give me better protection but i dont use winpatrol to protect me, i use it more as a system utility to give me more info on whats going on with my system and things i can adjust.
     
  15. Kernelwars

    Kernelwars Registered Member

    Joined:
    Aug 12, 2010
    Posts:
    2,155
    Location:
    TX
    oh yes yes definitely agree with you. :thumb:
     
  16. Boyfriend

    Boyfriend Registered Member

    Joined:
    Jun 7, 2010
    Posts:
    1,070
    Location:
    Pakistan
    Thanks Gobbler. Latest build is working very well and stable. Currently using 1068 K memory with 9 I/O Reads only [​IMG]
     
  17. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    2824 k memory here;) not even 3 megs:thumb:very light
     
  18. bellgamin

    bellgamin Registered Member

    Joined:
    Aug 1, 2002
    Posts:
    8,102
    Location:
    Hawaii
    No offense but RAM is not a significant measure of system drag. CPU cycles & I/O bytes - that's what counts.
     
  19. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    cp usage is at 2 %
     
  20. firzen771

    firzen771 Registered Member

    Joined:
    Oct 29, 2007
    Posts:
    4,815
    Location:
    Canada
    me as well as another person now have already commeneted on CPU time of winpatrol as well as its I/O reads and writes, we've consistantly shown its nearly non existant resource usage

    the only thing i wonder at this point is have u ever actually used winpatrol, cuz ive honestly never heard anyone say its a heavy program...
     
  21. shadek

    shadek Registered Member

    Joined:
    Feb 26, 2008
    Posts:
    2,538
    Location:
    Sweden
    WinPartol is the most lightweight program I have ever tried. Anyone who claims it's heavy is a liar. After 30 minutes having the computer on, the program uses 2004 K of memory. It has made 75 I/O reads (compared to Skype that uses 79260 K and has made 2536 I/O reads). I haven't even seen WinPatrol.exe use even 1% of the CPU at any time yet.

    Either you're just fooling around or being a troll, bellgamin. :)
     
  22. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    2% of what CPU? :D I have to agree with Bellgamin on that, as a matter of fact i 've closed WinPatrol and i will probably use it only on demand. Or maybe i will reinstall it as FREE version so that it won't have realtime protection. Avast uses less CPU and it's a full blown antivirus with behaviour blocker.

    This is 0.5MB video from my task manager:

    http://hotfile.com/dl/73850204/8021a69/New_folder.zip.html

    1% every 1 second, with spike at 16% and another at 2%.

    I 've AMD quad core@2300 Mhz and freshly restored Windows image. CPU is at full frequency because i am encoding video. Now what would these values be if i had a single core instead?

    I mean, come on, for a purist this is simply too much for a supposedly simple monitor. My firewall with full p2p or Avast don't eat that CPU.

    I love WinPatrol but probably i will revert to the free version.


    Just because all YOU care about is I/O reads and RAM, doesn't mean others have the same criteria. I encode video so i need all the CPU cycles i can get for example.

    Well, now you can! :)
     
    Last edited: Oct 5, 2010
  23. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Just double click it and it will add it to the registry of WinPatrol. Go to Registry protection to check whether they are included. When you are on Vista or Windows7 with UAC, UAC will protect the HKLM hive of the registry. The added current user protection will prevent intrusions allowed when running LUA or using UAC.

    Regards
     
  24. Kees1958

    Kees1958 Registered Member

    Joined:
    Jul 8, 2006
    Posts:
    5,857
    Only monitor startup and registry, with UAC others are sufficient protected. You will see that CPU drops to near zero. I use WP+ on my son's laptop. Startup and Registry monitoring (see earlier post with my extra rules) will make sure all registry startups in user land are protected. So this is a nice and light addition to people running LUA or using UAC on Vista/Win7
     
  25. Fuzzfas

    Fuzzfas Registered Member

    Joined:
    Jun 24, 2007
    Posts:
    2,753
    Good idea. I got rid of the big spikes, but still 1% every 1 sec. I think i will put back the previous version. It does plenty for me already. I have UAC on highest setting.
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.