Winpooch-0.5.4-src
所属分类:远程控制/远程桌面
开发工具:Visual C++
文件大小:254KB
下载次数:72
上传日期:2006-10-16 11:39:12
上 传 者:
fletcher
说明: Winpooch可以监控Windows 系统(2000, XP, 2003, but only 32-bits). 它能监测系统更改,以便能检测木马或间谍软件的安装。
(Winpooch can monitor Windows systems (2000, XP, 2003, but only 32-bits). It monitoring system changes in order to detect Trojan horse or spyware installed.)
文件列表:
languages (0, 2005-07-24)
languages\English.txt (6868, 2005-07-24)
languages\French.txt (7790, 2005-07-24)
languages\LICENSE_DE (17326, 2005-07-24)
languages\LICENSE_EN (15399, 2005-07-24)
languages\LICENSE_FR (15274, 2005-07-24)
languages\LICENSE_IT (19016, 2005-07-24)
languages\LICENSE_NL (17326, 2005-07-24)
winpooch (0, 2005-07-24)
winpooch\AboutWnd.c (5556, 2005-07-24)
winpooch\AboutWnd.h (1762, 2005-07-24)
winpooch\Application.c (9426, 2005-07-24)
winpooch\AskDlg.c (6645, 2005-07-24)
winpooch\AskDlg.h (1902, 2005-07-24)
winpooch\Assert.c (2520, 2005-07-24)
winpooch\Assert.h (1884, 2005-07-24)
winpooch\BuildCounter.pl (2089, 2005-07-24)
winpooch\CHANGELOG (4055, 2005-07-24)
winpooch\Condition.c (15170, 2005-07-24)
winpooch\Condition.h (3389, 2005-07-24)
winpooch\Config.c (8399, 2005-07-24)
winpooch\Config.h (2654, 2005-07-24)
winpooch\ConfigWnd.c (8540, 2005-07-24)
winpooch\ConfigWnd.h (1764, 2005-07-24)
winpooch\DbgPrint.c (3264, 2005-07-24)
winpooch\DbgPrint.h (1762, 2005-07-24)
winpooch\Disasm.c (5925, 2005-07-24)
winpooch\Disasm.h (1796, 2005-07-24)
winpooch\EventLog.c (10231, 2005-07-24)
winpooch\EventLog.h (2197, 2005-07-24)
winpooch\Filter.c (10667, 2005-07-24)
winpooch\Filter.h (2825, 2005-07-24)
winpooch\FilterFile.c (21381, 2005-07-24)
winpooch\FilterFile.h (1815, 2005-07-24)
winpooch\FilterSet.c (6431, 2005-07-24)
winpooch\FilterSet.h (2568, 2005-07-24)
winpooch\FilterWnd.c (21747, 2005-07-24)
winpooch\FilterWnd.h (1734, 2005-07-24)
winpooch\HistoryWnd.c (8024, 2005-07-24)
winpooch\HistoryWnd.h (1808, 2005-07-24)
... ...
Winpooch - Readme
*****************
Author Benoit Blanchon
Date 24/07/2005
Version 0.5.4 alpha
Web site http://www.winpooch.com/
Project page http://sourceforge.net/projects/winpooch/
About Winpooch
--------------
Winpooch is a watchdog for Windows. It watches running
programs and prevent them from doing dangerous operations.
This very simple program helps you to detect Trojans and
spywares. I can also detect virus : if ClamWin is installed on your
computer, you can tell Winpooch to scan each executable file before
allowing it to run.
Winpooch runs under 32-bits versions of Windows 2000, Windows XP and
Windows 2003. Support for ***-bits versions will come later.
Note about Windows *** support
-----------------------------
I found on a forum someone who explains how to make Winpooch runs
under Windows ***. It's no more needed to patch Winpooch, you can force
Winpooch by clicking Yes when you're asked to. But you have to keep in mind
that Winpooch can only spy 32 bits applications, and can't hook *** bits
applications.
About version 0.5.4
-------------------
This version adds multi-language support. We are proud to announce
that the Winpooch team is growing : Mick is now at the lead of the
translation team.
What Winpooch watches ?
-----------------------
By default, Winpooch will not spy services, but this can be
activated by modifying the value "Use debug privilege" in the key
HKEY_LOCAL_MACHINE\SOFTWARE\Winpooch.
With default rules, Winpooch will ask the user before allowing
a program to write the followings :
- C:\Windows\*.exe
- C:\Windows\*.dll
- HK??\Software\Microsoft\Windows\CurrentVersion\Run*
These are very simple rules, you may change them. Feel free
to send us you r good rules thru the "Patches" facility offered by
Source Forge.
Which API function are hooked ?
-------------------------------
This section is intended to users with some knowledge of the Win32 API.
If you don't know about it, you can skip it.
- Functions in advapi32.dll :
+ RegCreateKeyExA (and so RegCreateKeyA)
+ RegCreateKeyExW (and so RegCreateKeyW)
+ RegCloseKey
+ RegOpenKeyExA
+ RegOpenKeyExW
+ RegSetValueExA (but not RegSetValueA)
+ RegSetValueExW (but not RegSetValueW)
- Functions in kernel32.dll :
+ CreateProcessA
+ CreateProcessW
+ CreateFileA
+ CreateFileW, and so :
. CopyFileA
. CopyFileW
. CopyFileExA
. CopyFileExW
+ DeleteFileW, and so :
. DeleteFileA
+ MoveFileWithProgressW, and so :
. MoveFileA
. MoveFileW
. MoveFileExA
. MoveFileExW
. MoveFileWithProgressA
- Functions in ws2_32.dll
+ connect
+ listen
Next evolutions
---------------
What you may expect for next versions :
- Richer default filters (planned for next version)
- Beta version (planned for next version)
About licence
-------------
Winpooch comes with ABSOLUTELY NO WARRANTY.
This is free software, and you are welcome to redistribute it under
certain conditions. For details, please read LICENCE text file.
This software uses the FreeImage open source image library.
See http://freeimage.sourceforge.net for details.
FreeImage is used under the GNU GPL, version 2.
Authors
-------
Benoit Blanchon............ Program
Sylvain Fajon.............. Graphics
Amaury Bertron-Besnier..... Web site
Seather.................... Dirs and keys to watch
Nico (tBB)................. Tests
Mick Weiss................. Translators coordination
Andrea Vezzali............. Italian translation
Kai Scheller............... German translation
Danil Rokven (kierownik).. Dutch translation
近期下载者:
相关文件:
收藏者: