IWETHEY v. 0.3.0 | TODO
1,095 registered users | 0 active users | 0 LpH | Statistics
Login | Create New User
IWETHEY Banner

Welcome to IWETHEY!

New You are insane
But we knew that.
New No, just paranoid
If I absolutely had to know what happened during an installation, it's the only method that would satisfy me. Worms and net-based malware are getting very sophisticated about hiding themselves from the OS. Even an application you install intentionally will frequently leave traces of itself around when you try an uninstall, and the Windows community only sees this as "not well behaved."

Considering the people who are supposed to know the platform consider non-removable installations to be no worse than mis-behaving, I don't put a lot of trust in the tools they've come up with. Besides, you should only have to do the verification once. And it is a necessary step in a full-scale security audit.


So how paranoid do you want to be?
===

Purveyor of Doc Hope's [link|http://DocHope.com|fresh-baked dog biscuits and pet treats].
[link|http://DocHope.com|http://DocHope.com]
New Agreed.
Files are easy - just m5sum them and account for interlopers and changes - but the Registry is a Hard Problem, because it changes all the time.


Peter
[link|http://www.ubuntulinux.org|Ubuntu Linux]
[link|http://www.kuro5hin.org|There is no K5 Cabal]
[link|http://guildenstern.dyndns.org|Home]
Use P2P for legitimate purposes!
     Windows installation monitor - (broomberg) - (30)
         Sledgehammer approach - (drewk) - (3)
             You are insane - (broomberg) - (2)
                 No, just paranoid - (drewk) - (1)
                     Agreed. - (pwhysall)
         Hey, MS claims to have one for free! - (broomberg)
         Try this. - (inthane-chan) - (2)
             Err, this is a packager? - (broomberg) - (1)
                 Yep. - (inthane-chan)
         Advanced Registry Trace - (hnick) - (12)
             That sounds easy to write - (ben_tilly) - (11)
                 Here's the problem. - (pwhysall) - (7)
                     Good enough for this case though? - (ben_tilly) - (6)
                         Don't trust it - (broomberg) - (2)
                             VmWare? -NT - (Arkadiy) - (1)
                                 Too slow - (broomberg)
                         Experiment time! - (pwhysall) - (2)
                             What was running while you did that? - (drewk) - (1)
                                 Not much - (pwhysall)
                 Regedit itself can dump into a text file -NT - (Arkadiy) - (1)
                     I just did that, for curiosity's sake. - (pwhysall)
                 Probably is - (hnick)
         can you peel apart the install? - (boxley) - (1)
             Too hackish - (broomberg)
         Maybe contact the company's tech support? - (Another Scott) - (4)
             bwahahahahahaha - (broomberg) - (3)
                 I thought so. - (Another Scott) - (2)
                     Refer back to here - (broomberg) - (1)
                         Oh. Sorry. They've got you, don't they. :-( -NT - (Another Scott)
         Filemon might help some - (FuManChu) - (1)
             Yup, have it running - (broomberg)

Yes, no, maybe so.
53 ms