home
***
CD-ROM
|
disk
|
FTP
|
other
***
search
/
Softwarová Záchrana 3
/
Softwarova-zachrana-3.bin
/
Winsonar 2004
/
setup.exe
/
{app}
/
readme.txt
< prev
next >
Wrap
Text File
|
2004-03-26
|
18KB
|
400 lines
_________________________________________________________________________________________________________________________
Winsonar 2004 XP Freeware Edition - v. 4.01.04
Zancart Software (C) 2001- 2004 http://digilander.libero.it/zancart
_________________________________________________________________________________________________________________________
Winsonar 2004 XP Documentation file
Program overview ................1
Installation ....................2
What's new .....................3
General features ................4
Winsonar full interface .........5
Tech tools ......................6
Tools menu ......................7
Advanced options menu ...........8
FAQ and tips ....................9
License and usage ...............10
Disclaimer of warranty...........11
Program overview
________________
Winsonar 2004 XP is a program specifically designed for process monitoring and system protection from unknown processes:
the program detectes new processes permanently installed into memory while system is working off-line, offering also an
active Internet protection, by optional automatic termination of any unknown process trying to load itself into memory
when the system is on line.
The basic idea is that if the user could know a new program silently installed into memory when off-line, he could take
appropriate countermeasures. Unfortunately this does not offer any protection against downloading a malware when the system
is on-line.
For this reason the program detects the on-line status, asking then the user if an automatic termination of any unknown
processes is desired (this option can be also enabled by default). This leads to an active protection against
trojan\spyware-infected e-mail attachments: even if the user unfortunately opens the attachment, the malicious executable
process will be suddenly terminated, without having the time to perform any action.
Program installation
____________________
Files are distributed as a compressed archive that contains the setup.exe file, necessary for proper installation of
the program and documentation.
This version of Winsonar comes with VB6 runtime files needed to properly run the program.
List of files:
winsonar.exe --> to winsonar directory
file_id.diz --> to winsonar directory
readme.txt --> to winsonar directory
ports_list.txt --> to winsonar directory
msvbvm60.dll --> to windows\system directory ( only if needed )
oleaut32.dll --> to windows\system directory ( only if needed )
olepro32.dll --> to windows\system directory ( only if needed )
asycfilt.dll --> to windows\system directory ( only if needed )
stdole2.tlb --> to windows\system directory ( only if needed )
comcat.dll --> to windows\system directory ( only if needed )
mscomctl.ocx --> to windows\system directory ( only if needed )
mswinsck.ocx --> to windows\system directory ( only if needed )
To install the program simply run setup.exe file: an installation wizard will guide the user to a complete installation;
a Group entry will be created in the Programs menu, an icon will be placed on the desktop and command line will be added
to the Registry, to let the memory resident part of the program be loaded on system startup.
To uninstall program click on uninstall icon in Programs\Winsonar menu: Program menu entries, Winsonar program files
will be deleted and Winsonar key will be removed from Registry.
Versions later than 1.50.00 have been added of a new feature, to prevent the user from installing new versions of Winsonar
2004 while the older application is still running: an alert message will be displayed, requiring closure of the running
program.
The program has been tested and works under Windows XP and 98/Me
What's new
__________
Build 4.01.04 released on: March, 26th 2004
New features of the version 4.01.04:
* When run under Windows XP, the program displays the amount of memory requested by a process: double clicking the item
in the running processes list, a detailed memory analysis will be displayed. This can be useful to detect memory leaks,
memory-eating applications or o to suspect stealth injections of hostile code into the process memory working area
by malicious programs.
* Minor bugs fixed.
General features
_________________
The first time Winsonar is run, it inspects memory and compiles a list of processes (programs running at that moment,
as normal PC activity) that will be considered safe by default . It also reads Registry and compiles the list of programs
normally loaded on system start up: those programs will be considered safe by default.
Programs and Registry keys lists are CRC protected to avoid attacks by malicious programs. These lists are normally not
accessible by the user, as automatic safety, to avoid involuntary system process termination or Registry modifications.
User will be finally prompted for scanning local system ports, to retrieve a list of ports normally opened by system
services.
If a new program shows to be permanently installed into memory or a new autorun value has been written to Registry,
a first-step interface will pop-up, displaying an "unknown programs list" and four buttons that will be enabled by
selecting a name in the list:
* the ôgreen hand" button includes a program in a customizable list of safe programs, thus avoiding other alerts.
* the "red hand" button terminates the suspect process, including it in a list of programs considered as unsafe.
Winsonar will prompt the user if he wants to to automatically terminate the programs listed in the unsafe list,
if they will try to load again.
* the "magnifier" button starts automatic file seeking, if there are file(s) named as the selected process or copies
of the same file ( viruses sometimes do so).
* the "screwdriver" button starts full program interface, giving access to the tech tools.
If a modification in the Registry autorun sections is found, a similar interface will pop-up, consisting of an unknown
values list and four buttons that will be enabled by clicking a list name:
* the ôgreen hand" button includes a key value in a customizable list of safe Registry values, thus avoiding alerts.
* the "printer" button prints the displayed items list.
* the "magnifier" button starts automatic Registry seeking, to list all command lines executed on system start up.
* the "screwdriver" button starts full program interface, giving access to the tech tools.
Winsonar full interface
_______________________
The full interface mainly consists of two panels: the right one includes a red display, showing processes not
recognized from the safe lists, and some buttons, disabled until a name in the red display is highlighted by clicking on it.
" Green hand " button will add the highlighted process to the list of safe programs, thus avoiding other alerts.
" Red hand " button will add the selected process to a list of programs considered unsafe and the user will be prompted
to terminate the process. Winsonar will ask the user if he wants to to automatically terminate the program if it will
try to load again.
" Folder & green diskettes " button includes in the safe list all the unknown programs actually running in background.
Use it carefully, because it will include ALL displayed processes in the safe list.
" Magnifier " button starts automatic file seeking, giving the possibility to know if there are file(s) named as the
selected process or copies of the same file (viruses sometimes do so)
" Paper & pencil " button will open a specific service, giving the possibility, by double clicking on a list item, to remove
processes erroneously included in the safe or unsafe list.
" Printer " button will give option for printing the list of the programs marked as safe and unsafe, with date\time of
scanning.
The double click on an item in the red display will launch an automatic file finder service, to know what files are to be
scanned with an updated antivirus program or manually deleted from hard drive.
The right panel includes a green display, showing all currently running processes, and some buttons:
" Sonar screen " button is intended to perform a memory scan without waiting for automatic check (i.e. if an expert user
supposes some malicious program running in background or if he wants to check a specific program to be correctly
loaded into memory).
All running programs will be reported on the green display and unknown programs will be displayed on the upper red display.
After having scanned memory, a port scanner will be opened, to inspect local system ports: this interface consist of
two colored display and four buttons. The display on the right will show a report of all previous scans, while the display
on the left will show the opened ports actually detected in the local system.
" Eye " button will launch port scanning. Well-known ports will be scanned first, followed by all dynamic ports.
" Printer " button will print previous and\or actual scan report.
" Book " button will load this documentation interface.
" Exit " button will quit interface and recall Winsonar main program.
Comparing the ports found as in use at the moment with those previously found open, will help identifying if a new port
has been opened into your system. If a new open port and an unknown process are simultaneously detected, there is a
reasonable suspicion that a Trojan program established a backdoor.
" Box and question mark " button will display all running tasks, even if hidden. This could be useful to check actual tasks
of a program or to inspect if a known program is doing what it is expected to do.
" Windows logo " button will search the Registry for auto run values other than those included in the safe list, in order
to detect programs attempting to load themselves on every Pc start-up.
" Magnifier " button starts automatic file seeking, to know if there are file(s) named as the selected process or copies
of the same file ( viruses sometimes do so ).
" Screwdriver & PC " button will open a new window, giving access to advanced features. Further details in enhanced
features section.
" Exit " button will quit the program.
At bottom of the window there are some check boxes:
" Kill unknown processes while connected to the Internet "
implements an antivirus feature: if checked, all unknown processes will be automatically terminated when the system
is connected to the Internet. This could be useful to avoid automatic loading of malicious processes when an Internet
page is opened or involuntary launching of malicious executables hidden in e-mail attachments.
Terminated programs list will be logged to web_alert.txt file.
Winsonar starts by default with unchecked option checkbox (feature is not active); if an Internet connection is
established, the program will ask the user if he wants to activate the feature.
If you activated the option, remember to uncheck it if you are doing some online action involving third party programs
that could need automatic run ( i.e. antivirus programs update), otherwise they will be automatically terminated because
unknown.
If you want to let them run, because of the frequency of the online action ( i.e. daily antivirus update) uncheck the
option, run the Winsonar probe while programs are running and include them in the safe list, then check the option again:
Winsonar will recognize programs as safe and will not kill them anymore when online.
" Fast scan " allows the user to rapidly switch from default ( minutes ) to a fast paced ( seconds ) scanning mode, in
order to detect processes that rapidly load and discard from memory.
" On alert scan ports " allows the user to launch by default the port scanner after every alert for unknown programs.
Program tech tools
__________________
Some technical information about processes can be accessed from " Tech tools " button in the right panel:
a new window is opened, showing a green display on the leftand some buttons on the right, in the Main Panel.
When the Tech tools window is opened, the list of currently running processes is displayed on the green screen and the
program is ready to explore processes structure or to gather technical details about running processes.
" Socket " button will get the currently running processes list, refreshing the screen if needed.
" Gears " button gives the possibility to identify all the processes linked as a structure: user must highlight the process
he wants to know about by clicking on an item in the processes list and then repeatedly press the button to get parent
processes, until a warning message will be shown, alerting for main process reaching.
All the structure ( main and parent processes ) will be shown as highlighted items in the processes list.
" Question mark " button will show technical details about all the running processes, displaying for each process name,
primary ID and parent ID. Using this button will disable " Gears " button, until processes list has been refreshed
by clicking " Socket " button.
Tools menu
__________
The local ports scanning cal be launched from this menu, trying to know if there is an open port other than those already
known as open: if a new process is found into memory or a new autorun value is found in the Registry and an unknown port is
found open at the same time, there is a reasonable suspicion fora Trojan program having opened a backdoor into the system.
Advanced options menu
_____________________
Advanced options give power users the possibility to tweak the program and customize it. The user can choose to enable
by default automatic termination of any unknown process when the system is permanently connected, to avoid messages
of detected connection on every program startup.
User can also choose between an standard periodic scanning of the memory (minutes) and a fast scanning rate (seconds).
This can be useful if the user suspects malicious programs quickly loading and discarding from memory, to avoid periodical
Winsonar control.
The advanced menu gives also the possibility to edit the default safe list and to remove any process from the list.
This leads Winsonar to recognize as unknown that process, making possible to terminate it.
Use this feature very carefully, because terminating a system process could lead even to a system crash.
FAQ and tips
____________
Tip: remember to remove Winsonar 2003 from the system tray before uninstalling it, otherwise some elements or files could not
be removed from your system.
Tip: if you find many processes as unknown, scan your hard disk(s) with an updated antivirus program: if no virus is found
you can include them all in the safe list, sparing time.
Tip: you can switch from default to fast automatic scanning (and vice-versa) simply clicking on the checkbox in the
Sonar panel.
Tip: If you activated the option "Kill unknown processes while connected to the Internet", remember to uncheck it if you
are doing some online action involving third party programs that could need automatic run ( i.e. Microsoft Windows
Update), otherwise downloaded executable files will not be launched and installed, because unknown.
If you want to let them run, because of the frequency of the online action ( i.e. daily antivirus update) uncheck the
option, run the Winsonar probe while programs are running and include them in the safe list, then check the option
again: Winsonar will recognize programs as safe and will not kill them anymore when online.
Tip: The user can choose to enable by default automatic termination of any unknown process when the system is permanently
connected, to avoid messages of detected connection on every program startup.
License and usage
_________________
Use of this software by Zancart Software is submitted to acceptance of all the terms of this Licence.
This software is not sold, but only licensed. The license is free of charge to the user. This software cannot be sold or
included in any other program or commercial package. You may NOT alter, delete, or add any file in the distribution package.
It is strictly prohibited to reverse engineer, decompile, disassemble or modify in any way this software.
Disclaimer of warranty
______________________
The software and accompanying written materials are provided "as is" without warranty of any kind, either expressed or
implied. The Licensee agrees that the Author shall not be liable for any incidental, indirect, special, or consequential
damages, including, but not limited to, loss of profits, business interruption, loss of information, incurred by the
Licensee or any third party, even if the author has been advised of the possibility of such damages.
Upon using the software, the user agrees with the above statements.
The program has been tested and works under Windows XP and 98/Me.
Zancart Software, Copyright ⌐ 2001- 2004. All right reserved.
If you want to contact the author please use this e-mail address: zancart@yahoo.it