1 Aug
Windows does not provide an easy way to keep its system clean. For example, there are many different ways for a program to install itself so that it is run automatically, so it is not easy for you to track down which application decided “by itself” to use your system’s resources in the way it wants. Slowly, your machine becomes a mess. Your CPU is wasted by running processes that you don’t need. Applications create files in your system directories and leave them behind. You sometimes refrain to install and evaluate a new program because you are afraid that it will not uninstall everything afterward. Anyway, the time it takes you to start and stop Windows become longer and longer. You start thinking about reinstalling “just to get things clean again”…
Tiny Watcher is a freeware program to help you keep a clean Windows system. It monitors most changes to files, registry, processes, etc and works on Windows 95,98,ME, NT, 2000 and XP. The way Tiny Watcher works is pretty simple: basically, it starts by taking a snapshot of important parts of your Windows system; then it tracks changes (every time you log in, or whenever you want to). When a change is detected, you are notified.
Tiny Watcher has been designed to work discreetly. You will barely notice it at logon time: the about box shows for less than 5 seconds, and a progression gauge displays briefly.

Both of these windows being optional, Tiny Watcher can run completely silent. Most of the time, you will just forget that it’s here. Go to Start Menu, select Tiny Watcher > Options. The options window will show. Make sure that the “Show progress gauge” checkbox is unchecked. Then click OK to close the options window.
When Tiny Watcher detects a difference between your current machine state and what was monitored before, you will see the Warning window and you will be able to decide what to do about it (some items can be disabled or removed right away).

The good thing about Tiny Watcher is it is small and uses very little resources on your machine. It runs pretty fast and only when you request it. Tiny Watcher can also be configured to suit your needs. You can edit the list of directories and registry keys that are monitored, decide which files will be checked, etc. Most importantly, Tiny Watcher is FREE.
Although Tiny Watcher has its pros but there are weakness as well. Tiny Watcher detects changes afterward and no automatic cleanup feature which makes it not a novice tool. It is more for advanced users.
Let me tell you a little about my experience with Tiny Watcher. My Windows computer was infected by spyware few weeks ago and I kept on getting advertisement popups every hour. I’ve scanned my computer with Ad-Aware, SpyBot, SUPER AntiSpyware, Spyware Doctor but none is able to detect anything. I even ran HijackThis to check on any suspicious startup items but couldn’t find any. I actually had Tiny Watcher installed long ago, testing and thinking that maybe I’d write about it someday. I ran Tiny Watcher and it tells me that it has 24 scheduled tasks added. True enough that the spyware is automatically ran every hour using scheduled tasks. Question on my mind was, why none of the anti-spyware program scan and detect that area?
: Copying this article to your website is strictly NOT allowed. However, if you like this article, you can use the HTML code below to directly link to this article.
An On-Demand Windows System Folder Changes Monitoring Tool Lots of Hidden sqmdataXX.sqm and sqmnooptXX.sqm Files in C: drive Monitor Folders For EXE or DLL being Added, Renamed or Modified Monitor Processes That You Want With Kiwi Application Monitor How To Monitor for Registry and File Changes in Windows How to Extend the Trial period of a software Keep Application Running by Automatically ReRun When Closed
Have computer technical problems? Get FREE help from Raymond.CC FORUM
28 Responses for "A Very Tiny Tool to Monitor Changes in Windows Files, Registry and Processes"
nice article ray.. thankz..
I always wanted something like this.
Is there a portable(standalone exe) version of this ? BTW, we can use at /delete command to remove scheduled task. Many viruses schedule themselves like the famous ssvichosst.exe virus.Thanks Raymond.
Another great find from the great man.
FIRST!!!!
i hope my massage at the most top
thats odd about no other antispyware not being able to detect it wow seems like good software. Thanks Ray appreciate it
shit.. im fourth
Another awesome tip. 10q man.
Ref: Prashanth
You can make alost anything portable – when you install stuff, instead of installing it into your hard drive, install it into your USB Stick..
Great post Raymond..! I’m getting a new PC soon so this is going to be my first download
it also works with windows vista
Some heavy softwares place files in system32 folder & write registry entries, makes files in user settings dir. So installing to USB & then hoping the program to run on other PCs is not possible. If anything could be made portable, then we could just copy folder from Program Files ! For example VLC, Winamp is portable. Anyway Thanks.
so ray how did you manage to clean your pc?
WHOA! What a coincidence Ray! I was just looking for something that has to do with monitoring file modifications. And none of the ones I found, meets my needs.
Anyway, thanx Ray!
If you want a truly *magical* piece of software to test programs without worrying about system changes and a lot of great features, read about and try the free Altiris SVS (Software Virtualization Solution).
Cheers from Argentina!
truly an awesome proggy~
This is useful for monitering spyware moves!
I’ve always used hijackthis.. but this seems to be a little more user friendly. Thanks. for the tip
nice article ray
that’s why i always spare my time to see u’r blog
Love it raymond, basically it helps you spot progress of viruses such as ravrgn.exe (ravmon) and autorun.inf right?
Thought I would share,
created a Task in Task scheduler in VISTA to run on startup and then repeat every 10 minutes.
By the way, one thing.. after i did this.. IT DIDN’T INFORM ME ABOUT THE TASK I JUST CREATED! humph…
goldcoaster, I simply created a task to automatically run Windows Calculator and Tiny Watcher is able to detect it with a “Quick Check”
Maybe because the spyware is private, and can only be detected by heuristic analysis?
If the syware is private a heuristic analysis will be voided by the decinactal internal drivers from .dll server static. Thesiciallon analysis will detect the overall set frame internal network log.
@Raymond
>>I even ran HijackThis to check on any suspicious startup items but couldn’t find any.
Since many months now Hijackthis is getting old. It should be used for quick and simple stuff only.
If you use Autoruns from Sysinternal you\\\’ll see more problems. Just select the option to verify code and hide Microsoft to make the list shorter.
Example: yesterday I helped someone to clean infection with pop-ups, etc. HJT cannot find anything !
Autoruns can see 3 strange BHO and Winlogon entry and network socket layer !
I ran Malwarebytes\\\’ Anti-Malware that is now the more recommended way by Bleepingcomputer. It found ~50 problems and cleaned them. Most problems are Vundo. Reboot -> and the virus is still there immediately:(
Then I ran ComboFix. Just when starting it says \\\”Rootkit exist, must run in safe mode\\\”
WOW, this is the first real world rootkit I see.
ComboFix removed this virus.
hi , raymond im a new computer leaner .
why your computer can have so many antivirus???
my computer is even collide when runnings two antiviris????
Hope you reply me
[Sablelamb] they were anti spyware, anti adware programs.. not antivirus programs.they don\\\’t have to be running or online monitoring they can be switched on or run one at a time if you choose just to scan. they.Never run two antivirus programs it will most likely mess around and make your system unstable.
Yup thaks for sharing this toy, indeed why antivirus/spywares are not able to fix those issues. I used hikackthis and run scanner, and recently unhackme but this toy also will be of a great help in danger time!!!
Great little tool Ray, many thanks
Leave a reply