Re: Shaking a hacker
anonymous <[email protected]> Thu, 8 Dec 2022 01:10:51 -0000 (UTC)
| Newsgroups | alt.computer.security |
|---|---|
| Organization | DIS |
| Message-ID | <[email protected]> |
"NotReal" <[email protected]> wrote in news:[email protected]: > [email protected] wrote: > >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous >> <[email protected]> wrote: >> >> > If you have signs your windows machine is being hacked, but virus >> > checks show nothing. Other than reinstall the OS after wiping your >> > drive what can you do to shake the hackers. Will reboot or change >> > of mac address do it? I don't believe any of these AV programs >> > identify malware fully. Microsoft itself I suspect is hacking >> > their OS's. And probably most machines have hardware built in back >> > doors. Or am I just wearing my tin hat again? >> >> Use this program and forget about AVs and Security Suites. >> >> I've been using it for a few years now without any other "Security" >> program. It's a freebie. >> >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php > > Years ago when I was responsible for school computer labs and library > computers used by patrons, I installed a product called Deep Freeze to > protect the computers from changes, both unintentional and malicious. > When they went to a subscription service that meant paying every year, > I switched to a product called Shadow Defender. It is not free, but > the last I knew it was a life time license including free upgrades. > > Basically it keeps track or writes to disk every change made to the > system while it is being used and when you reboot, everything is > restored to the way it was when it was "frozen". > > I still use it on my personal Windows 7 PC to this day, and not only > does it protect the PC from permanent installation of malware, but it > makes testing new software and updates a breeze. If you do an install > and are happy with how the new software or the update performs, you can > disable Shadow Defender and do the install again to make it permanent. > If you are unhappy with how it works, you only have to reboot the PC to > remove all traces of the install. It does a much better job than an > uninstall at removing all files and system changes, and it is much > quicker. > > The only downside is that if the install requires a reboot before use > to fully test the new software, you will have to turn Shadow Defender > off which defeats its purpose. Most times the reboot is not really > necessary, or at least the software will perform well enough, to > determine if it warrants doing a regular back up before testing it > further. > > I have no connection to Shadow Defender other than using the product. > To me it seems to work well and it has saved me a lot of headaches and > reinstalls over the years. In the case of public PCs, it also protects > the user from the possibility of leaving files and data on the PC that > can be easily viewed by the next user. All it takes is a reboot > before leaving. > Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT program because if you use a system cleanup utility such as bleachbit and several others it does not protect against file deletions and will allow permanent deletion of files by you or by a third party hacker who has root or admin privileges to your box. I wonder if shadow does the same, did you test for that? I believe deep freeze will not allow that since it has an image of your system that is relaced every time you reboot unless you specifically direct it otherwise.