Re: Shaking a hacker

"NotReal" <[email protected]> Sun, 11 Dec 2022 20:29:40 -0000 (UTC)
Newsgroups alt.computer.security
Organization A noiseless patient Spider
Message-ID <[email protected]>
anonymous wrote:

> "NotReal" <[email protected]> wrote in
> news:[email protected]:
> 
> > [email protected] wrote:
> > 
> >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous
> >> <[email protected]> wrote:
> >> 
> >> > If you have signs your windows machine is being hacked, but virus
> >> > checks show nothing. Other than reinstall the OS after wiping
> your >> > drive what can you do to shake the hackers. Will reboot or
> change >> > of mac address do it? I don't believe any of these AV
> programs >> > identify malware fully.  Microsoft itself I suspect is
> hacking >> > their OS's. And probably most machines have hardware
> built in back >> > doors. Or am I just wearing my tin hat again?
> >> 
> >> Use this program and forget about AVs and Security Suites.
> >> 
> >> I've been using it for a few years now without any other "Security"
> >> program.  It's a freebie.
> >> 
> >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php
> > 
> > Years ago when I was responsible for school computer labs and
> > library computers used by patrons, I installed a product called
> > Deep Freeze to protect the computers from changes, both
> > unintentional and malicious.  When they went to a subscription
> > service that meant paying every year, I switched to a product
> > called Shadow Defender.  It is not free, but the last I knew it was
> > a life time license including free upgrades.
> > 
> > Basically it keeps track or writes to disk every change made to the
> > system while it is being used and when you reboot, everything is
> > restored to the way it was when it was "frozen".
> > 
> > I still use it on my personal Windows 7 PC to this day, and not only
> > does it protect the PC from permanent installation of malware, but
> > it makes testing new software and updates a breeze.  If you do an
> > install and are happy with how the new software or the update
> > performs, you can disable Shadow Defender and do the install again
> > to make it permanent.  If you are unhappy with how it works, you
> > only have to reboot the PC to remove all traces of the install.  It
> > does a much better job than an uninstall at removing all files and
> > system changes, and it is much quicker.
> > 
> > The only downside is that if the install requires a reboot before
> > use to fully test the new software, you will have to turn Shadow
> > Defender off which defeats its purpose.  Most times the reboot is
> > not really necessary, or at least the software will perform well
> > enough, to determine if it warrants doing a regular back up before
> > testing it further.
> > 
> > I have no connection to Shadow Defender other than using the
> > product.  To me it seems to work well and it has saved me a lot of
> > headaches and reinstalls over the years.  In the case of public
> > PCs, it also protects the user from the possibility of leaving
> > files and data on the PC that can be easily viewed by the next
> > user.   All it takes is a reboot before leaving.
> > 
> 
> Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT 
> program because if you use a system cleanup utility such as bleachbit
> and several others it does not protect against file deletions and
> will allow permanent deletion of files by you or by a third party
> hacker who has root or admin privileges to your box. I wonder if
> shadow does the same, did you test for that? I believe deep freeze
> will not allow that since it has an image of your system that is
> relaced every time you reboot unless you specifically direct it
> otherwise.

I never had a problem with missing files with Shadow Defender but I
thought I would test it to be sure.  I first tried deleting the entire
C:\Users directory and found I could not delete the entire directory
because of permissions.  As a result, I entered the C:\Users directory
where I was able to delete all the sub directories but the
C:\Users\Apps directory which came to over 2,000 files.  The only
problem was that I apparently messed up the Recycle Bin as there was
nothing in it and clicking on the icon resulted in an error.   I then
rebooted and all the files were restored.

Since I really wanted a test that included emptying the Recycle Bin, I
next tried deleting several directories under C:\Program Data which
totalled 1060 files and then I emptied the Recycle Bin.   When I
rebooted all those files were restored as well.

I cannot say for sure how it would work protecting against ransomware,
but I feel if the files were encrypted and renamed, I could still
restore them with a reboot.

I am using version 1.5.0.726 of Shadow Defender, which I would say is
at least a couple of years old, on my Windows 7 machine and I have been
happy enough with both that I have never felt the need to upgrade
either one.