Re: Shaking a hacker
"NotReal" <[email protected]> Sun, 11 Dec 2022 20:29:40 -0000 (UTC)
| Newsgroups | alt.computer.security |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <[email protected]> |
anonymous wrote: > "NotReal" <[email protected]> wrote in > news:[email protected]: > > > [email protected] wrote: > > > >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous > >> <[email protected]> wrote: > >> > >> > If you have signs your windows machine is being hacked, but virus > >> > checks show nothing. Other than reinstall the OS after wiping > your >> > drive what can you do to shake the hackers. Will reboot or > change >> > of mac address do it? I don't believe any of these AV > programs >> > identify malware fully. Microsoft itself I suspect is > hacking >> > their OS's. And probably most machines have hardware > built in back >> > doors. Or am I just wearing my tin hat again? > >> > >> Use this program and forget about AVs and Security Suites. > >> > >> I've been using it for a few years now without any other "Security" > >> program. It's a freebie. > >> > >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php > > > > Years ago when I was responsible for school computer labs and > > library computers used by patrons, I installed a product called > > Deep Freeze to protect the computers from changes, both > > unintentional and malicious. When they went to a subscription > > service that meant paying every year, I switched to a product > > called Shadow Defender. It is not free, but the last I knew it was > > a life time license including free upgrades. > > > > Basically it keeps track or writes to disk every change made to the > > system while it is being used and when you reboot, everything is > > restored to the way it was when it was "frozen". > > > > I still use it on my personal Windows 7 PC to this day, and not only > > does it protect the PC from permanent installation of malware, but > > it makes testing new software and updates a breeze. If you do an > > install and are happy with how the new software or the update > > performs, you can disable Shadow Defender and do the install again > > to make it permanent. If you are unhappy with how it works, you > > only have to reboot the PC to remove all traces of the install. It > > does a much better job than an uninstall at removing all files and > > system changes, and it is much quicker. > > > > The only downside is that if the install requires a reboot before > > use to fully test the new software, you will have to turn Shadow > > Defender off which defeats its purpose. Most times the reboot is > > not really necessary, or at least the software will perform well > > enough, to determine if it warrants doing a regular back up before > > testing it further. > > > > I have no connection to Shadow Defender other than using the > > product. To me it seems to work well and it has saved me a lot of > > headaches and reinstalls over the years. In the case of public > > PCs, it also protects the user from the possibility of leaving > > files and data on the PC that can be easily viewed by the next > > user. All it takes is a reboot before leaving. > > > > Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT > program because if you use a system cleanup utility such as bleachbit > and several others it does not protect against file deletions and > will allow permanent deletion of files by you or by a third party > hacker who has root or admin privileges to your box. I wonder if > shadow does the same, did you test for that? I believe deep freeze > will not allow that since it has an image of your system that is > relaced every time you reboot unless you specifically direct it > otherwise. I never had a problem with missing files with Shadow Defender but I thought I would test it to be sure. I first tried deleting the entire C:\Users directory and found I could not delete the entire directory because of permissions. As a result, I entered the C:\Users directory where I was able to delete all the sub directories but the C:\Users\Apps directory which came to over 2,000 files. The only problem was that I apparently messed up the Recycle Bin as there was nothing in it and clicking on the icon resulted in an error. I then rebooted and all the files were restored. Since I really wanted a test that included emptying the Recycle Bin, I next tried deleting several directories under C:\Program Data which totalled 1060 files and then I emptied the Recycle Bin. When I rebooted all those files were restored as well. I cannot say for sure how it would work protecting against ransomware, but I feel if the files were encrypted and renamed, I could still restore them with a reboot. I am using version 1.5.0.726 of Shadow Defender, which I would say is at least a couple of years old, on my Windows 7 machine and I have been happy enough with both that I have never felt the need to upgrade either one.