Re: Shaking a hacker
"NotReal" <[email protected]> Mon, 12 Dec 2022 00:10:43 -0000 (UTC)
| Newsgroups | alt.computer.security |
|---|---|
| Organization | A noiseless patient Spider |
| Message-ID | <[email protected]> |
anonymous wrote: > "NotReal" <[email protected]> wrote in > news:[email protected]: > > > [email protected] wrote: > > > >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous > >> <[email protected]> wrote: > >> > >> > If you have signs your windows machine is being hacked, but virus > >> > checks show nothing. Other than reinstall the OS after wiping > your >> > drive what can you do to shake the hackers. Will reboot or > change >> > of mac address do it? I don't believe any of these AV > programs >> > identify malware fully. Microsoft itself I suspect is > hacking >> > their OS's. And probably most machines have hardware > built in back >> > doors. Or am I just wearing my tin hat again? > >> > >> Use this program and forget about AVs and Security Suites. > >> > >> I've been using it for a few years now without any other "Security" > >> program. It's a freebie. > >> > >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php > > > > Years ago when I was responsible for school computer labs and > > library computers used by patrons, I installed a product called > > Deep Freeze to protect the computers from changes, both > > unintentional and malicious. When they went to a subscription > > service that meant paying every year, I switched to a product > > called Shadow Defender. It is not free, but the last I knew it was > > a life time license including free upgrades. > > > > Basically it keeps track or writes to disk every change made to the > > system while it is being used and when you reboot, everything is > > restored to the way it was when it was "frozen". > > > > I still use it on my personal Windows 7 PC to this day, and not only > > does it protect the PC from permanent installation of malware, but > > it makes testing new software and updates a breeze. If you do an > > install and are happy with how the new software or the update > > performs, you can disable Shadow Defender and do the install again > > to make it permanent. If you are unhappy with how it works, you > > only have to reboot the PC to remove all traces of the install. It > > does a much better job than an uninstall at removing all files and > > system changes, and it is much quicker. > > > > The only downside is that if the install requires a reboot before > > use to fully test the new software, you will have to turn Shadow > > Defender off which defeats its purpose. Most times the reboot is > > not really necessary, or at least the software will perform well > > enough, to determine if it warrants doing a regular back up before > > testing it further. > > > > I have no connection to Shadow Defender other than using the > > product. To me it seems to work well and it has saved me a lot of > > headaches and reinstalls over the years. In the case of public > > PCs, it also protects the user from the possibility of leaving > > files and data on the PC that can be easily viewed by the next > > user. All it takes is a reboot before leaving. > > > > Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT > program because if you use a system cleanup utility such as bleachbit > and several others it does not protect against file deletions and > will allow permanent deletion of files by you or by a third party > hacker who has root or admin privileges to your box. I wonder if > shadow does the same, did you test for that? I believe deep freeze > will not allow that since it has an image of your system that is > relaced every time you reboot unless you specifically direct it > otherwise. I happened to read your post again and noted that beside the problem of missing files, you also mentioned BleachBit. Based on that I decided to test Shadow Defender against BleachBit and the results produced both good news and possible bad news. I downloaded and installed BleachBit 4.4.2 and then ran it. Before running it I selected all options except Wipe Free Disk Space and those check marks for Flash. After it ran, I noticed my desktop icons seemed to be all there but relocated on the desktop. Included in the deleted files were a bunch log files and I made note of a couple of them to see if they would be restored. After the reboot the BleachBit program was gone, the log files were back, and my desktop icons were back where they belong. Everything seems normal. Unless I note something has changed down the road, I will consider that Shadow Defender worked as advertised. Now for the bad news. After running BleachBit, I noted at the bottom of the screen a note on the number of bytes that had been discovered and deleted and it was in the gigabytes. That is a lot more than I would have expected. As a result I installed and ran BleachBit a second time with the same parameters. The results were the same in that everything was restored on C:\, but this time the total number of bytes deleted was in the megabytes. I cannot say for sure why there is a difference, but I am guessing that BleachBit works on all drives, not just C:\. As near as I can tell no harm has been done, and I do have recent backups of the data drives if needed. It is however a little disconcerting. Perhaps it was mostly files in the Recycle Bin on the data drives. I can always hope.