Re: Shaking a hacker

anonymous <[email protected]> Sun, 22 Jan 2023 01:45:43 -0000 (UTC)
Newsgroups alt.computer.security
Organization DIS
Message-ID <[email protected]>
"NotReal" <[email protected]> wrote in news:tn5ejj$20na5$1@dont-
email.me:

> anonymous wrote:
> 
>> "NotReal" <[email protected]> wrote in
>> news:[email protected]:
>> 
>> > [email protected] wrote:
>> > 
>> >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous
>> >> <[email protected]> wrote:
>> >> 
>> >> > If you have signs your windows machine is being hacked, but virus
>> >> > checks show nothing. Other than reinstall the OS after wiping
>> your >> > drive what can you do to shake the hackers. Will reboot or
>> change >> > of mac address do it? I don't believe any of these AV
>> programs >> > identify malware fully.  Microsoft itself I suspect is
>> hacking >> > their OS's. And probably most machines have hardware
>> built in back >> > doors. Or am I just wearing my tin hat again?
>> >> 
>> >> Use this program and forget about AVs and Security Suites.
>> >> 
>> >> I've been using it for a few years now without any other "Security"
>> >> program.  It's a freebie.
>> >> 
>> >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php
>> > 
>> > Years ago when I was responsible for school computer labs and
>> > library computers used by patrons, I installed a product called
>> > Deep Freeze to protect the computers from changes, both
>> > unintentional and malicious.  When they went to a subscription
>> > service that meant paying every year, I switched to a product
>> > called Shadow Defender.  It is not free, but the last I knew it was
>> > a life time license including free upgrades.
>> > 
>> > Basically it keeps track or writes to disk every change made to the
>> > system while it is being used and when you reboot, everything is
>> > restored to the way it was when it was "frozen".
>> > 
>> > I still use it on my personal Windows 7 PC to this day, and not only
>> > does it protect the PC from permanent installation of malware, but
>> > it makes testing new software and updates a breeze.  If you do an
>> > install and are happy with how the new software or the update
>> > performs, you can disable Shadow Defender and do the install again
>> > to make it permanent.  If you are unhappy with how it works, you
>> > only have to reboot the PC to remove all traces of the install.  It
>> > does a much better job than an uninstall at removing all files and
>> > system changes, and it is much quicker.
>> > 
>> > The only downside is that if the install requires a reboot before
>> > use to fully test the new software, you will have to turn Shadow
>> > Defender off which defeats its purpose.  Most times the reboot is
>> > not really necessary, or at least the software will perform well
>> > enough, to determine if it warrants doing a regular back up before
>> > testing it further.
>> > 
>> > I have no connection to Shadow Defender other than using the
>> > product.  To me it seems to work well and it has saved me a lot of
>> > headaches and reinstalls over the years.  In the case of public
>> > PCs, it also protects the user from the possibility of leaving
>> > files and data on the PC that can be easily viewed by the next
>> > user.   All it takes is a reboot before leaving.
>> > 
>> 
>> Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT 
>> program because if you use a system cleanup utility such as bleachbit
>> and several others it does not protect against file deletions and
>> will allow permanent deletion of files by you or by a third party
>> hacker who has root or admin privileges to your box. I wonder if
>> shadow does the same, did you test for that? I believe deep freeze
>> will not allow that since it has an image of your system that is
>> relaced every time you reboot unless you specifically direct it
>> otherwise.
> 
> I never had a problem with missing files with Shadow Defender but I
> thought I would test it to be sure.  I first tried deleting the entire
> C:\Users directory and found I could not delete the entire directory
> because of permissions.  As a result, I entered the C:\Users directory
> where I was able to delete all the sub directories but the
> C:\Users\Apps directory which came to over 2,000 files.  The only
> problem was that I apparently messed up the Recycle Bin as there was
> nothing in it and clicking on the icon resulted in an error.   I then
> rebooted and all the files were restored.
> 
> Since I really wanted a test that included emptying the Recycle Bin, I
> next tried deleting several directories under C:\Program Data which
> totalled 1060 files and then I emptied the Recycle Bin.   When I
> rebooted all those files were restored as well.
> 
> I cannot say for sure how it would work protecting against ransomware,
> but I feel if the files were encrypted and renamed, I could still
> restore them with a reboot.
> 
> I am using version 1.5.0.726 of Shadow Defender, which I would say is
> at least a couple of years old, on my Windows 7 machine and I have been
> happy enough with both that I have never felt the need to upgrade
> either one.

Thanks for your followup on shadow defender. I think next I am going to 
try deep freeze. That is what all the cafes are using. It restores an 
image of your system partition such that any virus attack on it will have 
no permanent effect. Don't know if I can get a free version tho, it's 
expensive.