Re: Shaking a hacker
anonymous <[email protected]> Sun, 22 Jan 2023 01:49:45 -0000 (UTC)
| Newsgroups | alt.computer.security |
|---|---|
| Organization | DIS |
| Message-ID | <[email protected]> |
"NotReal" <[email protected]> wrote in news:tn5ri3$21pd1$1@dont- email.me: > anonymous wrote: > >> "NotReal" <[email protected]> wrote in >> news:[email protected]: >> >> > [email protected] wrote: >> > >> >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous >> >> <[email protected]> wrote: >> >> >> >> > If you have signs your windows machine is being hacked, but virus >> >> > checks show nothing. Other than reinstall the OS after wiping >> your >> > drive what can you do to shake the hackers. Will reboot or >> change >> > of mac address do it? I don't believe any of these AV >> programs >> > identify malware fully. Microsoft itself I suspect is >> hacking >> > their OS's. And probably most machines have hardware >> built in back >> > doors. Or am I just wearing my tin hat again? >> >> >> >> Use this program and forget about AVs and Security Suites. >> >> >> >> I've been using it for a few years now without any other "Security" >> >> program. It's a freebie. >> >> >> >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php >> > >> > Years ago when I was responsible for school computer labs and >> > library computers used by patrons, I installed a product called >> > Deep Freeze to protect the computers from changes, both >> > unintentional and malicious. When they went to a subscription >> > service that meant paying every year, I switched to a product >> > called Shadow Defender. It is not free, but the last I knew it was >> > a life time license including free upgrades. >> > >> > Basically it keeps track or writes to disk every change made to the >> > system while it is being used and when you reboot, everything is >> > restored to the way it was when it was "frozen". >> > >> > I still use it on my personal Windows 7 PC to this day, and not only >> > does it protect the PC from permanent installation of malware, but >> > it makes testing new software and updates a breeze. If you do an >> > install and are happy with how the new software or the update >> > performs, you can disable Shadow Defender and do the install again >> > to make it permanent. If you are unhappy with how it works, you >> > only have to reboot the PC to remove all traces of the install. It >> > does a much better job than an uninstall at removing all files and >> > system changes, and it is much quicker. >> > >> > The only downside is that if the install requires a reboot before >> > use to fully test the new software, you will have to turn Shadow >> > Defender off which defeats its purpose. Most times the reboot is >> > not really necessary, or at least the software will perform well >> > enough, to determine if it warrants doing a regular back up before >> > testing it further. >> > >> > I have no connection to Shadow Defender other than using the >> > product. To me it seems to work well and it has saved me a lot of >> > headaches and reinstalls over the years. In the case of public >> > PCs, it also protects the user from the possibility of leaving >> > files and data on the PC that can be easily viewed by the next >> > user. All it takes is a reboot before leaving. >> > >> >> Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT >> program because if you use a system cleanup utility such as bleachbit >> and several others it does not protect against file deletions and >> will allow permanent deletion of files by you or by a third party >> hacker who has root or admin privileges to your box. I wonder if >> shadow does the same, did you test for that? I believe deep freeze >> will not allow that since it has an image of your system that is >> relaced every time you reboot unless you specifically direct it >> otherwise. > > I happened to read your post again and noted that beside the problem of > missing files, you also mentioned BleachBit. Based on that I decided > to test Shadow Defender against BleachBit and the results produced both > good news and possible bad news. > > I downloaded and installed BleachBit 4.4.2 and then ran it. Before > running it I selected all options except Wipe Free Disk Space and those > check marks for Flash. After it ran, I noticed my desktop icons seemed > to be all there but relocated on the desktop. Included in the deleted > files were a bunch log files and I made note of a couple of them to see > if they would be restored. After the reboot the BleachBit program was > gone, the log files were back, and my desktop icons were back where > they belong. Everything seems normal. Unless I note something has > changed down the road, I will consider that Shadow Defender worked as > advertised. > > Now for the bad news. After running BleachBit, I noted at the bottom > of the screen a note on the number of bytes that had been discovered > and deleted and it was in the gigabytes. That is a lot more than I > would have expected. As a result I installed and ran BleachBit a > second time with the same parameters. The results were the same in > that everything was restored on C:\, but this time the total number of > bytes deleted was in the megabytes. > > I cannot say for sure why there is a difference, but I am guessing that > BleachBit works on all drives, not just C:\. As near as I can tell no > harm has been done, and I do have recent backups of the data drives if > needed. It is however a little disconcerting. Perhaps it was mostly > files in the Recycle Bin on the data drives. I can always hope. > I did not notice any bad effects the one time I ran BleachBit, but it did nuke the toolwiz program and I had to fix that. Also toolwiz I noted in my earlier post did not preserve the changes made by bleachbit. As I said earlier, I am going to look into deep freeze next. I will try shadow defender. Is that free or what? You have a link for the download? Thanks.