Re: Shaking a hacker

anonymous <[email protected]> Sun, 22 Jan 2023 01:49:45 -0000 (UTC)
Newsgroups alt.computer.security
Organization DIS
Message-ID <[email protected]>
"NotReal" <[email protected]> wrote in news:tn5ri3$21pd1$1@dont-
email.me:

> anonymous wrote:
> 
>> "NotReal" <[email protected]> wrote in
>> news:[email protected]:
>> 
>> > [email protected] wrote:
>> > 
>> >> On Wed, 30 Nov 2022 03:18:35 -0000 (UTC), anonymous
>> >> <[email protected]> wrote:
>> >> 
>> >> > If you have signs your windows machine is being hacked, but virus
>> >> > checks show nothing. Other than reinstall the OS after wiping
>> your >> > drive what can you do to shake the hackers. Will reboot or
>> change >> > of mac address do it? I don't believe any of these AV
>> programs >> > identify malware fully.  Microsoft itself I suspect is
>> hacking >> > their OS's. And probably most machines have hardware
>> built in back >> > doors. Or am I just wearing my tin hat again?
>> >> 
>> >> Use this program and forget about AVs and Security Suites.
>> >> 
>> >> I've been using it for a few years now without any other "Security"
>> >> program.  It's a freebie.
>> >> 
>> >> http://www.toolwiz.com/lead/toolwiz_time_freeze.php
>> > 
>> > Years ago when I was responsible for school computer labs and
>> > library computers used by patrons, I installed a product called
>> > Deep Freeze to protect the computers from changes, both
>> > unintentional and malicious.  When they went to a subscription
>> > service that meant paying every year, I switched to a product
>> > called Shadow Defender.  It is not free, but the last I knew it was
>> > a life time license including free upgrades.
>> > 
>> > Basically it keeps track or writes to disk every change made to the
>> > system while it is being used and when you reboot, everything is
>> > restored to the way it was when it was "frozen".
>> > 
>> > I still use it on my personal Windows 7 PC to this day, and not only
>> > does it protect the PC from permanent installation of malware, but
>> > it makes testing new software and updates a breeze.  If you do an
>> > install and are happy with how the new software or the update
>> > performs, you can disable Shadow Defender and do the install again
>> > to make it permanent.  If you are unhappy with how it works, you
>> > only have to reboot the PC to remove all traces of the install.  It
>> > does a much better job than an uninstall at removing all files and
>> > system changes, and it is much quicker.
>> > 
>> > The only downside is that if the install requires a reboot before
>> > use to fully test the new software, you will have to turn Shadow
>> > Defender off which defeats its purpose.  Most times the reboot is
>> > not really necessary, or at least the software will perform well
>> > enough, to determine if it warrants doing a regular back up before
>> > testing it further.
>> > 
>> > I have no connection to Shadow Defender other than using the
>> > product.  To me it seems to work well and it has saved me a lot of
>> > headaches and reinstalls over the years.  In the case of public
>> > PCs, it also protects the user from the possibility of leaving
>> > files and data on the PC that can be easily viewed by the next
>> > user.   All it takes is a reboot before leaving.
>> > 
>> 
>> Sounds pretty much the same as toolwiz freeze. Just uninstalled THAT 
>> program because if you use a system cleanup utility such as bleachbit
>> and several others it does not protect against file deletions and
>> will allow permanent deletion of files by you or by a third party
>> hacker who has root or admin privileges to your box. I wonder if
>> shadow does the same, did you test for that? I believe deep freeze
>> will not allow that since it has an image of your system that is
>> relaced every time you reboot unless you specifically direct it
>> otherwise.
> 
> I happened to read your post again and noted that beside the problem of
> missing files, you also mentioned BleachBit.  Based on that I decided
> to test Shadow Defender against BleachBit and the results produced both
> good news and possible bad news.
> 
> I downloaded and installed BleachBit 4.4.2 and then ran it.  Before
> running it I selected all options except Wipe Free Disk Space and those
> check marks for Flash.  After it ran, I noticed my desktop icons seemed
> to be all there but relocated on the desktop.  Included in the deleted
> files were a bunch log files and I made note of a couple of them to see
> if they would be restored.  After the reboot the BleachBit program was
> gone, the log files were back, and my desktop icons were back where
> they belong.   Everything seems normal.  Unless I note something has
> changed down the road, I will consider that Shadow Defender worked as
> advertised.
> 
> Now for the bad news.  After running BleachBit, I noted at the bottom
> of the screen a note on the number of bytes that had been discovered
> and deleted and it was in the gigabytes. That is a lot more than I
> would have expected.  As a result I installed and ran BleachBit a
> second time with the same parameters.  The results were the same in
> that everything was restored on C:\, but this time the total number of
> bytes deleted was in the megabytes.
> 
> I cannot say for sure why there is a difference, but I am guessing that
> BleachBit works on all drives, not just C:\.  As near as I can tell no
> harm has been done, and I do have recent backups of the data drives if
> needed.  It is however a little disconcerting.  Perhaps it was mostly
> files in the Recycle Bin on the data drives. I can always hope.
>         

I did not notice any bad effects the one time I ran BleachBit, but it did 
nuke the toolwiz program and I had to fix that. Also toolwiz I noted in 
my earlier post did not preserve the changes made by bleachbit. As I said 
earlier, I am going to look into deep freeze next. I will try shadow 
defender. Is that free or what? You have a link for the download? Thanks.