Rocksolid Light

Welcome to Rocksolid Light

mail  files  register  newsreader  groups  login

Message-ID:  

Apples have meant trouble since eden. -- MaDsen Wikholm, mwikholm@at8.abo.fi


computers / alt.comp.os.windows-10 / Re: Straange directory and files

SubjectAuthor
* Straange directory and filesMajorLanGod
+- Straange directory and filesVanguardLH
+- Straange directory and filesPaul
`- Straange directory and filesFrank Slootweg

1
Re: Straange directory and files

<XnsB00FAE696DE26lonelydad58.gmail.co@85.12.62.251>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=72093&group=alt.comp.os.windows-10#72093

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!usenet.blueworldhosting.com!diablo1.usenet.blueworldhosting.com!peer02.iad!feed-me.highwinds-media.com!news.highwinds-media.com!fx14.iad.POSTED!not-for-mail
Newsgroups: alt.comp.os.windows-10
Subject: Re: Straange directory and files
From: lonelydad58@gmail.com (MajorLanGod)
Organization: Me, Myself & I, Inc
Message-ID: <XnsB00FAE696DE26lonelydad58.gmail.co@85.12.62.251>
User-Agent: Xnews/5.04.25
Lines: 10
X-Complaints-To: abuse(at)newshosting.com
NNTP-Posting-Date: Thu, 25 May 2023 22:08:43 UTC
Date: Thu, 25 May 2023 22:08:43 GMT
X-Received-Bytes: 1061
 by: MajorLanGod - Thu, 25 May 2023 22:08 UTC

Since my other thread on this topic got hijacked I'm starting over. That
post told of a weird directory that appeared on one of my drives, with
1,319 files with random names, no date, and all the same size.

Well, another one appeared today, but I believe I have found the culprit. I
use Eraser to scrub a drive when I want to make sure something has been
completely eradicated. I ran it again yesterday, and sure enough, another
strange directory showed up. So I think I have found the culprit. I will
keep an eye out the next time I run Eraser to make sure, but I am glad I
have found the source.

Re: Straange directory and files

<15oxn5ofcagl8.dlg@v.nguard.lh>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=72096&group=alt.comp.os.windows-10#72096

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!news.samoylyk.net!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: V@nguard.LH (VanguardLH)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Straange directory and files
Date: Thu, 25 May 2023 23:00:23 -0500
Organization: Usenet Elder
Lines: 58
Sender: V@nguard.LH
Message-ID: <15oxn5ofcagl8.dlg@v.nguard.lh>
References: <XnsB00FAE696DE26lonelydad58.gmail.co@85.12.62.251>
Mime-Version: 1.0
Content-Type: text/plain; charset="iso-8859-7"
Content-Transfer-Encoding: 8bit
X-Trace: individual.net 7Mb2cCIjT+CIEDkDd9IkLAlKf9NTZqEUl3slIsyjKqpLusyOq8
Keywords: VanguardLH,VLH
Cancel-Lock: sha1:C54t8JU1f8aOmeXKlz0T9UxwPf4=
User-Agent: 40tude_Dialog/2.0.15.41
 by: VanguardLH - Fri, 26 May 2023 04:00 UTC

MajorLanGod <lonelydad58@gmail.com> wrote:

> Since my other thread on this topic got hijacked I'm starting over.
> That post told of a weird directory that appeared on one of my
> drives, with 1,319 files with random names, no date, and all the same
> size.
>
> Well, another one appeared today, but I believe I have found the
> culprit. I use Eraser to scrub a drive when I want to make sure
> something has been completely eradicated. I ran it again yesterday,
> and sure enough, another strange directory showed up. So I think I
> have found the culprit. I will keep an eye out the next time I run
> Eraser to make sure, but I am glad I
> have found the source.

Without clarification, I'm assuming "Eraser" means "Heidi Eraser".
There are lots of erase-deleted-file utilities.

VeraCrypt (aka TrueCrypt) let you add a fake partition. If you were
forced to give the password to the encrypted container (file that
becomes a drive when mounted), you could give the password to the bogus
partition with placeholder files to sate the opponents need to get
inside your encrypted container. The real protected data was in another
partition in the encrypted container that was accessed using a different
password, but it looked like garbage data in the sectors in the mounted
drive that were really in the hidden alternate partition. It was to
obfuscate what you really wanted to protect.

Heidi Eraser has a similar function. If you do a wipe of sectors using
whatever algorithm, the data left in the wiped sectors would not be all
zeroes (never used) nor remnant data typical of content that would've
actually been stored there. It could be detected that parts of the
drive had been erased. To obfuscate the wipe action, Eraser will insert
dummy data into those sectors, and which are assigned to dummy files.

https://eraser.heidi.ie/eraser-settings/

Replace erased files with the following files to allow plausible
deniability specifies a list of files to use to replace the erased
files’ space on the drive after deleting to give the impression that
no files were erased, except other files which were deleted before
(hence plausible deniability.)

Did you enable that option? Rather than overwrite the "erased" sectors
with random data, you list a set of files with coherent content, so it
looks like the content is legit in those sectors. It is unclear if new
fake files are created to point at those sectors, or if just the content
of the replacement files is written to those sectors (but no files are
created to point at those sectors).

I haven't used Heidi Eraser for many years. The info above is what I
found on how to use the software. To find other users of Heidi Eraser,
check out their forum:

https://eraser.heidi.ie/forum/

If "Eraser" means some other sector-wipe tool, you'll have to be more
explicit than just saying "Eraser".

Re: Straange directory and files

<u4pdvq$3slul$1@dont-email.me>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=72097&group=alt.comp.os.windows-10#72097

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!eternal-september.org!news.eternal-september.org!.POSTED!not-for-mail
From: nospam@needed.invalid (Paul)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Straange directory and files
Date: Fri, 26 May 2023 00:53:13 -0400
Organization: A noiseless patient Spider
Lines: 44
Message-ID: <u4pdvq$3slul$1@dont-email.me>
References: <XnsB00FAE696DE26lonelydad58.gmail.co@85.12.62.251>
MIME-Version: 1.0
Content-Type: text/plain; charset=utf-8; format=flowed
Content-Transfer-Encoding: 7bit
Injection-Date: Fri, 26 May 2023 04:53:14 -0000 (UTC)
Injection-Info: dont-email.me; posting-host="ebf9230a953d70aa9c2fe73eed5a9cfa";
logging-data="4085717"; mail-complaints-to="abuse@eternal-september.org"; posting-account="U2FsdGVkX1+3YzSZsWJmDB+gvrHvW5We7HFv2ZGFGks="
User-Agent: Ratcatcher/2.0.0.25 (Windows/20130802)
Cancel-Lock: sha1:nnR6k765jcE6rYqCZBVlfWQBGuI=
Content-Language: en-US
In-Reply-To: <XnsB00FAE696DE26lonelydad58.gmail.co@85.12.62.251>
 by: Paul - Fri, 26 May 2023 04:53 UTC

On 5/25/2023 6:08 PM, MajorLanGod wrote:
> Since my other thread on this topic got hijacked I'm starting over. That
> post told of a weird directory that appeared on one of my drives, with
> 1,319 files with random names, no date, and all the same size.
>
> Well, another one appeared today, but I believe I have found the culprit. I
> use Eraser to scrub a drive when I want to make sure something has been
> completely eradicated. I ran it again yesterday, and sure enough, another
> strange directory showed up. So I think I have found the culprit. I will
> keep an eye out the next time I run Eraser to make sure, but I am glad I
> have found the source.
>

This appears related to "Free Space Erasure", which erases the white space
on a partition. Google did not find this article for me earlier.

https://eraser.heidi.ie/forum/threads/eraser-creates-a-lot-of-big-files-during-unused-space-erasure.18689/

"there's a new folder named 4x8NmCn!UQgiKR1C+] with a lot of files having the same size 216MB"

*******

Here is another tool, that can erase white space.

https://learn.microsoft.com/en-us/sysinternals/downloads/sdelete

sdelete64.exe -z c: # White space cleaning

In a test, I salted a disk (NTFS FS) with a pattern, then used sdelete64 and
I could still detect a bit of the pattern later (maybe a hundred chunks).
Heidi should be better at this sort of thing. I still find
sdelete64 is good for prepping .vhd containers for compaction
operations (if you zero out white space, the .vhd does not need
to waste storage space to record the zeroed region).

Using unique patterns, you can attempt to "hide" materials on a
partition, use your favorite cleaner, then scan with HxD to see
if the cleaning worked or not. This has the ability to scan at
the sector level (do a Run As Administrator on the executable,
and then the disk opening menu will work).

https://mh-nexus.de/en/hxd/

Paul

Re: Straange directory and files

<u5qrhb.ne0.1@ID-201911.user.individual.net>

  copy mid

https://news.novabbs.org/computers/article-flat.php?id=72241&group=alt.comp.os.windows-10#72241

  copy link   Newsgroups: alt.comp.os.windows-10
Path: i2pn2.org!i2pn.org!weretis.net!feeder8.news.weretis.net!lilly.ping.de!fu-berlin.de!uni-berlin.de!individual.net!not-for-mail
From: this@ddress.is.invalid (Frank Slootweg)
Newsgroups: alt.comp.os.windows-10
Subject: Re: Straange directory and files
Date: 7 Jun 2023 19:07:04 GMT
Organization: NOYB
Lines: 17
Message-ID: <u5qrhb.ne0.1@ID-201911.user.individual.net>
References: <XnsB00FAE696DE26lonelydad58.gmail.co@85.12.62.251>
X-Trace: individual.net ztYq4UEgJ+ca//8qXQXcLQwRn+6pwwOGIpoRyGuo+zAuezSVeo
X-Orig-Path: not-for-mail
Cancel-Lock: sha1:zk8UAyAaK5bXuvYk/BW/bcw4pLY=
User-Agent: tin/1.6.2-20030910 ("Pabbay") (UNIX) (CYGWIN_NT-10.0-WOW/2.8.0(0.309/5/3) (i686)) Hamster/2.0.2.2
 by: Frank Slootweg - Wed, 7 Jun 2023 19:07 UTC

MajorLanGod <lonelydad58@gmail.com> wrote:
> Since my other thread on this topic got hijacked I'm starting over. That
> post told of a weird directory that appeared on one of my drives, with
> 1,319 files with random names, no date, and all the same size.
>
> Well, another one appeared today, but I believe I have found the culprit. I
> use Eraser to scrub a drive when I want to make sure something has been
> completely eradicated. I ran it again yesterday, and sure enough, another
> strange directory showed up. So I think I have found the culprit. I will
> keep an eye out the next time I run Eraser to make sure, but I am glad I
> have found the source.

FWIW, I find the "no date" bit a bit strange. AFAIK, a file cannot
have "no date". Perhaps the date is strange or all fields are zero or
something, but probably some tool - i.e. for example DIR instead of
File Explorer - will probably show some kind of date which might have
led you to the cause sooner.


computers / alt.comp.os.windows-10 / Re: Straange directory and files

1
server_pubkey.txt

rocksolid light 0.9.81
clearnet tor