Wilders Security Forums  

Go Back   Wilders Security Forums > Official Returnil Support Forum > Returnil releases
User Name
Password
Register FAQ Members List Calendar Search Today's Posts Mark Forums Read

 
 
Thread Tools Search this Thread
  #1  
Old August 21st, 2010, 07:46 AM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default RSS 2011 / Wipe All Disk Changes...

Hello

I've just switched from RVS 2010 to RSS 2011 and am interested in understanding the 'Wipe All Disk Changes at Computer Startup' feature.

If this option is checked under 'Virtual Mode' > 'Settings' > 'Advanced', what happens that is different to simply rebooting with 'Drop All Changes' selected?

(I have virtual mode set to start with Windows, have not created a VP and have checked 'Wipe All Disk Changes' under 'Advanced').

Thanks in advance.

philby

EDIT: I've just rebooted and noticed a quick notification box headed 'Saving Files' and showing 'Mount Real Partition' > 'Dismount Real Partition', so what's happening here that didn't happen in previous RVS versions?
__________________
Sandboxie + Macrium on Windows 8 Pro 64

Last edited by philby : August 22nd, 2010 at 04:00 AM.
  #2  
Old August 23rd, 2010, 10:04 AM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,750
Default Re: RSS 2011 / Wipe All Disk Changes...

The wipe simply overwrites the cache at restart. The saving files message appears when you have chosen to save content to disk.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #3  
Old August 23rd, 2010, 01:47 PM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default Re: RSS 2011 / Wipe All Disk Changes...

The saving files message appears when you have chosen to save content to disk

Ok - that was what's been confusing me: That message is coming up even with 'Drop All Changes' selected, ie when I've not chosen to save any content to disk.

Thanks

philby
__________________
Sandboxie + Macrium on Windows 8 Pro 64
  #4  
Old August 23rd, 2010, 02:03 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,750
Default Re: RSS 2011 / Wipe All Disk Changes...

Please describe the steps to get the result you are describing as the wipe does not save anything to disk.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #5  
Old August 23rd, 2010, 03:24 PM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default Re: RSS 2011 / Wipe All Disk Changes...

That message - 'Saving Files' showing 'Mount Real Partition' > 'Dismount Real Partition' pops up every time I invoke shutdown.

Settings (on Win7 64): Start Virtual Mode with Windows / Drop All Changes / Wipe All Disk Changes

I'm using the free version of RSS, which I installed over the top of RVS 2010.

I might be being dopey, but all I really want to understand is what the setting in question actually does, what the cache actually refers to and how adding this cache-clearing changes how returnil works - ie:

What's the material difference between rebooting with the setting checked or without the setting checked, assuming I'm in Virtual Mode + Drop All Changes in both cases.

Thanks for your help.

philby
__________________
Sandboxie + Macrium on Windows 8 Pro 64
  #6  
Old August 23rd, 2010, 03:38 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,750
Default Re: RSS 2011 / Wipe All Disk Changes...

Either way, the cache is reset at restart of the computer with the cache being where attempted changes to the real system were tracked during the current virtual mode session. This information, like the data in the Windows pagefile, can be discovered and retrieved using forensics tools and techniques but cannot be discovered through casual inspection.

When the cache wipe is turned off (default), RVS/RSS simply starts at the beginning of the cache and overwrites what is there. When the cache wipe is active, the program overwrites the cache with a single pass to destroy whatever data was there before the normal overwrite at the beginning of the cache for that virtual session begins (IOW - wipe at restart of the computer).

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
  #7  
Old August 23rd, 2010, 04:00 PM
philby's Avatar
philby philby is offline
Frequent Poster
 
Join Date: Jan 2008
Posts: 922
Default Re: RSS 2011 / Wipe All Disk Changes...

OK - understand the cache now - thanks Mike!

I think if the notification had said Overwriting Cache or something to that effect, I would have understood.

I was foxed (easily done) by getting the Saving Files wording when I had 'Drop All' checked.

philby
__________________
Sandboxie + Macrium on Windows 8 Pro 64
  #8  
Old September 1st, 2010, 03:43 PM
fosl fosl is offline
Regular Poster
 
Join Date: Mar 2007
Posts: 54
Default Re: RSS 2011 / Wipe All Disk Changes...

I also get the following msg during shutdown
'Saving Files' and showing 'Mount Real Partition' > 'Dismount Real Partition'

I have not selected wipe all disk changes but have selected drop all changes. I guess its safe to assume nothing is being saved to the real disk.
  #9  
Old September 1st, 2010, 04:30 PM
Coldmoon's Avatar
Coldmoon Coldmoon is offline
Returnil Moderator
 
Join Date: Sep 2006
Location: North Carolina USA
Posts: 2,750
Default Re: RSS 2011 / Wipe All Disk Changes...

It should be saving signature and/or policy updates updates downloaded during the virtual session.

Mike
__________________
Returnil: The Real Security!
Follow us on Facebook
 

Wilders Security Forums > Official Returnil Support Forum > Returnil releases « Previous Thread | Next Thread »

Thread Tools Search this Thread
Search this Thread:

Advanced Search

Posting Settings
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

vB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Forum Jump


All times are GMT -4. The time now is 06:00 PM.


Powered by vBulletin® Copyright ©2000 - 2013, Jelsoft Enterprises Ltd.
Copyright ©2002 - 2013, Wilders Security Forums