WannaCry vs Deep Freeze.

JHomes

Level 7
Verified
Well-known
Jul 7, 2016
339
There is something here I still don't understand. Why is it necessary to uninstall Rollback, in order to take a Macrium disk image?

When you capture your MBR in the disk image, it sees this weird block of encrypted data that because of the encryption, it doesn't know what to do with, so it will not include it in the disk image. When you restore the disk image, Rollback the windows client will be there, but not the subsystem (you know the menu you see when Rollback is loading?) I've tried for what feels like ages to get it to capture it, but it's never been successful without uninstalling Rollback or using Drive Cloner, or the new aforementioned disabling protection feature.

Also, I want to add to the actual post here, I was able to roll back my wife's machine with WannaCry on it. Not sure about Deep Freeze but I was able to do it with Rollback no issues.
 

shmu26

Level 85
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Jul 3, 2015
8,153
When you capture your MBR in the disk image, it sees this weird block of encrypted data that because of the encryption, it doesn't know what to do with, so it will not include it in the disk image. When you restore the disk image, Rollback the windows client will be there, but not the subsystem (you know the menu you see when Rollback is loading?) I've tried for what feels like ages to get it to capture it, but it's never been successful without uninstalling Rollback or using Drive Cloner, or the new aforementioned disabling protection feature.

Also, I want to add to the actual post here, I was able to roll back my wife's machine with WannaCry on it. Not sure about Deep Freeze but I was able to do it with Rollback no issues.
Thanks. Yes, it is messy if you make a system image with Rollback installed, and then restore it. But in worst case scenario, Macrium can fix the MBR, and you are good.
 
  • Like
Reactions: frogboy

JHomes

Level 7
Verified
Well-known
Jul 7, 2016
339
Thanks. Yes, it is messy if you make a system image with Rollback installed, and then restore it. But in worst case scenario, Macrium can fix the MBR, and you are good.

This is true. It's to each's own tbh. I mean I know some people who would outright refuse to pay $40 for a disk imager, but sometimes time > $$$. To give HDS credit, they aren't forcing you to use Drive Cloner, it's an option but so is disabling the protection and running any other disk imager.
 
D

Deleted member 178

Thanks. Yes, it is messy if you make a system image with Rollback installed, and then restore it. But in worst case scenario, Macrium can fix the MBR, and you are good.
but you dont use a product to fix the MBR every time because of it..
 
  • Like
Reactions: AtlBo and shmu26

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top