Deep Freeze Unfreezer Security Notice Deep Freeze Unfreezer effectively bypasses Deep Freeze security whether booting from a floppy drive or CD-ROM drive is permitted or not. The CMOS can be configured to prevent booting from the floppy drive or CD-ROM drive (i.e. set to boot to the hard drive) and Deep Unfreezer will still work. This is a normal precaution for most public access computers. The Windows Registry, the computer CMOS and the boot sector are protected by Deep Freeze from within Windows. But Deep Unfreezer can send signal to Deep Freezer driver (deepfrz.sys) to start the computer in thawed mode on next restart. No Password Required. Technical Support Every effort has been made to design this software for ease of use and to be problem free. If problems are encountered, contact Emiliano Scavuzzo: Email: anshoku@yahoo.com or Contact address on web site Contact Information Web: http://usuarios.arnet.com.ar/fliamarconato/pages/edeepunfreezer.html 1999-2005 Scavuzzo Corporation. All rights reserved. Deep Freeze Unfreezer
Deep Freeze Unfreezer works on all versions of Deep Freeze up to v5.60.120.1347 to thaw the system back to an unfrozen state without knowing the password (works on Windows 95/98 or 2000/XP). It is the result of many hours of hard work by a programmer in Argentina named Emiliano Scavuzzo. He deserves all the credit for this program. Here, I have laid out clearly for you the necessary steps and requirements on using the program. I am writing this October 2005. Faronics will soon be coming out with a newer version of Deep Freeze, post- Build 1347, which will probably prevent Deep Unfreezer from working, for a while at least, until and unless Emiliano is able to update his Deep Unfreezer program. I am hoping that others will join in the battle and contribute their reversing skills to continue the project at that point. It's going to be a very interesting coder vs. reverser war. If you know any RCEers that would enjoy a challenge, tell them to keep an eye on Deep Freeze. Only post-1347 versions will prevent Deep Unfreezer from working: that means only *NEW* installations of Deep Freeze. There are over four million installations of Deep Freeze worldwide. Unless the place where you are going to use it just recently purchased and installed Deep Freeze, Deep Unfreezer will work. Bottom line: if the version of Deep Freeze you need to thaw is v5.60.120.1347 or earlier, THIS WILL WORK! To check which version of Deep Freeze is installed, shift double-click the Deep Freeze polar bear or frozen, iced-over computer monitor icon in the system tray. It gives the version number at the top-right of the password dialog window. If the icon is absent, yet you suspect Deep Freeze is installed, press ctrl-alt-shift-f6 to bring it up. This keystroke combination is NOT customizable, i.e., it cannot be changed to something else by the person who configured the Deep Freeze installer. So if Ctrl-Alt-Shift-F6 does not bring up the password dialog, Deep Freeze is not installed. Or, someone was messing with it, and you need to restart the computer. Faronics Deep Freeze - Home Page http://www.faronics.com/html/deepfreeze.asp Deep Freeze Unfreezer - Home Page - Forum (for latest release & info) http://usuarios.arnet.com.ar/fliamarconato/pages/edeepunfreezer.html Deep Freeze - Latest Version Info Page http://www.faronics.com/html/support.asp Included in Zip file: 1) Deepunfreezer1.1.exe (works on all versions of Deep Freeze up to v5.60.120.1347) 2) ntrights.exe - from the Windows 2003 Server Resource Kit 3) showpriv.exe - from the windows 2003 Server Resource Kit 4) Special deepfrz.sys driver from Faronics to thaw machines* 5) Deep Unfreezer.pdf First, try to run Deep Unfreezer. Choose Load Status, then select Boot Thawed, then Save Status. If you encounter an Error message, it doesn t mean Unfreezer is not working. It means you do not have the Debug Programs privilege. And you must acquire it. The reason we want to try running it first is because only in recent versions did Deep Freeze disable this privilege. There is a good chance it will work without having to take additional steps. So try it. If it works for you, it means you are dealing with an older version of Deep Freeze. You are in luck. You can disregard the remainder of this tutorial. Now if it doesn t work you must acquire the "Debug Programs" privilege (disabled by Deep Freeze in frozen mode). It is necessary before using Deep Unfreezer. Deep Unfreezer will not work, and will return Errors if the user does not have the "Debug Programs" privilege. By default only members of the administrators group have
this right. But Deep Freeze revokes it in frozen mode, then reinstates it in thawed mode. The reason Deep Freeze turns it on in thawed mode is so that programs that automatically update your system can make the necessary changes when Deep Freeze is in Maintenance Mode. Maintenance Mode is just thawed mode without keyboard or mouse. Now that you understand a little bit about that, here's how to acquire Debug Privileges in frozen mode (if you are dealing with a newer version of Deep Freeze which disabled it): Method 1: By escalating to the Local System account using Task Scheduler from the command line (Start/Run, cmd): 1) Enter: at 11:23pm /interactive taskmgr.exe (add one or two minutes to the current time) Press Enter 2) Once Task Manager launches, End Task explorer.exe 3) On the Task Manager Menu, choose File / New Task (Run...), Enter explorer.exe, click ok, to launch the explorer shell under the Local System account which has Debug Privileges. (yeah!) 4) Run Deep Unfreezer from the System account OR, Method 2: Use ntrights.exe (included) from the Windows Server 2003 Resource Kit, to grant yourself the SeDebugPrivilege. SeDebugPrivilege is the internal name of the "Debug Programs" privilege. Syntax: ntrights -u Users +r SeDebugPrivilege If you use ntrights, you must logoff and logon again before the new privilege takes effect. Also, you should be the only user logged on. Don't have a second user logged on while you log off and on again. At this point, you should use showpriv.exe (also included) to verify that the SeDebugPrivilege was actually granted to your account. Syntax: showpriv SeDebugPrivilege Once you verify that you have the "Debug Programs" privilege, run Deep Unfreezer, View Status, click on the Boot Thawed button, Save Status, and restart the machine. Voila!! THAWED! <yippee!> Now place the Numa Numa Dance shortcut on your desktop! <just kidding> Do whatever you want! A similar technique can be used to remove Deep Freeze Evaluation version by forwarding the date on a machine past 60-days which will expire Deep Freeze, causing it to restart in thawed mode and allowing uninstall. Here's how: 1) Switch to the System account, as described above 2) Double-click the time in the system tray 3) Forward the date past 60-days 4) Restart in thawed mode 5) Use a DeepFreezeSTDEval.exe to uninstall Deep Freeze. Deep Freeze is not uninstalled through Add/Remove Programs. It is uninstalled with the installation file, and ONLY with an installation file. Yes, the same file is used to install and uninstall. Just execute it and choose Uninstall. If you don't have it, download it here: Deep Freeze Evaluation - Trial Version http://www.faronics.com/exe/deepfreezestdeval.exe
Or, use ntrights.exe from the Windows Resource Kit, included, to grant yourself the SeSystemtimePrivilege. Syntax: ntrights -u Users +r SeSystemtimePrivilege You must logoff and logon again for the new privilege to take effect. You can place the included files on your thumb drive and copy them to the target system, or you can email them to yourself. Here are the sizes of the included files necessary for the task: deepunfreezer1.1.exe 96.0 KB ntrights.exe 32.0 KB showpriv.exe 32.0 KB deepfreezestdeval.exe 2.46 MB deepfrz.sys 17KB Once again: Deep Unfreezer requires Debug Privileges. You must first acquire Debug Privileges by either 1) Switching to the System account, or 2) Using ntrights.exe *Deep Unfreezer does not work on regular, limited accounts. Such accounts do not have the Debug Programs privilege. If you need to thaw a machine and you only have a Limited account, you can use the included deepfrz.sys driver. The included deepfrz.sys file is a special driver issued by Faronics only in emergency situations to assist customers who are unable to remove Deep Freeze due to a lost password, terminated employee, etc. You must find a way to boot and mount the NTFS Windows drive (Winternals ERD Commander, Bart s, NTFSDOS Professional, Peter Nordahl s Offline Password & Registry Editor, etc.). And of course, BIOS must be configured to allow booting from the CD drive or floppy disk, etc. But most network administrators don t restrict that. If you are a network admin reading this and you answer, I do!, then good for you! You are smart! Once you have mounted the volume: 1) Use attrib to remove the hidden, read-only attributes on c:\windows\system32\drivers\deepfrz.sys file. 2) Replace with the included deepfrz.sys. 3) Reboot machine normally. When the machine boots up, Deep Freeze will be in thawed mode, regardless if it was frozen before, and the password dialog will be disabled. At this point you would need the installation file to uninstall Deep Freeze. Evaluation version files uninstall evaluation versions, and Professional installation files uninstall Professional versions. Frequently, administrators hide it somewhere on the computer. Go to a cmd prompt and cd\ to the root directory. Then type dir /a /s df5wks.exe or dir /a /s deepfreezestd.exe or dir /a /s deepfreezestdeval.exe. Perhaps dir /a /s de*.exe and dir /a /s df*.exe would be more comprehensive. You might get lucky and find it tucked away in some small folder somewhere, OR on a logical partition, such as d: or even a network drive. Poke around. If you find it, you can uninstall Deep Freeze once you thaw the machine. But, of course, getting it thawed is the main thing. The GOOD thing about using the driver is, although it is more hassle, it will work on all versions of Deep Freeze, even future releases. But Deep Unfreezer works on most of them anyway, up to v5.60.120.1347. If you have any problems, you can visit the forum and ask for help. And find out the latest! enjoy!