Shared workstations get used by different people all day, every day — and each session is a chance for something unwanted to take hold. A single infected download, a bad USB drive, or a malicious script can leave a system compromised long after the person responsible has logged off.Â
Protecting these machines takes more than one layer of defense. Here’s what that looks like in practice.
Why Persistent Malware Is Hard To Eliminate on Shared Workstations
Most endpoint security is built around identifying threats and blocking them. That works reasonably well on a single user’s assigned laptop, where the software environment is stable and changes are predictable. Shared workstations don’t behave that way.Â
Dozens of unrelated people touch the same machine in a day, each with different habits and different levels of caution. Antivirus software can only stop what it recognizes, so a novel or well-disguised threat can slip through and write itself into the system.
Once that happens, it survives log-offs. It survives new users. It often survives basic cleanup attempts, because nothing about a standard login session removes it. The machine drifts further from its intended state with every shift.
Protect Shared Workstations From Persistent Malware: 5 Strategies
Here are five strategies for protecting shared workstations from persistent malware.
Layer Real-Time Antivirus Protection
Real-time antivirus scans files and processes as they run, catching known malware signatures and flagging suspicious behavior before it executes. It’s still the right first layer, since it stops a large share of threats before they ever touch the disk.Â
The limitation is inherent to how it works: it depends on recognizing something as malicious, so it can’t catch what it hasn’t seen before. On a machine that meets a new set of hands every hour, that gap matters. Antivirus should be treated as one control among several (not the whole plan).
Control Which Applications Can Run
Application whitelisting flips the usual security model. Instead of blocking known bad programs, it allows only approved software to run and blocks everything else by default, including executables and scripts nobody has seen before.Â
On a shared machine where anyone can plug in a USB drive or download a file, this closes off most of the ways malware gets a foothold in the first place. Building the initial approved list takes some upfront work, usually by running an audit mode against a clean baseline. But it’s a one-time cost that pays off on every machine in the fleet.
Use Reboot-to-Restore To Eliminate Persistence
This is the control that actually solves the persistence problem. Reboot-to-Restore freezes a known-good system state and treats every write-to-disk during a session as temporary. Whatever happens next, whether it’s malware, a user-installed program, or an accidental setting change, gets discarded the moment the machine restarts.Â
Because nothing needs to be identified for this to work, it handles a zero-day threat exactly the same way it handles a known one. For shared workstations, this means every new user starts from a clean, predictable machine — regardless of what the last person did.
Schedule Maintenance Windows for Updates
A frozen baseline creates one obvious complication: updates written during a normal session disappear on restart along with everything else. The fix is a maintenance window: a scheduled period when the baseline is temporarily thawed, and patches and updates are applied.Â
The machine is then refrozen with the new state as the new baseline. Running this on a set schedule, outside of active hours, keeps machines current without leaving them exposed the rest of the time.
Separate User Data From the Protected Baseline
Wiping every session clean is only useful if it doesn’t also wipe out work people need to keep. Partitioning a separate data volume outside the frozen system drive lets user files, saved documents, and session data persist across reboots.Â
The operating system and installed applications reset every time. This is what makes Reboot-to-Restore practical on machines people actually need to save work on, like library computers or shared lab stations, rather than just kiosks with no persistent use case.
Discover Deep Freeze
Faronics Deep Freeze applies Reboot-to-Restore technology to shared and public access endpoints, returning each machine to its frozen baseline with a simple restart. It handles the persistence problem directly, without relying on recognizing every threat first.Â
Discover how Deep Freeze can protect your shared workstations.
FAQs
Does Reboot-to-Restore Replace Antivirus?
No. It complements antivirus rather than replacing it. Antivirus still matters for stopping threats like data theft during an active session. Reboot-to-Restore handles what antivirus can’t: guaranteeing the machine returns to a clean state no matter what happened while it was in use.
How Often Should Shared Workstations Be Rebooted?
Between users on high-traffic machines like kiosks, or at set intervals, such as at the end of each day, on machines used more casually. The right frequency depends on how often the machine changes hands and how much risk that turnover carries.
Can Persistent Malware Get Around Reboot-to-Restore?
Only if it manages to write itself during a maintenance window, while the baseline is thawed, or if it targets something outside the frozen drive entirely (like a network device). Under normal operation, nothing written during a session survives a restart.




