hidden hit counter
Welcome to Soft32 Forums!
FAQFAQ    SearchSearch      ProfileProfile    Private MessagesPrivate Messages   Log inLog in

Removing RootKits

 
   Soft32 Home -> Windows -> File Management RSS
Next:  Expanding folders & files command - gonzo?  
Author Message
cyranodesade

External


Since: Aug 05, 2007
Posts: 2



(Msg. 1) Posted: Sun Aug 05, 2007 9:52 am
Post subject: Removing RootKits
Archived from groups: microsoft>public>windows>vista>file_management, others (more info?)

All,
I hope this is a simple question does Formatting a Hard Drive and then
FDisk /MBR remove any rootkits or hidden files on a hard drive??
If the answer is no then could you please point me to a good resource
for formatting the boot sector/MBR? Thanks in advance. - CES
Back to top
Login to vote
Jerry

External


Since: Mar 01, 2007
Posts: 109



(Msg. 2) Posted: Sun Aug 05, 2007 9:56 am
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Reformatting the drive removes everything. FDISK /MBR is redundant if you
just formatted.

The only other option is a manufacturer's low-level format and that program
is probably not available for a user.

"cyranodesade" <cyranodesade DeleteThis @gmail.com> wrote in message
news:1186350724.255616.20280@r34g2000hsd.googlegroups.com...
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES
>
Back to top
Login to vote
romanom

External


Since: Jun 18, 2007
Posts: 50



(Msg. 3) Posted: Sun Aug 05, 2007 9:12 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: microsoft>public>security, others (more info?)

If your formatting just to remove the rootkit you may try this freeware first:

http://www.grisoft.com/doc/download-free-anti-rootkit/us/crp/0

It worked for me in finding and removing a Sony Music rootkit that Sony was
kind enough to install with Connect software, I guess to ensure I wasn't
passing on music to the Communist or something.

"Jerry" wrote:

> Reformatting the drive removes everything. FDISK /MBR is redundant if you
> just formatted.
>
> The only other option is a manufacturer's low-level format and that program
> is probably not available for a user.
>
> "cyranodesade" <cyranodesade.TakeThisOut@gmail.com> wrote in message
> news:1186350724.255616.20280@r34g2000hsd.googlegroups.com...
> > All,
> > I hope this is a simple question does Formatting a Hard Drive and then
> > FDisk /MBR remove any rootkits or hidden files on a hard drive??
> > If the answer is no then could you please point me to a good resource
> > for formatting the boot sector/MBR? Thanks in advance. - CES
> >
>
>
>
Back to top
Login to vote
Milo

External


Since: Jul 27, 2007
Posts: 1



(Msg. 4) Posted: Mon Aug 06, 2007 2:00 am
Post subject: RE: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

You can also use this application

Rootkit revealer
http://www.microsoft.com/technet/sysinternals/utilities/RootkitRevealer.mspx

thanks


--
Milo
MSPSS


"cyranodesade" wrote:

> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES
>
>
Back to top
Login to vote
Kerry Brown

External


Since: May 11, 2005
Posts: 316



(Msg. 5) Posted: Mon Aug 06, 2007 3:14 am
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: microsoft>public>windows>vista>file_management, others (more info?)

"cyranodesade" <cyranodesade RemoveThis @gmail.com> wrote in message
news:1186350724.255616.20280@r34g2000hsd.googlegroups.com...
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES
>


Yes it will remove the rootkit. You should figure how the rootkit got
installed and alter your computing habits so it doesn't happen again. One of
the reasons people ask this question is because they have done this then
become infected again because they didn't change their habits and the
rootkit got installed again by the same method it was the first time.

--
Kerry Brown
Microsoft MVP - Shell/User
http://www.vistahelp.ca
Back to top
Login to vote
Noddy

External


Since: Aug 03, 2007
Posts: 13



(Msg. 6) Posted: Tue Aug 07, 2007 7:16 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Jerry" <ChiefZekeNoSpam DeleteThis @MSN.com> wrote in message
news:%23nVlIu61HHA.5380@TK2MSFTNGP04.phx.gbl...
> Reformatting the drive removes everything. FDISK /MBR is redundant if you
> just formatted.

Format does not clear the mbr. If it did then Linux Grub or Lilo wouldn't be
left behind after a format, but it is and to get rid of it you run fdisk
/mbr. HDD manufacturers still provide what they call low level format
utilities but all they really are is a zero wipe utility which does
overwrite every sector on a HDD and is the best method to ensure you are
virus free. Or you can simply use Dban's quick wipe, same thing. Dban is
available as a separate download or on The Ultimate Boot Disk.
Back to top
Login to vote
Tyler Larson

External


Since: Aug 08, 2007
Posts: 3



(Msg. 7) Posted: Wed Aug 08, 2007 3:52 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Noddy wrote:
> "Jerry" <ChiefZekeNoSpam.DeleteThis@MSN.com> wrote in message
> news:%23nVlIu61HHA.5380@TK2MSFTNGP04.phx.gbl...
>> Reformatting the drive removes everything. FDISK /MBR is redundant if
>> you just formatted.
>
> Format does not clear the mbr. If it did then Linux Grub or Lilo
> wouldn't be left behind after a format, but it is and to get rid of it
> you run fdisk /mbr. HDD manufacturers still provide what they call low
> level format utilities but all they really are is a zero wipe utility
> which does overwrite every sector on a HDD and is the best method to
> ensure you are virus free. Or you can simply use Dban's quick wipe, same
> thing. Dban is available as a separate download or on The Ultimate Boot
> Disk.

The MBR is stored on sector 0, whereas partitions start at sector 1
(specifically to avoid overwriting the boot sector (MBR)). Therefore,
nothing you can do to the partition will affect the boot sector.
However, in the process of reinstalling windows, you'll automatically
write a new boot sector, since that's what SETUP does.
Back to top
Login to vote
Karl Levinson, mvp

External


Since: Jul 12, 2006
Posts: 1



(Msg. 8) Posted: Fri Aug 10, 2007 9:02 am
Post subject: RE: Removing RootKits [Login to view extended thread Info.]
Archived from groups: microsoft>public>security, others (more info?)

"cyranodesade" wrote:

> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES

It will remove the root kit. However, it is not the best first thing to
try, as there are better and easier ways to both remove root kits and to
reduce the risk of re-infection.

Most root kits in use nowadays have little to nothing to do with the MBR.
In old days, some people suggested running FDISK /MBR was recommended as a
virus removal method, but antivirus experts said this was a bad idea, and I
still agree.

Besides the other suggestions you received... if you have two computers that
are networked, using one known clean computer to virus scan the hard drive of
the suspect computer will allow you to detect the root kits commonly used
today. Root kits only hide objects from the infected local OS, not remote
connections to that OS.

--

kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
-------------------------
Security FAQ:
http://www.securityadmin.info
Back to top
Login to vote
May

External


Since: Aug 15, 2007
Posts: 2



(Msg. 9) Posted: Wed Aug 15, 2007 4:48 am
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Hello

Also by deleting all partitions and recreating new partitions will wipe the
MBR, albeit extreme unless you with to start from scratch. What ever
replaced the ‘Fdisk /MBR’ command?

May
Back to top
Login to vote
Crazy Noddy

External


Since: Aug 08, 2007
Posts: 55



(Msg. 10) Posted: Wed Aug 15, 2007 12:37 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: microsoft>public>windows>vista>file_management, others (more info?)

"Tyler Larson" <tylerl DeleteThis @discussions.microsoft.com> wrote in message
news:eToTfjj2HHA.5796@TK2MSFTNGP05.phx.gbl...
> The MBR is stored on sector 0, whereas partitions start at sector 1
> (specifically to avoid overwriting the boot sector (MBR)). Therefore,
> nothing you can do to the partition will affect the boot sector. However,
> in the process of reinstalling windows, you'll automatically write a new
> boot sector, since that's what SETUP does.


Then why are boot managers left behind when installing XP if the mbr is
overwrote completely? Because it obviously doesn't. You either have to
destroy the partition or use fdisk /mbr. Install Linux with a boot manager
and then go format it with XP and start setup, afterwards you will see that
Linux boot manager is still there. If XP setup overwrote the mbr then the
Linux boot manager wouldn't still be there. Same thing will happen if you do
a XP/Vista dual boot and you want to go back to just XP. The Vista boot
manager will still be there and you have to edit it with BCDedit.
Back to top
Login to vote
Crazy Noddy

External


Since: Aug 08, 2007
Posts: 55



(Msg. 11) Posted: Wed Aug 15, 2007 12:38 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: microsoft>public>security, others (more info?)

"Karl Levinson, mvp" <levinson_k DeleteThis @securityadmin.info> wrote in message
news:4A06D8AA-A00D-449B-9518-090A0E68DBCA@microsoft.com...
> Most root kits in use nowadays have little to nothing to do with the MBR.
> In old days, some people suggested running FDISK /MBR was recommended as a
> virus removal method, but antivirus experts said this was a bad idea, and
> I
> still agree.

Why did they say it is a bad idea and why do you agree?
Back to top
Login to vote
Crazy Noddy

External


Since: Aug 08, 2007
Posts: 55



(Msg. 12) Posted: Wed Aug 15, 2007 12:40 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"May" <May.J.Court DeleteThis @Blueyonder.co.uk> wrote in message
news:%23yGGW2x3HHA.1208@TK2MSFTNGP05.phx.gbl...
>What ever replaced the ‘Fdisk /MBR’ command?
>
> May


fixboot and fixmbr

http://support.microsoft.com/kb/314058
Back to top
Login to vote
Ronnie Vernon MVP

External


Since: Jan 18, 2007
Posts: 626



(Msg. 13) Posted: Wed Aug 15, 2007 12:40 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

Crazy

Many of the old XP Recovery Console commands have been changed in Vista. The
following website has these changes documented.

Windows RE Notes : Where are recovery console commands?:
http://blogs.msdn.com/winre/archive/2006/10/20/where-are-recovery-cons...-comman


--

Ronnie Vernon
Microsoft MVP
Windows Shell/User


"Crazy Noddy" <SPAM.RemoveThis@BLOCKER.ACTIVE> wrote in message
news:BUGwi.218652$ss3.90690@fe01.news.easynews.com...
> "May" <May.J.Court.RemoveThis@Blueyonder.co.uk> wrote in message
> news:%23yGGW2x3HHA.1208@TK2MSFTNGP05.phx.gbl...
>>What ever replaced the ‘Fdisk /MBR’ command?
>>
>> May
>
>
> fixboot and fixmbr
>
> http://support.microsoft.com/kb/314058
Back to top
Login to vote
Crazy Noddy

External


Since: Aug 08, 2007
Posts: 55



(Msg. 14) Posted: Thu Aug 16, 2007 1:37 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: per prev. post (more info?)

"Ronnie Vernon MVP" <rv.TakeThisOut@invalid.org> wrote in message
news:OPZngd43HHA.536@TK2MSFTNGP06.phx.gbl...
> Crazy
>
> Many of the old XP Recovery Console commands have been changed in Vista.
> The following website has these changes documented.
>
> Windows RE Notes : Where are recovery console commands?:
> http://blogs.msdn.com/winre/archive/2006/10/20/where-are-recovery-cons...-comman
>
>
> --
>
> Ronnie Vernon
> Microsoft MVP
> Windows Shell/User

Ok, thanks. And it is "Crazy Noddy" and not just "Crazy". Smile
Back to top
Login to vote
Alun Harford

External


Since: Apr 02, 2007
Posts: 9



(Msg. 15) Posted: Thu Aug 16, 2007 3:48 pm
Post subject: Re: Removing RootKits [Login to view extended thread Info.]
Archived from groups: microsoft>public>windows>vista>file_management, others (more info?)

cyranodesade wrote:
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES

Yes, it'll remove the rootkit - IF the rootkit lets you format the
drive. There would be nothing to stop somebody from writing a rootkit
that just made it look like the drive had been formatted.

You could delete and recreate the partition when you're booted from CD
(eg. installing Windows)

Alun Harford
Back to top
Login to vote
Display posts from previous:   
       Soft32 Home -> Windows -> File Management All times are: Pacific Time (US & Canada) (change)
Page 1 of 1

 
You can post new topics in this forum
You can reply to topics in this forum
You cannot edit your posts in this forum
You cannot delete your posts in this forum
You cannot vote in polls in this forum

Categories:
  Windows
 Linux
 Mac
 PDA


[ Contact us | Terms of Service/Privacy Policy ]