Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > Removing Rootkits from Boot Sector.

Reply
Thread Tools Display Modes

Removing Rootkits from Boot Sector.

 
 
cyranodesade
Guest
Posts: n/a

 
      08-05-2007
All,
I hope this is a simple question does Formatting a Hard Drive and then
FDisk /MBR remove any rootkits or hidden unwanted files on a hard
drive??
If the answer is no then could you please point me to a good resource
for formatting the boot sector/MBR? Thanks in advance. - CES

 
Reply With Quote
 
 
 
 
Richard Urban
Guest
Posts: n/a

 
      08-06-2007
If you delete all partitions on a hard drive, and then create and format new
partitions, a new MBR is created. The old one is gone. I do not know of any
malware that will survive this action but there "may" be some out there that
can.

--


Regards,

Richard Urban
Microsoft MVP Windows Shell/User
(For email, remove the obvious from my address)

"cyranodesade" <> wrote in message
news: oups.com...
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden unwanted files on a hard
> drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES
>


 
Reply With Quote
 
Andrew McLaren
Guest
Posts: n/a

 
      08-06-2007
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden unwanted files on a hard
> drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES


FDISK is a DOS/Windows 9x command ... there is no FDISK in Vista (or XP, or
Windows 2000).

The steps to recreate the MBR on Vista are described in Microsoft
KnowledgeBase article 927392:
http://support.microsoft.com/kb/927392
Basically, you boot up from the Vista DVD, go to the Repair option, and run
"bootrec /fixmbr". You can also format the hard disk, using the Repair
console.

As to whether this will reliably remove any rootkits ... well, disinfection
is not the stated or tested purpose of this "bootrec /fixmbr" command,
although that might be a side-effect. /fixmbr will rewrite the MBR. If you
have a virus in your MBR, I expect it will be over-written. Rootkits per se
(as opposed to viruses) usually live in the filesystem, disguising
themselves as legitimate operating system components. Formatting would
likely remove these; but again - formatting wasn't designed as an anti-virus
measure, as such. It's a good start. If you suspect you have a virus or
rootkit, the only reliable way to tackle it is to get a current version of a
reputable anti-virus program, with current signatures, and run a full scan
on your system. Rootkits by definition, are difficult to detect; but most of
the main, current anti-virus apps know how to detect the known rootkits.

Hope it helps,
--
Andrew McLaren
amclar (at) optusnet dot com dot au


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Removing RootKits cyranodesade Windows Vista File Management 14 08-16-2007 08:12 PM
Removing RootKits cyranodesade Windows Vista Security 14 08-16-2007 08:12 PM
Recovered from boot sector corruption - now can't login ALV Windows Vista Installation 2 08-11-2007 03:04 AM
Dual Boot Problem - Misplaced Boot Sector RoboDude Windows Vista General Discussion 1 06-16-2006 03:14 AM
Dual Boot Problem - Misplaced boot sector RoboDude Windows Vista General Discussion 0 06-15-2006 10:34 PM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59