Windows Vista Forums
Vista Forums Home Join Vista Forums Tech Publications Windows 7 Forum Vista Tutorials Webcasts Tags

Welcome to Vista Forums we are your forum for Windows Vista help and discussion. Whether you need help or just want to post an idea you have on Vista, this is the forum for you.
Register at Vista forums...the world biggest Windows Vista resource Join Vista Forums Now

Go Back   Vista Forums > Vista Newsgroups > Vista security

Removing RootKits

Update your Vista Drivers
Reply
 
Thread Tools Display Modes
Old 08-15-2007   #11 (permalink)
Crazy Noddy
Guest


 

Re: Removing RootKits

"Karl Levinson, mvp" <levinson_k@securityadmin.info> wrote in message
news:4A06D8AA-A00D-449B-9518-090A0E68DBCA@microsoft.com...
> Most root kits in use nowadays have little to nothing to do with the MBR.
> In old days, some people suggested running FDISK /MBR was recommended as a
> virus removal method, but antivirus experts said this was a bad idea, and
> I
> still agree.


Why did they say it is a bad idea and why do you agree?


My System SpecsSystem Spec
Old 08-15-2007   #12 (permalink)
Crazy Noddy
Guest


 

Re: Removing RootKits

"May" <May.J.Court@Blueyonder.co.uk> wrote in message
news:%23yGGW2x3HHA.1208@TK2MSFTNGP05.phx.gbl...
>What ever replaced the ‘Fdisk /MBR’ command?
>
> May



fixboot and fixmbr

http://support.microsoft.com/kb/314058

My System SpecsSystem Spec
Old 08-15-2007   #13 (permalink)
Ronnie Vernon MVP
Guest


 

Re: Removing RootKits

Crazy

Many of the old XP Recovery Console commands have been changed in Vista. The
following website has these changes documented.

Windows RE Notes : Where are recovery console commands?:
http://blogs.msdn.com/winre/archive/...-commands.aspx


--

Ronnie Vernon
Microsoft MVP
Windows Shell/User


"Crazy Noddy" <SPAM@BLOCKER.ACTIVE> wrote in message
news:BUGwi.218652$ss3.90690@fe01.news.easynews.com...
> "May" <May.J.Court@Blueyonder.co.uk> wrote in message
> news:%23yGGW2x3HHA.1208@TK2MSFTNGP05.phx.gbl...
>>What ever replaced the ‘Fdisk /MBR’ command?
>>
>> May

>
>
> fixboot and fixmbr
>
> http://support.microsoft.com/kb/314058


My System SpecsSystem Spec
Old 08-16-2007   #14 (permalink)
Crazy Noddy
Guest


 

Re: Removing RootKits

"Ronnie Vernon MVP" <rv@invalid.org> wrote in message
news:OPZngd43HHA.536@TK2MSFTNGP06.phx.gbl...
> Crazy
>
> Many of the old XP Recovery Console commands have been changed in Vista.
> The following website has these changes documented.
>
> Windows RE Notes : Where are recovery console commands?:
> http://blogs.msdn.com/winre/archive/...-commands.aspx
>
>
> --
>
> Ronnie Vernon
> Microsoft MVP
> Windows Shell/User


Ok, thanks. And it is "Crazy Noddy" and not just "Crazy".

My System SpecsSystem Spec
Old 08-16-2007   #15 (permalink)
Alun Harford
Guest


 

Re: Removing RootKits

cyranodesade wrote:
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES


Yes, it'll remove the rootkit - IF the rootkit lets you format the
drive. There would be nothing to stop somebody from writing a rootkit
that just made it look like the drive had been formatted.

You could delete and recreate the partition when you're booted from CD
(eg. installing Windows)

Alun Harford
My System SpecsSystem Spec
Reply
Update your Vista Drivers

Thread Tools
Display Modes



Similar Threads
Thread Thread Starter Forum Replies Last Post
RE: RootKits? oscar Vista General 3 08-13-2008 10:24 AM
Removing RootKits cyranodesade Vista file management 14 08-16-2007 04:12 PM
Removing Rootkits from Boot Sector. cyranodesade Vista General 2 08-05-2007 08:40 PM
Windows Rootkits/Virus Issues. Spot Vista security 2 01-24-2007 03:14 PM
Rootkits in Vista RC-1 and RC-2 ? breakin hardware Vista General 2 10-11-2006 09:54 AM


Complimentary Industry Resources

Vista Forums has joined forces with TradePub.com to offer you a new, exciting, and entirely free professional resource. Visit http://vistax64.tradepub.com today to browse our selection of complimentary Industry magazines, white papers, webinars, podcasts, and more across 34 industry sectors. No credit cards, coupons, or promo codes required. Try it today!




Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media 2005-2008

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51