Windows Vista Forums
Vista Forums Home Join Vista Forums Windows 7 Forum Vista Tutorials Tags
Welcome to Windows Vista Forums. Our forum is dedicated to helping you find solutions with any problems, errors or issues you are experiencing with Windows Vista. The Vista forum also covers news and updates and has an extensive Windows Vista tutorial section that covers a wide range of tips and tricks.

Go Back   Vista Forums > Vista Newsgroups > Vista security

Vista Tutorial - Removing RootKits

Reply
 
Old 08-15-2007   #11 (permalink)
Crazy Noddy
Guest


 
 

Re: Removing RootKits

"Karl Levinson, mvp" <levinson_k@securityadmin.info> wrote in message
news:4A06D8AA-A00D-449B-9518-090A0E68DBCA@microsoft.com...
> Most root kits in use nowadays have little to nothing to do with the MBR.
> In old days, some people suggested running FDISK /MBR was recommended as a
> virus removal method, but antivirus experts said this was a bad idea, and
> I
> still agree.


Why did they say it is a bad idea and why do you agree?


My System SpecsSystem Spec
Old 08-15-2007   #12 (permalink)
Crazy Noddy
Guest


 
 

Re: Removing RootKits

"May" <May.J.Court@Blueyonder.co.uk> wrote in message
news:%23yGGW2x3HHA.1208@TK2MSFTNGP05.phx.gbl...
>What ever replaced the ‘Fdisk /MBR’ command?
>
> May



fixboot and fixmbr

http://support.microsoft.com/kb/314058

My System SpecsSystem Spec
Old 08-15-2007   #13 (permalink)
Ronnie Vernon MVP
Guest


 
 

Re: Removing RootKits

Crazy

Many of the old XP Recovery Console commands have been changed in Vista. The
following website has these changes documented.

Windows RE Notes : Where are recovery console commands?:
http://blogs.msdn.com/winre/archive/...-commands.aspx


--

Ronnie Vernon
Microsoft MVP
Windows Shell/User


"Crazy Noddy" <SPAM@BLOCKER.ACTIVE> wrote in message
news:BUGwi.218652$ss3.90690@fe01.news.easynews.com...
> "May" <May.J.Court@Blueyonder.co.uk> wrote in message
> news:%23yGGW2x3HHA.1208@TK2MSFTNGP05.phx.gbl...
>>What ever replaced the ‘Fdisk /MBR’ command?
>>
>> May

>
>
> fixboot and fixmbr
>
> http://support.microsoft.com/kb/314058


My System SpecsSystem Spec
Old 08-16-2007   #14 (permalink)
Crazy Noddy
Guest


 
 

Re: Removing RootKits

"Ronnie Vernon MVP" <rv@invalid.org> wrote in message
news:OPZngd43HHA.536@TK2MSFTNGP06.phx.gbl...
> Crazy
>
> Many of the old XP Recovery Console commands have been changed in Vista.
> The following website has these changes documented.
>
> Windows RE Notes : Where are recovery console commands?:
> http://blogs.msdn.com/winre/archive/...-commands.aspx
>
>
> --
>
> Ronnie Vernon
> Microsoft MVP
> Windows Shell/User


Ok, thanks. And it is "Crazy Noddy" and not just "Crazy".

My System SpecsSystem Spec
Old 08-16-2007   #15 (permalink)
Alun Harford
Guest


 
 

Re: Removing RootKits

cyranodesade wrote:
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES


Yes, it'll remove the rootkit - IF the rootkit lets you format the
drive. There would be nothing to stop somebody from writing a rootkit
that just made it look like the drive had been formatted.

You could delete and recreate the partition when you're booted from CD
(eg. installing Windows)

Alun Harford
My System SpecsSystem Spec
Reply

Thread Tools


Similar Threads
Thread Forum
Scanning for rootkits Vista General
RE: RootKits? Vista General
Removing RootKits Vista file management
Removing Rootkits from Boot Sector. Vista General
Rootkits in Vista RC-1 and RC-2 ? Vista General


Vista Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows Vista", the Start Orb, and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46