RE: Removing RootKits
"cyranodesade" wrote:
> All,
> I hope this is a simple question does Formatting a Hard Drive and then
> FDisk /MBR remove any rootkits or hidden files on a hard drive??
> If the answer is no then could you please point me to a good resource
> for formatting the boot sector/MBR? Thanks in advance. - CES
It will remove the root kit. However, it is not the best first thing to
try, as there are better and easier ways to both remove root kits and to
reduce the risk of re-infection.
Most root kits in use nowadays have little to nothing to do with the MBR.
In old days, some people suggested running FDISK /MBR was recommended as a
virus removal method, but antivirus experts said this was a bad idea, and I
still agree.
Besides the other suggestions you received... if you have two computers that
are networked, using one known clean computer to virus scan the hard drive of
the suspect computer will allow you to detect the root kits commonly used
today. Root kits only hide objects from the infected local OS, not remote
connections to that OS.
--
kind regards,
Karl Levinson, CISSP, CCSA, MCSE [MS MVP]
-------------------------
Security FAQ:
http://www.securityadmin.info