Ghost 15: complete beginner questions

Dave,

 

That is exactly why I specifically said a LOW level format which guarantees that the whole drive gets overwritten.

 

A rootkit can survive a high level format, I never said it could survive a low level format, in fact I said just the opposite earlier.

 

Allen

I know you did Allen, I was just talking about the "myth" in general about things magically surviving a format.

 

Red has a point though, I forgot about the hidden part of the drive. The serial number, the backup sectors and most drives are actually bigger than the visible size.

But like he said, it's hard to get to and usually takes special tools.  I highly doubt that virus's or rootkits can use that area and it would still need a way on the "ouside" to access it and load something. Something that wouldn't exist if the drive was wiped.

 

The more I think about it, the harder it seems that anything complex could ever be in the BIOS.

 

 

First, I am a long way from being any kind of an expert on rootkits, other than I have been forced to recognize the lieklihood of there being one.  Quafds is the true expert, and hopefully he will comment.  I know he does not re-format his drives to clear them of a rootkit, and would not consider it necessary.

 

To restore a drive using Ghost or anything else, you would have to have a very clear and accurate idea of how and when you were infected, or the restore is just going to replace it.  To me that is the biggest danger in doing a reformat and restore.  Rootkits can remain hidden until the malware they attract becomes a noticeable issue.

 

I can recall at least one user who  "formatted" three times to get rid of a TDL2 rootkit and as far as I know failed each time.  The problem is that format means different things to different users.  In that case, it could have been an unsuccessful reinstall, instead of a true format and clean install, or it could have been a restore from an infected image.

 

This thread on Tech Outpost by Voyager10, with links to information is very good technical reading on rootkits.

 

http://community.norton.com/t5/Tech-Outpost/Technical-Development-TDSS-Rootkits/td-p/174026

HI Delph,

 

Thanks very much. Your comments and ideas are always welcome. Hopefully Quads will comment as well, as you said. :smileyhappy:

 

I think it would be safe to say that a HIGH level format followed by reinstall is probably one of the more risky removal attempts. Would you agree?

 

High level format simply does not wipe the entire drive. If someone really wanted to do this then a LOW level format would be the safest method in my opinion.

 

You also brought up a good point about just how long the rootkit could have been present on the system before being noticed. Naturally as you said, this could mean it is present on any number of backup images.

 

The more traditional malware is usually noticed pretty quickly but I think this is probably not necessarily true with rootkits, correct?

 

Thanks again Delph! :smileyvery-happy:

Allen

 


delphinium wrote:

 

To restore a drive using Ghost or anything else, you would have to have a very clear and accurate idea of how and when you were infected, or the restore is just going to replace it. 


 

delphinium,

Thank you. That pdf from Dr.Web was most interesting.

 

I guess we are still uncertain whether restoring a clean Ghost image will eradicate a rootkit.  I'd never consider formatting and reinstalling the OS, but a restore only takes me 5 to 10 minutes. If it works that would be nice but primary removal of the rootkit would be the first option.

I am Not going to comment on rookits, Bootkits, wipe levels and survival etc.

 

There are Gurus and others on this thread and I am no longer doing any sort of Malware on this forum.

 

Quads

Hi Quads,

 

For what its worth please allow me to say something. I think I at least partially understand where you are coming from.

 

But whether Gurus are involved in this thread or not does not change the fact that you are the recognized expert on this sort of thing. This is what you do and I have complete respect for you in that regard.

 

I have no problem admitting that you know far more about this sort of thing than I do. I've had a fair share of removing typical malware but next to none in removing Rootkits.

 

On both matters you are the recognized expert and I have no problem admitting that.

 

I just wanted to make that statement so you know how I feel.

 

Best wishes.

Allen

I won't be doing anything or explaining anything to do with Malware.

 

Quads

 


Quads wrote:
I am no longer doing any sort of Malware on this forum.

 


I've asked the question in Tech Outpost as I note you are involved in a rootkit and other malware threads.

 

All I did was give links to ThreatXpert reports and explain quickly there are probably different variant not just 2 quickly.

 

I have not explained the Malware itself how it works and how to remove it or make sure it's gone, that is the "Go to Bleeping Computer" message further up.

 

Quads

I don't want an explanation of the malware. Yes or No is sufficient. Is that too difficult?

Well, I can provide an answer and it is definitely "Yes".

 

If you restore a partition image and also restore the First Track (Restore MBR in Ghost 15), the rootkit will be gone.

 

With other software, if you restore an entire drive image,  the rootkit will be gone.

 

This should clear up a lot of myths.