Login Register






[Question] Reusing potentially infected drives filter_list
Author
Message
[Question] Reusing potentially infected drives #1
As I mentioned in my thread earlier today, my laptop's HDD broke. Luckily, I have a second copy of the exact same model from my previous laptop, as well as a Windows 7 install USB (which I could upgrade later). Perhaps not so lucky, however, is the fact that said previous laptop was mutilated, from what I can assume in retrospect now that I know more, by a particularly nasty rootkit.

If the rootkit is still on the drive (I cant remember if I've formatted or used it since), would it be safe to use if I formatted it and did a clean windows install? If not, would overwriting it by dd'ing or copying /dev/zero or /dev/urandom to the drive's location (/dev/sdX) be adequate?
(This post was last modified: 12-15-2016, 03:04 AM by Inori.)
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

Reply

RE: [Question] Reusing potentially infected drives #2
It should be fine, rootkits are still programs even if they work at a kernel level, so they can still be deleted like anything else.


(11-02-2018, 02:51 AM)Skullmeat Wrote: Ok, there no real practical reason for doing this, but that's never stopped me.

Reply

RE: [Question] Reusing potentially infected drives #3
(12-15-2016, 04:04 AM)Ender Wrote: It should be fine, rootkits are still programs even if they work at a kernel level, so they can still be deleted like anything else.

That was my initial guess, just wanted to be safe since they're so fucking dangerous.
It's often the outcasts, the iconoclasts ... those who have the least to lose because they
don't have much in the first place, who feel the new currents and ride them the farthest.

Reply

RE: [Question] Reusing potentially infected drives #4
(12-15-2016, 03:02 AM)Inori Wrote: As I mentioned in my thread earlier today, my laptop's HDD broke. Luckily, I have a second copy of the exact same model from my previous laptop, as well as a Windows 7 install USB (which I could upgrade later). Perhaps not so lucky, however, is the fact that said previous laptop was mutilated, from what I can assume in retrospect now that I know more, by a particularly nasty rootkit.

If the rootkit is still on the drive (I cant remember if I've formatted or used it since), would it be safe to use if I formatted it and did a clean windows install? If not, would overwriting it by dd'ing or copying /dev/zero or /dev/urandom to the drive's location (/dev/sdX) be adequate?




Yes, formatting it should work fine. I guess malware could get into the drive firmware, but that chance is about 1 in 100 trillion because I'm pretty sure the chip it's stored on is read-only. So it would basically have to be put in during the manufacturing process. Anyways, format the drives in gparted or diskpart or whatever once and you'll be ok.
Has anyone seen my berries?

Reply