LinuxQuestions.org
Visit Jeremy's Blog.
Home Forums Tutorials Articles Register
Go Back   LinuxQuestions.org > Forums > Linux Forums > Linux - Security
User Name
Password
Linux - Security This forum is for all security related questions.
Questions, tips, system compromises, firewalls, etc. are all included here.

Notices


Reply
  Search this Thread
Old 12-14-2008, 04:41 PM   #1
CitizenCCW
LQ Newbie
 
Registered: May 2006
Posts: 4

Rep: Reputation: 0
Question Help me scan/nuke from orbit a very sick XP HDD


Hello LQ security nerds. I've got a couple of questions regarding a heavily infected drive. As if Win XP weren't enough to qualify as a disease, this poor drive is also so riddled with malware as to make it unusable.
The original owner was ready to buy a new computer anyway (and "upgrade" to Vista!) and so decided to replace rather than repair. The upshot is that the owner gave me the old system and asked that I recover a few documents for her.
So I unplugged all the drives in my comp to avoid infection and put Mepis 7 on a blank drive (rather than using the live CD) and I copied all of her Office documents, her Firefox bookmarks and a few images and burned them to a CD. I scanned the CD with an up to date copy of AVG Linux and it found nothing. Now I plan to wipe this infected drive and use it to play with other linux distros

--So my first question is:
Is there any chance of the original owner infecting her new comp from the the backups I burned?

---Next question has to do with reformatting:
Should I wipe this Mepis install before plugging my other drives back in (one of them has XP on it)? Also...The infected drive has a MBR virus. Will GParted wipe the boot sector as well? Is a reformat with GParted enough to make this drive "clean" or do I need to run Dban on it?

I appreciate your advice, thanks in advance.
 
Old 12-14-2008, 04:50 PM   #2
MS3FGX
LQ Guru
 
Registered: Jan 2004
Location: NJ, USA
Distribution: Slackware, Debian
Posts: 5,852

Rep: Reputation: 361Reputation: 361Reputation: 361Reputation: 361
You say the machine had malware on it and a MBR-resident virus; neither of those are going to replicate through individual files on the machine (malware doesn't generally replicate, and a MBR virus is spread through removable storage devices). Combined with the clean bill of health from the AVG scan, I would say there is little chance of passing the infection along.

As for the drive, you don't need to run dban on it just to clear the MBR. You can wipe the MBR with dd from a live CD or the installed Mepis with the command:

Code:
dd if=/dev/zero of=/dev/hda count=1 bs=512
Replacing "/dev/hda" with the device in question if necessary (such as if it was in an external enclosure or is a SATA drive).
 
Old 12-14-2008, 05:22 PM   #3
jiml8
Senior Member
 
Registered: Sep 2003
Posts: 3,171

Rep: Reputation: 116Reputation: 116
Microsoft Office documents can have viruses in macros. I presume that AVG scanned them for that. The images are *probably* safe...depending on where the images came from

There was some issue of malware that could get onto a Windows system through an image due to something or other - I forget the details and am too lazy to look it up now - but Windows permitted and used some sort of active content in images that could become infected. IIRC there was a stink/scandal about the same time as many of these active picture frame viewers that you can buy were coming out infected with a virus because of this capability.

Again, though, I presume that AVG checks for that.
 
Old 12-15-2008, 03:02 AM   #4
H_TeXMeX_H
LQ Guru
 
Registered: Oct 2005
Location: $RANDOM
Distribution: slackware64
Posts: 12,928
Blog Entries: 2

Rep: Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301Reputation: 1301
Quote:
Originally Posted by MS3FGX View Post
As for the drive, you don't need to run dban on it just to clear the MBR. You can wipe the MBR with dd from a live CD or the installed Mepis with the command:

Code:
dd if=/dev/zero of=/dev/hda count=1 bs=512
You might wanna do that to the whole drive.
 
  


Reply



Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is Off
HTML code is Off



Similar Threads
Thread Thread Starter Forum Replies Last Post
Nuke and Erasing a HDD metallica1973 Linux - Hardware 13 11-26-2008 03:53 PM
Tool for HDD physical scan somarasa Mandriva 4 06-24-2005 02:53 AM
To SCAN or not to SCAN? HP750xi Suse 9.2 Pro newtwolinux Linux - Hardware 4 06-22-2005 04:02 PM
What is Orbit? everythingand2 Slackware 3 04-28-2004 02:30 AM
orbit? def1014 Linux - General 1 11-01-2002 09:50 AM

LinuxQuestions.org > Forums > Linux Forums > Linux - Security

All times are GMT -5. The time now is 12:25 AM.

Main Menu
Advertisement
My LQ
Write for LQ
LinuxQuestions.org is looking for people interested in writing Editorials, Articles, Reviews, and more. If you'd like to contribute content, let us know.
Main Menu
Syndicate
RSS1  Latest Threads
RSS1  LQ News
Twitter: @linuxquestions
Open Source Consulting | Domain Registration