Can sophos detect firmware rootkits?

Discussion in 'other anti-trojan software' started by famouspogs, Feb 23, 2009.

Thread Status:
Not open for further replies.
  1. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    can a clean fresh format wipe out this type of rootkit?or maybe using killdisk?thanks
     
  2. Searching_ _ _

    Searching_ _ _ Registered Member

    Joined:
    Jan 2, 2008
    Posts:
    1,988
    Location:
    iAnywhere
    Formating is done by the OS and the OS can't see the Hidden Partition Area/ Device Configuration Overlay. Formatting only gets rid of directory entries, data can persist.

    Killdisk is an average wiping program. In my case it showed some issues with unallocated space but could not wipe them.

    To wipe the HPA/DCO you need a program that specifically states that it wipes these areas. The amount of programs that do this you can probably count on one hand. Neither OSX nor Linux do it either.

    This may help the KB.
    Data Sanitization Tutorial
     
  3. jmonge

    jmonge Registered Member

    Joined:
    Mar 20, 2008
    Posts:
    13,744
    Location:
    Canada
    thanks for info
     
  4. andyman35

    andyman35 Registered Member

    Joined:
    Nov 2, 2007
    Posts:
    2,336
    I think that this util might fit the bill:

    http://cmrr.ucsd.edu/people/Hughes/SecureErase.shtml
     
Thread Status:
Not open for further replies.
  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.