Fedora Linux Support Community & Resources Center

Go Back   FedoraForum.org > Fedora 17/18 > Installation and Live Media
FedoraForum Search

Forgot Password? Join Us!

Installation and Live Media Help with Installation & Live Media (Live CD, USB, DVD) problems.

Reply
 
Thread Tools Search this Thread Display Modes
  #16  
Old 3rd October 2012, 01:13 AM
figleaf Offline
Registered User
 
Join Date: Sep 2012
Location: washington, dc
Posts: 25
windows_7ie
Re: GRUB2 survives deleting & preventing booting to live CDs

I cannot take your advice to retest after removing the internal hard drive. Asus netbooks open from the top. I broke a keyboard trying to take it out so I could get to the motherboard. Instead of paying again for a repairman to open my Asus, I used the internal Secure Erase tool in Erase Disk tool in Parted Magic Magic. Secure Erase wipes the entire drive including HPA. DBAN doesn't wipe HPA. Secure Erase solved the problem of my netbook trying to boot to a "invalid partition table" on the hard drive.

I then reran Navratil on UBCD. Navratil still detected a virus in memory. Thanks for the link to Kaspersky's TDSSKiller which detects MBR rootkits. Since there are no partitions on my internal hard drive, there is no MBR on my hard drive. The rootkit is not a MBR rootkit, it is a firmware rootkit. Thanks for the link to Kaspersky's Rescue CD. The description does not specify whether it scans memory and hidden protected area (HPA) in hard drives and removable media.

Nothing scans BIOS, graphic cards, video cards, external DVD players, etc. where firmware rootkits can infect. Do anyone know of a rootkit scanner that can scan RAM and HPA.

Thanks for recommending looking at rescue linux in Hiren's Boot CD. I will look for it in the menu and try it.

Thanks for recommending a manufacturer's flash for my external DVD players. I will ask Panasonic.

I have not found a tutorial on removing firmware rootkits. Articles on firmware rootkits recommend discarding the infected computer. Netbooks are cheap. I am willing to discard mine. Except my removable media (MP3 players, external DVD players, flashdrives and SDcards are also infected. Previously, I purchased replacements in the hope that the firmware rootkit was gone.

Burning a backup of my files on to DVDs and copying them to new removable media does not seem to be the solution as the DVDs autorun and then my removable media autorun.
Reply With Quote
  #17  
Old 3rd October 2012, 01:36 AM
sidebrnz's Avatar
sidebrnz Offline
Registered User
 
Join Date: Oct 2007
Location: Freedonia
Age: 63
Posts: 2,104
linuxfirefox
Re: GRUB2 survives deleting & preventing booting to live CDs

I'm beginning to get a bad, bad feeling here, for two reasons. One is the fact that you've neither tried rebooting without the external DVD player or explained why this isn't an option. The second is that this is beginning to remind me of something from an old book, Games People Play.

The particular game is, "Why don't you? Yes, but..." The way it's played is that all of us suggest ways to solve whatever problem you have and you win if you can show us that none of them will work. Until I see evidence that this isn't what's happening, such as your reporting what happens when you boot with all external drives and media removed, I'm not playing any more. I have better things to do.
__________________
Registered Linux user #470359 and permanently recovered BOFH.

Any advice in this post is worth exactly what you paid for it.
Reply With Quote
  #18  
Old 3rd October 2012, 05:04 AM
Dan's Avatar
Dan Offline
Administrator
 
Join Date: Jun 2006
Location: Paris, TX
Posts: 22,309
linuxfirefox
Exclamation Re: GRUB2 survives deleting & preventing booting to live CDs

Hmmm.

Quote:
Originally Posted by figleaf
... Articles on firmware rootkits recommend discarding the infected computer. Netbooks are cheap. I am willing to discard mine. ...
Okay. It sounds like that would perhaps be the best way to avoid a whole lot more trouble. However, one burning question remains. How is it that you think you managed to acquire this particularly pernicious rootkit in the first place?

That being said, if you are going to dispose of the thing anyway, I strongly recommend boxing it up with a complete and concise report of your efforts and findings, and send it for inspection and diagnosis to: http://www.us-cert.gov/ Address is available on the website, but a lead phone call would certainly help let them know it's coming.

They will be able to determine exactly what the issue is, and therefore be able to warn other folks about it, and perhaps advise how to defeat it.
__________________
Signature Links | New Posts | Who's on the forums (right now) |

© ® ™ № ¿
Reply With Quote
  #19  
Old 3rd October 2012, 01:52 PM
figleaf Offline
Registered User
 
Join Date: Sep 2012
Location: washington, dc
Posts: 25
windows_7ie
Re: GRUB2 survives deleting & preventing booting to live CDs

sidebrnz criticized that I was unwilling to boot up without the external DVD player. If he reread what I wrote, he will realize that I described booting up without an external DVD player twice:

(1) I wrote that booting up with or without my external DVD player, I received an error message: "invalid partition table." I wrote that running internal Secure Erase in Erase Disk tool in Parted Magic fixed getting "invalid partition table" upon booting.

(2) I wrote "there are no partitions on my internal hard drive. . ." When my netbook boots without an external DVD player, error message: "Reboot."

I don't want to reinstall linux on my internal hard drive until the firmware rootkit is removed from my memory, BIOS, graphic card, video card, external DVD players, MP3 players and removable media.

Thanks for recommending linux rescue in Hiren's Boot CD. However, it is merely Parted Magic. Parted Magic is terrific but I have been using it for several years now on its own live CD.

Thanks for recommending : http://www.us-cert.gov/. I will read their website.
Reply With Quote
Reply

Tags
booting, cds, deleting, grub2, live, preventing, survives

Thread Tools Search this Thread
Search this Thread:

Advanced Search
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off

Forum Jump

Similar Threads
Thread Thread Starter Forum Replies Last Post
dual booting fedora and ubntu should i use grub or grub2? sreek Installation and Live Media 5 13th November 2011 05:00 AM
[SOLVED] Grub2 and dual booting Hewjr100 Installation and Live Media 9 10th November 2011 09:01 AM
Grub2 quiet booting javiermon F16 Development 8 25th October 2011 10:33 PM
grub2 and booting iso images from harddisk alicemcline Using Fedora 4 3rd November 2010 12:38 AM
Deleting Fedora Live from USB Drive proto-man Using Fedora 1 5th February 2009 05:08 AM


Current GMT-time: 13:15 (Sunday, 19-05-2013)

TopSubscribe to XML RSS for all Threads in all ForumsFedoraForumDotOrg Archive
logo

All trademarks, and forum posts in this site are property of their respective owner(s).
FedoraForum.org is privately owned and is not directly sponsored by the Fedora Project or Red Hat, Inc.

Privacy Policy | Term of Use | Posting Guidelines | Archive | Contact Us | Founding Members

Powered by vBulletin® Copyright ©2000 - 2012, vBulletin Solutions, Inc.

FedoraForum is Powered by RedHat