Scanning hidden partitions

mjf

New member
Guru
Gold Member
VIP
Local time
6:11 AM
Messages
5,968
Location
Australia
When I run Malwarebytes it gives me the option to scan partitions assigned a letter but what about:
1) The hidden factory recovery partition
2) The System reserved (100MB partition
3) The MBR (first 512 bytes on HDD).

Can someone advise what software covers these areas for security checking?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1
I was under the impression that those areas could not be infected because they cannot be altered through any ordinary means. But I could be wrong. I've never heard of a program that can scan them.
 

My Computer

Computer Manufacturer/Model Number
Alienware X51
OS
Windows 7 Home Premium x64
CPU
Intel Core i7-2600 @3.40GHz
Memory
8.00GB DDR3
Graphics Card(s)
NVIDIA GeForce GTX 555 w/1.0GB RAM
Monitor(s) Displays
BenQ XL2420TX
Screen Resolution
1920x1080@120Hz
Hard Drives
1TB
PSU
330-watt
Keyboard
Logitech Wireless Illuminated Keyboard K800
Mouse
Razer Orochi
Internet Speed
Campus Internet
This is not an area I have any strength in and hence the post. I could envisage situations where code planted in those areas could cause havoc.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1

My Computer

Computer Manufacturer/Model Number
Hewlett Packard Compaq Presario CQ60-305au
OS
Windows Seven Home Premium 32bit SP1
CPU
AMD Athlon QI46 2.1Ghz
Motherboard
Wistron 303c
Memory
2048 Mb DDR2 SD RAM
Graphics Card(s)
NVidea GE GoForce 8200M G/256mb dedicated graphics memory
Sound Card
MCP78S NVidea high definition
Monitor(s) Displays
15.6" High definition Brightview Widescreen
Screen Resolution
1336x768
Hard Drives
Toshiba MK2555GSX ATA
The answer is yes they can become infected.

You have two easy options for scanning them:

1) Use a program that knows how to access them or
2) Boot on a CD/DVD AV recovery disc or in a *IX based OS that can scan them. -WS
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell OP7010
OS
Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
Memory
16GB
Monitor(s) Displays
4 Dell 24" LCD
Screen Resolution
1280x1024
Keyboard
Dell
Mouse
Dell Optical
Internet Speed
40meg
The answer is yes they can become infected.

You have two easy options for scanning them:

1) Use a program that knows how to access them or
2) Boot on a CD/DVD AV recovery disc or in a *IX based OS that can scan them. -WS
Are you able to comment on specific software?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1
Most AV software is supposed to scan them?? I don't rely on software, when I have an issue (virus or otherwise) I always boot off a CD and scan that way I know for sure.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell OP7010
OS
Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
Memory
16GB
Monitor(s) Displays
4 Dell 24" LCD
Screen Resolution
1280x1024
Keyboard
Dell
Mouse
Dell Optical
Internet Speed
40meg
Most AV software is supposed to scan them?? I don't rely on software, when I have an issue (virus or otherwise) I always boot off a CD and scan that way I know for sure.

:huh:What do you do exactly?
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1
Most AV software is supposed to scan them?? I don't rely on software, when I have an issue (virus or otherwise) I always boot off a CD and scan that way I know for sure.

:huh:What do you do exactly?

That can get complicated quickly, due to over 10 years of development. However if you want to get started like we did; download Ubuntu Desktop Edition v10.10 (32-bit). Burn the CD and then you can boot off it. Do a live boot (just boot the CD) don't do the install because you are not installing. Once the disk boots, go to the add applications and add the recommended Anti-Virus software. From there you can scan your machine and the Ubuntu will see all your partitions and the AV will scan them all. This is a bit cumbersome but will give you the basic idea of how this works. We have developed a CD that gives us utilities and AV to repair machines that will not boot or we suspect they have a virus on them. -WS

Download | Ubuntu
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Dell OP7010
OS
Windows 7 Enterprise (x64); Windows Server 2008 R2 (x64)
Memory
16GB
Monitor(s) Displays
4 Dell 24" LCD
Screen Resolution
1280x1024
Keyboard
Dell
Mouse
Dell Optical
Internet Speed
40meg
OK.
The Hirens boot CD (12.0 latest) is grub4dos based and has some AV utilities built in. They could be updated and new ones added.
I'm obviously not getting the reason for this AV checking to be done in a live boot environment ?

For the MBR with a stable partition structure, the MRB should be a static 512byte binary. A bit check of 2 small binaries is probably the safest check against inserted assembly code.
 

My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Own build
OS
Windows 7x64 Home Premium SP1
CPU
Intel i7 2600k
Motherboard
ASUS P8Z68 Deluxe
Memory
G.Skill Ripjaws (DDR3-1600) 2x4GB
Graphics Card(s)
Nvidia GeForce GTS 450; Intel HD Graphics 3000(GT2+)
Monitor(s) Displays
Dell Ultrasharp IPS panel U2311H, Samsung SyncMaster P2350
Screen Resolution
1920x1080
Hard Drives
Samsung 850 Pro SSD 256GB, Samsung SSD 840 120GB, Seagates 1TB Barracuda ST31000528AS x2
PSU
Seasonic M12II 520W
Case
Lian Li Lancool PC-K60
Cooling
Case: 1x120mm, 3x140mm CPU: Hyper 212+
Keyboard
Logitech MK520 (wireless)
Mouse
Logitech MK520
Internet Speed
6-7 Mbps
Antivirus
Norton Security Premium, Malwarebytes on 2 (MSE on 3rd PC)
Browser
FireFox
Other Info
Audio: Logitech Z523 2.1
Back
Top