Jump to content


 


Register a free account to unlock additional features at BleepingComputer.com
Welcome to BleepingComputer, a free community where people like yourself come together to discuss and learn how to use their computers. Using the site is easy and fun. As a guest, you can browse and view the various discussions in the forums, but can not create a new topic or reply to an existing one unless you are logged in. Other benefits of registering an account are subscribing to topics and forums, creating a blog, and having no ads shown anywhere on the site.


Click here to Register a free account now! or read our Welcome Guide to learn how to use this site.

Photo

3MB Mystery Partition on HD survives multiple disk wipes


  • Please log in to reply
2 replies to this topic

#1 Tyler336

Tyler336

  • Members
  • 1 posts
  • OFFLINE
  •  
  • Local time:07:14 PM

Posted 19 November 2013 - 04:00 PM

Hi everyone,

 

I suspected a rootkit infection on my computer and used Active@ Killdisk from LSoft to completely wipe the drive.  The wipe itself seemed to go fine, but after it was finished, I opened up Active@ Partition Manager, and its showing a 3MB partition labelled BOOT(X:) is still on the drive.  I got some help from another forum, but so far this partition has proven just about impossible to remove.

 

So far it's survived:

 

Killdisk - full wipe

DBAN "Quick" nuke that took 3 hours

DBAN "Autonuke" that took 10+ hours

Multiple "Clean all" commands in Diskpart (the partition doesn't show when you list partitions)

Attempts to write zeroes manually using a disk editor

 

I've used Hdat2 to check if there were HPA/DCO areas on the drive, but the program says there are not.

 

The partition does not show in Linux Parted Magic, or in Windows 7 Partition Manager, or in the Windows 7 setup.  So far, the only partition manager that I've used that seems to see it is LSoft's Active@ Partition Manager.

 

Googling hasn't turned up much, except for a few references to the "Alureon" rootkit, which seems to work by creating a small hidden partition and then booting the computer from there:

 

http://forum.kaspersky.com/lofiversion/index.php/t226093.html

http://en.wikipedia.org/wiki/Alureon

 

I'll attach a screenshot.  Please help

 

Attached File  PartManager.JPG   113.19KB   1 downloads



BC AdBot (Login to Remove)

 


#2 JHMcG

JHMcG

  • Members
  • 242 posts
  • OFFLINE
  •  
  • Local time:09:14 PM

Posted 19 November 2013 - 08:23 PM

You could try doing a low level format of the entire HDD, but that would wipe everything on it.



#3 KingdomSeeker

KingdomSeeker

  • Members
  • 458 posts
  • OFFLINE
  •  
  • Gender:Male
  • Local time:08:14 PM

Posted 30 November 2013 - 11:26 PM

I believe that is normal. Every time I've partitioned a drive there's been unalocated space. It's put there to hold the boot files for your OS.






0 user(s) are reading this topic

0 members, 0 guests, 0 anonymous users