• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

GTX 1070 Firmware Overwritten by Malware - Unable to Reset

Status
Not open for further replies.

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
This should be Stickied too
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
This should be Stickied too

Gonna be a news piece if W1zzard lets me, I intend to investigate it to the fullest.

Right now I'm kinda under the weather or I'd be doing the writeup already, honestly.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Gonna be a news piece if W1zzard lets me, I intend to investigate it to the fullest.

Right now I'm kinda under the weather or I'd be doing the writeup already, honestly.

Been dealing with crud myself.
PS, my signature, does it look right?
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
PS, my signature, does it look right?
Untitled.png
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I would like to commend and thank @R-T-B for his effort and professionalism, you have truly set an example how to help others.

Salute!

I can't imagine how irritating it must have been for him trying to get help and having everyone think he was a troll. Personally, I'd like to appologize to him for that false assumption. I know, I know... it was really really easy to do and we're all guilty (I mean how often does this happen?) but picture being in his shoes where he frickin PAYS symantec to help him and they basically tell him they think he's full of crap... must've sucked. My sympathies.
 
Last edited:
Joined
Sep 10, 2016
Messages
809 (0.29/day)
Location
Riverwood, Skyrim
System Name Storm Wrought | Blackwood (HTPC)
Processor AMD Ryzen 9 5900x @stock | i7 2600k
Motherboard Gigabyte X570 Aorus Pro WIFI m-ITX | Some POS gigabyte board
Cooling Deepcool AK620, BQ shadow wings 3 High Spd, stock 180mm |BQ Shadow rock LP + 4x120mm Noctua redux
Memory G.Skill Ripjaws V 2x32GB 4000MHz | 2x4GB 2000MHz @1866
Video Card(s) Powercolor RX 6800XT Red Dragon | PNY a2000 6GB
Storage SX8200 Pro 1TB, 1TB KC3000, 850EVO 500GB, 2+8TB Seagate, LG Blu-ray | 120GB Sandisk SSD, 4TB WD red
Display(s) Samsung UJ590UDE 32" UHD monitor | LG CS 55" OLED
Case Silverstone TJ08B-E | Custom built wooden case (Aus native timbers)
Audio Device(s) Onboard, Sennheiser HD 599 cans / Logitech z163's | Edifier S2000 MKIII via toslink
Power Supply Corsair HX 750 | Corsair SF 450
Mouse Microsoft Pro Intellimouse| Some logitech one
Keyboard GMMK w/ Zelio V2 62g (78g for spacebar) tactile switches & Glorious black keycaps| Some logitech one
VR HMD HTC Vive
Software Win 10 Edu | Ubuntu 22.04
Benchmark Scores Look in the various benchmark threads
I'll be honest, I certainly fell into that trap yesterday, it just seemed too unreasonable at first sight
 
Joined
Feb 21, 2014
Messages
1,383 (0.37/day)
Location
Alabama, USA
Processor 5900x
Motherboard MSI MEG UNIFY
Cooling Arctic Liquid Freezer 2 360mm
Memory 4x8GB 3600c16 Ballistix
Video Card(s) EVGA 3080 FTW3 Ultra
Storage 1TB SX8200 Pro, 2TB SanDisk Ultra 3D, 6TB WD Red Pro
Display(s) Acer XV272U
Case Fractal Design Meshify 2
Power Supply Corsair RM850x
Mouse Logitech G502 Hero
Keyboard Ducky One 2
Wow this is some high-level stuff. I remember hearing about a scare a few years back where a BIOS could be infected through wifi, and once one was gone it spread to every other possible device in range. Not just on network, in range of the wireless device. I figured it was a little far out but with something like this happening maybe not....

Glad you guys are fixing it up.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Wow this is some high-level stuff. I remember hearing about a scare a few years back where a BIOS could be infected through wifi, and once one was gone it spread to every other possible device in range. Not just on network, in range of the wireless device. I figured it was a little far out but with something like this happening maybe not....

Glad you guys are fixing it up.

Yeah, it's still a ways from reaching that point. Even this, as advanced as it is, is pretty primitive compared to what that would take...

But honestly, this is illustrating an attack vector I never wanted to think about all the same.

I think bios vendors need to go all pascal and start signing their updates, and I'm a bios modder, so the fact that I am now advocating for that should tell you that I was deeply disturbed by what I found today.

By the way, pieces of it were found in the management engine firmware, which ASUS left conveniently outdated.. Just wow, ASUS/Intel. Wow. Intel antidowngrade is at present attempting to protect a malware infected image. :banghead:

We are calling it quits for tonight because we don't want to try a reinstall with it in the management engine... I'm actually making a modified firmware for him with the management engine disabled right now because this is a case study in how stupid the management engine is.

What my folder for this dissected malware bios currently looks like:



Yep, it's bedtime.
 

qubit

Overclocked quantum bit
Joined
Dec 6, 2007
Messages
17,865 (2.98/day)
Location
Quantum Well UK
System Name Quantumville™
Processor Intel Core i7-2700K @ 4GHz
Motherboard Asus P8Z68-V PRO/GEN3
Cooling Noctua NH-D14
Memory 16GB (2 x 8GB Corsair Vengeance Black DDR3 PC3-12800 C9 1600MHz)
Video Card(s) MSI RTX 2080 SUPER Gaming X Trio
Storage Samsung 850 Pro 256GB | WD Black 4TB | WD Blue 6TB
Display(s) ASUS ROG Strix XG27UQR (4K, 144Hz, G-SYNC compatible) | Asus MG28UQ (4K, 60Hz, FreeSync compatible)
Case Cooler Master HAF 922
Audio Device(s) Creative Sound Blaster X-Fi Fatal1ty PCIe
Power Supply Corsair AX1600i
Mouse Microsoft Intellimouse Pro - Black Shadow
Keyboard Yes
Software Windows 10 Pro 64-bit
I'm trying to scrub the bios now of malware and force flash it with a dos tool in hopes it won't reload itself.

All his storage devices are infected, like Kaspersky labs reports. His SSD doesn't even identify as genuine anymore. I told him to flash in dos, chuck them, and see if he can boot a clean usb.
This kind of infection has been technically possible for years, so I'm not completely surprised that someone was unlucky enough to get nailed by it.

I think it's about time that mobos and anything else with a BIOS had a hardware write protect link that has to be physically moved to the Write position to enable flashing (same concept as the write protect tab on the old floppy disc, for those of us old enough to remember). Sure, it's a bit of an inconvenience, but otherwise it can mean kissing goodbye to your hardware in many cases. Jeez.
 
Joined
Aug 11, 2014
Messages
866 (0.24/day)
Processor ryzen 5 5600x
Motherboard AB350m Pro4
Cooling custom loop
Memory TEAMGROUP T-Force TXKD416G3600HC18ADC01 16gbs XMP
Video Card(s) HP GTX1650 super 4gb
Storage MZVLB256HBHQ-000H1 PM981a (256GB)/3TB HDD
Display(s) Nitro XF243Y Pbmiiprx
Case Rosewill CULLINAN
Audio Device(s) onboard
Power Supply Corsair 750w
Mouse Best Buy Insignia
Keyboard Best Buy Insignia
Software Win 10 pro
This kind of infection has been technically possible for years, so I'm not completely surprised that someone was unlucky enough to get nailed by it.

I think it's about time that mobos and anything else with a BIOS had a hardware write protect link that has to be physically moved to the Write position to enable flashing (same concept as the write protect tab on the old floppy disc, for those of us old enough to remember). Sure, it's a bit of an inconvenience, but otherwise it can mean kissing goodbye to your hardware in many cases. Jeez.

this is not a bad idea and should be added as an extra layer of security.
 
D

Deleted member 163934

Guest
they claim they are from "cannoical" which is a linux distributor

You wrote the name wrong or it's actualy "cannoical"? I'm asking this because the company behind Ubuntu is named Canonical ( https://www.canonical.com/ ) .

So they basicaly gained access to his router/modem due to the fact that the firmware was not update (and they happy stop updating it fast in most cases). They either gained access to his pc after that or they just monitored his traffic and redirected it to some fake sites (they somehow needed to get the informations about his hardware). Decided that his UEFI bios is the right target and basicaly crafted a bios for his machine and flashed that bios.

Basicaly we are talking about an attack that clearly targeted him. Either someone decided that he has valuable informations that they could use (still don't see why would they make it so obvious, I would just steal the stuff I want silently and clean the machine when I got what I wanted without making the user of that machine aware of what I did and the user of that machine will not really figure out because there will be no sign and it will be as it was before after I'm done (no malicious files on his hdd/sdd, bioses clean because I would flash them to the normal ones, router/modem firmware clean because I would reflash it to normal one once i'm done); I put myself in the place of the bad guy and this is how I would do it) or he pissed off the wrong people or if he is having a bussiness someone wanted to cause him financial problems.

The ability to flash bioses in windows (OS level because it applies to Linux also) is a security hole to begin with. It allows bad things to happen way too easy...
 
Last edited by a moderator:
Joined
May 12, 2017
Messages
2,207 (0.87/day)
If it's that bad, you could flash new firmware for all devices on a new ROM (pre-programmed) on an external programmable device & solder it back to GFX, SSD & motherboard. This way you know their all 100% clean. That's what I would do, but the SSD could be a little bit tricky.

Same can be done to the laptop. Just solder in a new pre-programmed rom along with a new hard drive.

Then I would start to take a closer look at each bit of the old firmware to see what's written (if any).
 
Last edited:
Joined
May 18, 2009
Messages
2,748 (0.50/day)
Location
MN
System Name Personal / HTPC
Processor Ryzen 5900x / i5-4460
Motherboard Asrock x570 Phantom Gaming 4 /ASRock Z87 Extreme4
Cooling Corsair H100i / stock HSF
Memory 32GB DDR4 3200 / 8GB DDR3 1600
Video Card(s) EVGA XC3 Ultra RTX 3080Ti / EVGA RTX 3060 XC
Storage 500GB Pro 970, 250 GB SSD, 1TB & 500GB Western Digital / 2x 4TB & 1x 8TB WD Red, 2TB SSD & 4TB SSD
Display(s) Dell - S3220DGF 32" LED Curved QHD FreeSync Monitor / 50" LCD TV
Case CoolerMaster HAF XB Evo / CM HAF XB Evo
Audio Device(s) Logitech G35 headset
Power Supply 850W SeaSonic X Series / 750W SeaSonic X Series
Mouse Logitech G502
Keyboard Black Microsoft Natural Elite Keyboard
Software Windows 10 Pro 64 / Windows 10 Pro 64
I can't imagine how irritating it must have been for him trying to get help and having everyone think he was a troll. Personally, I'd like to appologize to him for that false assumption. I know, I know... it was really really easy to do and we're all guilty (I mean how often does this happen?) but picture being in his shoes where he frickin PAYS symantec to help him and they basically tell him they think he's full of crap... must've sucked. My sympathies.

I've got a couple of friends that work at Veritas. One of them is a mid-level manager and he was happy as hell once Symantec sold off Veritas. He said a lot of the engineers working on the Norton AV department were worthless; not all of them, but a good majority he had worked around. He also said there was a good bit of mismanagement happening behind the scenes, too. It doesn't surprise me if the OP had to deal with some folks at Symantec that were rather clueless or just unwilling to help.
 
Joined
Sep 17, 2014
Messages
20,947 (5.97/day)
Location
The Washing Machine
Processor i7 8700k 4.6Ghz @ 1.24V
Motherboard AsRock Fatal1ty K6 Z370
Cooling beQuiet! Dark Rock Pro 3
Memory 16GB Corsair Vengeance LPX 3200/C16
Video Card(s) ASRock RX7900XT Phantom Gaming
Storage Samsung 850 EVO 1TB + Samsung 830 256GB + Crucial BX100 250GB + Toshiba 1TB HDD
Display(s) Gigabyte G34QWC (3440x1440)
Case Fractal Design Define R5
Audio Device(s) Harman Kardon AVR137 + 2.1
Power Supply EVGA Supernova G2 750W
Mouse XTRFY M42
Keyboard Lenovo Thinkpad Trackpoint II
Software W10 x64
fix them the hard way...

Oh I remember that punch like yesterday. Kudos for these efforts and your insights in the matter. I'm learning things ;)
 

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.66/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
RTB I cant help but think you are making a mistake helping this guy. Call it the Miami in me, but helping strangers with really odd problems never works out well. Ever. Fixing this guys issue might be more than you expect. You might be abiding a crime within a crime. Savvy?

Honestly I would hand this over to the FBI. If its legit they will handle it. If hes not in the US I would still hand it over. Explain exactly what happened and what you did. Be 100% transparent. An infection like this seems to be way more than whats on the surface.

I may disagree with you on dumb topics but, I would hate to see a good member of our community get pinched for trying to do the right thing for the wrong person.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Oh I remember that punch like yesterday. Kudos for these efforts and your insights in the matter. I'm learning things ;)

My bios skills are signifigantly better than my thermal paste skills. ;)

RTB I cant help but think you are making a mistake helping this guy. Call it the Miami in me, but helping strangers with really odd problems never works out well. Ever. Fixing this guys issue might be more than you expect. You might be abiding a crime within a crime. Savvy?

Honestly I would hand this over to the FBI. If its legit they will handle it. If hes not in the US I would still hand it over. Explain exactly what happened and what you did. Be 100% transparent. An infection like this seems to be way more than whats on the surface.

I know man, and I was suspicious initially too. He WANTS to go to law enforcement though and is cooperating completely. Makes me feel much better.

That, and all the modified modules are from asus or ASMedia. I think he's correct a leak or person in china may have let some source go. I might even be wrong about the one american binary (Intel ME) because it seems the update to it is signed.
 
Last edited:

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.66/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
My bios skills are signifigantly better than my thermal paste skills. ;)



I know man, and I was suspicious initially too. He WANTS to go to law enforcement though and is cooperating completely. Makes me feel much better.

That, and all the modified modules are from asus or asrock. I think he's correct a leak or person in china may have let some source go.
YOU need to go to the FBI. Not him. First man to the boat makes the deals. This could easily get tossed back on to you.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
YOU need to go to the FBI. Not him. First man to the boat makes the deals. This could easily get tossed back on to you.

I have a feeling if I send them the mess I have now I'll get ignored. My research is just starting and I want to show them real evidence they can't ignore. Sending the fbi a "malware bios.zip" and saying you got these modules from a clients computer probably won't get attention (unless it infects them lol).

That, and everything I have done thus far has been completely legal consultation work. I appreciate it mailman but I have this one covered I think.

Though, if I end up in jail, you guys visit me.
 

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.66/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
I have a feeling if I send them the mess I have now I'll get ignored. My research is just starting and I want to show them real evidence they can't ignore. Sending the fbi a "malware bios.zip" and saying you got these modules from a clients computer probably won't get attention (unless it infects them lol).

That, and everything I have done thus far has been completely legal consultation work. I appreciate it mailman but I have this one covered I think.
Well if nothing else its all pubic via the forum. Personally I would drop the mic on this one. Again I grew up in Miami during the 80's. Helping strangers with odd problems is a big "no, no". Good way to end up in jail or dead. ANYWAYS......I wish you luck man! I hope its all on the up and up and you don't get infected too lol

On a side note you send the FBI a "malware bios.zip" they might ignore. Send them "TRUMP-USSR-DOCUMENTS.zip" and you might get their attention lol
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I already am dropping the mic besides telling tech details and success / failure reports on removal.

I know a lot more than I've said here about the whole story, but that's none of your guys business, no offense intended.

Probably should not have even said that, frankly... going to shut up now. :laugh:
 

FreedomEclipse

~Technological Technocrat~
Joined
Apr 20, 2007
Messages
23,380 (3.76/day)
Location
London,UK
System Name Codename: Icarus Mk.VI
Processor Intel 8600k@Stock -- pending tuning
Motherboard Asus ROG Strixx Z370-F
Cooling CPU: BeQuiet! Dark Rock Pro 4 {1xCorsair ML120 Pro|5xML140 Pro}
Memory 32GB XPG Gammix D10 {2x16GB}
Video Card(s) ASUS Dual Radeon™ RX 6700 XT OC Edition
Storage Samsung 970 Evo 512GB SSD (Boot)|WD SN770 (Gaming)|2x 3TB Toshiba DT01ACA300|2x 2TB Crucial BX500
Display(s) LG GP850-B
Case Corsair 760T (White)
Audio Device(s) Yamaha RX-V573|Speakers: JBL Control One|Auna 300-CN|Wharfedale Diamond SW150
Power Supply Corsair AX760
Mouse Logitech G900
Keyboard Duckyshine Dead LED(s) III
Software Windows 10 Pro
Benchmark Scores (ノಠ益ಠ)ノ彡┻━┻

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.66/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
I already am dropping the mic besides telling tech details and success / failure reports on removal.

I know a lot more than I've said here about the whole story, but that's none of your guys business, no offense intended.

Probably should not have even said that, frankly... going to shut up now. :laugh:
Dude I wouldn't want details even if you wanted to share them. The less I know the better.
 

MadBrit

New Member
Joined
May 17, 2018
Messages
6 (0.00/day)
System Name HomeBuild
Processor Intel i7-7700K
Motherboard ASUS Z270F
Cooling Corsair H55 Hydro Series
Memory 32GB G.Skill Ripjaws V (PC4 25600)
Video Card(s) ASUS STRIX-GTX 1070 8G Gaming
Storage Samsung 850 Pro x 3, Crucial M4 (spare boot)
Display(s) LG 34UC79-G
Case Thermaltake View 31
Audio Device(s) N/A
Power Supply Thermaltake Toughpower 850W
Mouse Logitec
Keyboard Logitec
Software Win 10 1803
Benchmark Scores With or without malware infection?
YOU need to go to the FBI. Not him. First man to the boat makes the deals. This could easily get tossed back on to you.

No offense, but it sounds like Miami did a number on you Mailman78. Sorry about that. I have been 100% transparent and WANT this to escalate. If this type of device to device firmware infection is possible and gets into Critical Infrastructure, we're toast. Undetectable at enterprise level (or any level) with existing AV solutions. That's scary stuff. I have worked for 3 AV companies and other enterprise security companies and I know malware when I see it. I was just looking in the wrong space. Clearly, I'm non-technical compared to the Ninja's on this board.

I will personally walk into FBI headquarters with RTB leading the way if need be. Nothing to hide here. RTB is really on his game and I appreciate his expertise. He took the time to review the evidence then acted on it. He sets an exemplary example of helping someone without judgement - that some here fail to grasp. Isn't that the point of this forum in the first place? Otherwise, why are you here?
 
Last edited:
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
No offense, but it sounds like Miami did a number on you Mailman78. Sorry about that. I have been 100% transparent and WANT this to escalate. If this type of malware is possible and gets into Critical Infrastructure, we're toast. Undetectable at enterprise level (or any level) with existing AV solutions. That's scary stuff. I have worked for 3 AV companies and other enterprise security companies and I know malware when I see it. I was just looking in the wrong space. Clearly, I'm non-technical compared to the Ninja's on this board.

I will personally walk into FBI headquarters with RTB leading the way if need be. Nothing to hide here. RTB is really on his game and I appreciate his expertise. He took the time to review the evidence then acted on it. He sets an exemplary example of helping someone without judgement - that some here fail to grasp. Isn't that the point of this forum in the first place? Otherwise, why are you here?

Keep in mind mailman is known around these parts for his.... can I just say "different bedside manner?" :laugh:

I'm certain he wants the same thing you want he's just a natural skeptic of things like this. Don't take it personally.
 
Status
Not open for further replies.
Top