MadBrit
New Member
- Joined
- May 17, 2018
- Messages
- 6 (0.00/day)
System Name | HomeBuild |
---|---|
Processor | Intel i7-7700K |
Motherboard | ASUS Z270F |
Cooling | Corsair H55 Hydro Series |
Memory | 32GB G.Skill Ripjaws V (PC4 25600) |
Video Card(s) | ASUS STRIX-GTX 1070 8G Gaming |
Storage | Samsung 850 Pro x 3, Crucial M4 (spare boot) |
Display(s) | LG 34UC79-G |
Case | Thermaltake View 31 |
Audio Device(s) | N/A |
Power Supply | Thermaltake Toughpower 850W |
Mouse | Logitec |
Keyboard | Logitec |
Software | Win 10 1803 |
Benchmark Scores | With or without malware infection? |
My situation is sad, but true. I have attached requested evidence / screenshots below. Please be very, very careful with the .rom file though. I do not want to be responsible for spreading whatever *that* is any further.
GPU-Z was blank when I first ran it - and thought it was a bug. I have flashed MB Bios's for years - this is my second or third GPU flash ever.
Background: My first post many weeks ago before Symantec got involved.
<Bleeping Computer Link>
https://www.bleepingcomputer.com/forums/t/673759/chinese-malware-infecting-bios-hidden-on-hdd/
After a few weeks of trying to fix this myself, I got Symantec involved. Symantec couldn't find anything (paid for their cleaning service) with their forensic tool and gave up after a few days. I offered to personally drive one of the SSD's down to MountainView and put it in the hands of a virus researcher, but the support people were in India / Philippians and probably don't know where MV is. Their level 3 support was atrocious and they believed *something was there* but couldn't say what. Friend at Cylance's response was the same. They are too busy...however, many of these GPU findings were made today - as were the SSD firmware mods - but I had my suspicions.
The GPU screenshots are after the first flash. Luckily, I saved the rom before flashing.
I believe it may have used Spectre or Meltdown for the inital infiltration / exploit. The main payload came in via email. It was a spear phishing email. EaseUS is involved in this somehow. I saw the email notification and Norton jumped into Heuristics mode then died. Also had malwarebytes installed...nada. Nothing else (other than a 2012 version of SuperantiSpyware I had on an old USB stick) could detect anything. SAS detected Rouge.Agent.Gen Nullo (BIN) but I think it was a FPositive. Dr. Web caught some obscure userblocker and Winlogon was modified in the reg.
"Why not just do a fresh install of the OS to the HD or get a new HD.??"
You didn't read the post properly. It is embedded in the system GPU / SSD / MB firmware BIOS. Not making this up. IT is not detectable in user space. I have reinstalled / LL formatted over 20 times in the last few months. Same thing every time.
My wife told me to go get a new laptop so that I can continue my business, but I objected as I couldn't find the infection source. I lost that fight and I now have a bricked ASUS laptop sitting here as a doorstop. Right now, I don't trust anything on the network.
For all you neighsayers out there - rather than taking pot shots at my request for help and accusing me of *whatever*, please try and make a positive suggestion that does not involve torching the box...although, it may just come to that.
Cheers!
Here are the supporting files. Have other screens to substantiate my claims....
Rom Files / IFR Dump
GPU-Z was blank when I first ran it - and thought it was a bug. I have flashed MB Bios's for years - this is my second or third GPU flash ever.
Background: My first post many weeks ago before Symantec got involved.
<Bleeping Computer Link>
https://www.bleepingcomputer.com/forums/t/673759/chinese-malware-infecting-bios-hidden-on-hdd/
After a few weeks of trying to fix this myself, I got Symantec involved. Symantec couldn't find anything (paid for their cleaning service) with their forensic tool and gave up after a few days. I offered to personally drive one of the SSD's down to MountainView and put it in the hands of a virus researcher, but the support people were in India / Philippians and probably don't know where MV is. Their level 3 support was atrocious and they believed *something was there* but couldn't say what. Friend at Cylance's response was the same. They are too busy...however, many of these GPU findings were made today - as were the SSD firmware mods - but I had my suspicions.
The GPU screenshots are after the first flash. Luckily, I saved the rom before flashing.
I believe it may have used Spectre or Meltdown for the inital infiltration / exploit. The main payload came in via email. It was a spear phishing email. EaseUS is involved in this somehow. I saw the email notification and Norton jumped into Heuristics mode then died. Also had malwarebytes installed...nada. Nothing else (other than a 2012 version of SuperantiSpyware I had on an old USB stick) could detect anything. SAS detected Rouge.Agent.Gen Nullo (BIN) but I think it was a FPositive. Dr. Web caught some obscure userblocker and Winlogon was modified in the reg.
"Why not just do a fresh install of the OS to the HD or get a new HD.??"
You didn't read the post properly. It is embedded in the system GPU / SSD / MB firmware BIOS. Not making this up. IT is not detectable in user space. I have reinstalled / LL formatted over 20 times in the last few months. Same thing every time.
My wife told me to go get a new laptop so that I can continue my business, but I objected as I couldn't find the infection source. I lost that fight and I now have a bricked ASUS laptop sitting here as a doorstop. Right now, I don't trust anything on the network.
For all you neighsayers out there - rather than taking pot shots at my request for help and accusing me of *whatever*, please try and make a positive suggestion that does not involve torching the box...although, it may just come to that.
Cheers!
Here are the supporting files. Have other screens to substantiate my claims....
Rom Files / IFR Dump
Attachments
-
NVFlash Screen Output.txt5.1 KB · Views: 715
-
CPU-Z CPU.PNG45.8 KB · Views: 811
-
CPU-Z GPU.PNG29.3 KB · Views: 791
-
Crucial_SSD_BIOS.PNG90.2 KB · Views: 789
-
GPU-Z Sensors Results.gif14.8 KB · Views: 708
-
GPU-Z Advanced Results.gif12.7 KB · Views: 720
-
GPU-Z Results.gif28.7 KB · Views: 759
-
BIOS_Update_ErrorMsg.PNG111.4 KB · Views: 735
-
Asus.GTX1070.Malware.infoRom.txt880 bytes · Views: 446
-
Asus.GTX1070.malware.Rom.txt258.5 KB · Views: 263