• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

GTX 1070 Firmware Overwritten by Malware - Unable to Reset

Status
Not open for further replies.
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
UEFI malware isn't so common but its a real thing.

Yep, I knew of it but only as demonstration proof of concept kits initially. This is really my first in the wild sighting.
 
Joined
Nov 1, 2017
Messages
521 (0.22/day)
After reading all of this story, I booked myself a week-end of maintenance to update everything I have on the network. I had a nightmare last night and it wasn't cool at all.

R-T-B professionalism is exemplar. I want to become as cool as you.

Let's all hope this story will have a good ending for MadBrit. I'd like to help but this sutation seems over my field of expertise. If you have issues with malware over the network or packets to examine I'm glad to help you guys.

Cheers!
 

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.66/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
Hardware level infection is as old as computers. You guys just came up in an era of modern OS's. Ask guys like @95Viper or some of the reviewers on this site and they will tell you this isn't all that uncommon when dealing with a particular kinds of people. Pedofiles and terrorists.

NOW I AM NOT ACCUSING ANYONE OF THAT! I'm just saying this kind of thing isn't as uncommon as you suspect and its really a very old way of infecting systems reserved for people on the dark web and state actors.

RTB has a big heart and I myself love to help people. With that being said I wouldn't give a jump start to someone with a ski mask outside of a bank. Sure maybe he just came off the slopes, but why risk it.

@MadBrit I want to be clear. Im not accusing you of any of that. I dont know you and I dont assume this of you. With that being said you come in the TPU forums with a hardware level infection people are going to be suspicious. Trust me its nothing personal. This is just a community watching out for each other. I wish you the best if what you say is true AND I hope you catch who is responsible.
 
Last edited:

the54thvoid

Intoxicated Moderator
Staff member
Joined
Dec 14, 2009
Messages
12,458 (2.38/day)
Location
Glasgow - home of formal profanity
Processor Ryzen 7800X3D
Motherboard MSI MAG Mortar B650 (wifi)
Cooling be quiet! Dark Rock Pro 4
Memory 32GB Kingston Fury
Video Card(s) Gainward RTX4070ti
Storage Seagate FireCuda 530 M.2 1TB / Samsumg 960 Pro M.2 512Gb
Display(s) LG 32" 165Hz 1440p GSYNC
Case Asus Prime AP201
Audio Device(s) On Board
Power Supply be quiet! Pure POwer M12 850w Gold (ATX3.0)
Software W10
Thankfully @R-T-B pulled the truth out of this. I was skeptical but few of use knew enough background to the initial post.
As for helping, I support R-T-B and what he's doing. This is what the forum is for. Real problems sometimes hit walls but @MadBrit persevered and that got him the help he wanted.
If we weren't Samaritans occasionally, we may as well just wall our borders, turn on our allies and eat burgers in bed. Altruism makes us better, paranoia might keep you alive, but it also keeps you alone.
Pay it back.
 

MadBrit

New Member
Joined
May 17, 2018
Messages
6 (0.00/day)
System Name HomeBuild
Processor Intel i7-7700K
Motherboard ASUS Z270F
Cooling Corsair H55 Hydro Series
Memory 32GB G.Skill Ripjaws V (PC4 25600)
Video Card(s) ASUS STRIX-GTX 1070 8G Gaming
Storage Samsung 850 Pro x 3, Crucial M4 (spare boot)
Display(s) LG 34UC79-G
Case Thermaltake View 31
Audio Device(s) N/A
Power Supply Thermaltake Toughpower 850W
Mouse Logitec
Keyboard Logitec
Software Win 10 1803
Benchmark Scores With or without malware infection?
@TheMailMan78 ; I understand your hesitancy and no offence intended. Lots of trolls out there. It has just been 8 weeks of hell and I am stoked that R-T-B was willing to listen when no one else was. Kinda overwhelmed by all of this actually. Not every day you get something like this show up - and I am asking "Why me?". Perhaps I pissed off the wrong person (only one person I know could do the job to this level and they are very vindictive). Perhaps this was a dry run on a non-critical target(s) to test the malware by a state actor? Who knows...but with $3K of infected hardware and 8+ weeks of lost work (plus 5 months of lost project work), I want to nail this malware and stop it before it does some real damage. That's where you guy's come in.
 

TheMailMan78

Big Member
Joined
Jun 3, 2007
Messages
22,599 (3.66/day)
Location
'Merica. The Great SOUTH!
System Name TheMailbox 5.0 / The Mailbox 4.5
Processor RYZEN 1700X / Intel i7 2600k @ 4.2GHz
Motherboard Fatal1ty X370 Gaming K4 / Gigabyte Z77X-UP5 TH Intel LGA 1155
Cooling MasterLiquid PRO 280 / Scythe Katana 4
Memory ADATA RGB 16GB DDR4 2666 16-16-16-39 / G.SKILL Sniper Series 16GB DDR3 1866: 9-9-9-24
Video Card(s) MSI 1080 "Duke" with 8Gb of RAM. Boost Clock 1847 MHz / ASUS 780ti
Storage 256Gb M4 SSD / 128Gb Agelity 4 SSD , 500Gb WD (7200)
Display(s) LG 29" Class 21:9 UltraWide® IPS LED Monitor 2560 x 1080 / Dell 27"
Case Cooler Master MASTERBOX 5t / Cooler Master 922 HAF
Audio Device(s) Realtek ALC1220 Audio Codec / SupremeFX X-Fi with Bose Companion 2 speakers.
Power Supply Seasonic FOCUS Plus Series SSR-750PX 750W Platinum / SeaSonic X Series X650 Gold
Mouse SteelSeries Sensei (RAW) / Logitech G5
Keyboard Razer BlackWidow / Logitech (Unknown)
Software Windows 10 Pro (64-bit)
Benchmark Scores Benching is for bitches.
Thankfully @R-T-B pulled the truth out of this. I was skeptical but few of use knew enough background to the initial post.
As for helping, I support R-T-B and what he's doing. This is what the forum is for. Real problems sometimes hit walls but @MadBrit persevered and that got him the help he wanted.
If we weren't Samaritans occasionally, we may as well just wall our borders, turn on our allies and eat burgers in bed. Altruism makes us better, paranoia might keep you alive, but it also keeps you alone.
Pay it back.
You say eating burgers in bed like its a bad thing.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
@TheMailMan78 ; I understand your hesitancy and no offence intended. Lots of trolls out there. It has just been 8 weeks of hell and I am stoked that R-T-B was willing to listen when no one else was. Kinda overwhelmed by all of this actually. Not every day you get something like this show up - and I am asking "Why me?". Perhaps I pissed off the wrong person (only one person I know could do the job to this level and they are very vindictive). Perhaps this was a dry run on a non-critical target(s) to test the malware by a state actor? Who knows...but with $3K of infected hardware and 8+ weeks of lost work (plus 5 months of lost project work), I want to nail this malware and stop it before it does some real damage. That's where you guy's come in.

The amount of dead sweet ssd you went through alone makes me want to cry...
 

cadaveca

My name is Dave
Joined
Apr 10, 2006
Messages
17,232 (2.62/day)
@TheMailMan78 ; I understand your hesitancy and no offence intended. Lots of trolls out there. It has just been 8 weeks of hell and I am stoked that R-T-B was willing to listen when no one else was. Kinda overwhelmed by all of this actually. Not every day you get something like this show up - and I am asking "Why me?". Perhaps I pissed off the wrong person (only one person I know could do the job to this level and they are very vindictive). Perhaps this was a dry run on a non-critical target(s) to test the malware by a state actor? Who knows...but with $3K of infected hardware and 8+ weeks of lost work (plus 5 months of lost project work), I want to nail this malware and stop it before it does some real damage. That's where you guy's come in.
It's super odd, beucase people that usually would be a vector for this would simply just buy new hardware and be done with it. I mean, that's how you really fix stuff like this. There is no real defense from an active attack once your system is known, and the minor costs you have raised are just that.. minor. Change your mac id, and you're golden. They don't toss out phones in movies when being tracked for no reason.

You know, privacy doesn't really exist any more these days, so why don't you fill in the blanks that people seem to be asking for? There's no reason to hide anything.


Because to me, this just looks like social engineering. Catfishing, some would call it.

The amount of dead sweet ssd you went through alone makes me want to cry...
Comments like this merely affirm my thinking. You're alluding to a private conversation in public. Why, exactly? Doesn't seem to be any other reason other than a lack of testosterone if you're being honest.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
You're alluding to a private conversation in public. Why, exactly? Doesn't seem to be any other reason other than a lack of testosterone if you're being honest.

Because dead 850 pros make baby jesus cry.

That said, I'll really let my client be the judge of if I have said a little or a lot, thanks.

I've also been collecting viral samples and have absolutely no doubt that he is infected.
 
Last edited:
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
ROFL. Triggered. I really wondered if you'd take that tact, but you did, and I'm happy.

Conspiracy confirmed.

So have fun.

Helping a client with computer malware issues is a conspiracy now?

I mean, yeah, he pays me when I fix it we agreed on that. Is that a conspiracy? I don't think it's much of one. If it is...

...

I guess I love me a conspiracy. But I tend to refer to them as "jobs."
 
Last edited:
Joined
Feb 19, 2006
Messages
6,270 (0.94/day)
Location
New York
Processor INTEL CORE I9-9900K @ 5Ghz all core 4.7Ghz Cache @1.305 volts
Motherboard ASUS PRIME Z390-P ATX
Cooling CORSAIR HYDRO H150I PRO RGB 360MM 6x120mm fans push pull
Memory CRUCIAL BALLISTIX 3000Mhz 4x8 32gb @ 4000Mhz
Video Card(s) EVGA GEFORECE RTX 2080 SUPER XC HYBRID GAMING
Storage ADATA XPG SX8200 Pro 1TB 3D NAND NVMe,Intel 660p 1TB m.2 ,1TB WD Blue 3D NAND,500GB WD Blue 3D NAND,
Display(s) 50" Sharp Roku TV 8ms responce time and Philips 75Hz 328E9QJAB 32" curved
Case BLACK LIAN LI O11 DYNAMIC XL FULL-TOWER GAMING CASE,
Power Supply 1600 Watt
Software Windows 10
the direction the thread is going is starting to turn sour....bummer!
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
the direction the thread is going is starting to turn sour....bummer!

I'm sorry for that. I'm keeping it to technical posts from here. Update likely this evening.

EDIT: Furthermore, sorry for biting your head off Dave. I let my pride here get the better of me.
 
Last edited:

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
Last edited:
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
The management engine held on to the bitter end refusing downgrades or removal... but my claims of infection there were seemingly unfounded ( was an odd version but the firmware is signed by intel so infection is kinda hard to do, probably legit). It seems we have cleansed the machine. MadBrit is reinstalling now. So far, so good.

EDIT:

Ok, we're infected again. It took a long long time to come up to full speed but there you have it.

I'm going to have him send me the board for a hardware dump and reflash via spi. I don't think we can get on fair footing with a malware uefi calling the shots like this.
 
Last edited:
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
Did you at least manage to disable ME other than what's needed on POST?
 
Joined
Sep 10, 2016
Messages
809 (0.29/day)
Location
Riverwood, Skyrim
System Name Storm Wrought | Blackwood (HTPC)
Processor AMD Ryzen 9 5900x @stock | i7 2600k
Motherboard Gigabyte X570 Aorus Pro WIFI m-ITX | Some POS gigabyte board
Cooling Deepcool AK620, BQ shadow wings 3 High Spd, stock 180mm |BQ Shadow rock LP + 4x120mm Noctua redux
Memory G.Skill Ripjaws V 2x32GB 4000MHz | 2x4GB 2000MHz @1866
Video Card(s) Powercolor RX 6800XT Red Dragon | PNY a2000 6GB
Storage SX8200 Pro 1TB, 1TB KC3000, 850EVO 500GB, 2+8TB Seagate, LG Blu-ray | 120GB Sandisk SSD, 4TB WD red
Display(s) Samsung UJ590UDE 32" UHD monitor | LG CS 55" OLED
Case Silverstone TJ08B-E | Custom built wooden case (Aus native timbers)
Audio Device(s) Onboard, Sennheiser HD 599 cans / Logitech z163's | Edifier S2000 MKIII via toslink
Power Supply Corsair HX 750 | Corsair SF 450
Mouse Microsoft Pro Intellimouse| Some logitech one
Keyboard GMMK w/ Zelio V2 62g (78g for spacebar) tactile switches & Glorious black keycaps| Some logitech one
VR HMD HTC Vive
Software Win 10 Edu | Ubuntu 22.04
Benchmark Scores Look in the various benchmark threads
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Did you at least manage to disable ME other than what's needed on POST?

Nope.

And given it's come back, it is again a suspect area.

This shit is unreal, frankly. It does not play fair on any level. Short of an external programmer, there can be no victory.
 
Joined
Mar 23, 2016
Messages
4,839 (1.64/day)
Processor Ryzen 9 5900X
Motherboard MSI B450 Tomahawk ATX
Cooling Cooler Master Hyper 212 Black Edition
Memory VENGEANCE LPX 2 x 16GB DDR4-3600 C18 OCed 3800
Video Card(s) XFX Speedster SWFT309 AMD Radeon RX 6700 XT CORE Gaming
Storage 970 EVO NVMe M.2 500 GB, 870 QVO 1 TB
Display(s) Samsung 28” 4K monitor
Case Phantek Eclipse P400S (PH-EC416PS)
Audio Device(s) EVGA NU Audio
Power Supply EVGA 850 BQ
Mouse SteelSeries Rival 310
Keyboard Logitech G G413 Silver
Software Windows 10 Professional 64-bit v22H2
Ah ok, didn't see the edit you appended to your one post even though I scrolled up earlier.
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
Ah ok, didn't see the edit you appended to your one post even though I scrolled up earlier.

If @W1zzard is ok I can start posting technical evidence here of the malware here in the form of infected UEFI DXEs, PEIs and such. I just don't know if it's a good idea seeing as it's relatively easy to inject bios modules and many of them can/could be abused, possibly even on other boards.

If anyone wants to help me on something that could really prove something, I need a stock, known uninfected Intel Management Firmware region file version 11.8.50.3399 to compare to his.

There appears to be one from lenovo but it is completely locked down by a device specific exe and unextractable.

https://support.lenovo.com/us/en/downloads/ds501133

EDIT: Found one from a gigabyte board, the z370 aorus gaming 7, bios f4. Extracted the stock region version 11.8.50.3399 and working on a comparison now.
 
Last edited:

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
If @W1zzard is ok I can start posting technical evidence here of the malware here in the form of infected UEFI DXEs, PEIs and such. I just don't know if it's a good idea seeing as it's relatively easy to inject bios modules and many of them can/could be abused, possibly even on other boards.

If anyone wants to help me on something that could really prove something, I need a stock, known uninfected Intel Management Firmware region file version 11.8.50.3399 to compare to his.

There appears to be one from lenovo but it is completely locked down by a device specific exe and unextractable.

https://support.lenovo.com/us/en/downloads/ds501133

He needs to do security hardening then, purge all other systems off the network, replace his modem and router, request a new ip address, update firmware of modem and router, add a hardware firewall if possible.

If @W1zzard is ok I can start posting technical evidence here of the malware here in the form of infected UEFI DXEs, PEIs and such. I just don't know if it's a good idea seeing as it's relatively easy to inject bios modules and many of them can/could be abused, possibly even on other boards.

If anyone wants to help me on something that could really prove something, I need a stock, known uninfected Intel Management Firmware region file version 11.8.50.3399 to compare to his.

There appears to be one from lenovo but it is completely locked down by a device specific exe and unextractable.

https://support.lenovo.com/us/en/downloads/ds501133

EDIT: Found one from a gigabyte board, the z370 aorus gaming 7, bios f4. Extracted the stock region version 11.8.50.3399 and working on a comparison now.

Heres some info that might help.

https://hothardware.com/news/resear...-off-intel-management-engine-11-thanks-to-nsa

https://www.csoonline.com/article/3...able-intel-me-backdoor-thanks-to-the-nsa.html

http://blog.ptsecurity.com/2017/08/disabling-intel-me.html?m=1
 
Last edited:
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
He needs to do security hardening then, purge all other systems off the network, replace his modem and router, request a new ip address, update firmware of modem and router, add a hardware firewall if possible.



Heres some info that might help.

https://hothardware.com/news/resear...-off-intel-management-engine-11-thanks-to-nsa

https://www.csoonline.com/article/3...able-intel-me-backdoor-thanks-to-the-nsa.html

http://blog.ptsecurity.com/2017/08/disabling-intel-me.html?m=1

I've tried all the me_cleaner based techniques already. It's using an intel anti-downgrade feature to refuse all flashes to the ME region from UEFI.
 

eidairaman1

The Exiled Airman
Joined
Jul 2, 2007
Messages
40,435 (6.58/day)
Location
Republic of Texas (True Patriot)
System Name PCGOD
Processor AMD FX 8350@ 5.0GHz
Motherboard Asus TUF 990FX Sabertooth R2 2901 Bios
Cooling Scythe Ashura, 2×BitFenix 230mm Spectre Pro LED (Blue,Green), 2x BitFenix 140mm Spectre Pro LED
Memory 16 GB Gskill Ripjaws X 2133 (2400 OC, 10-10-12-20-20, 1T, 1.65V)
Video Card(s) AMD Radeon 290 Sapphire Vapor-X
Storage Samsung 840 Pro 256GB, WD Velociraptor 1TB
Display(s) NEC Multisync LCD 1700V (Display Port Adapter)
Case AeroCool Xpredator Evil Blue Edition
Audio Device(s) Creative Labs Sound Blaster ZxR
Power Supply Seasonic 1250 XM2 Series (XP3)
Mouse Roccat Kone XTD
Keyboard Roccat Ryos MK Pro
Software Windows 7 Pro 64
I've tried all the me_cleaner based techniques already. It's using an intel anti-downgrade feature to refuse all flashes to the ME region from UEFI.

I heard the ime is built into the cpu/pch. If it was a separate chip on the board too bad there is no way of tricking the cpu/pch thinking it is there but is not...
 
Joined
Aug 20, 2007
Messages
20,787 (3.41/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage 2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64
I heard the ime is built into the cpu/pch. If it was a separate chip on the board too bad there is no way of tricking the cpu/pch thinking it is there but is not...

Built into the cpu die in latest revisions.

Anyhow, attaching a me-tools layout anlaylsis of clean stock firmware vs his. Both identify as version 11.8.50.3399. Inside they are quite different. Note the versions.

versions.png


The infected one is really 11.6.0.1126 inside, horrifically outdated, and most likely has sig level exploits that let them run code.

I'm going to start dumping and attempting to read the individual partitions. Need to compile minix's filesystem into my linux server's kernel first I bet.

But bottom line: I think short of hardware killing the management engine, we'll never defeat this thing. So yeah, he needs to send it in.
 
Status
Not open for further replies.
Top