• Welcome to TechPowerUp Forums, Guest! Please check out our forum guidelines for info related to our community.

Probable mining virus or simple virus infection after flashing BIOS

Chipe

New Member
Joined
Jun 28, 2023
Messages
6 (0.02/day)
Let me tell you about my experience...

I have an Asus P6T Deluxe V2 motherboard with the X58 chipset (yes, quite old; I've had it since it was new, about 10 years ago, I believe). A few months ago, I decided to install an M.2 drive. I purchased a PCIe card and the M.2 drive. To my surprise, the system (BIOS) didn't recognize it. I spent some time searching for solutions and only found a boot loader on a USB drive that serves as a bridge for booting up. Well, while browsing forums (TechPowerUp Forums), I came across a technician (İsmailTPC_Hastanesi), it seems he's from Turkey, and if you know him i mean his work you know, he is the man! the master for that, also the comments and gratitude regarding his work and assistance were all positive, he is a crack on the topic. he help the people to modifies X58 BIOS he already have alot of firmware for several mothers.

I have an XPG M.2, apparently not on the firmware's list. When I sent him the M.2's code information for he enters the code lines on his firmware and work, it was too late; he announced that he couldn't help anymore because it takes too much time and he has obligations at work.

I wrote to ask for his help, offering compensation for his work, but he didn't respond. However, another forum member sent me a message (inbox), offering to help for the same compensation to add the M.2 to the firmware. I agreed, sent the information, but after some time, nothing happened. After several weeks, he contacted me, sent it, and said that if it worked, I should help with the compensation. Everything worked smoothly without any issues. I tried to contact him to express my gratitude and compensate him, but he never responded again.

I have an i7 950 3.07GHz with a liquid cooling AIO Cougar Gamer 120m, and here's where it all begins. Suddenly, the temperature gradually rises from one moment to another, reaching up to 100 degrees without having many apps open or using a significant percentage of CPU. Obviously, before it reaches the peak, I turn it off and wait for it to cool down, sometimes until for a couple of hours or more. When I turn it back on isn’t goes back to normal continue up the temperature it seems almost in the same point that turned it off. But when this one not happened the CPU working well at 25 or 30 degrees, even when using multiple programs. Currently, as I write this, it's at 27 degrees, and even when gaming and performing other tasks simultaneously, it only goes up to 70 or 75 degrees.

Even without entering Windows, just in the BIOS, the temperature keeps rising to the maximum and reaches 100, either inside the BIOS or within Windows. After reaching the peak, whether only in the BIOS or in Windows, it either shuts down on its own or I turn it off, and when I restart it without waiting for it to cool down, it works normally, returning to its normal levels, as if reaching 100 degrees were a task, and once completed, it returns to normal levels.

I think it could be a virus in the BIOS mining, causing the processor to accelerate and overheat. A virus that cannot be detected or removed because it's in the BIOS and activates from time to time, pushing it to the limit for intense mining. It's also possible that the BIOS is corrupted from being modified by a third party, infected or is incorrectly modified by the firmware modified by the forum member (not İsmailTPC_Hastanesi). If so, I can't revert to the original manufacturer's BIOS because I lose access to the M.2 and, consequently, the entire system.

my big quesiton... Is it possible for this to happen? it is a virus in the bios, what can I do to detect it and if positive, eliminate it?

Or could it be a problem with some other hardware like CPU or some other compon of the motherboard, could it be the AIO cooling? The strangest thing is that... the CPU heats up, it goes up, it doesn't go down until it reaches 100 degrees, after that it returns to normal temperature with any out wait time for cooling. It is worth mentioning that the percentage of CPU used is not greater than 20% or maximum 30% when the CPU is already reaching its maximum 100 degrees.

Greetings in advance and thank you for your support.
 

izy

Joined
Jun 30, 2022
Messages
950 (1.25/day)
You should replace your CPU thermal paste and check if the fan from the cooler is working and that the cooler is correctly mounted, i dont think you have any mining virus in your bios , at worst i think it can be bugged, you can always reflash the original bios back.

 

Toothless

Tech, Games, and TPU!
Supporter
Joined
Mar 26, 2014
Messages
9,450 (2.50/day)
Location
Washington, USA
System Name Veral
Processor 5950x
Motherboard Asus Crosshair VIII Hero Wi-Fi
Cooling Corsair H150i RGB Elite
Memory 2x16GB G.Skill TridentZ
Video Card(s) Powercolor 7900XTX Red Devil
Storage Crucial P5 Plus 1TB, Samsung 980 1TB, Teamgroup MP34 4TB
Display(s) Acer Nitro XZ342CK Pbmiiphx + 2x AOC 2425W
Case Fractal Design Meshify Lite 2
Audio Device(s) Blue Yeti + SteelSeries Arctis 5 / Samsung HW-T550
Power Supply Corsair HX850
Mouse Corsair Nightsword
Keyboard Corsair K55
VR HMD HP Reverb G2
Software Windows 11 Professional
Benchmark Scores PEBCAK
Flash a proper bios from Asus and honestly, accept the sata SSD speeds. NVME can be used for fast storage and if you're really, really needing NVME boot there is only one thread on this forum that has a huge bank of x58 modded bios files. I don't have a link to it sadly.

This is just something I personally wouldn't do to either of my x58 boards.
 

izy

Joined
Jun 30, 2022
Messages
950 (1.25/day)
Let me tell you about my experience...

I have an Asus P6T Deluxe V2 motherboard with the X58 chipset (yes, quite old; I've had it since it was new, about 10 years ago, I believe). A few months ago, I decided to install an M.2 drive. I purchased a PCIe card and the M.2 drive. To my surprise, the system (BIOS) didn't recognize it. I spent some time searching for solutions and only found a boot loader on a USB drive that serves as a bridge for booting up. Well, while browsing forums (TechPowerUp Forums), I came across a technician (İsmailTPC_Hastanesi), it seems he's from Turkey, and if you know him i mean his work you know, he is the man! the master for that, also the comments and gratitude regarding his work and assistance were all positive, he is a crack on the topic. he help the people to modifies X58 BIOS he already have alot of firmware for several mothers.

I have an XPG M.2, apparently not on the firmware's list. When I sent him the M.2's code information for he enters the code lines on his firmware and work, it was too late; he announced that he couldn't help anymore because it takes too much time and he has obligations at work.

I wrote to ask for his help, offering compensation for his work, but he didn't respond. However, another forum member sent me a message (inbox), offering to help for the same compensation to add the M.2 to the firmware. I agreed, sent the information, but after some time, nothing happened. After several weeks, he contacted me, sent it, and said that if it worked, I should help with the compensation. Everything worked smoothly without any issues. I tried to contact him to express my gratitude and compensate him, but he never responded again.

I have an i7 950 3.07GHz with a liquid cooling AIO Cougar Gamer 120m, and here's where it all begins. Suddenly, the temperature gradually rises from one moment to another, reaching up to 100 degrees without having many apps open or using a significant percentage of CPU. Obviously, before it reaches the peak, I turn it off and wait for it to cool down, sometimes until for a couple of hours or more. When I turn it back on isn’t goes back to normal continue up the temperature it seems almost in the same point that turned it off. But when this one not happened the CPU working well at 25 or 30 degrees, even when using multiple programs. Currently, as I write this, it's at 27 degrees, and even when gaming and performing other tasks simultaneously, it only goes up to 70 or 75 degrees.

Even without entering Windows, just in the BIOS, the temperature keeps rising to the maximum and reaches 100, either inside the BIOS or within Windows. After reaching the peak, whether only in the BIOS or in Windows, it either shuts down on its own or I turn it off, and when I restart it without waiting for it to cool down, it works normally, returning to its normal levels, as if reaching 100 degrees were a task, and once completed, it returns to normal levels.

I think it could be a virus in the BIOS mining, causing the processor to accelerate and overheat. A virus that cannot be detected or removed because it's in the BIOS and activates from time to time, pushing it to the limit for intense mining. It's also possible that the BIOS is corrupted from being modified by a third party, infected or is incorrectly modified by the firmware modified by the forum member (not İsmailTPC_Hastanesi). If so, I can't revert to the original manufacturer's BIOS because I lose access to the M.2 and, consequently, the entire system.

my big quesiton... Is it possible for this to happen? it is a virus in the bios, what can I do to detect it and if positive, eliminate it?

Or could it be a problem with some other hardware like CPU or some other compon of the motherboard, could it be the AIO cooling? The strangest thing is that... the CPU heats up, it goes up, it doesn't go down until it reaches 100 degrees, after that it returns to normal temperature with any out wait time for cooling. It is worth mentioning that the percentage of CPU used is not greater than 20% or maximum 30% when the CPU is already reaching its maximum 100 degrees.

Greetings in advance and thank you for your support.
Here you go , i found a modded bios for your MB on TPU:

 

Chipe

New Member
Joined
Jun 28, 2023
Messages
6 (0.02/day)
Deberías reemplazar la pasta térmica de tu CPU y verificar si el ventilador del disipador está funcionando y si el disipador está montado correctamente. No creo que tengas ningún virus de minería en tu BIOS. En el peor de los casos, creo que puede tener errores, siempre puedes actualizar. la bios original de vuelta.

https://www.asus.com/us/supportonly/p6t deluxe v2/helpdesk_bios/

You should replace your CPU thermal paste and check if the fan from the cooler is working and that the cooler is correctly mounted, i dont think you have any mining virus in your bios , at worst i think it can be bugged, you can always reflash the original bios back.

At first it was what I thought, changing the paste, I already did it with Thermal Grizzly Kryonaut but it continued the same,

the fan works well, the unit is new from a few months ago

one of the biggest problems is not being able to return to the original bios because It does not have support for m.2 and you would lose access to the system :(
 

izy

Joined
Jun 30, 2022
Messages
950 (1.25/day)
At first it was what I thought, changing the paste, I already did it with Thermal Grizzly Kryonaut but it continued the same,

the fan works well, the unit is new from a few months ago

one of the biggest problems is not being able to return to the original bios because It does not have support for m.2 and you would lose access to the system :(
Well im still thinking that is something wrong with your cooler but if you say its ok maybe it is , i linked you in the other post a modded bios with NVME support for your MB.
 
Joined
Feb 18, 2005
Messages
5,562 (0.78/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Logitech G613
Software Windows 10 Professional x64
The fact that you needed to mod your BIOS to make an M.2 drive work should be a hint to you that it's time to upgrade your system. Only an idiot flashes a BIOS modded by a random person on the Internet.

Here you go , i found a modded bios for your MB on TPU:

Read that topic FFS. The specific ID of the NVMe drive needs to be modded into the BIOS, so that likely isn't going to work for OP. It's also being done by the same user mentioned by OP, who has stopped doing this.

one of the biggest problems is not being able to return to the original bios because It does not have support for m.2 and you would lose access to the system :(
Tough shit. You should've thought about that before you did stupid shit like this.
 
Last edited:

izy

Joined
Jun 30, 2022
Messages
950 (1.25/day)
The fact that you needed to mod your BIOS to make an M.2 drive work should be a hint to you that it's time to upgrade your system. Only an idiot flashes a BIOS modded by a random person on the Internet.


Read that topic FFS. The specific ID of the NVMe drive needs to be modded into the BIOS, so that likely isn't going to work for OP. It's also being done by the same user mentioned by OP, who has stopped doing this.


Tough shit. You should've thought about that before you did stupid shit like this.
Yeah my bad, its not that hard to mod it yourself anyway, there are some guides on winraid but if you are a inexperienced with this stuff then better leave it alone , very high chance to brick the MB.

Well im still thinking that is something wrong with your cooler but if you say its ok maybe it is , i linked you in the other post a modded bios with NVME support for your MB.
Maybe you can dump your current bios and try the original one and see if it fixes the problem , if its a bios problem you dont need the modded one anyway but if you can dump your bios and it wasnt the bios fault you can flash it back.

You can also get a normal SATA drive for the OS and use the NVME for games or what else you like , as far as i know you dont need a modded bios to use it as a non boot drive.
 
Last edited:

Hugis

Moderator
Staff member
Joined
Mar 28, 2010
Messages
819 (0.16/day)
Location
Spain(Living) / UK(Born)
System Name Office / Gamer Mk IV
Processor i5 - 12500
Motherboard TUF GAMING B660-PLUS WIFI D4
Cooling Themalright Peerless Assassin 120 RGB
Memory 32GB (2x16) Corsair CMK32GX4M2D3600C18 "micron B die"
Video Card(s) UHD770 / PNY 4060Ti (www.techpowerup.com/review/pny-geforce-rtx-4060-ti-verto)
Storage P41Plat - SN770 - 980Pro - BX500
Display(s) Philips 246E9Q 75Hz @ 1920 * 1080
Case Corsair Carbide 200R
Audio Device(s) Realtek ALC897 (On Board)
Power Supply Cooler Master V750 Gold v2
Mouse Rii M01(3360Sensor)
Keyboard Logitech S530 - mac
Software Windows 11 Pro
Joined
Oct 17, 2021
Messages
807 (0.80/day)
Location
People's Republic of Banania
Processor Threadripper 3955WX
Motherboard M12SWA-TF
Cooling Arctic Freezer 4U SP3
Memory G.Skill Trident Z DDR4-3733 (2x8GB)
Video Card(s) 5700XT + 3x RX 590
Storage A lot
Display(s) ViewSonic G225fB
Case Corsair 760T
Audio Device(s) Sound Blaster Z SE
Power Supply be quiet! DPP12 1500W
Keyboard IBM F122
Software 10 LTSC
I think it could be a virus in the BIOS mining, causing the processor to accelerate and overheat. A virus that cannot be detected or removed because it's in the BIOS and activates from time to time, pushing it to the limit for intense mining.
Any actual proof of this? if fire up task manager to see what's eating all the processing power does it display anything? sort by CPU usage, mining stuff is usually heavy on RAM as well so if you see any process, perhaps disguised as svchost.exe (classic move) that's using up 100% of the CPU and a high amount of memory (I'd say over 1GB is super sus for a service process).

Another one. When you notice high CPU usage go ahead and unplug the ethernet cable, if it goes down again then it's definitely some sort of malware connecting to the internet, though CPU mining is rare... it gives you less than a penny a DAY with a good chip nowadays (hello, it's not 2012 anymore) so it's odd someone would go this route.

Rootkits run code that downloads malware to your hard drive, as the ROM size is small it can't run from there it has to call home to do its thing. They either infect the MBR by making use of the elevated access or operate at OS level to download more files, either way the working principles are almost the same. If the MBR is infected you'll have to wipe and rewrite, all of it, all drives, if not just reflash the BIOS with a 'normal' image file.

I'm more inclined to the AIO being crap, because you know, they tend to behave in funny ways, a clogged block might cause seemingly random temp spikes, if there's fungal growth or something on the loop it might go round with the pump until it clogs the impeller or gets stuck in the block, who knows... I've opened my fair amount of units and the coolant gets nasty after a few years of use, months if we're talking noname stuff, but it's usually the pump electronics that start failing before the coolant goes bad.

Some oldtimers might say "But Caroline, reflashing the BIOS won't fix it as sometimes the rootkits infect memory bits that aren't overwritten during reflashing!" and... you're right, that case you'll have to physically clear or replace the chip, but honestly what are the odds? why go to these lengths to infect a single, random computer? to try and mine dead cryptocurrencies? siphon out data of some anon on a forum? makes no sense at least to me, of course it could be an scriptkiddie with access to decent code and too much free time, but still...

As I said, I bet the cooler is the culprit here, try with the stock cooler if you still have it.
 
Joined
Aug 20, 2007
Messages
21,021 (3.40/day)
System Name Pioneer
Processor Ryzen R9 7950X
Motherboard GIGABYTE Aorus Elite X670 AX
Cooling Noctua NH-D15 + A whole lotta Sunon and Corsair Maglev blower fans...
Memory 64GB (4x 16GB) G.Skill Flare X5 @ DDR5-6000 CL30
Video Card(s) XFX RX 7900 XTX Speedster Merc 310
Storage Intel 905p Optane 960GB boot, +2x Crucial P5 Plus 2TB PCIe 4.0 NVMe SSDs
Display(s) 55" LG 55" B9 OLED 4K Display
Case Thermaltake Core X31
Audio Device(s) TOSLINK->Schiit Modi MB->Asgard 2 DAC Amp->AKG Pro K712 Headphones or HDMI->B9 OLED
Power Supply FSP Hydro Ti Pro 850W
Mouse Logitech G305 Lightspeed Wireless
Keyboard WASD Code v3 with Cherry Green keyswitches + PBT DS keycaps
Software Gentoo Linux x64 / Windows 11 Enterprise IoT 2024
Only an idiot flashes a BIOS modded by a random person on the Internet.
As a former bios modder, this is true lads. Only trust bioses modded by frogs.

dead cryptocurrencies
I wish they were dead. They aren't, but cpu mining pretty much is. That's good enough to rule this out.
 
Joined
Feb 18, 2005
Messages
5,562 (0.78/day)
Location
Ikenai borderline!
System Name Firelance.
Processor Threadripper 3960X
Motherboard ROG Strix TRX40-E Gaming
Cooling IceGem 360 + 6x Arctic Cooling P12
Memory 8x 16GB Patriot Viper DDR4-3200 CL16
Video Card(s) MSI GeForce RTX 4060 Ti Ventus 2X OC
Storage 2TB WD SN850X (boot), 4TB Crucial P3 (data)
Display(s) 3x AOC Q32E2N (32" 2560x1440 75Hz)
Case Enthoo Pro II Server Edition (Closed Panel) + 6 fans
Power Supply Fractal Design Ion+ 2 Platinum 760W
Mouse Logitech G602
Keyboard Logitech G613
Software Windows 10 Professional x64
As a former bios modder, this is true lads. Only trust bioses modded by frogs.
I always forget to add "or frog".
 
Joined
Dec 25, 2020
Messages
5,464 (4.17/day)
Location
São Paulo, Brazil
System Name "Icy Resurrection"
Processor 13th Gen Intel Core i9-13900KS Special Edition
Motherboard ASUS ROG MAXIMUS Z790 APEX ENCORE
Cooling Noctua NH-D15S upgraded with 2x NF-F12 iPPC-3000 fans and Honeywell PTM7950 TIM
Memory 32 GB G.SKILL Trident Z5 RGB F5-6800J3445G16GX2-TZ5RK @ 7600 MT/s 36-44-44-52-96 1.4V
Video Card(s) ASUS ROG Strix GeForce RTX™ 4080 16GB GDDR6X White OC Edition
Storage 500 GB WD Black SN750 SE NVMe SSD + 4 TB WD Red Plus WD40EFPX HDD
Display(s) 55-inch LG G3 OLED
Case Pichau Mancer CV500 White Edition
Power Supply EVGA 1300 G2 1.3kW 80+ Gold
Mouse Microsoft Classic Intellimouse
Keyboard Galax Stealth STL-03
Software Windows 11 IoT Enterprise LTSC 24H2
Benchmark Scores I pulled a Qiqi~
Honestly there is a time to face the music. You have a 15 year old machine. With a 15 year old processor. You don't need NVMe on that. You need a whole new computer but in the meantime, original BIOS + A SATA drive.

Honestly tin foil about a bios level rootkit dropper would maybe be funny or worth it if OP ran a state of the art Sapphire Rapids workstation... It's a old as dirt 45 nm Bloomy (not even extreme edition) on an old as dirt motherboard with slow as snails that play in said dirt RAM, so honestly I don't think so. Most phones are faster than OP's desktop today, CPU mining on that is simply not viable.
 
Top