My computer has been hacked badly, and any help would be appreciated.
I have tried virus scans, format + reinstall, linux + windows, nuke+boot, AV rescue discs, live cds, clearing cmos, and reflashing the bios. Bitdefender rescue disk finds no virus but finds 3000 I/O errors and cant access many folders.
The problem i think is that the rootkit is presenting a virtualised bios, such that any flashing of the bios doesn't delete the virus. A fake MBR partition with high permissions is created, that is undeletable no matter what I try.
I have tried booting only from a live linux cd with no hdd connected, but it persists so it is definitely a rootkit.
I am all out of ideas, aside from trying to gain access to the bios code itself or replacing the bios chip. But even then I am unsure if it is backed up in the graphics card and hdd firmware. I infected my laptop just by using a flash drive i had used with the pc, and that too now has a compromised bios. I noticed that the recycle bin on the laptop was the same as the recycle bin from the pc despite me never having used the same files. There are tcp and udp connections out that i cannot stop and form part of a botnet. The RPC calls are tied to the rootkit and the local address refers to a memory location, so I know it is coming from the bios.
Interestingly if I remove a stick of ram I get a PMBUS error, as the configuration of the pc has been saved by the hack; but i can then boot normally. I tried using an old mobo but naively didnt disconnect the HDD so that too got infected.
I have analysed a few of the ip locations the bios calls with the packet sniffing tool in trinity rescue disc, and they are global, from beijing to usa. The chinese connection made me think of mebromi but my bios isnt award
Virus scans find nothing except some PUP software that repeatedly installs itself even after deletion from fresh install of AV on fresh install of OS. They are no longer found after a restart as my antivirus reports being active but in fact is largely disabled. Rootkit scans find nothing.
I think the only thing to do is burn everything. I cant even donate it to charity.
Any suggestions welcome. <3
Edited by rootkithelp, 05 May 2014 - 11:07 PM.