I'm in serious trouble but I'm not sure if this is the right place to do a thread but I'm struggling with some kind of BIOS/UEFI rootkit.
I have for a while been getting weird entries in the Rootkit/Malware tab in Gmer. I have also noticed some strange executables running among processes.
All described as Windows services but you could easily see that those executables didn't belong to a clean Windows 7 install.
I have been using DBAN to wipe all disks, formatted them and reinstalled but I keep getting infected. All above mentioned returns.
To ensure that I'm infected I have compared processes running in the Task Manager with my neighbour. He has almost the same setup as me but most importantly he has the same motherboard as I.
We've compared the DMI information inside the BIOS and we can confirm that mine has been modified. My problem is that if I try to reflash the motherboard through USB it seems like the Virus/Rootkit just will write to the USB and execute its own code cause a USB is writable.
With that said I have also been working on making a bootable DOS-CD with a new BIOS version and a DOS Flash Utility with no success either. It's like the DOS can't read the files from the CD, even though I meddle a little with CONFIG.SYS and AUTOEXEC.BAT. It's like the DOS can't find any cd drivers.
Another mysterious thing that indicates infection is when I set the clear CMOS jumper or clear CMOS button with no effect, it looks like that the motherboard resets and runs normally for 3-5 seconds, and then it executes some other code.
A reason for me believing it runs another code is that I am using a Corsair H100i water cooling kit which you can't change the LED color on, unless you install Corsair Link in Windows and change the LED color.
When I reset the CMOS and want to boot, it lights up the cooler LED as white, as it should per default, if you don't change the color in Corsair Link it should show a damn white light! But then after 3-5 seconds the LED lights turns up as red. If I go to my neighbour with exact same motherboard, CPU and cooler the LED light is white all the time.
In the BIOS you have two functions, GO2BIOS and boot BIOS from file if I use the first function it just reboots to the screen where I can either enter BIOS or Boot Menu by pressing F2 or F11.
If I use the boot BIOS from file I get an error saying "The data mapping running is different from the BIOS you want to boot, if you press enter your system might not start." If I press enter it just reboots to the same screen as mentioned above.
Should the two functions act like that? Or is it the Rootkit messing things up?
I think my laptop has been infected too. Any feedback would be awesome since I'm becoming quite desperate!
Edited by MagicTux, 15 April 2016 - 05:01 PM.