Start a Conversation

Unsolved

This post is more than 5 years old

94964

October 15th, 2014 18:00

BIOS Virus Verification

I was recently the victim of a major hack where all my home systems were infected at the same time. Part of the hack included planting a virus in the BIOS of at least 2 of my systems, causing me to have to replace the motherboards (so far in 3 systems).  I'm now trying to verify that the BIOS on 2 of my Dell systems have not been altered but I cannot find a utility to back up the BIOS to verify it.

Is there a hidden switch or other way to "back up" the BIOS with the BIOS flash program so I can compare it to a known good BIOS file?

121 Posts

January 23rd, 2015 20:00

Okay, so now are stating that the white paper released by those two black hat hackers, investigating secuity vulnerabilities in the BIOS. Is false? Their data isn't correct?

Now, a malicious payload cannot be a virus? Does it really matter? Malware is malware, is Malware!  Anti-virus software isn't preventing a system compromise by the attacker,  with this type of infection. The effect is extremely effective.  All Dell(HP, Toshiba, ASUS, ACER,  and all other MANU's effected)  had to do was have computrace repair the vulnerability to their Lojack rootkit!

well I have zero written the drive after deleting the partition.  After writing this, the hacker was able to temp change the password needed to unlock my 2009 Studio 1735. Pulling BOTH BATTERIES,  seemed to allow me to regain access. I've removed the CMOS battery permanently,  I'll be replacing the motherboards. (on  1735,1737,  & 14z) All I need is a way to save the Bios,  and upload its contents. We'll find out what it is. I've heard many complaints about peeps having lost  total control over their laptops. Obviously there is much more being injected then a keylogger!

Dagra

121 Posts

January 23rd, 2015 20:00

Okay, so now are stating that the white paper released by those two black hat hackers, investigating secuity vulnerabilities in the BIOS. Is false? Their data isn't correct?

Now, a malicious payload cannot be a virus? Does it really matter? Malware is malware, is Malware!  Anti-virus software isn't preventing a system compromise by the attacker,  with this type of infection. The effect is extremely effective.  All Dell(HP, Toshiba, ASUS, ACER,  and all other MANU's effected)  had to do was have computrace repair the vulnerability to their Lojack rootkit!

well I have zero written the drive after deleting the partition.  After writing this, the hacker was able to temp change the password needed to unlock my 2009 Studio 1735. Pulling BOTH BATTERIES,  seemed to allow me to regain access. I've removed the CMOS battery permanently,  I'll be replacing the motherboards. (on  1735,1737,  & 14z) All I need is a way to save the Bios,  and upload its contents. We'll find out what it is. I've heard many complaints about peeps having lost  total control over their laptops. Obviously there is much more being injected then a keylogger!

Dagra

PS,  there are two of us asking how we can backup the BIOS,  so we can check the code!  That's what we need an answer for!

March 20th, 2015 15:00

Speedstep, I don't know what your angle is. My original post was to ask someone at Dell to verify if my BIOS was clean or not. Then you go into a long list of why this isn't possible, asking to post the offending code (which you know I don't know if I have or not since this was the entire point of my question, and the system I do know is guaranteed infected is non-Dell). So, instead of being productive and trying to find out what the issue is, you just want to keep on your tirade of this isn't possible. Well, here you go:

This is an article explaining how wrong you are.

www.theregister.co.uk/.../cansecwest_talk_bioses_hack

Noobs can pwn world's most popular BIOSes in two minutes

I hope that the help you provide others is a heck of a lot more useful than what you've provided here.

Maybe you should remove that Dell Community Rockstar logo from your signature.

May 4th, 2015 00:00

@SpeedStep What about ARKSTREAM and DEITYBOUNCE? Fake?

nsa.gov1.info/.../index.html

9 Legend

 • 

47K Posts

May 4th, 2015 10:00

nsa.gov1.info is a malware site and im not clicking on your link.

ARKSTREAM and DEITYBOUNCE are names thrown out there.

Any such "system" would require physical access to the machine to reflash the bios.  This is FUD. There is no such thing as BIOS Virus on Dell machines.

I absolutely dispute this claim in its entirety without specific models and code examples of infected machines.


 

9 Legend

 • 

47K Posts

May 4th, 2015 10:00

These supposed UEFI hackers are fradulent  Ransomware malware issuers.

They typically write randsomware to remove a virus that does not exist after you give them money.  You still have not shown specific bios or dell models or code examples.

I reject these assertions on the basis of fact not FUD.

FUD is generally a strategic attempt to influence perception by disseminating negative and dubious or false information. An individual  for example, might use FUD to invite unfavorable opinions and speculation about a competitor's product.

The only reason to keep slogging on about Bios virus is to be the boy who cried wolf.  The underlying reasoning is that if you can convince people that something in bios or some other part of their computer exists when it in fact does not you can then extort money from them to remove that which was never there in the first place. 


No Events found!

Top