PDA

View Full Version : BIOS infected: How can I clean a BIOS infected?



porfirio1830
2015-09-10, 02:22
I have a machine with these features:
1. MSI-U100/windowsXp
2. Once the OS is up, it deletes what I write and I can not navigate through the file manager because it sends me always to the desktop.
3. I disconnected the HD from the Laptop.
4. I test it booting with a USB live Linux. Surprise! The laptop made the same things like point 2.
5. I disconnected the battery from CMOS RAM during 1 hour, and reconnect it later.
6. I did a Flash to the BIOS with the last update obtained from the website of MSI and with help of FreeDOS.
7. The Laptop keeps making the same thing like point 2.
8. I've tried with different distributions of USB-Linux, and what I observed is that the "thing which is inside BIOS" rises similar privileges like root or administrator, so in this way it owns the Laptop.
9. My great question: How can I clean the BIOS and all the stuff related to the boot process? In order to get a clean boot.
10. Do you know about some tools that run with FreeDOS and remove rootkits, bootkits, and rare things from my BIOS.
10. I would appreciate your sincere help.
Thanks for your attention.

tashi
2015-09-10, 21:24
Hello porfirio1830,

For someone to take a look at the system in the Malware Removal Forum (http://forums.spybot.info/forumdisplay.php?f=22) you could start a new topic there after reading that forum's FAQ which also includes instructions in post #2 on how to provide the logs from Farbar Recovery Scan Tool and aswMBR. These are the logs used in the preliminary analysis so a volunteer analyst may advise.

http://forums.spybot.info/showthread.php?t=288

Please see these posts in that forum so that everyone is on the same track. :)

Microsoft End Of Support Cycle
(https://forums.spybot.info/showthread.php?425-UPDATED-WINDOWS-Your-first-line-of-defense&p=28501&viewfull=1#post28501)Microsoft: Infection rates and end of support for Windows XP (https://forums.spybot.info/showthread.php?425-UPDATED-WINDOWS-Your-first-line-of-defense&p=446431&viewfull=1#post446431)

Best regards