HD plus Motherboard rootkit infection

sfeg

Banned
Local time
6:53 AM
Messages
19
If both a HD and the motherboard firmware are infected by a trojan virus, how does one go about disinfecting? For the Mobo, does a Bios flash with updates take care of it?

But which one to do first? It seems that upon wipe/reinstall, the HD could get infected immediately again by the Mobo, and vice versa for the Mobo.

I'm thinking HD wipe, then Mobo flash, then HD format/reinstall... still not completely foolproof, but does that make sense or not?
 
Last edited:

My Computer My Computer

At a glance

Win7 Pro x64
OS
Win7 Pro x64
You might try to first remove the hard drive, then flash the BIOS from a USB stick. Then attach the hard drive, boot from a DVD and wipe the drive. As for the BIOS flash, I've heard mixed results from ridding yourself of an infection that way. I'd try it, though, since the alternative is to order a brand new BIOS chip - and that's assuming it is of the "pop-out chip" type. :)
 

My Computer My Computer

At a glance

Main - Windows 7 Pro SP1 64-Bit; 2nd - Window...Main - Core i7 2600K; 2nd - Core i7 920Main - 16GB Corsair Vengeance; 2nd - 12GB Cor...Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon ...
Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
But wouldn't the HD just re-infect the flashed Mobo? I don't suppose there is any way to wipe/reformat the HD without being connected to the Mobo. Unless you pay for services at a place which has "immune" Mobos, if that exists. So I'm thinking wipe then quickly PULL that HD's SATA plug (and risk crashing?!)

This Tom's Hardware article, especially the final comment on 2/4/12, makes me feel very pessimistic about getting rid of rootkits :(

Webroot Discovers BIOS Rootkit

The scary thing is, how would one even know if one was still infected and being keylogged/spied upon silently?
 
Last edited:

My Computer My Computer

At a glance

Win7 Pro x64
OS
Win7 Pro x64
If I use Diskpart or another utility (such as KillDisk or DBAN), is it possible to wipe the HD first but don't format it yet? (Or do all wipes also format?)

While still unformatted, will the HD be un-writable, and thus un-infectable?

Then I would do the HD format to NTFS later, after flashing Mobo. By the way, FYI my Mobo's updates can be flashed via a USB drive only (CD/DVD isn't an option).
 

My Computer My Computer

At a glance

Win7 Pro x64
OS
Win7 Pro x64
Booting from a DVD should allow you to wipe the HD without the HD having a chance to run anything. I'll hedge that a bit by saying that without knowing the nature of the worm in question I would hate to bet everything I own on that.

I haven't been in this situation myself so I can't offer any kind of precise "here's what I did and it worked" advice. Thinking by the seat of my pants, it seems your best option would be to give it a shot. If it doesn't work you'll be no worse off. The only 100% foolproof alternative I can think of would be to replace both the MB and the HD and toss the old ones in the trash.

You sound quite sure of the fact that the BIOS EEPROM is infected. I'm not doubting you, but I am curious as to how you came to this conclusion. I guess one of my worst fears when it comes to a MB would be something like this where it may be difficult to know that the patient has indeed been cured after treatment. :confused:
 

My Computer My Computer

At a glance

Main - Windows 7 Pro SP1 64-Bit; 2nd - Window...Main - Core i7 2600K; 2nd - Core i7 920Main - 16GB Corsair Vengeance; 2nd - 12GB Cor...Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon ...
Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
Sorry, I'm a slow typist and hadn't seen your reply when i posted back. :)

If I wipe the HD first but don't format it yet, will it be un-writable, and thus un-infectable?
That sounds very wise. I think that's an excellent way to go.

By the way, my Mobo's updates can be flashed via a USB drive only (CD/DVD isn't an option).
That's fine. I was just suggesting you isolate the two devices while cleaning things up. Otherwise it would be like getting the flu and being admitted to the hospital, then sharing a room with another flu patient. You'd just end up passing it back and forth.
 

My Computer My Computer

At a glance

Main - Windows 7 Pro SP1 64-Bit; 2nd - Window...Main - Core i7 2600K; 2nd - Core i7 920Main - 16GB Corsair Vengeance; 2nd - 12GB Cor...Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon ...
Computer Manufacturer/Model Number
Self
OS
Main - Windows 7 Pro SP1 64-Bit; 2nd - Windows Server 2008 R2
CPU
Main - Core i7 2600K; 2nd - Core i7 920
Motherboard
Main - Asus P8Z68-V Pro/Gen3; 2nd - Gigabyte GA-EX58-UDR3
Memory
Main - 16GB Corsair Vengeance; 2nd - 12GB Corsair Vengeance
Graphics Card(s)
Main - XFX Radeon 6870 1GB; 2nd - XFX Radeon 4870 1GB
Sound Card
Both: Onboard Realtek Azalia
Monitor(s) Displays
Main - Hann 25" + I-INC 25" + Acer 23"; 2nd - Upgrading Soon
Screen Resolution
Main - 1920x1080 (All Three Monitors); 2nd - Upgrading Soon
Hard Drives
Main - (1) Crucial M4 128GB (Boot)
Main - (1) Seagate 2TB 64MB Cache (Data)
Main - (1) Seagate 2TB 64MB Cache (Data Backup)
2nd - (1) Intel X25-M SSD 80GB (Boot)
2nd - (3) Seagate 1TB 32MB Cache (Data Backup)
2nd - (1) Seagate 320GB (Because)
PSU
Main - OCZ 600W Modular; 2nd - OCZ 600W
Case
Main - Thermaltake Element G; 2nd - NZXT something or other
Cooling
Main - Corsair H80; 2nd - Prolimatech Megahalems
Keyboard
Main - Razer Reclusa; 2nd - Old MS Keyboard
Mouse
Main - Logitech MX Revolution; 2nd - Old MS Mouse
Internet Speed
20Mbps Time-Warner Cable
No problem, thanks :)

So then the question becomes, are there any wipe programs which will simply wipe but hold off on the formatting?

If not, do I maybe need to use Linux OS CD to do the wiping... and reformat it to FAT32 temporarily?
 

My Computer My Computer

At a glance

Win7 Pro x64
OS
Win7 Pro x64
Hi,

You seem sure you have a rootkit. Do you know the name, and how did you uncover it?

Also, what is the make/name of your BIOS?

Regards,
Golden
 

My Computer My Computer

At a glance

Windows 10 Pro x64 ; Xubuntu x64Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz16GB Corsair Vengance DDR3 @ 661 MHz Dual Cha...EVGA NVidia GTX 560 1024MB
Computer type
PC/Desktop
Computer Manufacturer/Model Number
Golden Mk. I.4
OS
Windows 10 Pro x64 ; Xubuntu x64
CPU
Intel i7 860 @ 2.80 GHz O/C'ed to 4.0GHz
Motherboard
Gigabyte P55A-UD3R Rev.1. Award BIOS F13
Memory
16GB Corsair Vengance DDR3 @ 661 MHz Dual Channel (9-9-9-24)
Graphics Card(s)
EVGA NVidia GTX 560 1024MB
Sound Card
Realtek Integrated
Monitor(s) Displays
Dual Samsung SyncMaster 2494HS
Screen Resolution
1920*1080 and 1920*1080
Hard Drives
1*Samsung 840 EVO 120GB SSD;
1*OCZ Vertex 2 60GB SSD;
2*Samsung F3 SpinPoint 1TB in RAID0;
1*Samsung F1 SpinPoint 1TB;
2*Western Digital 1TB External USB 3.0
1*Western Digital 500GB External USB 3.0
1*Seagate 500GB External USB 2.0
PSU
Thermaltake ToughPower QFan 750W
Case
Thermaltake Element S VK60001W2Z
Cooling
Corsair H60 Water Cooling, 2*230mm and 2*80mm case fans
Keyboard
Logitech G110
Mouse
Logitech MX518
Back
Top