EVGA

Virus in acpi

Author
RFC Rudel
New Member
  • Total Posts : 4
  • Reward points : 0
  • Joined: 2009/10/23 19:36:47
  • Status: offline
  • Ribbons : 0
2011/01/06 04:50:09 (permalink)
I have a serious virus in the dsdt tables it hide in vga, lan card etc. (blue pill variation)
 
There is way reset the acpi entirely or some official tools to deal with hardware virus?
 
 
RGDS
 
 

Core I7 920 2.66D0
EVGA X58 classified 760
12G gskill trident 2000
2 480gtx
LSI Megariad SAS 9260-8I (love it)
4 SSD ocz summit Raid 0 OS
4 WD 2T Raid 5 Storage
Coolermaster 840 Chasis
Coolermaster v10 Cooler
X3 1600 Watts psu (220v at the wall)
AUS DVD-R
Dell 24 wide, Dell 17,
Saitek x52,
Antec spot cool (love it)
Windows 7 64bits RTM
Bios virus
#1

5 Replies Related Threads

    KMoore4318
    Pistoj Doulos Unum Pluribus
    • Total Posts : 17850
    • Reward points : 0
    • Joined: 2008/12/04 04:20:57
    • Location: Atlanta, Ga
    • Status: offline
    • Ribbons : 238
    Re:Virus in acpi 2011/01/06 05:51:27 (permalink)
    Execute Disable Bit in bios is supposed to protect from some hardware server leval virus's. not sure if it would affect what you have.
     
    Execute Disable Bit allows the processor to classify areas in memory by where application code can execute and where it cannot. When a malicious worm attempts to insert code in the buffer, the processor disables code execution, preventing damage and worm propagation.

      
    Just clink Link to Register >  My Affiliate Code:VTJPDC4OMB 
    1)965 V-8  E761(77)
    2)980X AX1200 E760(77) 980 ti
    3) E770 (77)2(590) SLI AX1200 
    4) X299 FTW K, 9980XE 2 2080 supers on AX1200
    #2
    RFC Rudel
    New Member
    • Total Posts : 4
    • Reward points : 0
    • Joined: 2009/10/23 19:36:47
    • Status: offline
    • Ribbons : 0
    Re:Virus in acpi 2011/01/07 00:08:46 (permalink)
    look at this
     
    ASL Input:  dsdt.dsl - 11446 lines, 403935 bytes, 5514 keywords
    AML Output: DSDT.aml - 47047 bytes, 980 named objects, 4534 executable opcodes
     
    I been fighting this thing from  may, it have many protections, it corrupts any os you install and if using VM technologies Your PC after POST is already Compromissed, you could been enter a virtual bios scren.
     
    hides on mbr,vga memory,fake hardware, any hardware buffer,cpu caches, encrypted partitions, files, also infects any cdor new harware.
     
    it uses very common virus/worms activity once you are in an OS

     
    I already try linux, Mac, you named I doit already.
     
    I now hardware and I have Microsoft Certifications, I now my Shi*
    But I Never see this tipe of bug, so many self protections......
     
    its core is baremetal virtualization with bad ass intentions. 
    post edited by RFC Rudel - 2011/01/07 00:20:24

    Core I7 920 2.66D0
    EVGA X58 classified 760
    12G gskill trident 2000
    2 480gtx
    LSI Megariad SAS 9260-8I (love it)
    4 SSD ocz summit Raid 0 OS
    4 WD 2T Raid 5 Storage
    Coolermaster 840 Chasis
    Coolermaster v10 Cooler
    X3 1600 Watts psu (220v at the wall)
    AUS DVD-R
    Dell 24 wide, Dell 17,
    Saitek x52,
    Antec spot cool (love it)
    Windows 7 64bits RTM
    Bios virus
    #3
    chinamusic
    New Member
    • Total Posts : 32
    • Reward points : 0
    • Joined: 2010/03/26 02:08:47
    • Status: offline
    • Ribbons : 0
    Re:Virus in acpi 2011/01/07 14:36:02 (permalink)
    How did you detect it?
    #4
    abecker
    Superclocked Member
    • Total Posts : 160
    • Reward points : 0
    • Joined: 2008/07/06 13:43:19
    • Status: offline
    • Ribbons : 1
    Re:Virus in acpi 2011/01/07 15:00:53 (permalink)
    I call shenanigans.

    What were you visiting that had it?

    ACPI tables are coded in the bios. For something to patch that and survive across power cuts would require flashing it.

    Also, couldn't you just turn off virtualization in the bios?

    Obsidian 800d
    i7 980X @ 3.87 GHz - 1.2375V
    EVGA x58 Classified3 (E770)
    Gskill 24GB 9/9/9/24 1333 
    EVGA GTX 580 SC/BlackOps SLI 822/1644/2046 
    Corsair AX1200
    OCZ Vertex2 120GB - Boot
    Seagate Barracuda 2TB - RAID5

    #5
    RFC Rudel
    New Member
    • Total Posts : 4
    • Reward points : 0
    • Joined: 2009/10/23 19:36:47
    • Status: offline
    • Ribbons : 0
    Re:Virus in acpi 2011/01/10 16:52:42 (permalink)
    There are many Virtualization techs that do not require VT CPUS
    If you look at linux/mac projects there are many types, the thing is that some ass use thath tech to make virus.
    M$ have many holes, adobe too, a remote execution bug will allow code inyection, from what I read they can virtualize whit only 600k injected on the bios. 
    early example
    http://en.wikipedia.org/wiki/Blue_Pill_(malware)
    Fisrt thing your PC uses a simulated efi to boot...., all your Windows installations use fake components, fake drivers (all signed, they hack that too). 
      
    a must read (root kit in acpi/ pic card)
    http://www.blackhat.com/presentations/bh-dc-07/Heasman/Paper/bh-dc-07-Heasman-WP.pdf
     
    the use acpi becouse of the irq and that IRQ in Windows work as SYSTEM so they own you, a look at your IRQ tables and hardware will show it: look for fake hardware Fireware/usb disable in bios and they remain in device manager the use extrange irq etc.
     
    My first symtom was red dots at post, so I change my vga but they show another video problems thats when my search for bad hardware starts, and find fake hardware etc.
    I have anothe machine HP hdx18 whit the same virus.
    From my research they use cpu bugs too, thay have many ways to get in.
     
     
    read your installation logs,windows and av logs, check the i/o read of your AV when you scan (they dont move much after 15000 files...)
     
    this is not a paranoid or rooky post.
     
     
     
     
    
    post edited by RFC Rudel - 2011/01/10 17:20:44

    Core I7 920 2.66D0
    EVGA X58 classified 760
    12G gskill trident 2000
    2 480gtx
    LSI Megariad SAS 9260-8I (love it)
    4 SSD ocz summit Raid 0 OS
    4 WD 2T Raid 5 Storage
    Coolermaster 840 Chasis
    Coolermaster v10 Cooler
    X3 1600 Watts psu (220v at the wall)
    AUS DVD-R
    Dell 24 wide, Dell 17,
    Saitek x52,
    Antec spot cool (love it)
    Windows 7 64bits RTM
    Bios virus
    #6
    Jump to:
  • Back to Mobile