Questions about detecting infection

Discussion in 'Malware Help - MG (A Specialist Will Reply)' started by Raimy, Dec 19, 2012.

  1. Raimy

    Raimy Private E-2

    I'll try to keep this short and to the point...

    I got a new laptop a couple weeks ago and it came with a 1tb drive (2 500gb drives in a raid configuration). I do 99% of my online stuff in Linux so I proceeded to install it and discovered that Linux does not like raid setups. I opted to replace the 2 drives with a single SATA drive. As my computer was under warranty the manufacturer insisted on sending a certified tech out to my house to replace the drives. After he physically put the new drive in he pulled out a thumb drive and inserted in my computer to run a diagnostics program. This kind of bothered me but it was already done. He said his program couldn't detect the new hard drive so he took it out, restarted and got into the diagnostics program that's in setup.

    Afterwards I was wondering why he would use a thumb drive to run a program that is in the computer setup area by default. Now at the time that he did this, the hard drive had just been put in so I figured he couldn't have installed anything bad since there was no OS installed yet. I proceeded to install Windows and went about my business but always had something in the back of my mind about it all. A few days later I noticed a Desktop.ini file ON the desktop. A google search told me it could either be an infection or that it was a bug in Windows 7. I started thinking about the bios and in searching the net discovered that the bios could indeed be infected. I also read that by flashing or updating the bios you could clear an infection so I went to the manufacturer's site and found a newer version of my bios available (both version A09 but my date was 6/29/12 and theirs was 10/12/12). I downloaded it and installed/flashed as it said and apparently it went off without a hitch but when I checked in msinfo32 the date still said 6/29/12. I also went and totally reformatted my drive and reinstalled the OS.

    As I think I said earlier, I do the majority of internet stuff and ALL sensitive stuff (banking, etc) from within Linux and not Windows. In fact most of the time that I'm in Windows I have the wireless turned off.

    So now that this post has been anything BUT short and to the point, here are my questions:
    1. What are the chances that there is any kind of infection on my computer and especially in the bios?

    2. Could a bios infection affect Linux or would that also be a windows based thing?

    3. I read somewhere on this site that some viruses/trojans/etc can prevent you from writing to the bios...if that were to happen would the flashing program just stop or would it let you think it worked? In other words how would you know?

    I do apologize for all the paranoid rambling and possibly stupid questions but I really need to know once and for all if everything is okay so I can get some piece of mind. As you can tell I'm starting to lose it! I ran the programs you suggested and am attaching the files and would really appreciate it if you guys could take a look and tell me what you think. I couldn't get the MGTools zip file and will try again tomorrow if you think it's necessary. Thanks!
     

    Attached Files:

  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    How is it that he expected it to do anything at all. You had no OS installed. Or are you not telling us everything? Did he actually try to BOOT from the USB drive?

    Nope. It is normal. It is just normally a hidden file. It will show up if hidden and system file viewing is enabled. In fact, you could see two of them since one would be from your user account and the second is from the All Users account.

    Not very likely but not impossible. The tools we run would typically find any Windows infections but BIOS is not Windows. It would not be detected. But you reflashed it so it is probably okay even if you think the reflashing did not change the date.

    Again, not likely but not impossible. But you would most likely notice it.

    The reflash would fail in some form. For example, a CRC check would fail and the writing software would know that the write failed. And then a reboot of your PC would now be met with nothing but a BEEP and you would be dead in the water. There is no backup BIOS. If you rewrite it and it fails or you get a power hit in the middle or some how stop it in the middle. The mother board would have to be exchanged unless you are great at removing and replacing surface mount chips at home. ;)

    The log file is C:\MGlogs.zip not MGTools.zip but I don't think we need it as there is nothing in any of your other logs and you really have not said that you are actually experiencing any problems.
     
  3. Raimy

    Raimy Private E-2

    If you put in a new hard drive and there is no OS installed yet, can't you still get into the setup area via the F2 key?

    He went into setup at one point because he changed the settings from RAID to AHCI and briefly went through all the other areas there (Security, Boot, etc). But he ran through a diagnostics test twice...the first time from the USB drive and that's when it failed to detect the new hard drive so he took it out. After he removed the drive he powered down the computer, restarted it, hit F2 to enter setup and continued on by running the diagnostics test again without the USB drive. It wasn't until this diagnostics had completed that he inserted the Windows disk to start the OS installation.

    But apparently all my paranoia was unfounded which is a good thing. Thanks for looking into it, I really appreciate it.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    Yes.

    You're welcome.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds