Smiley on the bios setup page

Discussion in 'Malware Help (A Specialist Will Reply)' started by pasound, Nov 28, 2007.

  1. pasound

    pasound Private E-2

    Here's one I've never seen before. Got a dead HP Pavilion ze4805us laptop on my desk. Owner said the keyboard was "stuck". Plugged in a regular keyboard to get it to boot (Win 2000, not XP - no idea why it was downgraded), hit ctrl/alt/del, and when it hit the log-in screen, the password section takes off with dots running across it. Can't get them off to type in the password. Every time I highlight the line and hit "backspace" it refills it in a split-second.

    I pulled the keyboard and tried it in my own Pavilion, and it works fine, so nothing's wrong with the keyboard.

    Pulled the drive and scanned it, slaved to my desktop machine, and it was "full" of copies of Trojan.Zlob, Trojan.Secup, and a rotten piece of crapware called SystemDoctor. Cleaned it, wiped it, and decided to start the reinstall process.

    Keyboard was still non-functional even after wipe, so with my spare plugged in, I hit F2 and get into the bios to set the boot order to get the cd started, and instead of "Pavilion ze4800" under Notebook Model, it says "Pa:)vilion ze480" Actually an ascii smiley, but you get the idea...

    A bios-residing rootkit? Simple hardware death? This is weird...

    I'm googled out trying to find a bios-resident rootkit, trojan or virus that would do this, so now it's time to "ask the experts".
     
  2. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    No I have never heard of this. If the BIOS is truly infected, you will have to look for a method of reprogramming it (assuming it is a FLASH device).
     
  3. pasound

    pasound Private E-2

    Follow-up. I flashed the bios from an external floppy, and it seems to be back to normal. The flash process backed up the old bios to the floppy, and a scan of the old bios file showed no infected files, so whatever it was, was "riding" on the chip.
     
  4. chaslang

    chaslang MajorGeeks Admin - Master Malware Expert Staff Member

    I'm happy to hear you got your problems resolved.
     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds