virus in my z97 sabertooth mark 1 bios.

Chaoticblackeagle

Honorable
Jun 21, 2013
137
0
10,690
Today i got a message in my bios saying unauthorized Bios firmware modification detected. My big brother went to a malicious web sites and got himself a virus called gameover zeus. It infected the router and spread through all the computers in the house including my new computer build. I was updating my bios with my usb and some how it got inside i think. My brother is a huge idiot what should i do?
 
Solution
Good, just try not to open up any attachments on any of your emails because that is where zeus gameover comes from and then it sends itself to everyone else in your contacts. I would still make an admin account on your system, and then make your account limited. Also do as I said with web of trust, and cryptoprevent which normally comes with the gameover virus, it will encrypt all of your data and hold them up for ransom

Yoplait95

Honorable
Jan 8, 2013
439
0
10,810


You realize you shouldn't be running anything on the network if you have a bug in it..... Unless the place you are downloading this bios is infected then there's really nowhere safe left to acquire one. Obviously if you know you have this exact root virus, you should be more capable of getting rid of it than coming to a tomshardware forum... I can walk you through this... but only if you have a certain level of competence..

(No offense entirely meant... just irritating)
 

lfkfkfkffs

Admirable
Gameover zeus hasn't been fully analysed yet. Bios viruses really aren't all that uncommon anymore, I would suggest not having your hard drive or even your video card plugged in while you clean your system. If you are able to boot into your system though don't disconnect the hard drive or the video card and just run http://free.avg.com/us-en/remove-win32-zbot If you have something like F-secure antivirus and kaspersky. You can download either here http://support.kaspersky.com/viruses/utility#kasperskyvirusremovaltool http://www.f-secure.com/en/web/home_global/online-scanner Most anti virus programs don't have anything currently don't have the virus on their database list. Once you remove the virus Go and make an admin account on your computer, just call it admin, and switch your current account to having limited access. After that install http://www.foolishit.com/vb6-projects/cryptoprevent/ This will prevent you from the crypto blocker virus that encrypts all of your data. Then I would recommend installing a key chain to store all of your passwords on. This is all coming from a malware analysis pov not a gamer.
 

lfkfkfkffs

Admirable
Well here is what you are going to need to do first you will need to make a bootable disk that can scan your boot sector of your hard drive for viruses. you can fallow these instructions to do so http://support.kaspersky.com/us/8097 after you finish scanning and this is important you need to unplug your hard drive, and your video card unless you don't have a igp. After that you need to flash your bios to the updated version from the ASUS website. After that plug your hard drive back in and start installing the os. The reason why we go through the steps like we did is because most viruses use a buddy system, so if one goes down the other part of it that is still remaining will pick it back up. But once that is done download the stuff that I originally listed in my first post about your problem. Making an admin and limited user account will help your security quite a bit in the future. After that is all done scan for the virus again with one of the first tools that I listed, if it comes back clean download and start storing all of your passwords on an encrypted key chain. If you do everything that I just said your computer will no longer be compromised. You may also want to reset your router back to the default settings as well while you wait for the other stuff to finish. Another safe practice is to install something like web of trust on google chrome or firefox, and always have JavaScript disabled and only add websites that you trust and visit frequently.
 

lfkfkfkffs

Admirable
Good, just try not to open up any attachments on any of your emails because that is where zeus gameover comes from and then it sends itself to everyone else in your contacts. I would still make an admin account on your system, and then make your account limited. Also do as I said with web of trust, and cryptoprevent which normally comes with the gameover virus, it will encrypt all of your data and hold them up for ransom
 
Solution