Strange Virus / Malware Comes Back

fpga123

Distinguished
Aug 31, 2011
117
2
18,715
Lets call it a virus. It disables the keyboard and mouse clicks do not work. It also messes up the BIOS and one cannot do anything with windows until one resets the BIOS.

The first time it happened was the time I first setup the PIN authentication method on my PC. It disabled keyboard in the BIOS even (not the mouse, thankfully). I reset the BIOS and flashed it anew (which was seemingly unnecessary still didn't want to take chances). I formatted the windows SSD through Ubuntu Live USB and reinstalled windows.

The virus didn't come back till I synced with my Firefox account. Or maybe that was the instant it acted up again.

The second time it wasn't able to disable anything in the BIOS, maybe the new firmware secured some of the vulnerabilities. Windows setup was not running, it ended up with the console X:\sources\ and a string of ^W adding in the line like I was typing them in. I then gulped the sour pill and formatted all the drives. Even took the opportunity to erase their partition tables. Still ultimately a BIOS reset was necessary to get the setup moving again. (Lost over 200GB of data, else I have backups of)

Now I am completing the setup. Can anybody give me pointers to how to handle the situation immediately after it gets to the desktop? Should I do something else too? I have not erased the partition table of the SSD yet.

I am extremely afraid, if the virus has penetrated the firmware of any of the devices... But as I have already purged everything, time is what I have the most...
 
Solution
Yep, I only use one macro on my Corsair K40 keyboard, "G6" is to lock my PC and that's it, nice and simple :D

But yes there is probably a vulnerability in your mouse software but it depends on your internet browsing habits, for example downloading programs from untrusted sources, that sort of thing.

GameFreak01048

Honorable
Feb 17, 2016
694
0
11,360
Hello!

Have you tried a different mouse and keyboard by any chance?

For a virus to be in your actual devices would be something I haven't heard of before...

Try to run a scan with MalwareBytes Anti-Malware and see where that gets you :)
 

fpga123

Distinguished
Aug 31, 2011
117
2
18,715
There is nothing in the HDDs... as I said, I purged my data...

But well I have discovered that the virus has embedded itself in my mouse! Its a Cooler Master Inferno with macros enabled... Whenever I press the macro key, the state becomes as how I describe...
As the situation is back to the essentially bricked state, I'll have to redo everything... I'll report any new discoveries after.

Going to get rid of this mouse the first thing tomorrow...
 

fpga123

Distinguished
Aug 31, 2011
117
2
18,715
I just ran it over my work laptop in a VM, and well there is a combination of commands embedded like Ctrl+W and others with 0 delays and endless looping through macro chaining...

Nevertheless this just means that either my PC was compromised or the mouse software has a vulnerability.
 

GameFreak01048

Honorable
Feb 17, 2016
694
0
11,360
Yep, I only use one macro on my Corsair K40 keyboard, "G6" is to lock my PC and that's it, nice and simple :D

But yes there is probably a vulnerability in your mouse software but it depends on your internet browsing habits, for example downloading programs from untrusted sources, that sort of thing.
 
Solution