1. This site uses cookies. By continuing to use this site, you are agreeing to our use of cookies. Learn More.

Other Virus -- FIXED -- WINNER

Discussion in 'Tech Support' started by Burnout21, 7 Jul 2012.

  1. azrael-

    azrael- I'm special...

    Joined:
    18 May 2008
    Posts:
    3,852
    Likes Received:
    124
    Where does that file come from?
     
  2. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    aramil supplied it in this post
     
  3. azrael-

    azrael- I'm special...

    Joined:
    18 May 2008
    Posts:
    3,852
    Likes Received:
    124
    I think you should use the files from the DOS Flash folder of SP57421. Just copy everything to a bootable USB drive substituting the J01_0221.BIN file with your modified BIOS image (I suppose the HP 6200 supports bootable USB drives).
     
  4. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    Do you think i'll get verification issues?

    Edit, exactly the problem, the Dosflash app

     
    Last edited: 2 Aug 2012
  5. azrael-

    azrael- I'm special...

    Joined:
    18 May 2008
    Posts:
    3,852
    Likes Received:
    124
    No, since DOSFlash doesn't use the .sig file and MMTool will have applied a valid checksum to the modified BIOS image.
     
  6. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    Its something to do with the flashuefi.cpu (possibly)
     
  7. azrael-

    azrael- I'm special...

    Joined:
    18 May 2008
    Posts:
    3,852
    Likes Received:
    124
    Flashuefi.cpu seems to be an UEFI application. I've no idea if it contains any additional checks. Does it throw a fit?
     
  8. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    Well first it points out the bios revision numbers are the same, (asks if i want to continue)

    Then is mentions flashuefi.cpu version being the same (ask if i want to continue)

    Uploads to 100%

    then reads

    Error! System Rom image is invaild
     
  9. aramil

    aramil One does not simply upgrade Forums

    Joined:
    10 Jul 2012
    Posts:
    961
    Likes Received:
    58
    Last edited: 3 Aug 2012
  10. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    Direction of investigation may have taken a new route away from the Bios/firmware, shall report back soon
     
  11. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    So the new direction I went in was to use the ATA-secure erase tools built into the firmware of the Hard drive, in hope of removing any HPA partitions that it could be hiding in. Apparently DBAN can miss these.

    Anyway, still got the same issue of the white screen. Feeling pretty rough today with a sore throat so not 100% behind it at the moment.

    Going to re-install and enable remote access to see if I can actually get anywhere with it after infection.
     
  12. aramil

    aramil One does not simply upgrade Forums

    Joined:
    10 Jul 2012
    Posts:
    961
    Likes Received:
    58
    I hope you feel better soon. health before tech :)
     
  13. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    So, I installed a spare network card that I knew windows would have drivers for.

    Installed Win7, whilst that was installing I download Comodo Internet Security to a flash drive. The instant Win7 was up, I installed Comodo and then gave the machine a physical network connection to allow Comodo to update.

    From there the machine had a decent Firewall in place, on the 2nd reboot it stopped rcpnetp from dialling out. All Windows updates installed, and its been up for 4 hours with out headache.
     
    Pliqu3011, Carrie and sp4nky like this.
  14. azrael-

    azrael- I'm special...

    Joined:
    18 May 2008
    Posts:
    3,852
    Likes Received:
    124
    Well, that's a solution of sorts. :)

    What about the spare HDD?

    BTW, hope you're feeling better.
     
  15. sp4nky

    sp4nky BF3: Aardfrith WoT: McGubbins

    Joined:
    15 Jul 2009
    Posts:
    1,706
    Likes Received:
    53
    Well done! 10/10 for perserverance. How much is this going to cost the customer?
     
  16. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    Feel like utter ****. With regards to the spare HDD I was going to test, I doubt it would resolve the problem as many people have tried the same. If the infection did create its own HPA, or if the computrace creates a HPA then I would be stuck with two drives being a pain in the backside.


    Zero, well maybe a beer..
     
  17. aramil

    aramil One does not simply upgrade Forums

    Joined:
    10 Jul 2012
    Posts:
    961
    Likes Received:
    58
    A well earned beer

    Sent on my CM10 JB powered i9100 by TapaTalk 2
     
  18. DeafGamer2015

    DeafGamer2015 Minimodder

    Joined:
    5 Jun 2010
    Posts:
    1,088
    Likes Received:
    53
    I'm a bit curious on Comodo Internet Security.. is it reliable?? just want to know..
     
  19. Shirty

    Shirty W*nker! Super Moderator

    Joined:
    18 Apr 1982
    Posts:
    12,937
    Likes Received:
    2,058
    I use Comodo firewall. It's fine, and has got me out of a few annoying problems in the past.
     
  20. Burnout21

    Burnout21 Mmmm biscuits

    Joined:
    9 Sep 2005
    Posts:
    8,616
    Likes Received:
    197
    Considering it's the only product offered online that has actually stopped this problem, yeah I would considered them reliable.
     
    Teelzebub likes this.

Share This Page