A forum for reverse engineering, OS internals and malware analysis 

Forum for analysis and discussion about malware.
 #15256  by kareldjag/michk
 Sun Aug 19, 2012 2:27 pm
Maybe this one
http://invisiblethingslab.com/resources ... 20BIOS.pdf

Or this more recent one from the same lab
http://www.invisiblethingslab.com/resou ... 20VT-d.pdf

also attached a Bios paper from a Chinese University, intereting with a good and accurate translation...

rgds
Attachments
(2.48 MiB) Downloaded 54 times
 #19887  by kareldjag/michk
 Sun Jun 30, 2013 6:27 pm
Hello,

Just another kit in the Bios...
In this sunny day in Paris, i did not take time to play with it.
http://exfiltrated.com/research.php#BIOS_Based_Rootkits
The PoC http://exfiltrated.com/research.php#BIO ... nd%20Notes

Some tools that can help http://www.bios-mods.com/tools/ (the Phoenix Bios editor is detected as a trojan by some avs https://www.virustotal.com/en/file/10f9 ... 372612208/ )
More trusted on this Chinese site where i have found the Bios Fix tool (click on the red links to download the tools)
http://www.biosrepair.com/pic/pic99.htm
http://www.biosrepair.com/pic/pic94.htm

Rgds
Last edited by kareldjag/michk on Sun Jun 30, 2013 7:01 pm, edited 1 time in total.
 #19895  by EP_X0FF
 Mon Jul 01, 2013 3:29 am
kareldjag/michk wrote:(the Phoenix Bios editor is detected as a trojan by some avs https://www.virustotal.com/en/file/10f9 ... 372612208/ )
This is detection of MakeScreen utility embedded inside main BiosEditor.exe main application.
https://www.virustotal.com/en/file/fc89 ... /analysis/

It is not hard to guess initial Kaspersky FP copy-pasted by VT fake av's. Very professional as always.
==== (c)Copyright 2005 Phoenix Startup Screen Bitmap utility
Version 0.1 (May 30 2007 14:52:24)File