Solved Strange situation; Hoping for answers

Status
Not open for further replies.

Redbeard

New Member
Thread author
Jan 4, 2014
12
I'm hoping this is the right forum for this and also that I have enough information for you guys.

I work at a retail store that does computer repairs also. A customer brought in a laptop (Toshiba M105 with a Phoenix CMOS) that when started would load straight to the BIOS password prompt. She had no idea how it got a password on it (I doubt she even knew how to get to the BIOS options) and it was definitely her computer, she bought it brand new. It was running Windows XP SP 2. Could not access the CMOS battery without disassembling half the laptop and we weren't willing to do that. I thought I would throw a Ubuntu LiveCD in on a lark and when I started it, it sure enough booted right into Windows XP like nothing was wrong. No prompt to ask which OS. Reset the BIOS through cmd, rebooted to check if the password was gone and it was. Ran malwarebytes, which found 51 objects (mostly registry key PUP's) the worst of which was a Trojan.P2P.worm. Kaspersky Rootkit killer found nothing.

I am hoping someone can shed some light on how Windows booted just fine with the Ubuntu disk in after a few hours of trying to without it and without success. Also if anyone has heard of a Trojan hijacking the BIOS or if there is something else I should be looking for. I fixed this one on pure luck and am really curious if it is a trick I can use in the future on the off chance I ever see it again or if it was just some strange fluke.

Sorry in advance for the lack of screenshots and details.
 

Venustus

Level 59
Verified
Honorary Member
Top Poster
Content Creator
Well-known
Dec 30, 2012
4,809
I've heard of Bios Trojans, but apparently they are very rare.
 
Upvote 0

Redbeard

New Member
Thread author
Jan 4, 2014
12
I knew it was possible but had never heard of one or seen one. Glad to know that may be answer to what hijacked the BIOS.
 
Upvote 0

MIKLO

New Member
Feb 5, 2014
1
W0W I had the same problem a few years ago, and like you I ran Ubuntu with the hopes I could somehow get to the C: drive and get some files I needed. I sure wish I could help with the correct answer but malware does some strange things, and I was often told it didn't matter how the jackass got in the ditch it just matters that the jackass gets out! Although I learned my computer skills from Business phone systems, I have had engineers tell me that the a problem I was having wasn't possible, I would always say why don't you come see for yourself and tell the system it cant do this. This didn't happen just one time but many times over the years, now with forensic software it is much easier to see what happened, I have just never taken the time to investigate. We all know that computers are gonna make our lives so much easier lol although now being retired I have the time to look at all this "stuff" I just don't have the willingness. Even though sometimes I will "waste" hours trying to see or prove to myself what happened, it doesn't ever change much except to get the computer working again how I want it to work. Times sure have changed from "DOS" days when leaving out one little . (DOT) stopped a whole page from not working and spending hours sayin to myself WTF is going on here. Im sure I wouldn't change anything even if I could, cuz learning the hard way was the best way at least 4me.
MIKLO

(Edited by Umbra for excessive formatting.)
 
Last edited by a moderator:
Upvote 0
Status
Not open for further replies.

About us

  • MalwareTips is a community-driven platform providing the latest information and resources on malware and cyber threats. Our team of experienced professionals and passionate volunteers work to keep the internet safe and secure. We provide accurate, up-to-date information and strive to build a strong and supportive community dedicated to cybersecurity.

User Menu

Follow us

Follow us on Facebook or Twitter to know first about the latest cybersecurity incidents and malware threats.

Top