💀Worst Computer Virus: BIOS Virus | Motherboard Virus | Antivirus | UEFI Rootkit

2023 ж. 30 Қыр.
15 170 Рет қаралды

💀Worst Computer Virus: BIOS Virus | Motherboard Virus | Antivirus | UEFI Ro
▶️Watch Part 1: • 💀 Worst Computer Virus...
🔗ESET Smart Security Premium: www.tkqlhce.com/click-1004721...
🔗ESET Coupon Codes: www.tkqlhce.com/click-1004721...
🔗Get a 14-day free trial with Aura and see where your personal information is being leaked online: Aura.com/nico
Scanners that detect Lojax:
🔗 Aura: aura.com/nico
🔗 ESET Smart Security: www.jdoqocy.com/click-1004721...
💢 Business Inquiries: garrettgateway@protonmail.com
🔐 Unveiling Lojax: The UEFI Firmware Rootkit You Can't Ignore 🔐
Welcome to a gripping exploration of cybersecurity's darkest corners: "Lojax - UEFI Firmware Rootkit Exposed." 🌐🔍
Embark on a spine-chilling expedition through the annals of cyberspace as we unveil the most treacherous computer viruses ever created. In this nerve-wracking video, we delve into the disturbing tales of malicious software that left a trail of chaos and disruption in their wake.
🛡️ THE THREAT UNLEASHED: Prepare to be gripped by the harrowing stories of infamous computer viruses that spread like wildfire, infiltrating networks, and causing unimaginable damage. Witness how these digital monsters evolved over the years, leaving a lasting impact on the digital landscape.
Ransomware:
Ransomware is a type of malware that encrypts a user's files and demands a ransom to restore access. Notorious examples include WannaCry and NotPetya.
Trojans:
Trojans disguise themselves as legitimate software to gain access to a system, often allowing unauthorized access or data theft. They can be highly destructive and may open a backdoor for other malware.
Spyware:
Spyware covertly collects information about a user's activities without their knowledge, including passwords, browsing habits, and sensitive data. It often aims to steal personal and financial information.
Worms:
Worms are self-replicating malware that spread across networks, exploiting vulnerabilities and consuming system resources. They can propagate rapidly and cause widespread damage.
Botnets:
Botnets consist of a network of compromised computers controlled by a central server, typically used to conduct distributed denial-of-service (DDoS) attacks, spam campaigns, or data theft.
Rootkits:
Rootkits are stealthy malware that hide within a system, granting unauthorized access and control over the computer. They are difficult to detect and remove.
Adware:
Adware displays unwanted advertisements on a user's device, often causing slowdowns and hindering the user experience. In some cases, it may collect user data to target ads.
Keyloggers:
Keyloggers record keystrokes, capturing sensitive information such as passwords, credit card numbers, and login credentials. They can transmit this data to malicious actors.
Fileless Malware:
Fileless malware resides in system memory, making it difficult to detect using traditional antivirus solutions. It leverages existing system tools and processes to execute malicious actions.
Malicious Mobile Apps:
Malicious applications on mobile devices can steal personal information, track user activities, or exploit vulnerabilities to compromise the device.
Drive-by Downloads:
Drive-by downloads automatically download malware onto a user's device when they visit a compromised or malicious website, often exploiting vulnerabilities in the browser or plugins.
Phishing Attacks:
While not a type of malware, phishing attacks involve tricking users into revealing sensitive information such as passwords or credit card numbers. Phishing often accompanies malware distribution.
Understanding these dangerous types of malware is crucial for maintaining a strong defense against cyber threats and adopting proactive security measures. Stay informed and prioritize cybersecurity to protect your digital assets and data.
Download Tron Script: / tronscript
---------------
▶️ Please subscribe: / nicoknowstech
---------------
▶️ Join my Discord: discord.io/NicoKnowsTech
▶️ Support me on Patreon: / nicoknowstech
---------------
▶️ Follow me on:
Instagram - / nicoknowstech
Twitter - / nicoknowstech
▶️ Frequently Asked Questions: • Frequently Asked Quest...
---------------
▶️ Check out my other videos:
Block ALL Ads, Malware Domain, Trackers & More: • Block ALL Ads, Malware...
NKM Minecraft Faction Server Launched: • NKM Minecraft Faction ...
Virus Removal Tutorial: • IBuddy, Idle Buddy, Br...
Can you trust virus scanners? : • Can you trust virus sc...
---------------
#BIOS #virus #trojans #computervirus

Пікірлер
  • Have you guys ever encountered a virus that was hard to remove?

    @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • daling with one at the moment pretty sure about it

      @ToPAwDDeR1846@ToPAwDDeR18467 ай бұрын
    • Sorry to hear that but glad you are telling me. I would be happy to advise you. Can you tell me a little about your infection?

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • @@NicoKnowsTech I think I have a virus on one of my computers that survives a reinstall of windows. This time I wiped my drives with secure erase on my MSI motherboard and flahsed my bios will that fix it, or is their another way without buying a new motherboard?

      @brantbolton1284@brantbolton12846 ай бұрын
    • Def not in the position to purchase a new motherboard, CPU, RAM, and CPU coollar.

      @brantbolton1284@brantbolton12846 ай бұрын
    • Yes😢

      @peppiino@peppiino6 ай бұрын
  • the effort you put it... these are great!! keep up the work man :)❤

    @awoou@awoou7 ай бұрын
    • I will do my absolute best!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Heres the worst part about UEFI malware. UEFI was meant to be more secure but it is literally less secure and more buggy. Intel and AMD forced UEFI to include spyware by putting code for the intel management engine inside of the firmware(amd has there own version of intel me to). Whats worse about uefi is that it gives these viruses network support. as UEFI can connect to the internet(theres no reason why UEFI should have network support but it has it for some reason), it means that malware can easily access the web. their claims to make it more secure than bios was a flat out lie. Whats worse is that UEFI is mostly proprietary. while its true that most UEFI firmware is based on the open source tianocore. Tianocore still requires propitiatory intel blobs in order to run. on top of that its then modified by companies like AMI and Phoenix to include even more propitiatory stuff in it. and then sold to motherboard manufactures. even worse is that they block you from flashing anything else. The worst thing however is the fact that its up to the motherboard manufacture to include a patch for these exploits that UEFI rootkits use and most of the time they dont release a patch or fix.

    @hunterrules0_o@hunterrules0_o7 ай бұрын
    • Well stated and insightful comment!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • ​@@NicoKnowsTech thanks man. this was a excellent video as well.

      @hunterrules0_o@hunterrules0_o7 ай бұрын
  • thank you so much for covering this appreciate the effort you've put in your the man

    @liameyles1450@liameyles14507 ай бұрын
    • That means so much to me hearing that. You make all the hard work worth it!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • These videos are amazing and really helpfull!! Appreciate it from you Nico!

    @Cloudinite.@Cloudinite.7 ай бұрын
    • Oh snap! Thank you! Really appreciate you telling me.

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Thanks. Great coverage of some sinister hacker bits ... Subscribed ... Cheers

    @algorithminc.8850@algorithminc.88507 ай бұрын
    • Thanks for the sub and for the comment! Glad to have you.

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Cant wait for part 3

    @farp6561@farp65617 ай бұрын
    • Working on it now!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • keep up the googd work man

    @mackharris879@mackharris8797 ай бұрын
    • I will do my best!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Very cool Nico. Good on you!

    @r3tri3ution_z3nith_point_z6@r3tri3ution_z3nith_point_z65 ай бұрын
  • You meant Live Guard :-) Live Grid is another more basic feature of ESET. Great video 😁

    @tivtag@tivtag7 ай бұрын
    • Maybe they are both features of ESET, but I did mean LiveGrid. help.eset.com/glossary/en-US/technology_livegrid.html

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • @@NicoKnowsTech LiveGuard is ESETs premium cloud sandbox feature. I was pretty confused about LiveGrid vs LiveGuard myself. For 0-days you’ll want LiveGuard. :-)

      @tivtag@tivtag7 ай бұрын
  • I have been running ESET's product for over 10 years [have not been infected during that time; I would consider myself a pretty "average" (internet) user ; aware of threats but not overly cautious]

    @TestTest-eb8jr@TestTest-eb8jr7 ай бұрын
    • That is great to hear buddy!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Great job! I sincerely appreciate your thoroughness in sharing the latest virus details. Your dedication is truly admirable, and I am immensely grateful for your valuable insights.

    @techsostip@techsostip7 ай бұрын
    • Wow thanks! I really needed to hear that right now. It has been a hard road but worth the outcome!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • I have a strong suspicion that I was infected by one of these pests, how can I reliably send a log of my computer for you to analyze? I suspect it was recorded in the bios of a video card from China I really need help, I'm trying the steps in the other video to remove persistent malware, but believe it or not the malware protected against this

    @gui.saito_cwb@gui.saito_cwb5 ай бұрын
  • Hey Niko i download a song from KZhead and my dj software started freezing, i then did the cleanup you suggested and even though it got much better i stil get some freezing hiccups about every hour when playing my music so i believe i still got a bug in my system, any suggestions please let me know soon thank you.

    @user-tr3yt7ky4w@user-tr3yt7ky4w7 ай бұрын
    • Did you check my video on how to detect viruses? Might want to see if you have an infection.

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • My asus laptop compromised. Bios updated, deleted and formatted ssd, reinstall windows. But nothing works. It continously showing its location to china. And hacker asking 1800usd. Helpless

    @AshokSihmar@AshokSihmar5 ай бұрын
    • Maybe using an SPI bios tool (+bios repair kit) to rewirte the bios chip itself.

      @terraincognita2973@terraincognita29732 ай бұрын
    • Hi, my friend got his computer infected too. We tried erasing everything and updating the bios and it always came back. BUT we found a solution : flashing every update of the bios from the first one to the last one without booting the motherboard itself. It rewrote the entire bios with clean firmware and it seems to have saved his computer. (We erased the whole memory too and flash a new OS)

      @frankykranky2992@frankykranky2992Ай бұрын
  • Hi bro, I want to copy data from external hdd to internal SSD do you know any fast way to copy large files?

    @v9956@v99567 ай бұрын
  • Isnt this anbevilware thing as i run linux andcrestrict updates from known sw providers?

    @terrygolden7726@terrygolden772628 күн бұрын
  • Hi nico I like your content,I'm a new subscriber. I downloaded a torrent and got a trogan virus. I factory reset my computer. And it was still there. I want to remove it offline if I can. Do you recommend USB windows 10 recovery like Norton and which do you recommend. I will do it in boot safe mode. If you can do a video I'm sure it will help people out. Thanks

    @petertaylor4758@petertaylor47587 ай бұрын
    • I will get right on that!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • @@NicoKnowsTech thank you very much. I'm learning a lot from you. . I want to try Tron as a last resort. I'm not very good on computer's. I can tell you are a good content provider, and you care about your community

      @petertaylor4758@petertaylor47587 ай бұрын
    • @@petertaylor4758I think I am having the same issue. Tron did not seem to work because the file was not able to be opened. It seems the computer connects to another computer as soon as I can connect to the internet after installing windows.Hopefully disconnecting from the internet will give me time to find and delete the file without them stopping me. But I think I either missed some or I don’t have access or authority to remove certain files. I don’t know enough to just delete files from the system or program files but I think that is where things can be fixed. But describing this is difficult and I doubt I grasp it fully.

      @israelgarcia7801@israelgarcia78012 ай бұрын
    • @@israelgarcia7801 I haven't sorted out my laptop yet. I don't use it on Internet and rarely use it What I suggest is download Tron in another computer that is virus free. Then boot your computer in safe mode. I think windows isn't active then. Put in USB and try to install Tron from there.. obviously with Internet off . Let me know if you get rid of virus. It might help me

      @petertaylor4758@petertaylor47582 ай бұрын
    • USB memory stick lol

      @petertaylor4758@petertaylor47582 ай бұрын
  • I am fully infected with everything in this video. 28 devices, 2 vehicles and no control going forward. Can you please help me?

    @N.Mc.-hr1nj@N.Mc.-hr1nj18 күн бұрын
  • How do I know if my PC is infected with UEFI virus? Just scan with ESET?

    @LegionRides@LegionRides7 ай бұрын
    • Correct. That is why I am only recommending them for antivirus. If ESET says you are clean the you absolutely do NOT have a UEFI Malware.

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • Thanks very much! I'm scanning with ESET free trial period right now.

      @LegionRides@LegionRides7 ай бұрын
  • Hi nico , your contents great ,I been trying to get rid of a serious virus or malware I have and nothing seemed to be working now I see this I believe I may have a LoJax I have done multiple windows installs used multiple antivirus tronscript I’m onto medicat but the virus seems to reinstall every startup ,any help would be great 👍🏼

    @frxstyybwoyy1939@frxstyybwoyy19397 ай бұрын
    • Scan with ESET. It will tell you if there is an infection or tampering there.

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • @@NicoKnowsTech thanks for the response ,would eset be able to remove it ?I have used medicat and I can confirm it’s a uefi malware as it’s persistent and it resides on drive X the boot files ,I have almost given up but I will try eset.I wanted to ask is there any chance the malware could spread to my other hardware like gpu and ram ?

      @frxstyybwoyy1939@frxstyybwoyy19396 ай бұрын
    • @frxstyybwoyy1939 ESET will validate if you indeed have a UEFI infection. Medicat is what we call "oversensitive" and it may be a false positive.

      @NicoKnowsTech@NicoKnowsTech6 ай бұрын
    • reinstall with a USB. reinstalling windows from windows will just redownload the same drivers you're using.

      @cattameme@cattameme6 ай бұрын
  • Could these viruses be spread through purchasing hardware? If so what kind? Do we not buy hokey brands? Could a compromised video card firmware spread virii? Could compromised or malicious hardware install these uefi virii?

    @BuPhoonBaba@BuPhoonBabaАй бұрын
  • Hi.I am using Kaspersky Premium.I know Kaspersky knows about UEFI Threads. In my Understanding Kaspersky must be able to defend these Threads too?

    @bigdaddycool1000@bigdaddycool10007 ай бұрын
    • Technically yes however it must be a known Malware and match signatures or else Kaspersky will miss it.

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
    • @@NicoKnowsTech Thx for answering.I'm asking,because in believe that Kaspersky still is one of the best AV Vendors.

      @bigdaddycool1000@bigdaddycool10007 ай бұрын
    • I would agree. 👍

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Subscribed! Three questions from a user + that is broadening out his knowledge. 1) Are these Firmware virus's a threat to Linux distributions as well? I understand that these virus's are introduced into the firmware/ BIOS, however, the "carrier" seems to be mostly Windows. Am I wrong? 2) Why is TPM 2.0 and Intel 8th gen + processors being mandated by Windows 11 in about a year? Is it because of these types of virus's? 3) What does TPM do for security?

    @FarmerRiddick@FarmerRiddickАй бұрын
  • one of my computers got infected. all of my computers are protected Eset EndPoint Security. The user installed some software with hacked license and that was the source as far as I know. I did try BIOS update but the Virus still there. its may be not a virus. ESET says -a variant of EFI/ CompuTrace.A potentially unsafe application- unable to clean messge starts \\Uefi Partition >> UEFI >> uefi:\\Volume 6\Firmware Volume Image. any suggestions?

    @loustenmmts@loustenmmtsАй бұрын
  • I'm currently trying to get rid of a I guess a bios bootkit, PITA.

    @DJTSmiley@DJTSmiley5 ай бұрын
  • hey nico!!

    @beckett2.064@beckett2.0647 ай бұрын
    • Hey beckett! Great to see you here!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • Will downgrading to the first bios version on my msi mag b450 tomahawk and upgrading to the most recent bios fix this issue if you might have a uefi bios

    @levelone8038@levelone80386 ай бұрын
    • I have had success with that method. Give it a shot then scan with ESET. If it comes back clean then you did it.

      @NicoKnowsTech@NicoKnowsTech6 ай бұрын
    • msi private keys were stolen so a custom image for the spi flash can be made and signed with this key. it is logical, that one of the first things to alter is the flashing utility itself. the attacker will add an anchor like code snipped at the end of the flash update or deactivate the flashing functionality but showing the user a progress bar faking the update. that sounds a bit crazy but considering the creation of an uefi malware sample is not something a script kiddie will do in less time. to alter the flashing utility is the first logical step from an attackers perspective if he wants to keeps persistence because he knows, that msi will revoke its keys. furthermore the attackers will stealth their activities on infected but fake flashed bioses to keep their access to the network. therefore i would not use anything of the old hardware.

      @Yadlina@Yadlina12 күн бұрын
  • Moonwalk nalware is also a bios virus it just has a different nsne because its in croation

    @JustinBeard-fz2xb@JustinBeard-fz2xbАй бұрын
  • great video

    @aleshperfiliv7979@aleshperfiliv79797 ай бұрын
    • Thanks!

      @NicoKnowsTech@NicoKnowsTech7 ай бұрын
  • So, how long has this vulnerability existed?

    @BuPhoonBaba@BuPhoonBabaАй бұрын
  • jungle

    @kennyheisen539@kennyheisen5397 ай бұрын
  • How well do eset stop firmware infections??

    @RachelBahtYisrael@RachelBahtYisrael5 ай бұрын
    • Better than anyone else currently. Firstly, ESET's engine is actually looking for them. Secondly, ESET is the cyber security firm that is actively hunting for these types of threats so we can detect them. Kaspersky finds one every now and then, but not quite like ESET at the moment.

      @NicoKnowsTech@NicoKnowsTech5 ай бұрын
  • I think my gamming computer was affected by this, will a bios flash fix this?

    @brantbolton1284@brantbolton12846 ай бұрын
    • Worth a shot, but first confirm you have an infection. Check with ESET

      @NicoKnowsTech@NicoKnowsTech6 ай бұрын
  • Do open source viewers allow uefi infections on a p.c.?

    @RachelBahtYisrael@RachelBahtYisrael5 ай бұрын
    • Its possible.

      @NicoKnowsTech@NicoKnowsTech5 ай бұрын
  • ohhhh

    @julyaaron3671@julyaaron36717 ай бұрын
  • Motherboard manufacturers could have saved the world a lot of pain by having a little dip-switch or jumper that can make the BIOS read-only, or read-write [so that you can update the BIOS with a genuine flash file]. Too basic and practical for the "geniuses" in IT, I guess. And sure, I get it, software switches can enable a lot of cool stuff, like "wake on LAN", "netboot" and so on. But no code ever written, be it malware or otherwise, can overcome a physical barrier.

    @roberthunter6927@roberthunter69274 ай бұрын
    • I couldn't of said it any better than you did

      @NicoKnowsTech@NicoKnowsTech4 ай бұрын
  • Pretty sure I got malware on my router, phone, and laptop via UEFI bs

    @GhostDog626@GhostDog626Ай бұрын
  • So basically don't use a laptop or a pc

    @haroldsmith768@haroldsmith7687 ай бұрын
  • ❤❤❤

    @Nancy-fq9ph@Nancy-fq9ph6 ай бұрын
  • When you have a rootkit and live targeted and it so bad, you cant even comment here without it being removed ...Luckely my email came through Nico (another account on my Cellphone now) taking a pc fight battle off today... Gert

    @dreamgertgoogledntcareitshaxed@dreamgertgoogledntcareitshaxed6 ай бұрын
    • Your comments got auto filtered for having links. ;)

      @NicoKnowsTech@NicoKnowsTech6 ай бұрын
    • Is see, good that not evertthing is bad... Thx for letting me Know PS tip for other warriors using ESET: check your rules regulary and disable filter, it Hides manually or other generated exceptions mostly system drivers and so on...after turning off interactive mode and going tot automatic, Rules got injected there,...if your malware Hides in system, it looks legit ...50 rules allowing remote interaction got inserted, detected it soon enough ...You can protect by adding a password to ESET, bit downside is having to give it in in every interactive global allow rule (pretty hard when your PW need to ben +15 characters to be secure enough... Total madness clicking on a Virustotaal connect Google account link and a script Ran, auto delering my Google account LOL, i saw it, recovered it and than checked my rules and Found out this is far Grol over 😂

      @dreamgertgoogledntcareitshaxed@dreamgertgoogledntcareitshaxed6 ай бұрын
    • From* my keyboard is acting up, on a compromised device..

      @dreamgertgoogledntcareitshaxed@dreamgertgoogledntcareitshaxed6 ай бұрын
    • @@NicoKnowsTech hi nico, still being haunted, in created a temp shared google drive to try and document some files, can i share you a link? Would love to contact some on 'prem' assistance, you have any ideas? You think local ESET support would want to hear my story out ? My identity card was next target...Gert

      @dreamgertgoogledntcareitshaxed@dreamgertgoogledntcareitshaxed5 ай бұрын
  • I desperatly need help

    @jasonlamey4695@jasonlamey46956 ай бұрын
    • uh...

      @NicoKnowsTech@NicoKnowsTech6 ай бұрын
  • Where's part 1?

    @pyresflood@pyresfloodАй бұрын
    • Right here: kzhead.info/sun/ptGniaWxbmNjZ3k/bejne.html

      @NicoKnowsTech@NicoKnowsTechАй бұрын
  • I made uefi ransomware for educational purposes only. It's scary easy.

    @xylentantivirus@xylentantivirusАй бұрын
  • Hi Nico and community friends, I posted a link on my account for those who want to see a funny (let us call it that) vid how many system apps a 'legit' phone needs 😂

    @dreamgertgoogledntcareitshaxed@dreamgertgoogledntcareitshaxed5 ай бұрын
  • Eset is based in Slovakia. Ironically, the word "Eset" means "Isis", which among other things is the name of a terrorist organization.

    @destitute8493@destitute84935 ай бұрын
    • The name... Not the acronym. en.wikipedia.org/wiki/Isis

      @NicoKnowsTech@NicoKnowsTech5 ай бұрын
    • They are multi-national by the way. I deal exclusively with ESET USA and Latin America as I run a US-based channel and live in Latin America.

      @NicoKnowsTech@NicoKnowsTech5 ай бұрын
    • ... And ESET formed in 1992. The terrorist organization formed in April 2014. If anything, they copied other people.

      @NicoKnowsTech@NicoKnowsTech5 ай бұрын
KZhead