05-29-2011, 08:41 AM
I purchased a laptop and took a gamble. It's a decent machine, and when I bought it I paid half as much as an Alienware m11 and had a system with better components. The seller was nice enough to discount me some because I had my own HDD and RAM to put in as well. Unfortunately, I know very little about laptops and this is the first one I've purchased since 2001 for graduate school. I build my own desktops so I'm not completely ignorant and I've spent a TON of time trying to track down the ODM of this laptop and I simply have had no luck. I found the actual company that sells it out of China but the contact didn't reply to me.
System
i3-350m
nVidia GT 335m
WD Scorpio 500 GB HDD
8 GB DDR3
14" RGB LED
Realtek RTL8191SE PCI-E Wireless
Realtek RTL8167 100Mb LAN Adapter
I have no idea what motherboard is in this. The seller included a driver disc and had perfect ratings on eBay, but this was his first laptop venture and I think it bit him in the rear because getting any driver updates is impossible. I had to use a modded display adapter driver since n-suck-vidia said this wasn't a supported device. The only way I found out who mfg. the laptop was the user manual .pdf properties, it had the model # the Chinese company used. There were a few posts on technet I found when someone was getting drivers working for it. He never replied either.
The BIOS is a complete joke and I want to know the ODM of the motherboard/laptop if possible. I've used every program I know to read all the system info. and all the fields used as descriptors are just blank and say OEM.
Long story short, my laptop had a rootkit on it. The date and time for the changes were the day I did my taxes at my in-laws. I'm guessing rootkits can easily proliferate over a homegroup? My log had a ton of attempts from my mother-in-laws laptop (she's not smart enough to do anything malicious). I ended up having to completely rebuild the mbr in the recovery console using bootrec.exe and bcdedit.exe to rebuild the registry. I'm almost certain I did remove the rootkit but I'm not certain because this BIOS puts some b.s. ATA Erase lock on my HDD when originally trying to use BCWipe TotalWipeout. I wasn't sure if it would work on my desktop by plugging the power in to the laptop HDD after the BIOS posts (probably going to try it later). Since getting the rootkit (mainly a redirector I believe but all AV stuff didn't definitively give any specific name which sucks and is why I considered firmware/drivers/BIOS may have something) my laptop has been running slower. I don't have access to some programs like Windows Defender command line console, avast! command line console, and for some reason rkill terminates afwserv.exe. This is the first infection I've had in almost a decade and it's driving me nuts. I never looked at processes using Process Explorer so I don't know what's normal, my logon takes forever after typing in my password, BCWipe wasn't able to erase everything so I'm not sure if something remained on another area of the HDD and/or the infection resides in firmware/driver/BIOS as said above.
Wall of text, I know right? TLDR: I have finally acquired a copy of the BIOS that is updated and was wondering if anyone could tell me anything at all about the laptop. What motherboard mfg/ODM? The BIOS has to be locked out to [censored] because there are like 3 options in it and I find it annoying I have to use EasyBCD to use USB devices to boot from, can't disable ATA Erase, can't do anything. Luckily the kind folks at laptopvideo2go mod drivers or I'd be stuck with a video driver from a year ago. Are there a bunch of features locked out of the BIOS or is it simply stripped? I don't know anything about this type of stuff but I glanced at the rom in WinHex.
Thanks for any help anyone can provide. Aside from this rootkit the laptop has been great.
System
i3-350m
nVidia GT 335m
WD Scorpio 500 GB HDD
8 GB DDR3
14" RGB LED
Realtek RTL8191SE PCI-E Wireless
Realtek RTL8167 100Mb LAN Adapter
I have no idea what motherboard is in this. The seller included a driver disc and had perfect ratings on eBay, but this was his first laptop venture and I think it bit him in the rear because getting any driver updates is impossible. I had to use a modded display adapter driver since n-suck-vidia said this wasn't a supported device. The only way I found out who mfg. the laptop was the user manual .pdf properties, it had the model # the Chinese company used. There were a few posts on technet I found when someone was getting drivers working for it. He never replied either.
The BIOS is a complete joke and I want to know the ODM of the motherboard/laptop if possible. I've used every program I know to read all the system info. and all the fields used as descriptors are just blank and say OEM.
Long story short, my laptop had a rootkit on it. The date and time for the changes were the day I did my taxes at my in-laws. I'm guessing rootkits can easily proliferate over a homegroup? My log had a ton of attempts from my mother-in-laws laptop (she's not smart enough to do anything malicious). I ended up having to completely rebuild the mbr in the recovery console using bootrec.exe and bcdedit.exe to rebuild the registry. I'm almost certain I did remove the rootkit but I'm not certain because this BIOS puts some b.s. ATA Erase lock on my HDD when originally trying to use BCWipe TotalWipeout. I wasn't sure if it would work on my desktop by plugging the power in to the laptop HDD after the BIOS posts (probably going to try it later). Since getting the rootkit (mainly a redirector I believe but all AV stuff didn't definitively give any specific name which sucks and is why I considered firmware/drivers/BIOS may have something) my laptop has been running slower. I don't have access to some programs like Windows Defender command line console, avast! command line console, and for some reason rkill terminates afwserv.exe. This is the first infection I've had in almost a decade and it's driving me nuts. I never looked at processes using Process Explorer so I don't know what's normal, my logon takes forever after typing in my password, BCWipe wasn't able to erase everything so I'm not sure if something remained on another area of the HDD and/or the infection resides in firmware/driver/BIOS as said above.
Wall of text, I know right? TLDR: I have finally acquired a copy of the BIOS that is updated and was wondering if anyone could tell me anything at all about the laptop. What motherboard mfg/ODM? The BIOS has to be locked out to [censored] because there are like 3 options in it and I find it annoying I have to use EasyBCD to use USB devices to boot from, can't disable ATA Erase, can't do anything. Luckily the kind folks at laptopvideo2go mod drivers or I'd be stuck with a video driver from a year ago. Are there a bunch of features locked out of the BIOS or is it simply stripped? I don't know anything about this type of stuff but I glanced at the rom in WinHex.
Thanks for any help anyone can provide. Aside from this rootkit the laptop has been great.