Windows 10: Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside...

Discus and support Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside... in Windows 10 Software and Apps to solve the problem; This article provides steps to deducting BLACKLOTUS bootkit-infected EFI partition files and disabling security features inside Windows 11 and Windows... Discussion in 'Windows 10 Software and Apps' started by RAJU.MSC.MATHEMATICS, May 14, 2023.

  1. Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside...


    This article provides steps to deducting BLACKLOTUS bootkit-infected EFI partition files and disabling security features inside Windows 11 and Windows 10.My laptop hardware is working with Windows 11 64 22H2 Build no 22622.1702.Step1 Boot Windows os with normal modeOpen Command prompt application with administrator rights type the below command to mount efi partition with the letter available say XMountvol X: /sStep2Find all files included under the boot folder in the EFI partition, to viewtype below command Dir X:EFI\Microsoft\Boot\*.efiThe following files are included in the Boot folder1.

    :)
     
    RAJU.MSC.MATHEMATICS, May 14, 2023
    #1
  2. Brink Win User

    BlackLotus UEFI bootkit: Myth confirmed

    Read more: BlackLotus UEFI bootkit: Myth confirmed | WeLiveSecurity
     
    Brink, May 14, 2023
    #2
  3. trog100 Win User
    Move EFI partition

    its to enable win 10 to update to its anniversary edition.. it cant do this due to lack of C drive space i have had a quick try with the trial version of easus.. it didnt seem to be able to do what i want..

    i am assuming i cant just delete the efi partition but maybe i could.. as yet i havnt even figured out how to get into the bios of the thing.. maybe that should be my next step.. *Smile Deducting and preventing  Blacklotus bootkit injected files in to EFI partition and inside... :)

    diskpart could probably do it but figuring out how (it aint that user friendly) might be difficult without step by step instructions..

    trog
     
    trog100, May 14, 2023
    #3
  4. Try3 Win User

    Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside...

    BlackLotus UEFI bootkit: Myth confirmed  

    Thanks for posting this.

    I'm confused by two parts of the Eset description:
    1 The third item in the section Following are the key points about BlackLotus and a timeline summarizing the series of events related to it
    2 Under the heading Mitigations and remediation
    I think they are saying that an MS update fixed the problem of future infiltration but did not fix the problem for systems that have already been infiltrated.
    But I'm not sure.
    Perhaps my interpretation is too optimistic.

    I also noticed, under the heading Step 3 – Disabling BitLocker, "... would lead to a BitLocker recovery screen at the next bootup and would tip the victim off that the system had been compromised".
    There have been some Ten/ElevenForums reports of this recovery screen appearing unexpectedly.

    All very worrying,
    Denis
     
Thema:

Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside...

Loading...
  1. Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside... - Similar Threads - Deducting preventing Blacklotus

  2. How to access files in the EFI partition

    in Windows 10 Gaming
    How to access files in the EFI partition: The EFI partition on HP systems contains bios backups and has run out of space. I cannot enlarge the partition. When I shrunk "C" the free space showed up on the right hand side instead of next to the EFI. I tried mounting the EFI using diskpart as suggesteddiskpartlist...
  3. How to access files in the EFI partition

    in Windows 10 Software and Apps
    How to access files in the EFI partition: The EFI partition on HP systems contains bios backups and has run out of space. I cannot enlarge the partition. When I shrunk "C" the free space showed up on the right hand side instead of next to the EFI. I tried mounting the EFI using diskpart as suggesteddiskpartlist...
  4. Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside...

    in Windows 10 Gaming
    Deducting and preventing Blacklotus bootkit injected files in to EFI partition and inside...: This article provides steps to deducting BLACKLOTUS bootkit-infected EFI partition files and disabling security features inside Windows 11 and Windows 10.My laptop hardware is working with Windows 11 64 22H2 Build no 22622.1702.Step1 Boot Windows os with normal modeOpen...
  5. Windows 11 Security at risk? BlackLotus UEFI bootkit defeats Secure Boot

    in Windows 10 News
    Windows 11 Security at risk? BlackLotus UEFI bootkit defeats Secure Boot: ESET security researchers have discovered an UEFI bootkit malware that defeats secure boot on Windows 11 and Windows 10 devices. Named BlackLotus, it is considered the first UEFI bootkit malware that has been detected in the wild. [ATTACH] The UEFI bootkit runs on fully...
  6. EFI Partition

    in Windows 10 Network and Sharing
    EFI Partition: Attached below is a screenshot of my disk managerI would like to make my C drive adjacent to the unallocated space so that I can expand the C drive into the 97 free gb. Is there a way I can move the EFI partition so that the C drive is adjacent to the unallocated space.Also...
  7. EFI Partition

    in Windows 10 Gaming
    EFI Partition: Attached below is a screenshot of my disk managerI would like to make my C drive adjacent to the unallocated space so that I can expand the C drive into the 97 free gb. Is there a way I can move the EFI partition so that the C drive is adjacent to the unallocated space.Also...
  8. EFI Partition

    in Windows 10 Software and Apps
    EFI Partition: Attached below is a screenshot of my disk managerI would like to make my C drive adjacent to the unallocated space so that I can expand the C drive into the 97 free gb. Is there a way I can move the EFI partition so that the C drive is adjacent to the unallocated space.Also...
  9. Access to EFI Partition

    in Windows 10 Drivers and Hardware
    Access to EFI Partition: After the latest windows update, when I open file explorer, three extra drives were added besides the c drive. Winretool partition was assigned y drive, PBR partition was assigned x drive and ESP (efi system partition) was assigned e drive. I was able to remove the y and x...
  10. EFI partition deleted

    in Windows 10 Drivers and Hardware
    EFI partition deleted: While installing a different OS. My EFI partition was wiped and set as unallocated space. I booted up a linux live cd and partitioned the unallocated space, formatting it back to FAT32. I was able to restore grub and boot into my linux distro. Now I want to restore windows'...