Jump to content

EFI\Computrace.A is this a virus ?


Recommended Posts

guys check these pictures ....

i cant even stop the service from the taskmanger ....!!!

even i run the safemode with network still cant stop the service !!

 

1.JPG

2.JPG

Link to comment
Share on other sites

  • Administrators

The detection is correct. However, CompuTrace is not a virus but a potentially unsafe application and this detection is optional. Detections in UEFI cannot be cleaned and the only option is to upgrade your UEFI firmare provided the vendor offers a version without CompuTrace which is very unlikely. Therefore we recommend creating a detection exclusion as per the instructions at https://support.eset.com/en/kb6567.

Link to comment
Share on other sites

so if the application is weak it might be exploit or rootkit behind this file work in the shadow  or stealth mode...

uefi:\\Volume 5\Application {057AD6B7-3525-40C8-9D21-552642894E3A} - a variant of EFI/CompuTrace.A potentially unsafe application - retained

 at least tell me what is this key ?

{057AD6B7-3525-40C8-9D21-552642894E3A}

do you have the same key with other customers ?

Link to comment
Share on other sites

  • 3 weeks later...

I have te same issue and this is on an Asus H270M-Plus motherboard. I know Lenovo portables have these kind of tracing elements built in where you can take a subcription with Absolute Software to trace the notebook when stolen. But i have never seen this on a Desktop integrator part like a motherboard. 

 

Also there are no selectable or visible settings in my BIOS (v1605). 

 

I also have the feeling that something is not right here. 

Link to comment
Share on other sites

Posted (edited)
5 hours ago, Another-ESET-User said:

I have te same issue and this is on an Asus H270M-Plus motherboard.

Here's the manual for the motherboard: https://dlcdnet.asus.com/pub/ASUS/mb/LGA1151/PRIME_H270M-PLUS/E12027_PRIME_H270M-PLUS_UM_WEB.pdf . I didn't see any references to Computrace/Absolute settings but those are often hidden settings;

Quote

Computrace related settings are not visible in BIOS Setup of ASUS X102BA

It seems that the BIOS Setup Utility developer decides whether to include the feature to enable/disable the Computrace module in BIOS Setup. There are no policies that force the developer to implement this feature. This creates a serious obstacle for ordinary users in disabling Computrace.

https://www.blackhat.com/docs/us-14/materials/us-14-Kamluk-Computrace-Backdoor-Revisited-WP.pdf

Note that a mATX motherboard could be used in either a laptop or desktop enclosure.

You would have to contact Asus tech support to fully verify that Computrace/Absolute feature was not included in UEFI/BIOS firmware.

Edited by itman
Link to comment
Share on other sites

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.
Note: Your post will require moderator approval before it will be visible.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

  • Recently Browsing   0 members

    • No registered users viewing this page.
×
×
  • Create New...