Craziest thing ever that I need help with

So I bought a PC from some kid, and its an STGAUBRON branded piece of crap basically. He’s loaded it with some kind of custom BIOS using the PKFile data “DO NOT TRUST” exploit and there are a ton of keys in the bios. My computer keeps getting connections from him no matter what I do, and i think he’s downloading logs.

Ive nuked all 4 of my drives, did a fresh usb install from a different PC and it keeps directing to use a fake windows update server that his keys have authenticated as legit.

I cant even tell what bios version it is using, as he’s got the custom BIOS to report the motherboard as a H5104M-S and there is NO info on that at all.

Im at a loss at this point and am thinking of just getting a new motherboard entirely. A real one lol.

What about physical identification, like the serial number on the motherboard? Are there none at all?

Did some poking around on the net.

This is your board on the Gigabyte website:

Get the BIOS right away and flash it. If you don’t you could be open to fraud/blackmail/etc, or someone setting up a fake ID in your name. It’s open season on you until you flash the BIOS.

That could be problem solved. It’s worth a shot as you never know what the guy that sold you the pc is looking at. Probably everything you do/see/use. So, it’s either do the above or buy a new motherboard. Or take the darn thing back and demand a refund.

Edit: I would reinstall Windows after you flash the BIOS but before you do that use the Diskpart ‘clean’ command to ensure there is nothing left your Windows drive, including the EFI and Boot partitions. If you can, do the same for any data drives you have been using. Don’t use diskpart to clean a full drive, it wipes everything inc all partitions.
Then install a good AV and scan all your drives. Bitdefender is good.

1 Like

ZRD5104

SN:MB2307173|54Z

That is the only information on the board

Cpuld you possibly directly link me to a download for the suite? The bios and the flash tool? Im using my phone and bluetoothing everything over to the PC with the ethernet disconnected lmao so its quite a pain. Sorry to ask this of you guys

Dont do that… this is a POS chinese motherboard, green SATA ports are visible…


You will probably get a flash error or a death motherboard

@basil1492
Hey buddy… how do you relate this to a GigaByte motherboard???

1 Like

Yep! Thats the EXACT board. It says “ultra stable” in the corner.

Now the question is… do i just stay offline until tuesday when i can get a new motherboard?

Update : ive finally found a little information. The motherboard can be purchased here in bulk :

I also found logs online of my PC running PIKO OS 3, showing bios, hardware, software, etc.

Literally looks like the only PC in the world with this bios / firmware which is telling that the AMI 5.19 written on 03-01-2023 is bogus as fk.

I tried to flash a stock ASUS H510M v2402 using the AMI tool but got a size mismatch error and like… yea of course i did because its a custom fkn bios :frowning:

I think i need to extract this bios rom (but from what i remember, in my frenzy of trying to fix it i saw errors regarding the extraction so i believe its locked out)

When i get a new mobo i’m going back to this kids house and yeeting this one through his high-end crack-shack window lol

I’ve found the appropriate bios file (i believe!) And have attempted to flash using USB boot. No go.

This is my result

File not found…
i think its an obvious report of the error…
Did you made backups of the current SPI with FPT, i do advise you so…
FPT writes wrong/correct data, its doesnt care, so if the “new” flashed bios is not suitable for the mb, you’ll probably can get a death mb…
You cant simple get an Asus or other brand bios file and flash it… bios vendors have its own IDs. You’ll get a mismatch error or a security error.

No this is the bios file from Shenzhen TRZI or whatever it was called.

The problem is now that FS2: has no mapping so it exits :frowning:

Maybe ill try from windows using the AMI flash tool

So ive been able to get inside the PKfile of the PC i believe.

I launched an EFI shell, launched fs0: and ls showed an EFI directory, and 2 files (dbx and PK)

Edit PK brings this up (verifying the “DO NOT TRUST” crap related to the massive failure of Secureboot

Now… where to go from here?

(Remember, im offline and dont really care too much if I brick this thing im ordering a mobo regardless. I just want to figure out how to remove all these keys in the bios that are redirecting Windows to download the rest of the RAT package for the better of everyone lol)

Mikey said the board was reported as a H5104M-S which is a gigabyte board. All I did was google it. I didn’t see the pic of green sata ports and did not know that this meant it could be chinese. Surely Mikey would have seen that the Gigabyte board was not the same as his had he looked at the Gigabyte site pics. Had I been given the same advice and looked at the Gigabyte site on the net I would have thought Nope, that’s not mine and not flashed it. I would have taken the pc back to the seller and demanded a refund.