Vault 7: Projects

INSTALLER STATUS CODES AND MESSAGES
The installer may output the following status codes:
0x80000001 - Firmware Parse Error•
0x80000002 - Firmware Append Error•
0x80000003 - Firmware Write Error•
0x80000004 - Firmware Compression Error•
0x80000005 - Firmware Out of Space Error•
0x40010000 - Firmware Unlock Patch Warning•
0x40020000 - Receipt Warning: The receipt could not be written to the installation
media
•
0x40040000 - PEI Find Warning: Unable to find PEI Core. Update persistence will not be
enabled.
•
0x40080000 - PEI Append Receipt Warning: Unable to append implant to PEI Core. Update
persistence will not be enabled
•
0x40100000 - PEI Write Warning: Unable to write implant to PEI Core. Update
persistence will not be enabled
•
During Install the following message indicates the installer detected a machine that can be
unlocked by holding the power butter for 10 secs:
ERROR: TRIGGER NOT NEEDED•
UNINSTALL COMMENTS
After an uninstall, the flash memory will be unlocked until an Apple firmware update
is applied
•
If patch firmware option was not enabled, the implant is deactivated by setting a
variable in NVRAM. If NVRAM is cleared and the "Uninstall if NVRAM Cleared option is
not set, then the implant may become active again.
•
Secure deletion of implant is performed on the first system reboot after an uninstall
is triggered. It increases boot time by 30-60 seconds. Since BIOS/EFI will need to
flush NVRAM every 40-60 boots, it is reasonable to ocassionally see boots that take a
longer amount of time.
•
If the power button is held down or power is lost during a secure delete of the
implant, MacBooks mid 2012 and newer have run length fields that prevent the laptop
from bricking. Parts of the implant may still forensically exist in firmware, but only
as partial encrypted blobs. On laptops older than mid 2012, there is a possiblity of a
corrupt firmware, but it has also been observed that secure deletes take less time on
older hardware.
•
BOOTCAMP COMMENTS
Booting Windows may affect the time and date settings in OS X. This can cause Der
Starke to beacon several hours later than expected.
•
SECRET//NOFORN