acer aspire e380 dvd burner not found on bios maybe a rootkit?

Discussion in 'Malware Help (A Specialist Will Reply)' started by solidesign, Jun 3, 2010.

  1. solidesign

    solidesign Private E-2

    My cousin's Acer Aspire e380 Desktop running Vista SP 2 has lost it's Dvd Burner numerous times. I have determined that it was not the drive, because I bought a brand new Pioneer DVR-A18M, and installed it. It worked for a little while and then apparently when the computer went into hibernation (a guess) it disappeared, and wouldn't start up. Through all kinds of blog and help info I tried everything. I actually just yesterday got them both working at the same time, and everything was great. They both showed up on the bios, one was set to master and one slave on the IDE channel/internal cable and everything was working perfectly, flawlessly. But just last night apparently the computer went to sleep and the dvd drives didn't wake up.

    I have been over everything with a fine toothed comb. I did the reg edit trick with the upper and lower filters (there were none), I tried reflashing the bios with a newer version, only to have other problems, so I flashed it back to the original (all of these things were done before I got them both to come up again and work), and now I am left pretty much thinking it could be some sort of virus or rootkit. I did all the steps in the Malware removal blog, except posting the rootkit logs. So that is kind of why I am here to day asking someone for some help or advice. It's driving me bonkers. And maybe they could review my rootkit logsfor possible answers.

    I did try running the "GMER" rootkit and the computer kept giving me the blue screen when it got to "Devices", so I unclicked that one on the scan and let it run. I will try a separate run with just that clicked. But it appears to be the issue. One of the messages that came up was: "PFN_LIST_CORRUPT" and another was "PAGE_FAULT_IN_NON_PAGED_AREA" .
    When I try to run just the "Devices" part it crashes when it get's to: "\Devices\HarddiskVolumeShadowCopy1"
    Does that mean anything to anyone?

    I am pretty much at my wit's end with the IDE thang. I also tried reinstalling the drivers for the PCI IDE cables/bios/etc. That didn't work. I tried the trick with the san disk usb boot key startup with a new master boot flile someone said would trigger the bios to see the ide devices. Some of these things may have worked, because this has been going back and forth now for 4 days. One day the drive will be there, the next day it won't. Then I'll do a few things, and wala, it's back again. And then it disappears again the next day. I have messed with the cable, I've checked the drives to make sure they are not conflicting letters when they do come up. The bios is all prepped for finding dvd/rom drives, the drives are set to Master and Slave. The power supply turns both drives on. It's just crazy.

    Help.
     

    Attached Files:

  2. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

  3. solidesign

    solidesign Private E-2

    I have run all of the programs listed, but at the time I didn't want to go through with the post because when I did all of those things the dvd player was working... so I didn't think it was necessary to post everything. I was just running them to make sure there were no immediate virus's. But as it has escalated. I will run them again, since I have already gotten rid of the combo fix and mglogs. I still have the RootRepeal log and the sas log, and the mbam log. I hope that will be okay.
    Thanks,
    Scott
     
  4. solidesign

    solidesign Private E-2

    Here are the rest of the logs I had saved, but didn't post.
     

    Attached Files:

  5. solidesign

    solidesign Private E-2

    Here are the rest
     

    Attached Files:

  6. TimW

    TimW MajorGeeks Administrator - Jedi Malware Expert Staff Member

    Your logs are clean. I suggest that you post in the software or hardware forum for further assistance with your DVD player.

    If you are not having any other malware problems, it is time to do our final steps:

    1. We recommend you keep SUPERAntiSpyware and Malwarebytes Anti-Malware for scanning/removal of malware. Unless you purchase them, they provide no real time protection. They do not use any significant amount of resources ( except a little disk space ) until you run a scan.
    2. If we had you use ComboFix, uninstall ComboFix (This uninstall will only work as written if you installed ComboFix on your Desktop like we requested.)
      • Click START then RUN and enter the below into the run box and then click OK. Note the quotes are required
      • "%userprofile%\Desktop\combofix" /uninstall
        • Notes: The space between the combofix" and the /uninstall, it must be there.
        • This will uninstall ComboFix and also reset hidden files and folders settings back to Windows defaults.


    3. Go back to step 6 of the READ ME and renable your Disk Emulation software with Defogger if you had disabled it.
    4. Any other miscellaneous tools we may have had you install or download can be uninstalled and deleted.
    5. If we had you download any registry patches like fixme.reg or fixWLK.reg (or any others), you can delete these files now.
    6. If running Vista, it is time to make sure you have reenabled UAC by double clicking on the C:\MGtools\enableUAC.reg file and allowing it to be added to the registry.
    7. Go to add/remove programs and uninstall HijackThis.
    8. Goto the C:\MGtools folder and find the MGclean.bat file. Double click on this file to run this cleanup program that will remove files and folders related to MGtools and some other items from our cleaning procedures.
    9. If you are running Win 7, Vista, Windows XP or Windows ME, do the below:
      • Refer to the cleaning procedures pointed to by step 7 of the READ ME
        for your Window version and see the instructions to Disable System Restore which will flush your Restore Points.
      • Then reboot and Enable System Restore to create a new clean Restore Point.

    10. After doing the above, you should work thru the below link:

     

MajorGeeks.Com Menu

Downloads All In One Tweaks \ Android \ Anti-Malware \ Anti-Virus \ Appearance \ Backup \ Browsers \ CD\DVD\Blu-Ray \ Covert Ops \ Drive Utilities \ Drivers \ Graphics \ Internet Tools \ Multimedia \ Networking \ Office Tools \ PC Games \ System Tools \ Mac/Apple/Ipad Downloads

Other News: Top Downloads \ News (Tech) \ Off Base (Other Websites News) \ Way Off Base (Offbeat Stories and Pics)

Social: Facebook \ YouTube \ Twitter \ Tumblr \ Pintrest \ RSS Feeds