BSOD and missing HDD

hotelmariofan

Honorable
May 14, 2012
94
0
10,630
Alright, to start things off, I'll describe my current setup.
MOBO: Sabertooth Z77
RAM: 16GB
GPU: GTX 680
HDD + SSD (OS)
OS: Win7 64bit
Currently, I have my OS installed on an 120GB SSD with a few other programs I use frequently. As for everything else, well it's on a 1TB HDD. Today, I decided I would copy some hefty files over to my flash-drive. While doing so, I received a message asking for adminstrative rights to copy one of the files. I granted it said rights and almost instantly after doing so, I got the BSOD. My PC rebooted automatically, and upon reboot, I realized nearly all of my icons were broken on my desktop. (I pretty much immediately thought the HDD had died, but I'm still hoping for the best.) I open up "my computer" and lo and behold, no D: drive. Wonderful. It was only an entire terabyte of data. Not having dealt with this before, I wasn't sure where to begin. Usually I am able to find volumes of forum posts to scour through, but not this time apparently. I may be missing the right key words, but I usually don't have issues with that. Knowing what you do now, what do you think I should try? I'm at a loss, and I hate it. Thanks in advanced.
 

SirSub42

Honorable
Aug 31, 2013
367
1
10,960
What error was displayed with the BSOD? I believe we should start there as that will likely lead us to the cause of the problem. Try a program such as WhoCrashed. This should give us a little more information on the cause of the crash.

Best of luck and look forward to a response. - Sub
 

hotelmariofan

Honorable
May 14, 2012
94
0
10,630


I'm not seeing the drive in the BIOS. As far as the crash dump goes, well, I'm stumped. Neither "WhoCrashed" or "BlueScreenView" worked. By that I mean they both say there is no crash dump available. I'm confused as to why that would be, a BSOD definitely happened before the auto reboot.

Update: My anti-virus just located an "unknown application" as a virus. The only description it gave was that it was "part of the operating system". This "unknown application" was identified by the anti-rootkit scan. This is worrisome...

Update 2: HA! Alright, great news! After removing this unknown application, my D: drive reappeared! All is well there then, now it's dealing with this rootkit... The odd thing is, I haven't downloaded any files as of late, nor have I visited any questionable websites. I'm wondering where this could have originated from.
 

SirSub42

Honorable
Aug 31, 2013
367
1
10,960
Rootkit you say? Do you have a specific version so we can look into step specific instructions for removal? Also, for future reference. Right click on "My Computer" (click properties), "Advanced", then "Startup and Recovery Settings". Put a check next to "Write an event to the system log" and remove the check next to "Automatically Restart". This should help us next time around to make sure the BSOD writes a log file for us to investigate.
 

hotelmariofan

Honorable
May 14, 2012
94
0
10,630


While I did need to uncheck the Automatic Restart, the "Write an event to the system log" was already checked. If I get any specific information from these other anti-virus programs, I'll post it. AVG was of no use when it comes to telling me anything other than the fact that it was a rootkit.

It's odd, while I have had some experience with rootkits, I've never seen one that disables drives.
 

hotelmariofan

Honorable
May 14, 2012
94
0
10,630


Heh, I've had it going for the last 25 minutes. That's usually the first scan I run after AVG catches something. If AVG misses something, malwarebytes usually has no issue picking up its leftovers.
 

hotelmariofan

Honorable
May 14, 2012
94
0
10,630
Well, the symptom has returned. The D: drive has disappeared, although this time, there was no BSOD when it happened. I just suddenly lost access to all data on the drive. No amount of malwarebyte, AVG, or spybot scanning can seem to find anything this time. Restore points apparently only keep the day before, which was when I discovered the virus. Any other suggestions would be greatly appreciated.

Update: Well, now CPUtemp is saying all of my cores are at 105C... unlikely, as I'm not having any crashing issues and the cores are no where near being maxed in usage. My liquid cooling system seems to be functioning without issue. Once again, I am confused.

The computer also now refuses to shut down by the start menu button. It just sits there saying "Shutting Down" endlessly. Either than or it's just taking decades to actually do it.
 


I got a rootkit from what I thought was a valid Adobe update quite some time ago. AVG and Malwarebytes didn't touch it. Kaspersky had a free download that had to be burned to a CD. I did that and booted from the CD and it fixed it. It was a nasty ah heck. That was quite some time ago but you might check Kaspersky.
 

hotelmariofan

Honorable
May 14, 2012
94
0
10,630

I see, I'll look into that. Another symptom has appeared now. None of my usb drives are being recognized. It almost seems like my mobo is failing, my drive came back when I booted up this morning. It will surely disappear again, but then again, what if it's just a virus causing these symptoms? Bleh, I suppose I could try some anti-virus forum as well. I really want to avoid formatting, that's last resort.

Update:
Well, being that I'm new to this sort of troubleshooting, I didn't think to check Event Viewer. Now that I've done so, I am noticing a few errors that have been appearing since I've started having these issues. For one, every time I plug in a USB drive I get Event ID: 24620. This is apparently related to bitlocker. I'm not sure what that is, nor have I ever used it. Another error that has been appearing is Event ID: 11. These both appear when I plug in a flash drive. At this point, I'm wondering if this is due to a virus, or just coincidence. Any suggestions would be greatly appreciated.