
Unable to boot after Patched_c.Jee malware
#1
Posted 13 October 2010 - 03:25 AM
Register to Remove
#2
Posted 13 October 2010 - 04:08 AM
To make cleaning this machine easier
- Please do not uninstall/install any programs unless asked to
It is more difficult when files/programs are appearing in/disappearing from the logs. - Please do not run any scans other than those requested
- Please follow all instructions in the order posted
- All logs/reports, etc.. must be posted in Notepad. Please ensure that word wrap is unchecked. In notepad click format, uncheck word wrap if it is checked.
- Do not attach any logs/reports, etc.. unless specifically requested to do so.
- If you have problems with or do not understand the instructions, Please ask before continuing.
- Please stay with this thread until given the All Clear. A absence of symptoms does not mean a clean machine.
AVG may have been the cause of the problem.
There are a few things we can try to see if you can get windows to load.
The Windows CD you have what kind is it? Is it a retail copy of Windows and what is the operating system?
First we'll try the easy.
- Restart your computer
- After hearing your computer beep once during startup, but before the Windows icon appears, tap the F8 key continually;
- Instead of Windows loading as normal, a menu with options should appear;
- Use the arrow key to highlight Last Known Good Configuration
- Press Enter.
Thanks
Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.
#3
Posted 13 October 2010 - 08:01 AM
I tried this already and it didn't work. I also tried F9 which told me to insert a recovery CD 'Gigabyte CD' which I haven't heard of and seems like another scam.I downloaded Adobe Flash Player update from a reputable site. A short time later I started to get AVG messages repeating every few seconds telling me that Trojan Horse Patched_c.Jee (or Jed) was affecting the system and this was not removable "in a white area". I ran Malwarebytes and AVG, neither found anything. I removed all Adobe products using Windows. At the end of the process I was advised to restart. Since then the PC will not reboot even in Safe mode and it keeps retrying. I disabled the retry option and I get BSOD with a message C000021a 0xC0000034 Logon Process Error.
How do I recover? Can I reboot from CD and get the system back or will I have to reboot from CD and format the hard disk etc. etc.
#4
Posted 13 October 2010 - 08:08 AM
#5
Posted 13 October 2010 - 01:04 PM
You didn't mention you tried Last Known Good Configuration, you said you tried Safe Mode. Gigabyte is a legitamate company. The F9 menu on your computer could be the restore options.
It would be better if we had the CD that came with the computer. We can try the CD you have and see if we can access the Recovery Console and look for a file.
Do not make any changes or use any other options.
We'll need to use the Recovery Console that is on your CD. This will allow use to gain access to some areas of windows.
You computer must be able to boot from the CD.
Insert the Windows XP startup disk into the floppy disk drive, or insert the Windows XP CD-ROM into the CD-ROM drive, and then restart the computer.
1. Click to select any options that are required to start the computer from the CD-ROM drive if you are prompted.
2. When the "Welcome to Setup" screen appears, press R to start the Recovery Console.
3. You should now see a list of installations and the prompt "Which Windows Installation would you like to log on to?"
Select the appropriate number for the Windows installation that you want to repair. If you only have one, press 1.
4. When you are prompted, type the Administrator password. If the administrator password is blank, just press ENTER.
You should now have a C:\windows> prompt
-From the prompt, type the following commands, one at a time, hitting enter after each:
cd system32
dir
Note in the first line there is a space after cd
Use the space bar to scroll down the list and look for the presence of this file winlogon.exe
Let me know if it's there and the file size and date.
See if you can find your CD as you may need it to do a reinstall if it comes that. The CD that you can't find, is it a full retail version of XP or an OEM such as Dell, HP etc?
Thanks
Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.
#6
Posted 13 October 2010 - 03:23 PM
#7
Posted 13 October 2010 - 03:33 PM

Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.
#8
Posted 14 October 2010 - 04:21 AM
#9
Posted 14 October 2010 - 04:36 AM
This is the message you are recieving?I get BSOD with a message C000021a 0xC0000034 Logon Process Error.
Or
insert a recovery CD 'Gigabyte CD'
Does Bios recognize that the CD drive is installed?
Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.
#10
Posted 14 October 2010 - 07:35 AM
Register to Remove
#11
Posted 14 October 2010 - 12:14 PM
Given the BSOD you received it sounds like your computer is still trying to boot to Windows and not the CD.
Possible problem could be loose cable, have you been in the computer recently doing some cleaning?
Possible that the drive has died. Did the drive actually spin up or just have a power light briefly?
Not being recognized in the bios may very well explain why you can't change the boot order in F12, there isn't anything to change it to.
Please post your computer specs. Brand, model, motherboard if possible, etc.
Is it possible to set it to boot from CD but report the errors?I've been into the BIOS and set the PC to boot from the CD and ignore all errors
Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.
#12
Posted 14 October 2010 - 01:33 PM

Edited by Alantb, 14 October 2010 - 01:34 PM.
#13
Posted 14 October 2010 - 01:49 PM

Not quite that old but getting there.

If the drive is indeed dead the bios won't see it as there would be no communication between them. Have a look in the older computer's bios and see what you can find out, just don't make any changes. If we knew the brand of computer we may be able to guide you to the area of the bios to look in.
The CD roms usually have a small light on the front that will flash on and off as the unit is being read or powered up. They are usually fairly noisy when running, kind of like a fan.
Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.
#14
Posted 15 October 2010 - 09:44 AM

#15
Posted 15 October 2010 - 10:26 AM
Proud Graduate of the WTT Classroon
If you are happy with the help you recieved, please consider making a Donation
Curiosity didn't kill the cat. Ignorance did, curiosity was framed.
Learn how to protect Yourself
Microsoft MVP 2011-2015
Threads will be closed if no response after 5 days.0 user(s) are reading this topic
0 members, 0 guests, 0 anonymous users