I started having problems with Windows not booting. The computer (Acer Laptop Aspire 3690 running Windows XP Starter Edition) is set up for dual boot with Xubuntu, which runs fine. Ultimately, I got the following error:
Stop: c000021a(Fatal Ssytem Error)
Windows Logon Process terminated with a status of 0x00000406 (0x00000000 0x00000000)
On occasion, I have been able to get in to a disc scan prior to boot, and there have been a couple of corrupted files (one was a Google updater).
Finally, I was able to get Windows to boot into Safe mode, and found that my Restor will not let me restore to a date earlier than Monday, March 3 at 6 PM, which happens to coincide with when I downloaded an upgrade to Avira Antivirus Personal Addition. I note also that Avira no longer works, nor does my Comodo fire wall (I can not activate either)
Running RootKitRevealer, I find that I have two Registry Keys with "key name contains embedded nulls (*)"
HKLM\SECURITY\Policy\Secrets\SAC*
HKLM\SECURITY\Policy\Secrets\SAI*
Running RegDelNull results in a response "access denied".
I have found a copy of RtkBtMnt.exe in the Documents and Settings\Owner\Local Settings\Temp folder, which I have tried to delete, but it keeps coming back. It has a creation date of today (at the latest boot time).
I have tried to add additional antivirus software (including Comodo and Malwarebyte, among others), none of which will load on the computer. RegistryBooster from www.file.net, which is supposed to help detect problems with RtkBtMnt.exe won't run after downloading.
CCleaner and Glary Utilities do not clean up the registry. There is a prefetch file in C:\Windows\Prefetch called RTKBTMNT.EXE-170A120F.pf, although I have used a utility to discard all prefetch files (19022 bytes, dated at my last boot). I just discovered that the file in the temp folder is written in Chinese, Version 1.0.0.5, and it appears to be adding other language codes to the folder (Turkish.bin, Thai.bin, etc- 25 different languages. Even renaming the program in the Temp folder doesn't do any good. I also find a file named wpa.dbl in Windows\system32 with the same date stamp at the RtkBtMnt.exe file. There were several .log and .txt files in the Windows folder with the same date stamp, and files, wiaservc.log and SchedLgU.Txt and WindowsUpdate.log and wiadebug.log, that could not be deleted.
So, where do I go from here?
Good Answers:
"Almost" Good Answers: