- Thread Author
- #1
Hi, sorry for the long first post but I’ve been on this a while.
recently, after the last windows 10 update ever, my pc went to reboot as normal but failed with a message that mentions “klelam.sys”.
Ive searched multiple sites and found that this file belongs to the Kaspersky AV suite that i uninstalled nearly 2 years ago. Ive been using Defender since then with zero issues after multiple reboots.
I cannot start windows in any form including safe mode.
i can start the RE but the find/repair options do not work.
if I select option 8 (‘do not use elam’) from the RE menu options the pc just hangs.
ive run multiple virus scans and removed a few bits of malware that the various tools identified.
ive searched the pc and cannot find klelam.sys but there are a number of elam.sys (which i think are the windows default files).
Ive used the 3 bcdedit commands to recreate the boot files just in case.
I’ve used bcdboot /c to force windows to recreate the boot files
I have run various repair tools from companies like easus, amoei, etc with no success as the error remains.
i have searched the system hive (mounted into Hirems windows recovery toolset) and cannot see any keys referencing Elam other than backup location so presume there are no policies set that would force the use of klelam.sys over Elam.sys
I have a hidden EFI partition of 300mb
boot drive is c
windows is located at c:\windows
i can read all of my NTFS c drive (including the files on the EFI partition which is formatted as fat32 and another 500mb system partition which is formatted to NTFS) using hirens recovery cd
I cannot:
uninstall recent updates or
Roll back to a previous restore point (even though I use them religiously every change I make it seems there is not a single one in the relevant folder)
I have searched the entire registry - no mention of klelam.sys
i have searched the entire c drive - ditto.
this is what is infuriating, there isn’t a klelam.sys file in existence nor referenced anywhere (but there is an Elam.sys) yet boot fails with the same error ‘a file is missing - klelam.sys, please locate and reboot’ or words to the effect.
I’ve reset the Amd bios on my ASU’s tuf 450 plus gaming mobo to system defaults and will try to reset the nvram just in case there is something in there.
I am not keen on turning off secure boot just in case there is something really nasty in the boot files that has evaded the 5 av scanners used so far.
I really do not want to blow away the drive and reinstall windows as i have a few hundreds apps that would need reinstalling as i create music.
my question is how do i force the boot loader to use the default elam.sys file and remove references to klelam.sys when i cant boot windows to run an in place upgrade?
Thanks
recently, after the last windows 10 update ever, my pc went to reboot as normal but failed with a message that mentions “klelam.sys”.
Ive searched multiple sites and found that this file belongs to the Kaspersky AV suite that i uninstalled nearly 2 years ago. Ive been using Defender since then with zero issues after multiple reboots.
I cannot start windows in any form including safe mode.
i can start the RE but the find/repair options do not work.
if I select option 8 (‘do not use elam’) from the RE menu options the pc just hangs.
ive run multiple virus scans and removed a few bits of malware that the various tools identified.
ive searched the pc and cannot find klelam.sys but there are a number of elam.sys (which i think are the windows default files).
Ive used the 3 bcdedit commands to recreate the boot files just in case.
I’ve used bcdboot /c to force windows to recreate the boot files
I have run various repair tools from companies like easus, amoei, etc with no success as the error remains.
i have searched the system hive (mounted into Hirems windows recovery toolset) and cannot see any keys referencing Elam other than backup location so presume there are no policies set that would force the use of klelam.sys over Elam.sys
I have a hidden EFI partition of 300mb
boot drive is c
windows is located at c:\windows
i can read all of my NTFS c drive (including the files on the EFI partition which is formatted as fat32 and another 500mb system partition which is formatted to NTFS) using hirens recovery cd
I cannot:
uninstall recent updates or
Roll back to a previous restore point (even though I use them religiously every change I make it seems there is not a single one in the relevant folder)
I have searched the entire registry - no mention of klelam.sys
i have searched the entire c drive - ditto.
this is what is infuriating, there isn’t a klelam.sys file in existence nor referenced anywhere (but there is an Elam.sys) yet boot fails with the same error ‘a file is missing - klelam.sys, please locate and reboot’ or words to the effect.
I’ve reset the Amd bios on my ASU’s tuf 450 plus gaming mobo to system defaults and will try to reset the nvram just in case there is something in there.
I am not keen on turning off secure boot just in case there is something really nasty in the boot files that has evaded the 5 av scanners used so far.
I really do not want to blow away the drive and reinstall windows as i have a few hundreds apps that would need reinstalling as i create music.
my question is how do i force the boot loader to use the default elam.sys file and remove references to klelam.sys when i cant boot windows to run an in place upgrade?
Thanks