Possible virus problem?
-
Possible virus problem?
Hi all,
I am having some strange problems with my PCs and hopefully someone will be able to advice me. Thanks in advance.
How it started was that my sis's notebook running windows 2000 starts to act werid. Sometimes the notebook can bootup, other times, it will not boot up and you will get this error:
Windows 2000 could not start because the following file is missing or corrupt:
<Windows root>\system32\ntoskrnl.exe.
Please reinstall a copy of the above file.
And if successfully bootup, I will sometimes get a domain is not avaliable error and still not able to login. After many many tries, I will be able to get in. So we suspect it's a virus, and I tried running virus scan (Norton, AVG, Online scanning) but the virus scan will not be able to complete the scan, it will usually hang around 50-53%).
So what I did next was to take out the hdd and connect it as a USB drive to my PC. The hdd show up and I attempt to carry out a virus scan with AVG. But of course, the scan could not complete and again hangs at around 53%. And it also cause some of the programmes running in my windows XP system to lock up. When I do a reboot at this point, I was not able to get my XP system to start up and I get the following error:
Windows 2000 could not start because the following file is missing or corrupt:
<Windows root>\system32\ntoskrnl.exe.
Please reinstall a copy of the above file.
I am totally buffled since I am running XP and not Win2k, how is that error possible? A vrius..A boot sector virus ? So I tried to reboot the system from cd-rom, with the XP pro cd in it, it failed. So I decided to pop in my Win2k Pro cd, and what happen next is very strange.
I let the system reboot, and when the prompt came up "press any key to contiune booting from cd-rom", I ignore that and the system bypass the cd-rom, but somehow, because the win2k cd is in the drive, my system manage to boot into xp normally ( I tried the same thing without the win2k cd in the cd-rom and the system just return me the same ntoskrnl.exe error, a win XP cd will not work too).
I make the mistake of replacing the ntoskrnl.exe through repair console from the XP pro cd, and after this, the system no longer boot up at all. So I did a format on the C: (holding the OS), and did a clean install of XP. Everything went well until I had to reboot after the installation, and to my horror, the same ntoskrnl.exe error came back. Again I had to pop in the win2k cd into cd-rom and do the same thing as before to boot up XP.
I did not give up, and went into bios to set the boot up device [1] as Hdd, and disabled the rest of the options. And somehow, this seems to set everything right, and I was able to boot into XP normally.
(My previous boot set up are [1] cd-rom, [2] hdd, [3] floopy).
I also run a full system scan on my system (all my 5 partitions) and AVG was able to complete the scans and all partitions came up as clean.
But I am still not sure if my system is indeed ok. Is there any chance, anyone knows what is happening here? Work of a virus?
Another question, how can I check if my boot sector is really clean? If I am indeed infected by a boot sector virus, I would not have been able to boot up my system, is that right?
I still don't know what to do with or what is wrong with my sis's notebook hdd.
Thank you for reading such a long post.
-
Assuming you have the necessary CD's to Clean install both XP and 2K I would recommend running some type of FDISK program on both drives/computers and then reinstalling Windows from scratch.
Boot Sector Viruses