Tek-Tips is the largest IT community on the Internet today!

Members share and learn making Tek-Tips Forums the best source of peer-reviewed technical information on the Internet!

  • Congratulations strongm on being selected by the Tek-Tips community for having the most helpful posts in the forums last week. Way to Go!

stoned.monk.empire 1

Status
Not open for further replies.

dsawyer

IS-IT--Management
Jan 15, 2003
14
US
On of my machines here is a windows NT which got the stoned.monk.empire virus. Unfortunately it was not discovered until after the computer was rebooted and now all i get is a blue screen with hex numbers on start up and it is unbootable from disk. any advice would be greatly appreciated. thanks in advance..........dsawyer.
 
It is unbootable from floppy?
Is the floppy clean?
Is it set to boot from floppy first in the BIOS?

This is one nasty virus.....it relocates the boot sector and is memory resident.
The best way to get rid of it is to FDISK from a clean floppy and then format.

I am looking around to see if I can find a removal util...there used to be add ons for this virus to go with certain antivirus programs.

Good Luck! Kimber

The more I learn,I realize how much more there is to know!
 
thanks kimber, ill give that a shot and keep you posted.
dsawyer
 
first how do i access the c drive and second how can i boot to an msdos prompt because right now it appears that my only options are to power cycle the machine which eventually leads me back to the previously mentioned screen of hex numbers? the reason i ask is because the killmonk utility forementioned needs to be executed from the c drive of the infected pc. thanks....dsawyer.
 
Do you have a copy of you Emergency Repair Disk from when you installed NT?

This virus is a pain because NT doesnt do dos...unless you use a utility.

Is there any way you can put the drive into something else to scan it?
It would have to be NTFS if you have formatted it that way..

Post back and let us know. Kimber

The more I learn,I realize how much more there is to know!
 
yes i do have an erd for this machine and putting the hard drive on another machine to scan it is an option as well.
 
Status
Not open for further replies.

Part and Inventory Search

Sponsor

Back
Top