1. You are viewing our forum as a guest. For full access please Register. WindowsBBS.com is completely free, paid for by advertisers and donations.

NTOSKRL unfairly blamed?

Discussion in 'Windows XP' started by masonite, 2009/05/19.

  1. 2009/05/19
    masonite

    masonite Well-Known Member Thread Starter

    Joined:
    2002/09/02
    Messages:
    445
    Likes Received:
    1
    If, like me, you've been around the pull-it-to-bits-to-see-what-makes-it-tick side of computing for a a few years, you've probably seen this dreaded message more times than you want to remember:

    "Windows NT could not start because the below file is missing or corrupt:
    C:\Windows\System32\Ntoskrnl.exe "

    I've been doing a bit of research on this, following a current situation where this error message is appearing on a customer's machine. Some experienced commentators have expressed doubt that a faulty Ntoskrnl executable is the cause of the problem, in which case it seems to me that the usual recommended fixes are probably irrelevant. Certainly, in case of my recent customer, all that's needed as a workaround is to leave the machine running for a few minutes, displaying the DOS screen error message, then hit Ctrl\Alt\Delete to have it boot normally.

    So it seems that there might a whole bunch of other factors that aren't commonly reported. What do you folks think are likely causes, or what fixes have you found to be effective?

    There are a couple of links below which are informative, particularly the WinBBS one. But I'm more interested in what you people have found to work.

    Code:
    http://www.windowsbbs.com/windows-xp/59089-ntoskrnl-missing-corrupt-2.html
    http://www.computerhope.com/issues/ch000646.htm
     
  2. 2009/05/19
    Arie

    Arie Administrator Administrator Staff

    Joined:
    2001/12/27
    Messages:
    15,174
    Likes Received:
    412
    Arie,
    #2

  3. to hide this advert.

  4. 2009/05/20
    masonite

    masonite Well-Known Member Thread Starter

    Joined:
    2002/09/02
    Messages:
    445
    Likes Received:
    1
    Thanks Arie, I'll try it. But I'm not looking to get a dump analyser on the case - I was just curious to see what other WinBBS members have done when confronted with this 'ntoskrnl,exe' error message.
     
  5. 2009/05/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    As Arie said, without seeing at least few dmp files, it's hard to say, and even dmp files info is not always clear regarding Ntoskrnl.exe, simply because what you just said...many possible causes.
    Besides the file itself being corrupted, from my experience, two main causes of the above error are: RAM issues, or an infection (possibly a rootkit).
     
  6. 2009/05/20
    masonite

    masonite Well-Known Member Thread Starter

    Joined:
    2002/09/02
    Messages:
    445
    Likes Received:
    1
    The customer's machine that I was referring to earlier is still here and still showing the ntoskrnl error on the first boot of the day. But if I hit the reset button, or Ctrl\Alt\Del, away it goes as if nothing had happened.

    I'd doubt that ram is the problem, as the machine has removable hard drives, and his other two drives function perfectly normally in the same case.

    And the XPP install on the problem drive is brand new, with good quality AV and AS apps - namely NOD32 and Malwarebytes, and it's been thoroughly scanned by those programs as well as PrevX.

    No, there's something else afoot here, which is why I was curious to see what other people had to say about ntoskrnl error messages. Seems to me that this is yet another Microsoft catchall, an error message which appears to be specific, but has little relevance to the named process.
     
  7. 2009/05/20
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    .....
     
  8. 2009/05/21
    masonite

    masonite Well-Known Member Thread Starter

    Joined:
    2002/09/02
    Messages:
    445
    Likes Received:
    1
    OK, I'll try it. Let's see if I've got this straight:
    1. I install (run) debugwiz?
    2. I install (run) dbg_x86_6.11.1.404.msi (32bit)?

    Not too sure if I need one or both of these......

    OK, so I install the required software.
    Then, I boot the pc. If it follows its usual pattern, it'll fail to start the first time, but will display the 'error-ntoskrnl.exe' message.
    So I hit the reset button, (or Ctrl\Alt\Del), and the pc will start normally. As I said, this is what it now does every time. One refusal followed by a normal start.
    But now, I can search for *.dmp files and the latest dated file will contain information about what caused the stalled boot. Correct?
     
  9. 2009/05/21
    broni

    broni Moderator Malware Analyst

    Joined:
    2002/08/01
    Messages:
    21,701
    Likes Received:
    116
    Navigate to: C:\Windows\Minidump folder.
    If you see any .dmp files, zip all of them, and upload them here: http://www.filedropper.com/
    Post download link.
     
  10. 2009/05/21
    Admin.

    Admin. Administrator Administrator Staff

    Joined:
    2001/12/30
    Messages:
    6,687
    Likes Received:
    107
    Install #2 first. Nothing to run

    Next install debugwiz, run it, browse to one dump file at a time. It will create a dump log for you to post here.
     

Share This Page

  1. This site uses cookies to help personalise content, tailor your experience and to keep you logged in if you register.
    By continuing to use this site, you are consenting to our use of cookies.