Windows 7 Forums


Windows 7: ntoskrnl.exe showing up in task manager,malware?

08 Dec 2012   #1

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
Thessaloniki
 
 
ntoskrnl.exe showing up in task manager,malware?

I noticed a couple of days ago,a process "SYSTEM PID 4 ntoskrnl.exe",located in windows,C,system32.A bit of searching indicates that this particular process,should never show up in TM.As a precaution,could you help me out?Malware or not,should it be there in plain sight,or not?

My System SpecsSystem Spec

08 Dec 2012   #2

Windows 7 Home Premium 32 bit
In a house with a cat trying to kill me
 
 

Quote:
ntoskrnl.exe is a critical process in the boot-up cycle of your computer although should never appear in WinTasks whilst under normal circumstances

Note: ntoskrnl.exe can be altered by the w32.bolzano and variants. If this process appears in WinTasks, please update your virus definitions immediately.
Quote:
Note that ntkrnlpa.exe is not malware, provided that it is found in %SystemRoot%\System32. The following malware is known to disguise itself as ntoskrnl.exe:
  • W32/Rbot-FB (%SystemRoot%\System32)
    • This is a backdoor Trojan that can spread over network shares. It allows a remote attacker to take full control over an infected system.
  • You should never see ntoskrnl.exe running in the Task Manager. The presence of an instance of it in the task manager is a strong indicator of a malware infection.
Might be a good idea to run a full scan with Malwarebytes or Windows Defender Offline
My System SpecsSystem Spec
08 Dec 2012   #3

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
Thessaloniki
 
 

It is due to this kind of articles,that worried me about this process.Did a full scan with M,while in safe mode,no results found.Should i keep on with the defender?I must say,the process showed itself in safe mode too,does that comfort me or is it the other way around?
My System SpecsSystem Spec
.


08 Dec 2012   #4

Windows 7 Ultimate 32bit SP1
 
 

My System SpecsSystem Spec
08 Dec 2012   #5

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
Thessaloniki
 
 

Interesting approach,had already the process under surveillance via process explorer.The point is,i do not have any CPU spikes,nor a specified version or command line of this process.PE shows that it handles interrupts and smss.exe,two legitimate processes,i think its clean,unless advised otherwise.
My System SpecsSystem Spec
09 Dec 2012   #6

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
Thessaloniki
 
 

Windows defender scan came up with no results,i am giving it a rest,if MBAM and WDO,couldnt find any culprits,all should be fine.Thanks everybody for the support,marking as solved.
My System SpecsSystem Spec
Reply

 ntoskrnl.exe showing up in task manager,malware? problems?



Thread Tools



Similar help and support threads for: ntoskrnl.exe showing up in task manager,malware?
Thread Forum
Task Manager is showing weird.! General Discussion
Task Manager not showing applications General Discussion
task manager is showing only one core vs two Hardware & Devices
Task Manager showing just 1 Processor Performance & Maintenance
Triple core CPU showing ONE in task manager Performance & Maintenance


All times are GMT -5. The time now is 07:42 AM.


Seven Forums Android App Seven Forums IOS App Follow us on Facebook

Windows 7 Forums is an independent web site and has not been authorized,
sponsored, or otherwise approved by Microsoft Corporation.
"Windows 7" and related materials are trademarks of Microsoft Corp.
© Designer Media Ltd
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32