Windows 7 Forums
Welcome to Windows 7 Forums. Our forum is dedicated to helping you find support and solutions for any problems regarding your Windows 7 PC be it Dell, HP, Acer, Asus or a custom build. We also provide an extensive Windows 7 tutorial section that covers a wide range of tips and tricks.


Windows 7: ntoskrnl.exe showing up in task manager,malware?


08 Dec 2012   #1

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
 
 
ntoskrnl.exe showing up in task manager,malware?

I noticed a couple of days ago,a process "SYSTEM PID 4 ntoskrnl.exe",located in windows,C,system32.A bit of searching indicates that this particular process,should never show up in TM.As a precaution,could you help me out?Malware or not,should it be there in plain sight,or not?


My System SpecsSystem Spec
.

08 Dec 2012   #2

Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1 Pro
 
 

Quote:
ntoskrnl.exe is a critical process in the boot-up cycle of your computer although should never appear in WinTasks whilst under normal circumstances

Note: ntoskrnl.exe can be altered by the w32.bolzano and variants. If this process appears in WinTasks, please update your virus definitions immediately.
Quote:
Note that ntkrnlpa.exe is not malware, provided that it is found in %SystemRoot%\System32. The following malware is known to disguise itself as ntoskrnl.exe:
  • W32/Rbot-FB (%SystemRoot%\System32)
    • This is a backdoor Trojan that can spread over network shares. It allows a remote attacker to take full control over an infected system.
  • You should never see ntoskrnl.exe running in the Task Manager. The presence of an instance of it in the task manager is a strong indicator of a malware infection.
Might be a good idea to run a full scan with Malwarebytes or Windows Defender Offline
My System SpecsSystem Spec
08 Dec 2012   #3

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
 
 

It is due to this kind of articles,that worried me about this process.Did a full scan with M,while in safe mode,no results found.Should i keep on with the defender?I must say,the process showed itself in safe mode too,does that comfort me or is it the other way around?
My System SpecsSystem Spec
.


08 Dec 2012   #4
Microsoft MVP

Windows 7 Ultimate 32bit SP1
 
 

My System SpecsSystem Spec
08 Dec 2012   #5

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
 
 

Interesting approach,had already the process under surveillance via process explorer.The point is,i do not have any CPU spikes,nor a specified version or command line of this process.PE shows that it handles interrupts and smss.exe,two legitimate processes,i think its clean,unless advised otherwise.
My System SpecsSystem Spec
09 Dec 2012   #6

Microsoft Windows 7 Ultimate 64-bit Service Pack 1
 
 

Windows defender scan came up with no results,i am giving it a rest,if MBAM and WDO,couldnt find any culprits,all should be fine.Thanks everybody for the support,marking as solved.
My System SpecsSystem Spec
Reply

 ntoskrnl.exe showing up in task manager,malware?




Thread Tools



Similar help and support threads for2: ntoskrnl.exe showing up in task manager,malware?
Thread Forum
Task Manager not showing applications General Discussion
Task Manager is showing weird.! General Discussion
Task Manager showing old computer/user name (and i don't like it!) General Discussion
Solved task manager showing memory issue General Discussion
task manager is showing only one core vs two Hardware & Devices
Task Manager showing just 1 Processor Performance & Maintenance
Triple core CPU showing ONE in task manager Performance & Maintenance

Our Sites

Site Links

About Us

Find Us

Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

Designer Media Ltd

All times are GMT -5. The time now is 08:15 AM.
Twitter Facebook Google+



Windows 7 Forums

Seven Forums Android App Seven Forums IOS App
  

1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33