ntoskrnl.exe showing up in task manager,malware?


  1. Posts : 541
    Microsoft Windows 7 Ultimate 64-bit Service Pack 1
       #1

    ntoskrnl.exe showing up in task manager,malware?


    I noticed a couple of days ago,a process "SYSTEM PID 4 ntoskrnl.exe",located in windows,C,system32.A bit of searching indicates that this particular process,should never show up in TM.As a precaution,could you help me out?Malware or not,should it be there in plain sight,or not?
      My Computer


  2. Posts : 7,781
    Win 7 32 Home Premium, Win 7 64 Pro, Win 8.1, Win 10
       #2

    ntoskrnl.exe is a critical process in the boot-up cycle of your computer although should never appear in WinTasks whilst under normal circumstances

    Note: ntoskrnl.exe can be altered by the w32.bolzano and variants. If this process appears in WinTasks, please update your virus definitions immediately.
    Note that ntkrnlpa.exe is not malware, provided that it is found in %SystemRoot%\System32. The following malware is known to disguise itself as ntoskrnl.exe:
    • W32/Rbot-FB (%SystemRoot%\System32)
      • This is a backdoor Trojan that can spread over network shares. It allows a remote attacker to take full control over an infected system.

    • You should never see ntoskrnl.exe running in the Task Manager. The presence of an instance of it in the task manager is a strong indicator of a malware infection.
    Might be a good idea to run a full scan with Malwarebytes or Windows Defender Offline
      My Computer


  3. Posts : 541
    Microsoft Windows 7 Ultimate 64-bit Service Pack 1
    Thread Starter
       #3

    It is due to this kind of articles,that worried me about this process.Did a full scan with M,while in safe mode,no results found.Should i keep on with the defender?I must say,the process showed itself in safe mode too,does that comfort me or is it the other way around?
      My Computer


  4. Posts : 8,608
    Windows 7 Ultimate 32bit SP1
       #4
      My Computer


  5. Posts : 541
    Microsoft Windows 7 Ultimate 64-bit Service Pack 1
    Thread Starter
       #5

    Interesting approach,had already the process under surveillance via process explorer.The point is,i do not have any CPU spikes,nor a specified version or command line of this process.PE shows that it handles interrupts and smss.exe,two legitimate processes,i think its clean,unless advised otherwise.
      My Computer


  6. Posts : 541
    Microsoft Windows 7 Ultimate 64-bit Service Pack 1
    Thread Starter
       #6

    Windows defender scan came up with no results,i am giving it a rest,if MBAM and WDO,couldnt find any culprits,all should be fine.Thanks everybody for the support,marking as solved.
      My Computer


 

  Related Discussions
Our Sites
Site Links
About Us
Windows 7 Forums is an independent web site and has not been authorized, sponsored, or otherwise approved by Microsoft Corporation. "Windows 7" and related materials are trademarks of Microsoft Corp.

© Designer Media Ltd
All times are GMT -5. The time now is 16:03.
Find Us