Topic:Solved: ntkrnlpa.exe and ntoskrnl.exe trojans? Remainpoint:0
   
PostTime:12/16/2008 11:09:24 AM FloorTop
Lv is 1
Avatar
Level:
1
Professional point:
36
Experience:
4
Thread:
297
Post:
994
Total online time:
4M
Joined date:
4/28/2007 10:56:00 PM
Last Visit:
12/16/2008 11:36:14 PM
Status:
Offline
I just ran A Squared 3.0 and it reported as a high risk two trojans ntkrnlpa.exe and ntoskrnl.exe

ntkrnlpa.exe. this is a required program for Microsoft and/or it could be a trojan. I am afraid to quarantine it for it may be the required krnl of the OS XP Pro. When I researched this on google I came up with this:

Operating System Kernel could be legitimate Windows OS process. Operating System Kernel is the Operating System (OS) kernel for computers with memory of 4GB or more. CAUTION: Various trojan/worm/spyware overwrite or create a file by this name.

When I googled ntoskrnl.exe I came up with this:

ntoskrnl.exe or ntoskrnl
Process Name: Microsoft Boot Up Kernel
They are reported to be here: C:\WINDOWS\$hf_mig$KB890859\SP2QFE\intkrnlpa.exe
C:\WINDOWS\$hf_mig$KB890859\SP2QFE\intoskrnl.exe

I have run A Squared several times and this is the first time it came up with this. None of the other malware and antivirus programs show it.
What should I do to check this out and see if they are trojans or not. I am as I said afraid to put them in quarantine until I know if they are trojans.
Sluggo123
 
     
   
Gender PostTime:12/16/2008 2:56:38 PM Point:0 | Floor# 1
Lv is 1
portrait
Level:
1
Professional point:
62
Experience:
12
Thread:
287
Post:
938
Total online time:
12M
Joined date:
4/29/2007 2:35:00 AM
Last Visit:
12/17/2008 12:42:43 AM
Status:
Offline
Turned out that A-Squared is super sensitive and sometimes produces false positives. After removing all the files that had been quarantined in Spybot the false postives went away. It checked somethings that had been in the Quarantined area. When deleted everything looked better and I did a little more housekeeping and everything looks good now.
sluggo123
 
     
1

Sorry, you are not login, click here to login

 

About us | Advertise | Contact us | Partner | Bug Report|Suggesting box|Donation
Home | Forum | Affiliate program| Remote help | Setting | Search | Document | Help | Download|Message

 

Start new topicAdvanced search