• Some users have recently had their accounts hijacked. It seems that the now defunct EVGA forums might have compromised your password there and seems many are using the same PW here. We would suggest you UPDATE YOUR PASSWORD and TURN ON 2FA for your account here to further secure it. None of the compromised accounts had 2FA turned on.
    Once you have enabled 2FA, your account will be updated soon to show a badge, letting other members know that you use 2FA to protect your account. This should be beneficial for everyone that uses FSFT.

NTOSKRNL.EXE?

Rustynuts

[H]F Junkie
Joined
Feb 6, 2003
Messages
10,346
why does my NTOSKRNL.EXE keep trying to go online? I have my firewall set to block it and it keeps randomly popping up as being blocked. I doubt it's a virus as I have NOD32 running. Is this legitimate and should just allow it to communicate?
 
First, don't rule out it's a virus just because you have a A/V program. None of them are 100%. You're protected, but your not invulnerable. :)

Second, did you install anything recently? Do other use this computer? Did somebody else maybe install something? It's likely you have some spy/ad/crapware that is trying to dial home.

Run something like hijackthis or one of the other process inspectors and have a peek to see if there are some "curious" processes running.
 
Checked the last one. It was INCOMING? From 192.168.1.102, MAC 00-18-DE-52-F0-00, source 1371, TCP protocol. Mean anything?
 
Checked the last one. It was INCOMING? From 192.168.1.102, MAC 00-18-DE-52-F0-00, source 1371, TCP protocol. Mean anything?

Not a darn thing with that amount of information. Did you read the link I posted? If you did- you should understand that ntoskrnl isn't something you want to be messing with.

Try doing just the slightest little bit of searching next time- please. It took me 10 seconds to find this page with what port 1371 is: http://www.auditmypc.com/port/udp-port-1371.asp
Doesn't mean much with the info given, but as I already said- read the link I posted.
 
My question is why would it need to access the network? It doesnt make any bit of sense.

If I were in your shoes I would continue blocking it. I wouldnt trust a boot up process that is trying to access the network for some unknown reason. The general rule of thumb. If you dont know what it is, and your computer still works with it blocked, then block it.

Just becouse it was written by MS --doesnt-- mean you should trust it. If you dont know what it is, block it...... It really is that simple.
 
Not a darn thing with that amount of information. Did you read the link I posted? If you did- you should understand that ntoskrnl isn't something you want to be messing with.

Try doing just the slightest little bit of searching next time- please. It took me 10 seconds to find this page with what port 1371 is: http://www.auditmypc.com/port/udp-port-1371.asp
Doesn't mean much with the info given, but as I already said- read the link I posted.

Uh, yes I did goggle the EXE, said the same thing your link did. Says its a BOOTUP process, not something that continuously calls back. That's all the info the block gives me, nothing about which application. Hijackthis has no suspicious stuff either. I run Spybot, Spywareblaster, and AdAware all the time in addition to NOD32.

The main problem is the block is annoying. Sometimes the thing pops up every few minutes, sometimes hardly at all. Was playing a game last nite and the block kept dumping me to desktop (very annoying!). Didn't close the game, just minimized it, so I could get back to playing quickly at least
 
My question is why would it need to access the network? It doesnt make any bit of sense.

If I were in your shoes I would continue blocking it. I wouldnt trust a boot up process that is trying to access the network for some unknown reason. The general rule of thumb. If you dont know what it is, and your computer still works with it blocked, then block it.

Just becouse it was written by MS --doesnt-- mean you should trust it. If you dont know what it is, block it...... It really is that simple.

Please, for the love of GOD, keep your mouth shut. "If you don't know what it is- block it".
Not only do we already know what this is- it isn't something to be blocked.
I don't know- how every site I found (at least the top 5 results I looked at)- recommends NOT blocking this process- do you still come to the conclusion to "block it". I mean- words fail me... the amount of nonsense advice you shell out is aweful.

OP: Here is the Wikipedia entry. It really does so much- it would take forever to describe everything it does (you could call it "dynamic" as well- it really isn't designed for one specific task...)
It provides the Microkernel and Executive layers of the Windows NT kernel space, and is responsible for various system services such as hardware virtualisation, process and memory management, etc., thus making it a fundamental part of the system. It contains the Cache Manager, the Executive, the Kernel, the Security Reference Monitor, the Memory Manager, and the Scheduler, among other things.
Although if you have any AV installed it should prevent this from happening... it is entirely possible a virus can cause it to do odd things. However these are generally well documented and stopped by AV software. But as I said before- with the information given- it doesn't mean a darn thing and isn't something to be worried about. The most likely problem is you have your firewall set on an "exeption" list to explicitly allow or deny everything going in and out- otherwise any good firewall knows what is safe and what isn't (or should be prompted).
 
There is absolutely no reason that process should ever, and I mean --ever-- need to access the network.... ever.....

If it does try to access the internet, then billy is trying to do something you dont want him to do... So block it. Again the rule applies. If you dont know what it is and it still works, then block it.

If it doesnt break things, and you dont specifically for a known reason need it, then block it. This applies for everything, and I mean --everything-- that tries to access the network.... everything....

Dont let some fanboy zealot confuse you into compromising your computers security. Realize that this is a MS operating system. It isnt secure in any way imaginable. The only way to keep it secure is to actively prtect yourself. Suspect everything. If you dont know what it is then you dont allow it. If you dont know what it is, then dont click on it. If you dont know what it is, then dont open it. If you dont know what it is then dont allow it to access the internet.

I'm sorry if this isnt what you wanted to hear, but this is the unfortunate truth.
 
Realize that this is a MS operating system. It isnt secure in any way imaginable.

That's quite a leap, even for you, duby.

As you say, "I'm sorry if this isnt what you wanted to hear, but this is the unfortunate truth."

While I agree with some of the points made so far in this thread, in the end it comes down to a "bash Microsoft security" post yet again. That's not helpful, not in the least, from my perspective. Even going so far as to use the dreaded "f" word (guess they removed the censorship on that one), ugh.

And the "billy" comment.

My word.

Obviously one step no one mentioned or even hinted at would be a possible corrupt file that could be easily checked with sfc (System File Checker). Warning: running the sfc might actually come up with hundreds of instances of files that have been modified from the original distribution media, especially because of Windows Updates, etc. SFC is smart enough to do a check to see if a file has been updated because of Windows Updates and hence will pull the replacement file from the $xxxxxx subdirectory appropriate to the hotfix as long as you weren't so crazy as to have gone in and deleted all those hotfixes in the \Windows directory.

sfc /scannow

issued from a Command Prompt or even from the Run prompt would go through and check all the system related files (like NTOSKRNL.EXE) and verify they're solid and uncorrupted.

While this doesn't specifically address the issue of why that process/file is trying to get access to the Internet or go outbound, it does address the possibility of a corrupt file causing the process/file to do stuff it's not technically supposed to be doing in the first place.

Hope this helps...
 
While I agree with some of the points made so far in this thread, in the end it comes down to a "bash Microsoft security" post yet again. That's not helpful, not in the least, from my perspective. Even going so far as to use the dreaded "f" word (guess they removed the censorship on that one), ugh.

That was certainly not the intent. Windows is a perfectly capable OS. Telling someone to search for answers, and then pointing him to a perfectly useless link that does nothing to help him, and then berating him for asking for help.... Needless to say I got a little worked up. Sorry for the inconvenience. I'll try to keep the tone down alittle from that level. Thank you for pointing it out.
 
Actually the one event I checked more closely said it was INBOUND! Not the file trying to call home. Why would something try to access NTOSKRNL.EXE from outside? Maybe the file is corrupt and is trying to communicate back/forth (zombified or something?)

I'll try to run that scan and see if the file is OK. Thanks!
 
NTOSKRNL has its fingers in so many things... it isn't something I'd be too terribly worried about if you have NOD32 installed (the viruses that hijack it are documented and easily found unless you have a brand spanking new virus that nobody knows about- I would still think NOD32 would flag it though).

I think you just have your security set too tight- and you are getting overprompted.
 
I guess it could be some portion of a game that has an online component. I don't play online though, only single player. I just wish I could figure out which application it is so i can delete. The blocks are distracting (using the personal sygate firewall). I tried a backtrace on one event and got nowhere. I keep clicking the "do no notify me" button for future blocks, but it keeps coming back.
 
OK, if it's incoming, and the IP address is 192.168.1.102 (gotta be on your local network), and the port is 1371, which appears to be "Fujitsu Config Protocol"... I'd guess it's your printer talking to your OS. Does that sound logical?
 
OK, if it's incoming, and the IP address is 192.168.1.102 (gotta be on your local network), and the port is 1371, which appears to be "Fujitsu Config Protocol"... I'd guess it's your printer talking to your OS. Does that sound logical?

Yes, but as I said: NTOSKRNL is involved in so many things- hard telling what is going on.

What OS are you running? I'd just as soon get rid of the firewall... I used Kerio when it used to be Kerio before as well- and ditched it for Windows Firewall which I found worked just as well.
 
I'm running Windows XP with automatic updating. I have nothing Fujitsu (AFAIK) in or attached to my computer. Printer is Canon, router is Linksys, modem is Motorola.

I thought using Sygate is superior to windows firewall?
 
ntoskrnl.exe is the Kernel. Apparently a lot of you have never taken an operating systems class.

http://en.wikipedia.org/wiki/Operating_system_kernel

Alright, now that's out of the way. If your firewall is saying something is trying to listen on a port, from ntoskrnl, odds are it's a driver you have on the system. Maybe your printer has an Auto-Config driver, I don't know.

As to Duby's posts... Don't just blindly shut off or block stuff, espically in the kernel. You could seriously damage your windows install. (Or any operating system doing that)

So My guess is you have a driver listening on port 1371. Without knowing what drivers you have on your system, I can't make a better guess than that.

I also suggest running a scan with http://safety.live.com because while unlikely, you could have a kernel mode malware listening on that port. (Again, very unlikely, but I want to make sure to give you the best information.)

Note:
I'm Biased!

This posting is provided "AS IS" with no warranties, and confers no rights.
 
As to Duby's posts... Don't just blindly shut off or block stuff, espically in the kernel. You could seriously damage your windows install. (Or any operating system doing that)

I'm a firm believer that if you block it, and the system still works then leave it blocked. That goes for everything. If the system breaks then it is easy enough to unblock it. It's just a general rule that doesnt always apply, but will apply far more often then not.

If you dont know what it is, then block it. If it breaks something then unblock it, but in avery other case leave it blocked. This goes for everything. Everything should be blocked by default. It is your duty as the user to unblock what you want and need. Leaving things unblocked by default and blocking on an "as noticed" basis is just plain stupid in my experience. Block everything by default, and unblock as needed.

In my mind this is simple common sense. If everybody followed this simple rule of thumb then the amount of malware affecting average users would diminish to a point of irritation rather then the plague it is today.
 
Uh huh, and tommorow when that application blindly expects to send to a port it can't anymore, what happens? (If it's well written, it'll put up a nice message, if it assumes it can always talk, it crashes.) What happens when a driver crashes in kernel mode? We call that a Blue Screen, or Kernel Panic, Or Sad Mac... (Does OS X do Sad Mac's anymore? Haven't used a mac since OS 9)

Just because something worked the second you blocked it, doesn't mean tommorow something won't break horribly. You should at least lookup why something wants that access before making the decision to block it. But if this philosophy works for you, so be it. I however, wouldn't follow it. ;)

As to the malware scene, most of it is installed through Social Engineering. The users will always want to see the Dancing Pigs, and no matter what messages the user gets, they will click whatever it takes to see the dancing pigs. (Note, I speak in the abstract.)

This posting is provided "AS IS" with no warranties, and confers no rights.
 
In my mind this is simple common sense. If everybody followed this simple rule of thumb then the amount of malware affecting average users would diminish to a point of irritation rather then the plague it is today.
You've got it all figured out then, do you?

I'm a firm believer that if you block it, and the system still works then leave it blocked. That goes for everything. If the system breaks then it is easy enough to unblock it. It's just a general rule that doesnt always apply, but will apply far more often then not.
Tell me, what happens three months later when something's broken, and you've forgotten this change you've made? How do you make it work? How do all the users in the world (you know: everyone who should be following your common sense advice) recover when they forget which settings are on which computer, but know that one works and one doesn't?
 
Uh huh, and tommorow when that application blindly expects to send to a port it can't anymore, what happens? (If it's well written, it'll put up a nice message, if it assumes it can always talk, it crashes.) What happens when a driver crashes in kernel mode? We call that a Blue Screen, or Kernel Panic, Or Sad Mac... (Does OS X do Sad Mac's anymore? Haven't used a mac since OS 9)
.

And that is the whole point. --THE-- reason why --everything-- should be blocked by default. Blocked by default and unblocked as needed. You --DONT-- want those things accessing the network. If they cause a blue screen then I'll have an idea of what the problem is.

In your scenario that thing is going to be doing it's thing behind your back and you'll ignorantly never know anything about it. If that floats your boat, then so be it, I however prefer to control what my computer does and does not do. My computer is a tool that --I-- use.

Again if you dont know what it is then block it. If things break then unblock it.
 
Tell me, what happens three months later when something's broken, and you've forgotten this change you've made? How do you make it work? How do all the users in the world (you know: everyone who should be following your common sense advice) recover when they forget which settings are on which computer, but know that one works and one doesn't?

If you use a proper firewall..... Ooopps, sorry I forgot... It's not designed that way.


MS has a tendancy to design things with a "do it first then ask later" approach. Unfortunatly this approach isnt very conducive to a secure computing environment and we users suffer for it.

In the mean time simply block by port and --not-- application. That application should have no reason to throw a fit if you simply blocked the ports it is trying to communicate through. Again --ALL-- ports should be blocked by default. On the local machine, as well as the Gateway device. The only ports that should be allowed are those that you know you need or want open. All incoming all outgoing.

As an added layer of security block tha application as well. If it throws a fit unblock it. Your the user. If you want your computer to be secure then it is your duty to secure it. Yours and yours alone.
 
Haven't run the scans yet, but now I'm getting it at work too! Been happening a long time at home, and I just started a new job and installed Sygate. Must be something Sygate doesn't like.

Looks like it's the NT Kernel & System (naturally based on the name!) and Sygate has blocked 92 incoming, allowed 15307 incoming, and has allowed all outgoing traffic.
 
MS has a tendancy to design things with a "do it first then ask later" approach. Unfortunatly this approach isnt very conducive to a secure computing environment and we users suffer for it.

How funny. Is that not exactly what you're doing by blocking first then if it breaks unblock; kind of the "do it first then ask later approach"? Sorry, I just couldn’t resist. No harm intended :)

I'll agree that Windows isn't perfect, but no other OS is either. To the OP, you've been given solid advice here and from what I can gather from reading your posts, the messages are probably benign.
 
Back
Top