ntoskrnl in C:\Windows\System32 is proxying my system and letting applications bypass the comodo firewall

Lumia925

Reputable
Oct 16, 2014
403
1
4,860
Ok here's what's going on, I have Comodo firewall and Windows defender as my security programs. I would block firefox with comodo and try to open wikipedia with firefox after clearing the browsers cache, and it would load straight up. The same is with internet explorer, I would block internet explorer and log on to websites like yahoo, msn, and wikipedia, IE would have no trouble accessing the internet at all! Comodo's log would say it just blocked IE, and IE/Firefox doesn't appear in active connections list in comodo. What does show up are svchost.exe, and "system" with PID: 4. Windows Task manager's process list has a "system" with PID: 4, right clicking and "open file location" takes me to C:\Windows\System32\ntoskrnl. I tried everything, Updated Comodo, blocked ntoskrnl in Comodo, even re-installed Windows 8, the same problem shows up. After the problem persisted in the fresh install, i reverted back to my original install using a system image saved to an external drive just before the nuke. Almost every application gets access to the internet, even after they are being blocked. And blocking ntoskrnl has no effect, "system" process with PID: 4 would still show up in active connections, and start downloading data on behalf of blocked applications. Can't be a virus cause the issue stays even after a fresh install. Can't be comodo IMO, cause it blocks firefox just as it should, firefox, and IE are blocked, but ntoskrnl ("system") is downloading data when the browsers load a page.
Specially weird cause the issue persisted after a complete re-install + drivers + comodo and nothing else loaded.
OS: Windows 8 Pro x64.
What's going on here? Could you guys solve this please? Thanks. :(
 
Solution
Nomatter the software, there are always issues. I've yet to see any significant piece of software that didn't have to be patched or replaced at some point after release. There are always going to issues and vulnerabilities that come up here and there. I'd go check out the comodo forum and see if anybody else has had the same issues and what they did to permanently fix it. There may even be a patch, who knows. Is your software currently up to date?
Windows update is probably accessing the internet, or another windows service like error reporting (Just as an example). Ntoskrnl.exe is the core system, Windows NT operating system kernel, and has many services that would report back as ntoskrnl.exe.

You would need to find which specific windows service was using it and block that, although unless it's a deviant application like a malware infection using the core services, which is possible, it's probably ok. Update your virus and malware scanner definitions and do a full system scan. Download the Malwarebytes rootkit scanner and run that. If nothing comes up, it's probably ok and is just windows accessing the internet.
 

Lumia925

Reputable
Oct 16, 2014
403
1
4,860


Hello Darkbreeze, thanks for your reply :)
Well, I ran a full scan with Windows defender, comes clean.
Ran a full scan with Avira Free, comes clean.
Ran a full scan with the malwarebytes rootkit scanner you mentioned, comes clean.
Other than that, I tried Windows 8.1 on a different computer, and noticed the exact same behavior!
ntoskrnl creates a connection to 192.88.99.1, which is the IP address of 6to4.
If I create a system wide global rule to ban connections to 192.88.99.1 in comodo, the firewall stops leaking, it doesn't allow connections to blocked applications any more.
And another interesting observation, if I disable this rule to ban 192.88.99.1, and then disable the "IP HELPER" service in services.msc, the firewall again stops leaking.
Didn't anyone test this simple thing in comodo before they released the firewall? Weird!



 
Nomatter the software, there are always issues. I've yet to see any significant piece of software that didn't have to be patched or replaced at some point after release. There are always going to issues and vulnerabilities that come up here and there. I'd go check out the comodo forum and see if anybody else has had the same issues and what they did to permanently fix it. There may even be a patch, who knows. Is your software currently up to date?
 
Solution