cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
546
Views
0
Helpful
6
Replies

CSA 6.0 Problem with \??\ preceding a file.

pmccubbin
Level 5
Level 5

We have a message in the Event Log about a Kernel functionality being modified by the module:

\\??\Windows\system32\drivers\mkbd.sys

\\??\Windows\system32\drivers\mkbd.sys is monitoring the keyboard.

Any idea what the "??" mean? We can't use the wizard to tune it.

Thanks in advance.

6 Replies 6

jan.nielsen
Level 7
Level 7

Could be vmware workstation virtual keyboard driver. You should be able to whitelist as an option in the wizard.

Hi Jan,

Thanks for the reply.

When we try to whitelist via the Wizard the CSAMC throws an error and doesn't allow this operation to procede.

I am opening a TAC case and will post results.

What is the error that it throws ?

Just wanted to offer an update. We have a TAC case open and the Business Unit is looking into the case.

Attached is the error message.

As a bit of background we are running the CSAMC on a VMWare machine.

When I hear more I will post it. Thanks.

We have also faced similar issues with CSA 6.0 and this known issue is fixed in 6.0.0.220 and later versions.

daneilhudson
Level 1
Level 1

You could manually write a rule using **\Windows\system32\drivers\mkbd.sys as a definition for the application. I suspect that @system would work as well. Just create an application class and add that as an exception to the triggering rule.

Getting Started

Find answers to your questions by entering keywords or phrases in the Search bar above. New here? Use these resources to familiarize yourself with the community: