cancel
Showing results for 
Search instead for 
Did you mean: 
cancel
Announcements
348
Views
0
Helpful
6
Replies
pmccubbin
Contributor

CSA 6.0 Problem with \??\ preceding a file.

We have a message in the Event Log about a Kernel functionality being modified by the module:

\\??\Windows\system32\drivers\mkbd.sys

\\??\Windows\system32\drivers\mkbd.sys is monitoring the keyboard.

Any idea what the "??" mean? We can't use the wizard to tune it.

Thanks in advance.

6 REPLIES 6
jan.nielsen
Rising star

Could be vmware workstation virtual keyboard driver. You should be able to whitelist as an option in the wizard.

Hi Jan,

Thanks for the reply.

When we try to whitelist via the Wizard the CSAMC throws an error and doesn't allow this operation to procede.

I am opening a TAC case and will post results.

What is the error that it throws ?

Just wanted to offer an update. We have a TAC case open and the Business Unit is looking into the case.

Attached is the error message.

As a bit of background we are running the CSAMC on a VMWare machine.

When I hear more I will post it. Thanks.

We have also faced similar issues with CSA 6.0 and this known issue is fixed in 6.0.0.220 and later versions.

daneilhudson
Beginner

You could manually write a rule using **\Windows\system32\drivers\mkbd.sys as a definition for the application. I suspect that @system would work as well. Just create an application class and add that as an exception to the triggering rule.

Content for Community-Ad

This widget could not be displayed.