Jump to content

MBAMSwissArmy.sys Page Fault


Recommended Posts

After updating latest Windows 10 update, I've been getting page fault BSOD with MBAMSwissArmy.sys.

I've tried full clean install, but it is still cause the BSOD.

Anyone want to help, I forgot where to get a minidump, so please remind me.

I know the BSOD comes from a rootkit scan.

Thanks in advance.

Page.jpg

Link to post
Share on other sites

Hello pakhoi:

Analysis experts will also appreciate the addition of the following:

  1. Please read the locked/pinned topic Diagnostic Logs and then individually ATTACH the 3 requested logs in your next reply to this thread only.
  2. The 3 files, from Step 1, to be individually ATTACHED from your desktop are CheckResults.txt, FRST.txt and Addition.txt.  Please do not Zip or Copy and Paste them into a reply.  Please do not alter, any FRST categories as the configuration is well suited for this forum.

Thank You.

Link to post
Share on other sites

Thanks again 1PW,

I've attached all 3 files in this reply.

Also, to hopefully make it more useful, these scans were made in the same environment as one that can replicate the BSOD.

I've rebooted, ran a rootkit scan, which caused the crash, then ran the scans after rebooting.

Thank you.

Oh, I know about the whole Malwarebytes community doesn't like torrenting much, I can say I use them for good, aka my school uses Ubuntu and torrenting is my best option.

FRST.txt

Addition.txt

CheckResults.txt

Link to post
Share on other sites

Hello pakhoi:

Unfortunately, Log Set 2's CheckResults.txt was severely truncated as posted.  Please consider deleting all copies of mbam-check-2.3.2.0.exe/CheckResults.txt, do a conventional system restart to normal mode, and repeat the instructions from within Log Set 2 for the analysis experts who follow.  A valid CheckResults.txt file will usually be several hundreds of lines long, and the last readable line will always be END OF FILE.

In the interim, since the system in question seems to be running W10x64Pro Insider Preview Version 1607, 10.0.14931, please untick any MBAM parameter calling for the scanning of rootkits to see if the BSoD occurrences cease.

Thank you for your patience and understanding.

Edited by 1PW
Link to post
Share on other sites

Hi 1PW,

Unfortunately, after rerunning the mbam-check, the file does still seems to be the same.

I've also tried running it as admin, along with running it while the exe is in the B drive.

In terms of running anti-malware scans without rootkit, it does not crash the system in both drives.

I might have to mention that I have bit-locker enabled for both drives.

Thanks

CheckResults.txt

Link to post
Share on other sites

Hello pakhoi:

mbam-check-2.3.2.0.exe should be able to run.  Corrective actions for this, and your system's original BSoD issue are not permitted in this sub-forum.

I recommend following the advice from the topic: Available Assistance for Possibly Infected Computers and have one of the Malware Removal Experts assist you with your issue.

If, as recommended, you do open a topic in Malware Removal Help, please make reference to this thread.

If you would like to get off to a very fast start, the Malware Removal Experts would appreciate it if you would also attach (not compress/copy/paste) both the FRST.txt and the Addition.txt output diagnostic reports from only Log Set 1 into your new topic.  Please do not alter any pre-configured FRST categories as the default settings are well suited for malware removal actions.

Thank you.

Link to post
Share on other sites

  • 2 weeks later...

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
 Share

  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.