Jump to content

drmk.sys ks.sys improperly tagged as rootkit


kbsilver

Recommended Posts

In the lastest scan today drmk.sys and ks.sys were tagged as rootkits and quarantined.  This not only broke the audio system/drivers the computer (windows 10 64 bit) started crashing which never happened before.  After wasting 2 hours trying to repair I just did a restore from recent back-up, but stopped Malwarebytes from quarantined the files again.  I also tried to put them in the exclusion list but they would not display to be selected for exclusion (just a handful of the hundreds of files in windows/system32/drivers would display).  I've been using Malwarebytes for about a decade. This is the first time I've ever had to do a restore due to software issues.  What's going on??   

Link to post
Share on other sites

Hello @kbsilver:

Thank you for reporting the system's driver issue.  The Malwarebytes' staffers/helpers must have good log data for a quality fault analysis to begin.  Let's what the system's logs show.

  1. Please save your work and close all running user applications for your convenience.
  2. Please follow the steps within the locked/pinned topic at Having problems using Malwarebytes? Please follow these steps.

  3. The system's drivers should be recoverable from quarantine and then temporarily added to MB3's exclusions until a solution is found.

  4. In your next reply to your topic, please only attach the three (3) separate files that are developed above: mb-check-results.zip, FRST.txt, and Addition.txt.

Thank you.

Edited by 1PW
Link to post
Share on other sites

I'm not installing software I'm not sure about to do scans, but the attached screen grabs should clarify my issue.  If I scan with Rootkit detection enabled it will pick up the 2 indicated files.  I already know if I allow MAB to quarantine these files it breaks the audio system and makes Windows 10 crash. kb.sys CANNOT be restored from quarantine (file is in use).  

I've tried to exclude these files, but MAB will not allow me to select them, does not show up in the list (only 5 files out of the hundreds in this directory appear), and cannot type them in manually.

 

Thank-you.596b9fb4a9e90_CantExcludeFiles.JPG.fa0bf82df3bf2bf306a6bd50d73c57f0.JPG

MAB Rootkit.JPG

Link to post
Share on other sites

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
  • Recently Browsing   0 members

    • No registered users viewing this page.
Back to top
×
×
  • Create New...

Important Information

This site uses cookies - We have placed cookies on your device to help make this website better. You can adjust your cookie settings, otherwise we'll assume you're okay to continue.