Health Check FailureId[390]: Agent Kernel Is Missing
search cancel

Health Check FailureId[390]: Agent Kernel Is Missing

book

Article ID: 284736

calendar_today

Updated On:

Products

Carbon Black App Control (formerly Cb Protection)

Issue/Introduction

  • Agent generating Events for Health Check FailureId[390] similar to:
    Agent kernel is missing. Options[00000007] TotalFailures[14] FailureId[390]
  • Rebooting the endpoint does not resolve health check errors.

Environment

  • App Control Server: All Supported Versions
  • App Control Agent: All Supported Versions

Cause

The Agent Health Check Guide states:

FailureID[390] indicates the parity.sys driver did not appear in a system enumeration of device drivers. This can sometimes occur due to flaws in the system API on older versions of Windows prior to Vista, but often times can indicate kernel model manipulation of data structures used to track device drivers. Such manipulation may be malicious and indicate kernel mode malware is present.

Resolution

The Agent will need to be uninstalled and reinstalled.

Additional Information

When the Agent Kernel is missing, this can trigger additional Health Checks, such as FailureId[590] example:

The Service[wuauserv] State[4] Pid[113208] is running but process information is missing. Options[00000003] TotalFailures[17] FailureId[590]