Interoperability between SEP 16 SymAMSI.dll module and Windows Device Guard
search cancel

Interoperability between SEP 16 SymAMSI.dll module and Windows Device Guard

book

Article ID: 381711

calendar_today

Updated On:

Products

Endpoint Protection Endpoint Security

Issue/Introduction

When SEP 16 (Endpoint Security Agent) is installed you may see Windows Security Event log errors similar to:

Event ID:      5038

Description:
Code integrity determined that the image hash of a file is not valid.  The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

OR

Event ID:      3004

Description:
Windows is unable to verify the image integrity of the file because file hash could not be found on the system. A recent hardware or software change might have installed a file that is signed incorrectly or damaged, or that might be malicious software from an unknown source.

Environment

  • Endpoint Security Agent
  • SEP 16
  • Microsoft Windows: All Supported Versions

Cause

Issue is caused by an interoperability issue due to Windows Code Integrity enforcement policy.

Resolution

This is expected behavior and SEP 16 (Endpoint Security Agent) functionality is not impacted. A fix is not necessary for SEA as these errors are due to Windows Code Integrity enforcement.