Hello,
Thank you for keeping us updated.
It seems that the issue is resolved.
I appreciate your efforts and time.
Please do let us know if you need any assistance in regards to Windows.
Thank you
This browser is no longer supported.
Upgrade to Microsoft Edge to take advantage of the latest features, security updates, and technical support.
Hi,
My System is Windows 7 SP1 Home Premium. Recently the Event Viewer has shown the following Audit failure after every fresh startup after the system has been powered off:
Record Number : 145537
Log Type : Security
Event Type : Audit Failure
Time : 28/06/2016 18:57:39
Source : Microsoft-Windows-Security-Auditing
Category : 12290
Event ID : 6281
User Name :
Computer : Chris-PC
Event Data Length : 0
Record Length : 352
Event Description : Code Integrity determined that the page hashes of an image file are not valid. The file could be improperly signed without page hashes or corrupt due to unauthorized modification. The invalid hashes could indicate a potential disk device error. File Name: \Device\HarddiskVolume3\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys
I have been in touch with IBM Trusteer Support but they have been unable to help - their initial suggestion was as follows:
In order to resolve this issue, please follow the steps below:
1. Run → Enter secpol.msc in the search box.
*Please note, that an error message may appear. Disregard it and wait for a few seconds until the "Local Security Policy" window appears.
2.Open “Local Policies”.
3.Open “Audit Policy”.
4.Enter “Auditor privilege use”
5.Verify both check-boxes are unchecked.
6. Restart your computer.
However Windows 7 Home Premium does not have the the group policies editor 'secpol.msc' so I am unable to carry out their suggestion. Because of this they advised I contact Microsoft.
I have ruled out 'disk error' by running HD Tune which found no errors on the hard drive. IBM appear to have ruled out a problem with my malware protection (Avast 2016 anti-virus and Comodo Firewall) after I had sent the details to them.
The problem has occurred over the last few days (starting Monday 27 June 2016).
Any advice and suggestions would be much appreciated, thank you.
Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.
Hello,
Thank you for keeping us updated.
It seems that the issue is resolved.
I appreciate your efforts and time.
Please do let us know if you need any assistance in regards to Windows.
Thank you
Hello,
Thank you for replying.
I would suggest you to refer this article and check.
Refer:
Advanced Security Audit Policy Settings
https://technet.microsoft.com/en-us/library/dn319056.aspx
I hope it helps.
Thank you
Hi Ratandeep,
Thank you for getting back.
I don't think the link you gave me helps with my situation as there doesn't seem to be a driver problem and there is no driver update or rollback for the Trusteer Rapport driver concerned. Also a similar integrity warning has appeared for a file relating to Malwarebytes Anti-Rootkit (which is only run on demand and not during startup). The following is a copy of this morning's full html report from the Event Viewer concerning the Trusteer Rapport driver:
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
<EventID>6281</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2016-07-12T06:27:02.178051300Z" />
<EventRecordID>148376</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="68" />
<Channel>Security</Channel>
<Computer>Chris-PC</Computer>
<Security />
</System>
<Data Name="param1">\Device\HarddiskVolume3\ProgramData\Trusteer\Rapport\store\exts\RapportMS\baseline\RapportIaso.sys</Data>
</EventData>
</Event>
About a minute later the Rapport service started successfully and the Event Viewer reported as follows:
<Provider Name="Service Control Manager" Guid="{555908d1-a6d7-4695-8e1e-26931d2012f4}" EventSourceName="Service Control Manager" />
<EventID Qualifiers="16384">7045</EventID>
<Version>0</Version>
<Level>4</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8080000000000000</Keywords>
<TimeCreated SystemTime="2016-07-12T06:28:59.478145500Z" />
<EventRecordID>2180734</EventRecordID>
<Correlation />
<Execution ProcessID="944" ThreadID="5360" />
<Channel>System</Channel>
<Computer>Chris-PC</Computer>
<Security UserID="S-1-5-21-3671549593-626941379-2875692321-1001" />
</System>
<Data Name="ServiceName">RapportIaso</Data>
<Data Name="ImagePath">c:\programdata\trusteer\rapport\store\exts\rapportms\baseline\rapportiaso.sys</Data>
<Data Name="ServiceType">kernel mode driver</Data>
<Data Name="StartType">demand start</Data>
<Data Name="AccountName" />
</EventData>
</Event>---------------------------------------------------------------------------------
I believe the problem is related to settings within Group Policy which I cannot easily edit in my Home premium version of Windows 7. I don't know if you have any thoughts on that or any other suggestions but thanks for your continued help.
Regards.
Hello,
Thank you for the update.
I appreciate your efforts.
Please refer suggestions marked as answer by Karen Hu, Microsoft contingent staff on October 23, 2014 and check.
Please keep us informed.
Thank you
Hi ElderN,
Still no joy - the same error message appears and I waited quite a while before opening the link and while the link was open.
Added Edit:
The result of further research on the internet suggests I would be unwise to attempt to add any Microsoft group policy editing software to a Home Premium version of Windows 7. It could risk messing up the system so I will respectfully decline your offer of a copy of secpol.msc and hope there is an alternative solution. There must be a suitable registry edit for example.
Anyway thanks for your efforts on my behalf, much appreciated.
Regards.