Event log Audit Failure - invalid hash on acronis\cyberprotect\remediation.exe
I noticed by chance a security event log entry after a cold boot of my PC, Event 5038: "Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Program Files\Acronis\CyberProtect\remediation.exe"
More details below.
Q: if this is some kind of corruption, it looks like I should uninstall and re-install? Or do a repair? Or is this a known issue? Will I lose any settings doing a complete uninstall? I don't want to re-do all my backup configurations...
I am up to date on all my verisons and patches on everything, Windows 10 and Acronis True Image 2021.
File version of remediation.exe as reported by file properties is 1.0.0.804, product version 1.0.804. Date created/modified: 11/23/2020 1:02 PM.
- <Event xmlns="[removed since hyperlinks are not allowed]">
- <System>
<Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-a5ba-3e3b0328c30d}" />
<EventID>5038</EventID>
<Version>0</Version>
<Level>0</Level>
<Task>12290</Task>
<Opcode>0</Opcode>
<Keywords>0x8010000000000000</Keywords>
<TimeCreated SystemTime="2021-01-11T21:07:04.3892243Z" />
<EventRecordID>3358108</EventRecordID>
<Correlation />
<Execution ProcessID="4" ThreadID="15824" />
<Channel>Security</Channel>
<Computer>Sassypants</Computer>
<Security />
</System>
- <EventData>
<Data Name="param1">\Device\HarddiskVolume2\Program Files\Acronis\CyberProtect\remediation.exe</Data>
</EventData>
</Event>


- Log in to post comments

OK I've done a repair install which went perfect. One thing I forgot to note from the original error message: "Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error."
So I suppose it could have been some random corruption, which is a scary thought. Even worse is the "unauthorized modification" possibility!
It's one of those errors where if you don't look specifically for it, it doesn't show up anywhere. I just stumbed into it.
It looks like the errors are triggered by my nightly backups so I'll report back later to see if those errors have stopped getting logged.
- Log in to post comments

No luck. I got the same code integrity error when my cloud backup task ran in ATI this morning. I'm doing another repair and saving a copy of remediation.exe elsewhere so I can see if it is actually getting corrupted somewhere along the line, though I have no idea if the corruption is happening on install, in which case I'm comparing a corrupt copy with a corrupt copy. Doing an fc/ b with the previously installed file and a fresh one from a repair install showed that they were identical.
Any idea what remediation.exe actually does?
All backups seem to be completing normally, no errors or anything... this sure is suspicious though, what is going on?
BTW the only other anti-virus or security software installed is Malwarebytes Free, not the paid version with real-time checking. It's installed... but never running unless I launch it to do a scan. I will uninstall it.
I pulled a copy of remediation.exe from a backup before the code integrity errors started showing up. So now I have 3 copies, from the backup, from a fresh repair, and from the hard drive right after the error. All are identical which is good. Doesn't look like the binary was changed...
- Log in to post comments

Eric, I would recommend raising a support ticket for this issue direct with Acronis to let them investigate it in more depth, especially given this is part of the new Cyber Protect features they introduced with ATI 2021.
Which actual edition of ATI 2021 are you using here? The editions are Standard (Perpetual), then Essential, Advanced and Premium as shown on the Account page in the GUI, where only the Advanced and Premium versions have the full Cyber Protect feature enabled to provide realtime protection etc.
Remediation, for me, suggestions it is code that tries to act upon any detected malware threats to either nullify or reverse any negative effects of the malware. I have not seen any official Acronis description of this program!
- Log in to post comments

After uninstalling malwarebytes Free, the errors stopped. So... I'm going to reinstall malwarebytes. I suspect it's a red herring... malwarebytes free doesn't do anything in the background, it only runs on demand... but we'll see.
This is ATI Advanced. It doesn't say that on the Account page in the app, but I found it online.
Will update after I reinstall Malwarebytes and run a few backups.
- Log in to post comments

The plot thickens. Now I am getting the security audit failures AND a new error, same one, on \Device\HarddiskVolume2\Program Files\Malwarebytes\Anti-Malware\MBAMWsc.exe and the log entries are at the same exact time, 3am, which doesn't correspond to any of my backup times, so I have no idea what was going on at that time on my PC.
I saved a copy of the freshly installed remediation.exe elsewhere and did a fc /b comparison and it reports the binaries are identical.
I'll open up a support incident, this just looks so suspicious. It's very weird that now I'm getting the same security failure with malwarebytes now. I wasn't, before.
- Log in to post comments

Eric, doing some more general searches in Google using "security audit failure 5038" shows that this is a more widespread issue that can impact multiple different vendors of security applications!
See webpage: Question about Event Id 5038
Webpage: Norton 360 Event 5038 security audit failure
Webpage: Win 10 Event Log - fsamsi64.dll - image hash of a file is not valid (F-Secure)
- Log in to post comments

Well that was extremely illuminating, I did some googling on that but didn't find those issues, so thanks for hunting those down. I think it's pretty obvious at this point it's not an actual problem. The first link in the first article you posted has a mind-numbing amount of detail on this issue :) I think we can wrap this up as current expected behavior until it is either changed on the MS or ATI side but it doesn't look like I've got some sneaky virus on my PC at this point, thank you.
- Log in to post comments

Hello, I am seeing many occurrences of this error in my logs as well. I don't have malwarebytes so it seems like that is not a common factor. This is with build 18363 of windows 10 and acronis 2021 build 35860. Now it seems to be working but the message is foreboding. More as I try to figure it out.
- Log in to post comments

Okay one more tidbit. I just ran a backup on a machine with the same Windows build but with Acronis 2020. The backup ran to completion and when I looked in the security event log under audit failure there were no 5038 errors. So it seems like it may be unique to acronis 2021
I see no occurrences of this error in the windows 10 problem report or reliability app.
- Log in to post comments