Advice Request svchost process is blocking a non-Microsoft-signed binary: fsamsi64.dll

Please provide comments and solutions that are helpful to the author of this topic.

Zartarra

Level 8
Thread author
Verified
Well-known
Forum Veteran
May 9, 2019
394
2,266
670
-_-
Hello all

I am using F-Secure Safe 18.2. In the Security-Mitigrations logs I found many warning with all the same message:

Process '\Device\HarddiskVolume4\Windows\System32\svchost.exe' (PID 2520) was blocked from loading the non-Microsoft-signed binary '\Program Files (x86)\F-Secure\SAFE\Ultralight\ulcore\1642777614\fsamsi64.dll'. The PID points to Windows management Instrumentation service.

I found on the F-secure community the following: Win 10 Event Log - fsamsi64.dll - image hash of a file is not valid. On the Avast community I found a similar message (Avast and Security-Mitigations warning events).

I tried to turn off the code integrity for svchost.exe in the Exploit protection setting but that did not resolve the issue.

Does anyone have an idea to solve this issue?
 
I turned off the memory protection but the issue is still there :cry:. I even used the regkey in Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\DeviceGuard\Scenarios.
 
I tested a bit further. I disabled the exploit protection, still the same issue.

I have a policy enabled to protect svchost.exe. Maybe that can be an issue. I disabled it on a test machine but still the same. Going to search further on an fresh installed VM.
 
I maybe found the issue. I have a policy enabled to enable svchost.exe mitigrations. When I set the policy back to "not configured" and delete manually the regkey, the event is not registered again in the eventviewer.

Policy - Mitigratie svchost.png