Security Event Log Audit Failure 5038 in Windows 7 Home Premium SP1

Answered Security Event Log Audit Failure 5038 in Windows 7 Home Premium SP1

  • Thursday, April 19, 2012 8:06 AM
     
     

    I have this Event Log Audit Failure 5038 on this computer and can't seem to find a solution online. I have seen the same problem reported by others on Vista SP1 and don't seem to have a solution for it till today. Can anyone please help?

    Rgds,

    Hans

    Log Name:      Security
    Source:        Microsoft-Windows-Security-Auditing
    Date:          4/19/2012 12:32:12 PM
    Event ID:      5038
    Task Category: System Integrity
    Level:         Information
    Keywords:      Audit Failure
    User:          N/A
    Computer:      LXATDxxxxx
    Description:
    Code integrity determined that the image hash of a file is not valid.  The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume2\Windows\System32\drivers\Haspnt.sys 
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
        <EventID>5038</EventID>
        <Version>0</Version>
        <Level>0</Level>
        <Task>12290</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8010000000000000</Keywords>
        <TimeCreated SystemTime="2012-04-19T04:32:12.279236500Z" />
        <EventRecordID>67547</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="52" />
        <Channel>Security</Channel>
        <Computer>LXATDxxxxx</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="param1">\Device\HarddiskVolume2\Windows\System32\drivers\Haspnt.sys</Data>
      </EventData>
    </Event>

    Log Name:      Security
    Source:        Microsoft-Windows-Security-Auditing
    Date:          4/19/2012 12:32:12 PM
    Event ID:      5038
    Task Category: System Integrity
    Level:         Information
    Keywords:      Audit Failure
    User:          N/A
    Computer:      LXATDxxxxx
    Description:
    Code integrity determined that the image hash of a file is not valid.  The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.

    File Name: \Device\HarddiskVolume2\Windows\System32\drivers\Haspnt.sys 
    Event Xml:
    <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
      <System>
        <Provider Name="Microsoft-Windows-Security-Auditing" Guid="{54849625-5478-4994-A5BA-3E3B0328C30D}" />
        <EventID>5038</EventID>
        <Version>0</Version>
        <Level>0</Level>
        <Task>12290</Task>
        <Opcode>0</Opcode>
        <Keywords>0x8010000000000000</Keywords>
        <TimeCreated SystemTime="2012-04-19T04:32:12.279236500Z" />
        <EventRecordID>67547</EventRecordID>
        <Correlation />
        <Execution ProcessID="4" ThreadID="52" />
        <Channel>Security</Channel>
        <Computer>LXATDxxxxx</Computer>
        <Security />
      </System>
      <EventData>
        <Data Name="param1">\Device\HarddiskVolume2\Windows\System32\drivers\Haspnt.sys</Data>
      </EventData>
    </Event>

    • Moved by Carey FrischMVP, Moderator Wednesday, April 25, 2012 8:46 PM Moved to more appropriate forum category (From:Windows Vista Service Packs/Windows Server 2008 Service Packs)
    •  

All Replies

  • Thursday, April 26, 2012 6:08 AM
    Moderator
     
     Answered

    Hi,


    I noticed that the error is related to Haspnt.sys. And based on my research, Haspnt.sys is provided by Aladdin Knowledge Systems. Please try reinstalling or updating the software and see how it works.


    Meanwhile, considering this issue might be related to the specific software, it is recommended to contact Aladdin Knowledge Systems Support for help.


    Hope this helps.


    Jeremy Wu

    TechNet Community Support

  • Saturday, May 05, 2012 8:22 PM
     
     Answered

    Thanks! Jeremy.

    Yes, you are right about the error caused by Haspnt.sys a USB Security Dongle Driver provided by Aladdin Knowledge Systems.

    The problem with it is by uninstalling and reinstalling the driver will not solve the problem due to the fact that it was caused by the older HASP4 driver when uninstalling left behind a number of files that will cause problem after installing and running the newer HASP5 driver.

    The following are the steps that I had taken to resolve this problem:

    1) First goto the Aladdin site to download the latest HASP driver, at this moment is the HASP6 driver.

    2) I also went to the CNET site to download the free Wise Disk Cleaner as well as the Free Wise Registry Cleaner, which has been verified to be virus and trojen free by CNET as well as by Kaspersky and Norton softwares.

    3) Temporary disable any anti-virus protection software until next restart.

    4) Next goto C:\Program Files\Common Files\Aladdin Shared\HASP or the equivalent folder for your version of Windows to erase every haspvlib*.dll files.

    5) Select START - Control Panel - Programs and Features - to uninstall the "Sentinel HASP Run-Time" program.

    6) Select START - Administrative Tools - Services - to stop any services that start with "Hasp" or "HLServer"

    7) Goto C:\Windows\System32\Drivers or equivalent folder for your version of Windows to remove any "aks*.*" files, "hardlock.sys" and "haspnt.sys".

    8) Next Select START - Control Panel - Device Manager - and select the "View" tab to activate "Show Hidden Devices".

    9) Expand the "Non plug and play divers"

    10) Uninstall each of the following by right clicking if it exists: "Hardlock", "Haspnt", "HASP fridge" or "aksfridge".

    11) At this moment I would have install both the Wise Disk Cleaner and Wise Registry Cleaner onto the computer. Start the Registry Cleaner and select "Backup" to create a "System Restore Point" as well and a"Full Registry Backup" just in case we need it.

    12) Select START - All Programs - Accessories - activating the "Command Prompt" by right clicking it using "Run as administrator".

    13) Type "regedit" to open the registry editor, and goto HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/Services/, and delete the following files: "aksfridge" or "HASP fridge", "akshasp", "aksusb", "hardlock", "haspnt" and "hasplms".

    14) Close all applications and restart the computer.

    15) Start the Wise Disk Cleaner to clean all unwanted files that were left over by the previous HASP driver installation and restart the computer.

    16) Start the Wise Registry Cleaner to remove all unwanted registries left over by the previous HASP driver installation and restart the computer.

    17) Install the latest HASP driver and restart the computer to activate it.

    18) Wahlah! Event ID: 5038 is gone for good.