zodiacon / TotalRegistry

Total Registry - enhanced Registry editor/viewer
MIT License
1.41k stars 119 forks source link

System Integrity problem with KRegExp.sys #54

Open mkali67 opened 1 year ago

mkali67 commented 1 year ago

Event viewer reports system integrity problem with KRegExp.sys.

Code Integrity Checker detected that the file image hash is invalid. The file may have been corrupted due to unauthorized modification. An invalid hash may indicate a potential problem with the disk device.

Filename: \Device\HarddiskVolume2\Windows\System32\drivers\KRegExp.sys

[ Name] Microsoft-Windows-Security-Auditing [ Guid] {54849625-5478-4994-a5ba-3e3b0328c30d} EventID 5038 Version 0 Level 0 Task 12290 Opcode 0 Keywords 0x8010000000000000

zodiacon commented 1 year ago

I'll look into it, as currently, TotalRegistry does not use this driver.