Author Topic: Avast and Security-Mitigations warning events  (Read 1862 times)

0 Members and 1 Guest are viewing this topic.

Offline AZBruno

  • Jr. Member
  • **
  • Posts: 60
Avast and Security-Mitigations warning events
« on: September 16, 2020, 11:13:39 PM »
I've been getting warnings in the Event Viewer under Applications and Services Logs\Microsoft\Windows\Security-Mitigations\Kernel Mode. These started only about 6 weeks ago and I suspect that it started when updating Avast Free one or two versions back.

On each boot, I get this Event ID 12 warning repeated 10 times:
Process '\Device\HarddiskVolume8\Program Files\Windows Defender\MpCmdRun.exe' (PID 10816) was blocked from loading the non-Microsoft-signed binary '\Program Files\AVAST Software\Avast\aswAMSI.dll'.

I'm also getting a few other messages, e.g.
Process '\Device\HarddiskVolume8\Windows\System32\dllhost.exe' (PID 8536) was blocked from generating dynamic code.

Is Avast causing these events to be generated? Is it part of the new Ransomware protection?

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast and Security-Mitigations warning events
« Reply #1 on: September 17, 2020, 03:26:19 PM »
- Which version/build of Avast Free..?
- OS..? (32/64 Bit..? - which SP/Build..?)
- Other security related software installed..?
- Which AV(s) did you use before Avast..?
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0

Offline igor

  • Avast team
  • Serious Graphoman
  • *
  • Posts: 11849
    • AVAST Software
Re: Avast and Security-Mitigations warning events
« Reply #2 on: September 17, 2020, 03:46:53 PM »
We are aware of the aswAMSI.dll-related entries. This is a bug on Microsoft side; we're reported this long time ago - but nothing is happening.

Technically, Avast is correctly registered as an AMSI (antimalware) provider. Some time ago, Defender started using JavaScript engine - which also attempts to load the current AMSI provider. However, due to the settings in the Defender process itself, it doesn't "like" the module signed with an Avast (i.e. non-Microsoft) signature. So... it's up to Microsoft to decide whether they want to actually use AMSI in their JavaScript engine (or rather in the engine used by Defender), and if they do, to accept further signatures, or provide another way to allow that DLL in their process.

Offline Asyn

  • Avast Überevangelist
  • Certainly Bot
  • *****
  • Posts: 76037
    • >>>  Avast Forum - Deutschsprachiger Bereich  <<<
Re: Avast and Security-Mitigations warning events
« Reply #3 on: September 17, 2020, 04:04:25 PM »
Quite interesting info, thanks Igor.
W8.1 [x64] - Avast Free AV 23.3.8047.BC [UI.757] - Firefox ESR 102.9 [NS/uBO/PB] - Thunderbird 102.9.1
Avast-Tools: Secure Browser 109.0 - Cleanup 23.1 - SecureLine 5.18 - DriverUpdater 23.1 - CCleaner 6.01
Avast Wissenswertes (Downloads, Anleitungen & Infos): https://forum.avast.com/index.php?topic=60523.0