Security Compliance

Windows error during startup after enabling the FIM driver in SEM

An error screen appears during startup of a Windows host after enabling the File Integrity Monitor (FIM) driver or connector.

First published date

11/29/2018 10:57 PM

Last published date

11/29/2018 10:57 PM

Overview

This article applies to Security Event Manager (formerly Log & Event Manager).

An error screen appears during startup of a Windows host after enabling the File Integrity Monitor (FIM) driver or connector.

Product section

Security Event Manager

Cause

The mini driver installed with FIM is in conflict with the Windows host.

Resolution

Warning:

  • Consult your System Administrator before performing the following procedure. 
  • SolarWinds strongly recommends that you only edit the SWFsFltr.sys file as instructed. Any additional modifications may result in system performance issues or may create an error state.
  • Save a copy of the original SWFsFltr.sys file to your local drive as a backup file, in case you need to roll back later.
     
  1. Start Windows in Safe Mode. Refer to Microsoft Support (© 2019 Microsoft, available at https://support.microsoft.com/en-us, obtained on December 2, 2019) on starting Windows in Safe Mode by version.
  2. Log in to Windows with an administrator account.
  3. Go to %Windir%\System32\drivers\ and delete SWFsFltr.sys‏.
  4. Perform the following using the Registry Editor. Refer to How to Modify the Windows Registry (© 2019 Microsoft, available at https://www.microsoft.com/en-us/, obtained on 11/19/2018). 
    1. Create a backup of the registry. 
    2. Delete the following registry key and all its entries:
      HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SWFsFltr‏
  5. Restart Windows in Normal Mode.
Disclaimer: Please note, any content posted herein is provided as a suggestion or recommendation to you for your internal use. This is not part of the SolarWinds software or documentation that you purchased from SolarWinds, and the information set forth herein may come from third parties. Your organization should internally review and assess to what extent, if any, such custom scripts or recommendations will be incorporated into your environment.  You elect to use third party content at your own risk, and you will be solely responsible for the incorporation of the same, if any.