Security Compliance
Windows error during startup after enabling the FIM driver in SEM
An error screen appears during startup of a Windows host after enabling the File Integrity Monitor (FIM) driver or connector.
First published date
Last published date
Overview
An error screen appears during startup of a Windows host after enabling the File Integrity Monitor (FIM) driver or connector.
Product section
Cause
Resolution
Warning:
- Consult your System Administrator before performing the following procedure.
- SolarWinds strongly recommends that you only edit the SWFsFltr.sys file as instructed. Any additional modifications may result in system performance issues or may create an error state.
- Save a copy of the original SWFsFltr.sys file to your local drive as a backup file, in case you need to roll back later.
- Start Windows in Safe Mode. Refer to Microsoft Support (© 2019 Microsoft, available at https://support.microsoft.com/en-us, obtained on December 2, 2019) on starting Windows in Safe Mode by version.
- Log in to Windows with an administrator account.
- Go to %Windir%\System32\drivers\ and delete SWFsFltr.sys.
- Perform the following using the Registry Editor. Refer to How to Modify the Windows Registry (© 2019 Microsoft, available at https://www.microsoft.com/en-us/, obtained on 11/19/2018).
- Create a backup of the registry.
- Delete the following registry key and all its entries:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\services\SWFsFltr
- Restart Windows in Normal Mode.