Quantcast
Channel: THWACK: Message List - Security Event Manager (SEM) - Formerly Log & Event Manager
Viewing all articles
Browse latest Browse all 5385

Re: FIM: disabled on startup

$
0
0

How to gather some information that might help below.  All steps should be on the system running FIM/the LEM Agent.

 

  1. Open a command prompt as an administrator
  2. Run FLTMC, get the results (screenshot)
  3. Run TASKLIST, get the results
  4. Run VERIFIER (Details on verifier are here: https://support.microsoft.com/en-us/kb/244617 )
    1. Create custom settings
    2. Enable Special Pool, Pool Tracking, I/O Verification, IRP Logging and Miscellaneous Checks
    3. Choose to select driver names from a list
    4. Pick the swfsfltr.sys driver, click FINISH
    5. THE SYSTEM WILL NEED TO REBOOT

 

After the reboot, you can re-run VERIFIER and see the state of the FIM driver on the desktop.  Was it "Unloaded" or "Never Loaded"?


Viewing all articles
Browse latest Browse all 5385

Trending Articles



<script src="https://jsc.adskeeper.com/r/s/rssing.com.1596347.js" async> </script>