IBM Security Join our 16,000+ members as we work together to overcome the toughest challenges of cybersecurity. Join the Community
Hello Experts, Hope all is well.
We had GIM & STAP Agents were running on Windows Server OS 2016. we were able to Uninstall GIM and STAP Agents from Control Panel by using Add/Remove Programs. Post removing the agents, we restarted the servers. Post restarting the server. I tried to Remove the directories/files associated with Guardium Agents. However, I was able to delete the GIM directory but not the STAP one. it was throwing an error saying " it is currently being used by some other program/process.
So, I checked STAP Drivers by running below commands & there are still very old drivers associated with the server. I tried to stop them but it did not work. Can anyone please assist me on this. How I can completely clean uninstall STAP .
C:\WINDOWS\system32>driverquery |findstr guardium
C:\WINDOWS\system32>driverquery | findstr GuardiumDrvTrc IBM Security Guardium Kernel 27/08/2021 10:07:47 AMNmpProxy IBM Security Guardium Kernel 27/08/2021 10:04:05 AM
C:\WINDOWS\system32>net stop DrvTrcThe requested pause, continue, or stop is not valid for this service.
More help is available by typing NET HELPMSG 2191.
C:\WINDOWS\system32>net stop NmpproxyThe requested pause, continue, or stop is not valid for this service.
C:\WINDOWS\system32>sc query Guardium[SC] EnumQueryServicesStatus:OpenService FAILED 1060:
The specified service does not exist as an installed service.
C:\WINDOWS\system32>net stop DrvtrcThe requested pause, continue, or stop is not valid for this service.
In general, Windows S-TAP is supposed to be uninstalled via GIM if GIM is installed.
Anyway, if Windows S-TAP uninstaller worked fine, these drivers should be completely removed after the OS reboot. Could you please reboot again to see if these drivers are not loaded and the files are completely removed?
If the issue persists even after the reboot, the uninstaller didn't work properly. In this case, please run must gather and send the output to Technical Support. If the must gather script (diag.bat and diag.ps1) are no longer existing, you can simply open a support ticket and ask for the script, then run it and send the output to the support.Thanks,Satoshi