Updates on today’s issue with CrowdStrike Falcon Sensor
Official advice:
Most up to date info is here: Falcon Content Update Remediation and Guidance Hub: https://www.crowdstrike.com/falcon-content-update-remediation-and-guidance-hub/
Additional Blogs from CrowdStrike:
Statement on Falcon Content Update: https://www.crowdstrike.com/blog/statement-on-falcon-content-update-for-windows-hosts/
Technical Details: https://www.crowdstrike.com/blog/technical-details-on-todays-outage/
Unofficial advice:
https://www.reddit.com/r/crowdstrike/comments/1e6vmkf/bsod_error_in_latest_crowdstrike_update/
Bootable USB to Fix CrowdStrike Content Update Issue with Bitlocker Support https://www.reddit.com/r/msp/comments/1e7xt6s/bootable_usb_to_fix_crowdstrike_issue_fully/?rdt=64175
Self-updating fix:
Falcon Sensor is now self-fixing the issue. The trick is keeping your device on long enough to update.
e.g. We’ve observed a device that was in a boot loop for 2 hours, and self-healed.
Anecdotally, it may help to power a PC off completely to get it out of a reboot loop. Also see the link below under Azure VMs are a problem.
Manual Workaround Steps:
1. Boot Windows into Safe Mode or the Windows Recovery Environment (If bitlocker is OFF, then any way you can access the local disk without the standard Windows boot will work. You can mount a virtual disk, or use an alternate bootable disk.)
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
3. Locate the file matching “C-00000291*.sys”, and delete it.
4. Boot the host normally
Using SCCM to apply the Manual Workaround
We have a SCCM Task Sequence that will automate some of the change via PXE booting.
Find it here: https://github.com/EndpointFocus/CrowdStrike-Jul24-Fix-via-ConfigMgr
Using Falcon RTR to apply the Manual Workaround
We have a customer reporting that issuing RTR commands to delete C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys is helping. Maybe the RTR command is processed sooner than the fix via built-in channel update.
Azure VMs are a problem
To resolve this problem, back up the OS disk, and attach the OS disk to a rescue VM, and then follow the solution options accordingly, or try the solutions one by one. More info here: https://learn.microsoft.com/en-us/troubleshoot/azure/virtual-machines/windows/troubleshoot-reboot-loop
Watch out for disk space issues
BSODs can create dump files, and boot loops will create lots of them.
