Yep, happy friday. Just reboots have been solving it for many of our systems (Advanced Startup options then continue to Windows 10/11/Server). For the rest, we have to do the following steps:
1. Boot Windows into Safe Mode or WRE.
2. Go to C:\Windows\System32\drivers\CrowdStrike
3. Locate and delete file matching "C-00000291*.sys"
4. Boot normally.

Jim

On Fri, Jul 19, 2024 at 12:45 AM Eric Bennick via USHE-ISO <ushe-iso@lists.dixie.edu> wrote:
Are you guys up recovering servers knocked offline by CrowdStrike? ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍ ‍
Are you guys up recovering servers knocked offline by CrowdStrike?

--
USHE-ISO mailing list
USHE-ISO@lists.dixie.edu
https://urldefense.com/v3/__http://lists.dixie.edu/cgi-bin/mailman/listinfo/ushe-iso__;!!BSlRHw!5epqkjpeSgZoLCnrnefSW412_TlJlJAhXAAgFQ1WI3IjrLyvOdhzSg9FOOMNTbahTlu44uCG5UW0BT-asT4iD0EH$


--
suu.eduJIM SHAKESPEAR   |   Chief Information Security Officer / Director of IT Security / Institutional Data Privacy Officer
INFORMATION TECHNOLOGY, SOUTHERN UTAH UNIVERSITY
ELC513  |   (435) 865-8202