Vinman
Well-known member
Relax, it’s just Bill Gates reminding people who’s really in charge.
Kurtz was on Jim Cramer this morning, I was wondering if the broadcast was from VIR or if he has headed back to HQ already.Ohhhf. Pack up boys, you're headed home today. Never a fun to watch another race crew pack in early.
Yup. Called in for my 2 Friday morning calls, but blind as can be.This was my morning, or watching a movie. Same blue screen. Restart just brought a different blue screen. Fuckers had it fixed before lunch though.
This isn't really related to Microsoft at all. This is 100% a CrowdStrike EDR fuck up. They sent a channel file out that was full of Null. This is essentially a small driver file that is loaded at the kernel level of the OS, BEFORE everything, including the network stack. The kernel attempts to load the null driver and to protect itself, it blue screens, as it is designed to do.
The primary issue here is that this happens before the network stack is loaded, so there is no way to send an updated channel file before the BSOD hence the fix HAS to be manual intervention. The reboots thing may or may not work. I've heard reports of people rebooting 20+ and still nothing. The issue is also more complicated if a whole disk encryption is used like BitLocker.
I don't envy IT right now. And for the first time I am glad we use Trellix for EDR and not CrowdStrike
basically boot to safe mode without networking, remove a set of files, reboot.Probably have to boot the affected into safe mode and update the driver via USB. I don’t do MS stuff, so just a guess.
It’s a goat rope at best.
1. Boot Windows into safe mode or the Windows Recovery Environment.Probably have to boot the affected into safe mode and update the driver via USB. I don’t do MS stuff, so just a guess.
It’s a goat rope at best.
Exact instructions our IT sent out this morning. But everyone in the company has bitlocker.1. Boot Windows into safe mode or the Windows Recovery Environment.
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.
3. Locate the file matching “C-00000291*.sys” and delete it.
4. Reboot
Can you still do a DOS style command from the root so you don't have to hunt it down?Exact instructions our IT sent out this morning. But everyone in the company has bitlocker.
And for the IT challenged, the file starts with "C-00000291". It has some more numbers after that.
I would assume so. I am not an IT guy though.Can you still do a DOS style command from the root so you don't have to hunt it down?
Ohhhf. Pack up boys, you're headed home today. Never a fun to watch another race crew pack in early.
Stock down 15% and now no race cars?Car doesn't run without being hooked to the cloud or are they so embarrassed they packed up and left?
Had to sell the car to raise funds to buy back some discounted stock.Stock down 15% and now no race cars?
Had to sell the car to raise funds to buy back some discounted stock.
Fixt it for ya.Exact instructions our IT sent out this morning. But everyone in the company has bitlocker.
And for the IT challenged, the file starts with "C-00000291". It has some more numbers after that.
you just email it in plain textFixt it for ya.
1. Boot Windows into safe mode or the Windows Recovery Environment.
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.
3. Locate the file matching “C-00000291*.sys” and delete it.
4. Reboot
5. If you have BitLocker, jump of a bridge.
But really, if the enterprise was keeping the BitLocker recovery keys in Active Directory (like they should be), it shouldn't add but a little more time telling someone over the phone their 48 digit key "No, I said E, not C"
Same but I got pissed, ripped the power cord out, plugged it in and it fixed it. Next step if that didn't was punching it.Got into work to find my computer in a blue screen loop. Oh well for the stuff I was trying to run overnight.
I don't even have internet on my own computer.As it's been said, this is another good reason to not use cloud based services.
I'm stuck in Raleigh trying to get home. Delta flights cancelled. Can't rent a car, they are down or not allowing one ways.
Found a southwest flight to Atlanta, then going to get a ride home and go pick up my car from Chattanooga later.
Fuck computers
Do you even know what I'm talking about?I don't even have internet on my own computer.
Fixt it for ya.
1. Boot Windows into safe mode or the Windows Recovery Environment.
2. Navigate to the C:\Windows\System32\drivers\CrowdStrike directory.
3. Locate the file matching “C-00000291*.sys” and delete it.
4. Reboot
5. If you have BitLocker, jump of a bridge.
But really, if the enterprise was keeping the BitLocker recovery keys in Active Directory (like they should be), it shouldn't add but a little more time telling someone over the phone their 48 digit key "No, I said E, not C"
Need to end up back in Chattanooga to get my car at some point, but my house is halfway better Atlanta and Chattanooga, if I can just get home today I'll be happy.Where you headed. Im into a 6-8 hour delay.
Hoping it will hold, and maybe home tonight
Fuuuuuuck!Our son and family were red-eye flying out from California to Georgia last night, and made it as far as their first leg to Denver They had boarded their connection flight to Houston, then were told to deplane due to a "glitch". They slept at the airport. Just found out at 6:30 pm that they finally made to Houston, but there were further delays for final destination to Atlanta. So far they have logged 30 hours of little travel, on what would normally have been a 4.5 hour flight....
Our son and family were red-eye flying out from California to Georgia last night, and made it as far as their first leg to Denver They had boarded their connection flight to Houston, then were told to deplane due to a "glitch". They slept at the airport. Just found out at 6:30 pm that they finally made to Houston, but there were further delays for final destination to Atlanta. So far they have logged 30 hours of little travel, on what would normally have been a 4.5 hour flight....
Need to end up back in Chattanooga to get my car at some point, but my house is halfway better Atlanta and Chattanooga, if I can just get home today I'll be happy.
Delta offered me tomorrow at 1pm with 3 legs and 14 hours total time or 8pm with 3 legs and 11 hours flight time. Southwest got a lot of business today
Yep. Exact same with our system (Samsara)Our GPS systems are active, but the electronic logs aren't transmitting. violation reports are rolling in left and right, as the server isn't being told of any status changes where the drivers went to sleep after midnight and the mainframe thinks they have been driving up to 18 hours straight..