Global BSOD

Associate
Joined
19 Oct 2002
Posts
316
Location
The Faithful City
And the ******* thing about all this is that the advent of automation means smaller and smaller IT teams are looking after bigger and bigger estates.... then suddenly along comes something where the fix cannot be automated ....
In my role i've seen it happen, since roughly around the end of the 00s, companies have downsized or deskilled their own IT departments (partially I imagine because of cost, but also the increased complication and specialisation of running all the IT functions). This work has been farmed out to 3rd parties, good luck with that on a widespread incident such as today when I imagine everyone's ticket is P1 and there's only a finite amount of bodies they can throw at a problem (hence why it's cheaper in the first place ;). Oh, the irony.
 
Soldato
Joined
17 Nov 2007
Posts
3,190
And the ******* thing about all this is that the advent of automation means smaller and smaller IT teams are looking after bigger and bigger estates.... then suddenly along comes something where the fix cannot be automated ....

This ^

For a lot of fixes this will require someone in front the box, if there are support staff on site they could have 1000s of machines no longer reachable remotely :D
 
Soldato
Joined
3 Jun 2005
Posts
3,115
Location
The South
Today is the day most schools in England break up. I know it's a worldwide issue but I can't help thinking this is deliberate to tank the tourism industry, even if the press isn't making out that it's malicious.
SUs62.gif
 
Soldato
OP
Joined
6 Jan 2013
Posts
21,922
Location
Rollergirl
You should be straight onto the OS drive, if not try a few drive letters till you find the directory.

Depending on the build of the machine, if its been upgraded etc, you can try the following

c:\windows\system32\drivers\crowdstrike
d:\windows\system32\drivers\crowdstrike

even had one machine where it was on x:, no idea how that was built :D :-

x:\windows\system32\drivers\crowdstrike

Then once in there you can delete the file causing the issue :-

dir C-00000291*.sys
del C-00000291*.sys

It's not showing any volumes in DISKPART, I suspect because the drive is encrypted.
 
Soldato
Joined
9 Aug 2013
Posts
2,772
Location
S. Wales
gora love virgin broadband today, yes your internet is down, well our system is down so cant check what is the issue:cry: thankfully my BT is still active and working before contract ends
 
Soldato
Joined
12 Mar 2008
Posts
23,025
Location
West sussex
Today is the day most schools in England break up. I know it's a worldwide issue but I can't help thinking this is deliberate to tank the tourism industry, even if the press isn't making out that it's malicious.
it's not that deep.. rubbish gets pushed to production all the time. The difference is this one causes a BSOD, that's it.
 
Associate
Joined
10 Jan 2009
Posts
755
Location
London
I saw a headline earlier saying 'Microsoft has a lot to answer for'. With relatively little experience of these things, is this true? As it was a third party companies update? I've had a friend say yes due to certain 3 letter requirements and regulations.
 
Soldato
Joined
13 Apr 2009
Posts
6,258
Location
UK
I saw a headline earlier saying 'Microsoft has a lot to answer for'. With relatively little experience of these things, is this true? As it was a third party companies update? I've had a friend say yes due to certain 3 letter requirements and regulations.
Awful media gonna awful media.

Microsoft have nothing to answer for regarding the BSOD issue. They had their own Azure outage a few hours earlier but that seems to be unrelated.
 
Soldato
Joined
20 Dec 2004
Posts
16,003
I saw a headline earlier saying 'Microsoft has a lot to answer for'. With relatively little experience of these things, is this true? As it was a third party companies update? I've had a friend say yes due to certain 3 letter requirements and regulations.
Nothing Microsoft can do if people install third-party software that ****s all over people's systems.

Super easy way to see which companies have competent IT departments that roll out to staging environments and test anything like this before it hits prod.
 
Soldato
Joined
6 Feb 2019
Posts
17,910
gora love virgin broadband today, yes your internet is down, well our system is down so cant check what is the issue:cry: thankfully my BT is still active and working before contract ends

Crowd strike is a security software right and it's brilliant really, because you can't be hacked if your PC isn't on, so really the update is just working at 200% efficiency
 
Soldato
Joined
18 Oct 2002
Posts
8,160
Location
The Land of Roundabouts
Tbf MS also have a history of releasing updates that have caused havoc, not long back a defender update kindly deleted a ton of shortcuts that needed to be recovered from the shadow copies. (Not this level granted)

But this is amazing incompetence of the highest order, CS must do zero testing of their definition updates for this to get out so quickly.
 
Soldato
Joined
9 Aug 2013
Posts
2,772
Location
S. Wales
Crowd strike is a security software right and it's brilliant really, because you can't be hacked if your PC isn't on, so really the update is just working at 200% efficiency
even better i can play my game with internet down and not get hacked, its a win in my book :D
 
Soldato
Joined
3 Jun 2005
Posts
3,115
Location
The South
It's not showing any volumes in DISKPART, I suspect because the drive is encrypted.
If this is a local system and it is BitLocker'd, then access CMD through recovery mode where you should be asked the BitLocker key.
Alternatively, you may be able to force safe mode using bcdedit or constantly rebooting the system, hoping the network stays up long enough for the agent to download the new update.

Saying that, i would look on CrowdStrike's support portal as it looks like, from some screenshots floating around, they have a support page dedicated to the incident with instructions for a fix including BitLocker'd systems.
Alternatively contact your CrowdStrike rep and have a moan.
 
Back
Top Bottom