Soldato
Where is the folder located?
Code:
del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
Where is the folder located?
del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
...and I'm in charge of a team looking after a medium-sized University's entire Windows server infrastructure. If your opinion doesn't count, mine definitely doesn't?I run the European IT for a bank, Do I get to have an opinion or not?
There must be an ansible playbook for thatwe've been slowly recovering the boxes manually..
detach disc
attach to another instance that is running
remove file
re-attach
reboot
back online..
it's a Friday special for sure.
Thanks, no directory there so can't just be solely Crowd Strike.
- Boot Windows into Safe Mode or the Windows Recovery Environment
- Navigate to the C:\Windows\System32\drivers\CrowdStrike directory
- Locate the file matching “C-00000291*.sys”, and delete it.
- Boot the host normally.
...and I'm in charge of a team looking after a medium-sized University's entire Windows server infrastructure. If your opinion doesn't count, mine definitely doesn't?
EDIT: A university *not* using Crowdstrike, I might add.
Its funny; most of us in here probably work in places that don't use Crowdstrike; its why we have time to sit here andgloat(sorry I mean banter about it!)
fomo
Good thing for us it happened on Friday, our office is usually at >5% capacity. VPN and DCs have gone down so no doubt everyone working from home will be out sunbathing
I'm sat here having a quiet Friday morning while my mate over in Germany is losing her mind as all their sites are down. She isn't happy!Its funny; most of us in here probably work in places that don't use Crowdstrike; its why we have time to sit here andgloat(sorry I mean banter about it!)
Anyone scoring the day off for this one?
Who are we blaming, Putin..?
As mentioned, if our company was hit then it would absolutely be me getting it fixed.Small fish, big pool and no one, NO ONE, on this forum is getting hit up to do anything important other than present opinion as fact because they run some car boot sale's EFTPOS system.
Question to those in the knowCode:del "C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys"
You have no idea what any of us do
Not stopping a global outage, apparently.
Looks like my work PC did a BSOD due to crowdstrike however after restarting it booted up fine.
Not stopping a global outage, apparently.