/build/static/layout/Breadcrumb_cap_w.png

Fix the CrowdStrike BSOD with KACE SDA

Update: We also have an official KB article for it, check it out here.


Hey,

I know, everyone saw the news last week about CrowdStrike and their faulty files that caused a BSOD on millions of machines. If you have KACE SDA (Systems Deployment Appliance) you can easily delete the faulty files.

Login to you KACE SDA webui, go to "Library/Mid-Level Tasks" and create a new BAT-Script.

D+sN1I6QsHbEQAAAABJRU5ErkJggg==

As BAT code please use the following:

del C:\Windows\System32\drivers\CrowdStrike\C-00000291*.sys

If you wonder, we can not use the %systemroot% variable since we boot into the KBE and the variable would point to X:\Windows which does not contain the faulty files.


After you created the Mid-Level task you can go to "Deployments/Custom Deployments", create a new custom deployment and add the created Mid-Level task to the mid-level area.

3pSYlorE60sAAAAAElFTkSuQmCC

Once you created the custom deployment, you can either boot via PXE and run this manually, or you create an automated deployment, choose all affected devices and then you just have to network boot the devices and the KBE and script will run automatically.

To create an automated deployment, go to "Deployments/Automated Deployments" and add a New Boot Action.

AbZKDcATmT1HAAAAAElFTkSuQmCC


8JSrUj7Cn7+g516ZQsUJT6UsUDhxjoc2RoppT6gPrvyiEuDwPDKnRDXmgtJlZeCXJ3vda2DoPE0x7wDKF2p3CbbYVZSAEmgcgTYVg23crWlpJaAElIASUAIrj4Aq2JXHXs+sBJSAElACqzCBNhuDXYWfSavcmmQYI3bISVGFvmjVKheglSoBJaAEVjMCbTYGu5o9p2bfLqaQJPPEm5t9Aq1ACSgBJaAEXATURezCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGgCrYluGotSgBJaAElIAScBFQBevCoStKQAkoASWgBFqGwP8DolvHL+OSaBwAAAAASUVORK5CYII=


For more details please look at the official CrowdStrike websites here.


Comments

  • Thank you for this - lama01 1 month ago
This post is locked
 
This website uses cookies. By continuing to use this site and/or clicking the "Accept" button you are providing consent Quest Software and its affiliates do NOT sell the Personal Data you provide to us either when you register on our websites or when you do business with us. For more information about our Privacy Policy and our data protection efforts, please visit GDPR-HQ