Skip to main content
  • Place orders quickly and easily
  • View orders and track your shipping status
  • Enjoy members-only rewards and discounts
  • Create and access a list of your products
  • Manage your Dell EMC sites, products, and product-level contacts using Company Administration.

Blue Screen Error Occurs After Updating CrowdStrike

Summary: This article references a recent CrowdStrike update which causes issues such as Blue Screen errors, and provides workarounds and solutions as available.

This article may have been automatically translated. If you have any feedback regarding its quality, please let us know using the form at the bottom of this page.

Article Content


Symptoms

Affected Products:

  • CrowdStrike

Note: Statement from CrowdStrike: Statement on Falcon Content Update for Windows Hosts This hyperlink is taking you to a website outside of Dell Technologies..

Users may encounter a blue screen error after updating CrowdStrike.

The error message reads:

Stop Code:Page_fault_in_nonpaged_area
What failed: csagent.sys
Note: Channel file C-00000291*.sys (CrowdStrike driver file) with a timestamp of 0527 UTC or later is the reverted (good) version.

Blue Screen after updating CrowdStrike

Cause

The cause is under investigation by CrowdStrike. Contact CrowdStrike for details. https://www.crowdstrike.com/contact-us/ This hyperlink is taking you to a website outside of Dell Technologies.

Resolution

This article is updated as more information becomes available.

Workaround:

A restart of the computer can allow it to download a functional channel file.

If the blue screen error occurs after a restart, follow these steps as a workaround:

  1. Boot the computer to Safe Mode. For information about booting to Safe Mode, reference the Dell knowledge base article How to Boot into Safe Mode in Windows 11 or Windows 10
  2. Go to the CrowdStrike directory. Open File Explorer by clicking the folder icon in the Taskbar. Alternately you can click Start and search for File Explorer and select the File Explorer application (do one of the following):
    • Paste the path C:\Windows\System32\drivers\CrowdStrike into the Address Bar at the top of File Explorer and press Enter.
    • Go to the CrowdStrike folder following these steps:
      1. Click the Start Menu
      2. Click the File Explorer application
      3. Click C:/ drive
      4. Click the Windows folder
      5. Click the System32 folder
      6. Click the drivers folder
      7. Click the CrowdStrike folder
  3. Delete the following file, C-00000291*.sys
  4. Boot to Windows.

Identifying Affected Machines:

Note: The following is for CrowdStrike IT Admins, reach out to your IT department to see if your computer is impacted.

Query to identify impacted hosts using Advanced event search (within the CrowdStrike application):

}
| default(value="0", field=[CSUcounter, SHBcounter])
// Make sure both ConfigState update and SensorHeartbeat have happened
| selfJoinFilter(field=[cid, aid, ComputerName], where=[{ConfigStateUpdate}, {SensorHeartbeat}])
// Aggregate results
| groupBy([cid, aid], function=([{selectFromMax(field="@timestamp", include=[CFVersion])}, {selectFromMax(field="@timestamp", include=[@timestamp]) | rename(field="@timestamp", as="LastSeen")}, max(CSUcounter, as=CSUcounter), max(SHBcounter, as=SHBcounter)]), limit=max)
// Perform check on selfJoinFilter
| CFVersion=* LastSeen=*
// Calculate time between last seen and now
| LastSeenDelta:=now()-LastSeen
// Optional threshold; 3600000 is one hour
| LastSeenDelta>3600000
// Calculate duration between last seen and now
| LastSeenDelta:=formatDuration("LastSeenDelta", precision=2)
// Convert LastSeen time to human-readable format
| LastSeen:=formatTime(format="%F %T", field="LastSeen")
// Enrich aggregation with aid_master details
| aid=~match(file="aid_master_main.csv", column=[aid])
| aid=~match(file="aid_master_details.csv", column=[aid], include=[FalconGroupingTags, SensorGroupingTags])
// Convert FirstSeen time to human-readable format
| FirstSeen:=formatTime(format="%F %T", field="FirstSeen")

// Move ProductType to human-readable format and add formatting
| $falcon/helper:enrich(field=ProductType)
| drop([Time])
| default(value="-", field=[MachineDomain, OU, SiteName, FalconGroupingTags, SensorGroupingTags], replaceEmpty=true)
| case{
    CSUcounter=0 AND SHBcounter=0 | Details:="OK: Endpoint did not receive channel file during impacted window. Endpoint was offline.";
    CSUcounter=0 AND SHBcounter=1 | Details:="OK: Endpoint did not receive channel file during impacted window. Endpoint was online.";
    CSUcounter=1 AND SHBcounter=1 | Details:="CHECK: Endpoint received channel file during impacted window. Endpoint was online. Endpoint has not been seen online in past hour.";

Article Properties


Affected Product

CrowdStrike

Last Published Date

19 Jul 2024

Version

2

Article Type

Solution