/
July 2024 Crowdstrike Windows Fix

July 2024 Crowdstrike Windows Fix

There are two methods to repair systems affected by the Crowdstrike issue.

  1. The Automated Tool. You need to be on campus and connected directly to the network (not wireless). This is the easiest solution.

  2. The Manual Method. Use this method if off-campus or using wireless on or off campus. The steps are fairly straightforward but you will need to follow instructions carefully and enter commands exactly as written.

1. Automated Tool (on Campus with a Wired Network Connection Only):

  1. Restart your machine (either by powering on the computer or using the Restart button on the blue screen).

  2. As the system restarts, press F12 on the keyboard repeatedly until you see a boot menu.

    1. Note: if you are using a wireless keyboard, you may need to hold the Fn key constantly while hitting F12 to activate the Function key.

  3. You should see a screen with the option Onboard NIC (IPV4) on the left-hand column.

    1cd.jpg
  4. Find and select the option that includes the words IPV4 (IPv4) or PXE. You may need to use your mouse or keyboard to highlight the right option. Press ENTER to select this option.

  5. Your computer will reboot.

  6. If you are prompted with a Boot Menu after the reboot, select the option that says IPV4 (IPv4) or PXE and hit Enter again.

2c.jpg
  1. If you see this screen, just hit Enter

    3c.jpg

  2. On the next screen (below), use the keyboard to scroll down to select LTS Crowdstrike Fix and hit Enter.

5c.jpg

Depending on the network speed in your building, you may or may not see the following screen:

6c.jpg
  1. A white/gray blank screen will pop up next. This is normal (wait). The blank screen will change to the screen in step 10.

    IMG_4131.JPG
    Screen says: “Waiting for network, attempt 1 of 20”

     

  2. After a few moments, you will see this screen.

    IMG_4132.JPG
    Screen says: “Network ready!”
  3. The computer should automatically reboot and you should be able to log back in. If this fix does not work, you may try the Manual Method listed below.

2. Manual Method (more steps but can be done from any location, on or off campus)

If you do not feel comfortable attempting this method, please submit a helpdesk ticket here.

  1. On the Windows 10 or 11 recovery screen, please click “See advanced repair options.”

recovery selection.jpg
The See advanced repair options are circled here.
  1. On the Troubleshoot window, click “Advanced options.”

advanced options.jpg
Choose Advanced options.
  1. On the Advanced options menu, click on “Command Prompt.”

command prompt.jpg
Choose Command Prompt.
  1. Now the system will prompt you to unlock the drive with the Bitlocker recovery key. To obtain the BitLocker recovery key, use one of the following websites:

Important: Before you press Continue, note the first 2 letters adjacent to the Drive Label at the bottom of the screen (either FS or AP).

commandpromptwred.jpg
Enter the recovery key and note the Drive label.

If you have any issues getting the recovery key, please put in a helpdesk ticket here.

 

  1. If you enter your Bitlocker key successfully, a command prompt window will appear:

commandprompt2.jpg
X:\Windows\System32> is the command prompt.
  1. At the command prompt, type this command: wmic logicaldisk list brief

enter the command.jpg
Enter the command as shown.
  1. A listing of device information displays. Find the WINDOWS VolumeName. Note the DeviceID that is on the same line. In this case, the DeviceID on the same line as WINDOWS is C:

volumename.jpg
C: is on the same line as the VolumeName WINDOWS.
  1. Next, type the command below at the command line. Type the text exactly using your DeviceID letter where you see the green highlighted example. In this example, the example DeviceID letter C: is highlighted green.

del /p C:\windows\system32\drivers\CrowdStrike\C-00000291*.sys

secondtolastedited.jpg
Type this command, substituting the drive letter/DeviceID for your device.
  1. Then you will get a confirmation message that says “Are you sure you want to delete that file?”  Make sure you have the right file, ending 291*.sys, then press Y.

unnamed.jpg
Confirmation Screen for the file deletion

 

  1. Finally, click X to close the black window and restart your computer. 

If neither method works for your computer, please submit a helpdesk ticket here.

 

Related content

Windows: Connect to H: Drive Personal Network Storage
Windows: Connect to H: Drive Personal Network Storage
Read with this
Windows Crowdstrike Recovery
Windows Crowdstrike Recovery
More like this
Storage Quotas for Cloud-Based Data
Storage Quotas for Cloud-Based Data
Read with this
Deploy a Departmental Classroom OS Image via MDT - Network Boot
Deploy a Departmental Classroom OS Image via MDT - Network Boot
More like this
Gmail mail merge/mass email
Gmail mail merge/mass email
Read with this
Report Network Connection Problems
Report Network Connection Problems
More like this

For immediate help, contact the LTS Help Desk (Hours)
EWFM Library | Call: 610-758-4357 (8-HELP) | Text: 610-616-5910 | Chat | helpdesk@lehigh.edu
Submit a help request (login required)