A faulty update from the cybersecurity company Crowdstrike has led to system failures worldwide and paralyzed airports, banks and hospitals. Millions Windows devices are affected by the outage. Microsoft has therefore released a recovery tool to resolve the error.
According to experts, the largest IT outage of all time occurred on July 19, 2024. The reason: A faulty software update from the cybersecurity company Crowdstrike had paralyzed numerous Windows systems at airports, banks, hospitals and emergency services.
Crowdstrike: Microsoft releases recovery tool
As a result, many Microsoft devices could no longer be booted and displayed so-called blue screens. Crowdstrike officially confirmed the incident on the same day, removed the faulty update and released a new version. The problem: On devices already affected, the error can only be fixed manually – by a specialist.
Microsoft has therefore released a recovery tool to speed up the process. It contains the script “MsftRecoveryToolForCSv2.ps1”, which is automatically executed within the command line. It is supposed to automatically delete the faulty files in the folder “%WINDIR%\System32\drivers\CrowdStrike”.
According to Crowdstrike, the faulty files are named “C-00000291.sys” and have the time stamp “2024-07-19 UTC”. Microsoft has meanwhile signed its recovery tool to prevent further errors from occurring. The tool can be copied to a USB stick or DVD, among other things. On affected devices, after booting, it executes the commands recommended by CrowdStrike to get the system running again.
Step-by-step instructions
Alternatively, Windows can also be started in safe mode. According to Microsoft, this is possible because the so-called Falcon sensor, which is affected by the faulty Crowdstrike update, is not started, so that a boot loop can be avoided.
In an official blog post, Microsoft has published step-by-step instructions so that users can restore affected systems. The tool is available for free download there. However, some users are already reporting limitations and errors in the comments. The tool may therefore not work on all devices.
Also interesting:
Source: https://www.basicthinking.de/blog/2024/07/22/crowdstrike-microsoft-veroeffentlicht-wiederherstellungstool-zu-fehlerbebung/