Jump to content
  • 0

Bluescreen on unirsd.sys ATTEMPTED WRITE TO READONLY MEMORY


Sergio Masone1709161115

Question

We are using Falcon Crowdstrike as EDR solution in our PVS app layered image, these agents are very small in size and auto update themselves every month. everything looked to be working fine with the sensor version 6.29.x and below, after it updates to sensor versions 6.30+ it blue screens on unirsd.sys. I tried creating a new app layer entirely, install 6.30 or 6.31 version of the sensor, when rebooting the machine it bluescreens also on unirsd.sys.

 

Just curious if anyone else is running into this as well with falcon complete 6.30+ sensors using app layering. I already have a ticket opened up with citrix on this and sent them the debug logs waiting on return rom them.

Link to comment

12 answers to this question

Recommended Posts

  • 0

We are experiencing the same issue using VMware Horizon instant clones (version 8.1 2012) and vCenter 6.7.  With 6.30 I see the BSOD when logging in under a domain account and with 6.31 I get the BSOD after logging off the domain account.  When logging into the image as local admin account, I got the below message (This was with the 6.30 app layer):

 

1116804627_CitrixAppLayererrorBSODissue.thumb.JPG.df874655c51c080a230b2812a0175849.JPG

 

 

Link to comment
  • 0
On 12/1/2021 at 8:14 AM, Ken Berghom said:

We are experiencing the same issue using VMware Horizon instant clones (version 8.1 2012) and vCenter 6.7.  With 6.30 I see the BSOD when logging in under a domain account and with 6.31 I get the BSOD after logging off the domain account.  When logging into the image as local admin account, I got the below message (This was with the 6.30 app layer):

 

1116804627_CitrixAppLayererrorBSODissue.thumb.JPG.df874655c51c080a230b2812a0175849.JPG

 

 

I can confirm same behavior, logging in with domain account bluescreen on 6.30, 6.31 looks to be when logging off the machine.

Link to comment
  • 0
On 11/24/2021 at 1:23 PM, Sergio Masone1709161115 said:

We are using Falcon Crowdstrike as EDR solution in our PVS app layered image, these agents are very small in size and auto update themselves every month. everything looked to be working fine with the sensor version 6.29.x and below, after it updates to sensor versions 6.30+ it blue screens on unirsd.sys. I tried creating a new app layer entirely, install 6.30 or 6.31 version of the sensor, when rebooting the machine it bluescreens also on unirsd.sys.

 

Just curious if anyone else is running into this as well with falcon complete 6.30+ sensors using app layering. I already have a ticket opened up with citrix on this and sent them the debug logs waiting on return rom them.

 

I'm hearing that there was an app layering update that resolves this issue? Can you confirm?

Link to comment
  • 0
51 minutes ago, Sergio Masone1709161115 said:

The fix is GA now included in the latest ELM update, 2112

For us - it is still not working. Same BSOD.

Can you share the exact steps you followed while setting up the template and also the command line switches? Did you use VDI=1 or VDI=1 and NO_START=1 both?

Link to comment
  • 0
15 minutes ago, Hemant Kumar said:

For us - it is still not working. Same BSOD.

Can you share the exact steps you followed while setting up the template and also the command line switches? Did you use VDI=1 or VDI=1 and NO_START=1 both?

After updating the ELM appliance, I created brand new App Layer, inside that layer, installed crowdstrike with both VDI=1 NO_START=1, if when finalizing it asks to reboot the machine, reboot it, then log back in and delete the following two registry keys before finalizing again.
image.thumb.png.60dfec63b6d0634a88030a0d669aee0d.png

Link to comment

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now
×
×
  • Create New...