Share via

My laptop is blue screening with the stop code PAGE_FAULT_IN_NONPAGED_AREA and apparently csagent.sys failed and I have done no hardware or software changes this happened all of us sudden?

Anonymous
2024-07-19T06:37:29+00:00

My laptop is blue screening with the stop code PAGE_FAULT_IN_NONPAGED_AREA and apparently csagent.sys failed and I have done no hardware or software changes this happened all of us sudden?

Also whenever I go to safe mode and press the f5 key it still doesn't let me connect to the internet.

Windows for home | Windows 10 | Performance and system failures

Locked Question. This question was migrated from the Microsoft Support Community. You can vote on whether it's helpful, but you can't add comments or replies or follow the question.

0 comments No comments

3 answers

Sort by: Most helpful
  1. Anonymous
    2024-07-19T07:24:01+00:00

    there is a global outtage for crowdstrike security you can do a quick bing search since multiple news have been posted

    3 people found this answer helpful.
    0 comments No comments
  2. Sumit 43,786 Reputation points Volunteer Moderator
    2024-07-22T01:51:42+00:00

    New Recovery Tool to help with CrowdStrike issue impacting Windows endpoints - Microsoft Community Hub

    As a follow-up to the CrowdStrike Falcon agent issue impacting Windows clients and servers, Microsoft has released an updated recovery tool with two repair options to help IT admins expedite the repair process. The signed Microsoft Recovery Tool can be found in the Microsoft Download Center: https://go.microsoft.com/fwlink/?linkid=2280386. In this post we include detailed recovery steps for Windows client, servers, and OS's hosted on Hyper-V. The two repair options are as follows:

    • Recover from WinPE – this option produces boot media that will help facilitate the device repair.
    • Recover from safe mode – this option produces boot media so impacted devices can boot into safe mode. The user can then login using an account with local admin privileges and run the remediation steps.

    Determining which option to use

    Recover from WinPE (recommended option)
    This option quickly and directly recovers systems and does not require local admin privileges. However, you may need to manually enter the BitLocker recovery key (if BitLocker is used on the device) and then repair impacted systems. If you use a third-party disk encryption solution, please refer to vendor guidance to determine options to recover the drive so that the remediation script can be run from WinPE.

    Recover from safe mode
    This option may enable recovery on BitLocker-enabled devices without requiring the entry of BitLocker recovery keys. For this option, you must have access to an account with local administrator rights on the device. Use this approach for devices using TPM-only protectors, devices that are not encrypted, or situations where the BitLocker recovery key is unknown. However, if utilizing TPM+PIN BitLocker protectors, the user will either need to enter the PIN if known, or the BitLocker recovery key must be used. If BitLocker is not enabled, then the user will only need to sign in with an account with local administrator rights. If third-party disk encryption solutions are utilized, please work with those vendors to determine options to recover the drive so the remediation script can be run.

    Additional considerations
    Some devices may not be allowed to connect to a USB drive. In this case, it may be better to reimage the device.

    As with any recovery option, test on multiple devices prior to using it broadly in your environment.

    Prerequisites to create the boot media

    1. A Windows 64-bit client with at least 8GB of free space from which the tool can be run to create the bootable USB drive.
    2. Administrative privileges on the Windows client from prerequisite #1.
    3. A USB drive with min 1GB and max of 32GB. All existing data on this USB will be wiped and will be formatted automatically to FAT32.

    Instructions to generate the WinPE recovery media
    To create recovery media, follow these steps on the 64-bit Windows client mentioned in prerequisite #1:

    1. Download the signed Microsoft Recovery Tool from the Microsoft Download Center.
    2. Extract the PowerShell script from the downloaded solution.
    3. Run MsftRecoveryToolForCSv2.ps1 from an elevated PowerShell prompt.
    4. The ADK will download and media creation will start. It may take several minutes to complete.
    5. Choose one of the two options mentioned above for recovering affected devices (see additional details below).
    6. Optionally select a directory that contains driver files to import into the recovery image. Keyboard and mass storage drivers may be needed. Network or other drivers are not required. We recommend you select “N” to skip this step. The tool will import any SYS and INI recursively under the specified directory.
    7. Select the option to either generate an ISO or USB drive and specify drive letter.

    Prerequisites for using the boot media
    The BitLocker recovery key for each BitLocker-enabled impacted device on which the recover media is used may be required. If you are using TPM-only protectors and using the safe boot option, then the recovery key will not be required. If you are using TPM+PIN protectors, then you may need the recovery key if you do not know the PIN for the device.

    Using Recovery from WinPE media

    1. Insert the USB key into an impacted device.
    2. Reboot the device.
    3. During restart, press F12 (or follow manufacturer-specific instructions for booting to BIOS).
    4. From the BIOS boot menu, choose Boot from USB and continue.
    5. The tool will run.
    6. If BitLocker is enabled, the user will be prompted for the BitLocker recovery key including the dashes. The recovery key options are provided here. For third-party device encryption solutions, follow any steps provided by the vendor to gain access to the drive.
    7. The tool will run the issue-remediation scripts as recommended by CrowdStrike.
    8. Once complete, remove the USB drive and reboot the device normally.

    Using Safe Boot media
    To repair an impacted device without using the BitLocker recovery key and if you have access to the local administrator account:

    1. Insert the USB key into an impacted device.
    2. Reboot the device.
    3. During restart, press F12 (or follow manufacturer-specific instructions for booting to BIOS).
    4. From the BIOS boot menu, choose Boot from USB and continue.
    5. The tool runs.
    6. The following message appears: "This tool will configure this machine to boot in safe mode. WARNING: In some cases you may need to enter a BitLocker recovery key after running."
    7. Press any key to continue.
    8. The following message appears: "Your PC is configured to boot to Safe Mode now."
    9. Press any key to continue.
    10. The machine reboots into safe mode.
    11. The user runs repair.cmd from the root of the media/USB drive. The script will run the remediation steps as recommended by CrowdStrike.
    12. The following message appears: "This tool will remove impacted files and restore normal boot configuration. WARNING: You may need BitLocker recovery key in some cases. WARNING: This script must be run in an elevated command prompt."
    13. Press any key to continue.
    14. The user repair will run and the normal boot flow will be restored.
    15. Once successful, the user will see the following message: “Success. System will now reboot.”
    16. Press any key to continue. The device will reboot normally.
    1 person found this answer helpful.
    0 comments No comments
  3. DaveM121 871.3K Reputation points Independent Advisor
    2024-07-19T07:09:28+00:00

    Hi, I am Dave, I will help you with this.

    Please check to see if your PC is producing any minidump files, I will check those to see if they provide any insight into a potential cause of the system crashes.

    Open Windows File Explorer.

    Navigate to C:\Windows\Minidump

    Copy any minidump files onto your Desktop, then zip those up.

    Upload the zip file to the Cloud (OneDrive, DropBox... etc.), then choose to share those and get a share link.

    Then post the link here to the zip file, so we can take a look for you.

    1 person found this answer helpful.
    0 comments No comments