Hapat e Recovery per Windows:
- Boot system in Safe Mode or Windows Recovery Environment
- Got to: C:\Windows\System32\drivers\CrowdStrike directory
- Locate the file matching “C-00000291*.sys”, and delete it or rename it “C-00000291*.bak”
- Boot host machine
Hapat per Server Virtual (Mund te perdoret dhe procedura me siper ose si me poshte:
- Detach OS disk volume from impacted server.
- For your security make a backup/copy of this disk.
- Attach/mount this disk to a working server.
- Got to: C:\Windows\System32\drivers\CrowdStrike directory.
- Locate the file matching “C-00000291*.sys”, and delete it or rename it “C-00000291*.bak”
- Detach volume from working server.
- Reattach fixed disk volume to impacted virtual server.
Nese BitLocker eshte aktiv:
Ne opsionin e pare me siper mund te hiqet disk dhe te behet attach ne nje kompjuter tjeter.
Per serverat mund te perdoret opsioni i 2-te.
*** Ne te 2 rastet duhet patjeter te keni backup te bitlocker recovery key***