<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: Cortex XDR block explorer.exe, network interfaces and other programs - PC (Windows) isn't usable in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510773#M2458</link>
    <description>&lt;P&gt;&lt;SPAN&gt;The customer made a lot of checks and tests and we've found the main cause.&amp;nbsp; O&lt;/SPAN&gt;&lt;SPAN&gt;n some of the affected clients (not all), there was an embedded antivirus/security agent installed, that the customer has disabled at the start of the PC's configuration (it was not possible to uninstall it).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And the issue has been solved &lt;/SPAN&gt;&lt;SPAN&gt;after a clean installation of the OS on the affected endpoint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The customer was also able to find a way to uninstall the software causing this issue, and after removing it the problems did not show up again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;It is a very odd thing, as we didn't find any log or entry that explains it.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;And the strangest thing is that it didn't occur on all the clients that had the agent installed.&lt;BR /&gt;&lt;BR /&gt;Thank you for your help!&lt;/SPAN&gt;&lt;/P&gt;</description>
    <pubDate>Thu, 04 Aug 2022 13:08:36 GMT</pubDate>
    <dc:creator>A_Adamski</dc:creator>
    <dc:date>2022-08-04T13:08:36Z</dc:date>
    <item>
      <title>Cortex XDR block explorer.exe, network interfaces and other programs - PC (Windows) isn't usable</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510715#M2450</link>
      <description>&lt;P&gt;Dear Live Community Members,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I have an issue and I'm struggling to find the reason behind it&amp;nbsp;and need your help.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;To give you some background on the problem at hand, my customer&amp;nbsp;installed the Cortex XDR agent, and it works fine on some machines but on others when the installation process finished the problem occurred immediately and the &lt;STRONG&gt;PC is unusable&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Explorer stops working and the user is not able to do anything, he can use only the mouse but can't open any folders.&lt;/P&gt;
&lt;P&gt;It also looks like the taskbar doesn't work, and if the user uses the keyboard's shortcut he's able to "navigate" in the file explorer or open the control panel and things like&amp;nbsp;that.&lt;/P&gt;
&lt;P&gt;We were also able to use the PC with the shortcut to do RDP on other computers and use some applications. But the ethernet NIC is like uninstalled and is not visible under the device manager&amp;nbsp;or the network snap-in.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;And during tests issue seems to be related to Cortex XDR, as after we uninstall the agent on the affected endpoint the problems disappear.&lt;BR /&gt;The problems don't appear on all clients, and the customer doesn't have particular policies applied to these groups, he is blocking the USB devices but all other policies are at their default values.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;This issue affects the &lt;STRONG&gt;Cortex XDR Prevent&lt;/STRONG&gt;, versions &lt;STRONG&gt;7.7.1.62043&lt;/STRONG&gt; to&amp;nbsp;&lt;STRONG&gt;7.7.2.1822&lt;/STRONG&gt;, and all the&amp;nbsp;clients are on &lt;STRONG&gt;Windows 10 PRO 21H2&lt;/STRONG&gt; or higher. And all the clients&amp;nbsp;are &lt;STRONG&gt;HP's notebooks&lt;/STRONG&gt;.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;After checking the logs I could see that the user was removing the Sophos Anti-Virus prior to installing Cortex XDR, but can't see anything suspicious with the installation and why this issue occurs.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Windows Installer installed the product. Product Name: Cortex XDR 7.7.2.1822. Product Version: 7.7.2.1822. Product Language: 1033. Manufacturer: Palo Alto Networks, Inc.. Installation success or error status: 0.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;Updated Cortex XDR™ Advanced Endpoint Protection status successfully to SECURITY_PRODUCT_STATE_ON.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've also found an older entry in the logs for&lt;STRONG&gt; TrapsV2&lt;/STRONG&gt;:&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The description for Event ID 93 from source TrapsV2 cannot be found. Either the component that raises this event is not installed on your local computer or the installation is corrupted. You can install or repair the component on the local computer.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;If the event originated on another computer, the display information had to be saved with the event.&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;STRONG&gt;The following information was included with the event:&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;STRONG&gt;The message resource is present but the message was not found in the message table&lt;/STRONG&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;--------------------------------------------------------------------------------------------------------------------------------------------------------------------------&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;I'm leaning forward to issues with the Windows, and I'm wondering if you maybe have&amp;nbsp;some ideas.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;Could it be that there are still some reminiscences of an old Traps installation on the endpoint (or any other security app) causing these issues?&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;Did anyone have a similar issue and could help out?&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;BR /&gt;I will appreciate your help and any hints will be welcome to solve this issue.&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;Thank you in advance!&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 17:02:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510715#M2450</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2022-08-03T17:02:50Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR block explorer.exe, network interfaces and other programs - PC (Windows) isn't usable</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510716#M2451</link>
      <description>&lt;P&gt;Hi A_Adamski,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Please open a TAC case via the Customer Support Portal for assistance on this issue.&lt;/P&gt;</description>
      <pubDate>Wed, 03 Aug 2022 17:07:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510716#M2451</guid>
      <dc:creator>afurze</dc:creator>
      <dc:date>2022-08-03T17:07:13Z</dc:date>
    </item>
    <item>
      <title>Re: Cortex XDR block explorer.exe, network interfaces and other programs - PC (Windows) isn't usable</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510773#M2458</link>
      <description>&lt;P&gt;&lt;SPAN&gt;The customer made a lot of checks and tests and we've found the main cause.&amp;nbsp; O&lt;/SPAN&gt;&lt;SPAN&gt;n some of the affected clients (not all), there was an embedded antivirus/security agent installed, that the customer has disabled at the start of the PC's configuration (it was not possible to uninstall it).&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;And the issue has been solved &lt;/SPAN&gt;&lt;SPAN&gt;after a clean installation of the OS on the affected endpoint.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;The customer was also able to find a way to uninstall the software causing this issue, and after removing it the problems did not show up again.&lt;/SPAN&gt;&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;&lt;SPAN&gt;It is a very odd thing, as we didn't find any log or entry that explains it.&amp;nbsp;&lt;/SPAN&gt;&lt;SPAN&gt;And the strangest thing is that it didn't occur on all the clients that had the agent installed.&lt;BR /&gt;&lt;BR /&gt;Thank you for your help!&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 04 Aug 2022 13:08:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cortex-xdr-block-explorer-exe-network-interfaces-and-other/m-p/510773#M2458</guid>
      <dc:creator>A_Adamski</dc:creator>
      <dc:date>2022-08-04T13:08:36Z</dc:date>
    </item>
  </channel>
</rss>

