<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cyvrtrap.dll causing spoolsv.exe crashes? in Cortex XDR Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594152#M7038</link>
    <description>&lt;P&gt;We've got 20 (nearly identically configured WS2019 VMs where print spooler service needs to run, and where if it crashes, users usually call to let us - the IT helpdesk - know). That - in addition to a bunch of other servers that need to print and where Cortex XDR is running - yet we're only seeing the adverse impact on those specific LoB servers.&lt;/P&gt;
&lt;P&gt;Some notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The default print spooler service configuration is to auto-restart twice on a crash&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kindzma_0-1722955701646.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61358i6BD31D11B0823386/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kindzma_0-1722955701646.png" alt="kindzma_0-1722955701646.png" /&gt;&lt;/span&gt;
&lt;P&gt;... which means not all crashes will get noticed - at least in our env - only ones that fail to start after 2 retries.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;After we updated Cortex XDR to 8.5 across the board (200+ servers and workstations or so), the only immediate adverse impact (crashed print spoolers) was on those specific types of servers, and then - not all of them - about 5 initially, with 5 more joining the party a week later. We still have about 10 of them with Cortex XDR 8.5 that do not exhibit any crashes, and don't have those application errors mentioning both&amp;nbsp;cyvrtrap.dll and spoolsv.exe. (I know, a mystery.&amp;nbsp;&lt;SPAN&gt;🤷)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;When downgraded to 8.4, there may be &lt;EM&gt;one&lt;/EM&gt; application error like the above - yet the service recovers if it's configured to auto-retry, and then the errors seem to go away. I.e. so far (knock on wood) 8.4 fixes the issue.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
    <pubDate>Tue, 06 Aug 2024 15:06:47 GMT</pubDate>
    <dc:creator>kindzma</dc:creator>
    <dc:date>2024-08-06T15:06:47Z</dc:date>
    <item>
      <title>cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594034#M7029</link>
      <description>&lt;P&gt;We updated Cortex XDR agent on a number of VMs and on some of them the Print Spooler service (spoolsv.exe) started crashing repeatedly, causing disruptions to operations.&lt;/P&gt;
&lt;P&gt;Is this a known issue? Are there available workarounds or ways to resolve it short of downgrading the agent?&lt;/P&gt;
&lt;P&gt;Sample events:&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;LI-CODE lang="markup"&gt;Log Name:      Application
Source:        Application Error
Date:          7/31/2024 7:59:28 AM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      V******a.*****.COM
Description:
Faulting application name: spoolsv.exe, version: 10.0.17763.4644, time stamp: 0xacbcf874
Faulting module name: cyvrtrap.dll, version: 8.5.0.624, time stamp: 0x667afdda
Exception code: 0xc0000005
Fault offset: 0x00000000000175d1
Faulting process id: 0xf28
Faulting application start time: 0x01dae2a0fe85bd33
Faulting application path: C:\Windows\System32\spoolsv.exe
Faulting module path: C:\Windows\System32\cyvrtrap.dll
Report Id: 8a26e6e7-e8e7-4dc9-9cdb-dce6c0798d81
Faulting package full name: 
Faulting package-relative application ID: &lt;/LI-CODE&gt;&lt;LI-CODE lang="markup"&gt;Log Name:      Application
Source:        Application Error
Date:          8/1/2024 7:29:24 AM
Event ID:      1000
Task Category: (100)
Level:         Error
Keywords:      Classic
User:          N/A
Computer:      V****a.****.COM
Description:
Faulting application name: spoolsv.exe, version: 10.0.17763.4644, time stamp: 0xacbcf874
Faulting module name: cyvrtrap.dll, version: 8.4.0.51691, time stamp: 0x667afdda
Exception code: 0xc0000005
Fault offset: 0x00000000000175d1
Faulting process id: 0x2f50
Faulting application start time: 0x01dae35a42e79f3d
Faulting application path: C:\Windows\System32\spoolsv.exe
Faulting module path: C:\Windows\System32\cyvrtrap.dll
Report Id: 90dc4222-bee6-42fd-a6a7-5c4f076c9e99
Faulting package full name: 
Faulting package-relative application ID: &lt;/LI-CODE&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;P.S. Downgrading from 8.5 to 8.4 seems to help but does not completely eliminate the crashes.&lt;/P&gt;
&lt;P&gt;The version prior to 8.4 and 8.5 was 8.2 or lower - and that one didn't seem to cause these crashes at all.&lt;/P&gt;
&lt;P&gt;The host OS is WS2019.&lt;/P&gt;
&lt;P&gt;Thank you!&lt;/P&gt;</description>
      <pubDate>Mon, 05 Aug 2024 18:54:35 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594034#M7029</guid>
      <dc:creator>kindzma</dc:creator>
      <dc:date>2024-08-05T18:54:35Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594076#M7030</link>
      <description>&lt;P&gt;Hi&amp;nbsp;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/301505"&gt;@kindzma&lt;/a&gt;&amp;nbsp;,&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Seems this was reported by another customer on another thread as well and its recommended to open a case with the support team.&lt;/P&gt;
&lt;P&gt;Link to discussion:&amp;nbsp;&lt;A href="https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-8-5-0-print-servers-error/td-p/593625" target="_blank"&gt;https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/xdr-8-5-0-print-servers-error/td-p/593625&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 02:21:00 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594076#M7030</guid>
      <dc:creator>neelrohit</dc:creator>
      <dc:date>2024-08-06T02:21:00Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594111#M7033</link>
      <description>&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I've encountered the same issue, but in my case, I have 15 print servers, and the problem appears on all of them when upgrading to version 8.5.0.&lt;/P&gt;
&lt;P&gt;When I downgrade to version 8.4.0, everything works fine.&lt;/P&gt;
&lt;P&gt;Today, a Cortex system crash occurred on a print server (Version 8.4.0.51691, Content Version 1430-86494).&lt;/P&gt;
&lt;P&gt;&lt;BR /&gt;At this moment, my question is whether the problem might be related to the content version rather than the agent version, since the content version is the same in both versions.&lt;BR /&gt;&lt;BR /&gt;&lt;/P&gt;
&lt;P&gt;My HostOS is W2022&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 10:01:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594111#M7033</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-08-06T10:01:21Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594114#M7034</link>
      <description>&lt;P&gt;With agent release 8.5 and 3.11, we have an option in device configuration profile to control print jobs in the environment. Try to check if it is enabled..if it is then disable that and see if it solves the issue. See the release notes accordingly.&lt;/P&gt;
&lt;P&gt;Capability should not crash the service generally but check with support if it is the root cause.&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 10:43:46 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594114#M7034</guid>
      <dc:creator>Fm12345</dc:creator>
      <dc:date>2024-08-06T10:43:46Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594121#M7037</link>
      <description>&lt;P&gt;Yes, but by default, this is disabled. To enable it, you need to assign an Extensions Profile with the required settings.&lt;/P&gt;
&lt;P&gt;In my case, I don't use Extensions Profiles and the problem persists.&lt;/P&gt;
&lt;P&gt;I've opened a case, and support advised me to disable the Logical Exploits Protection module in the respective Exploit Profile.&lt;/P&gt;
&lt;P&gt;&lt;SPAN&gt;&amp;nbsp;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 06 Aug 2024 11:33:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594121#M7037</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-08-06T11:33:13Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594152#M7038</link>
      <description>&lt;P&gt;We've got 20 (nearly identically configured WS2019 VMs where print spooler service needs to run, and where if it crashes, users usually call to let us - the IT helpdesk - know). That - in addition to a bunch of other servers that need to print and where Cortex XDR is running - yet we're only seeing the adverse impact on those specific LoB servers.&lt;/P&gt;
&lt;P&gt;Some notes:&lt;/P&gt;
&lt;UL&gt;
&lt;LI&gt;The default print spooler service configuration is to auto-restart twice on a crash&lt;BR /&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="kindzma_0-1722955701646.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/61358i6BD31D11B0823386/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="kindzma_0-1722955701646.png" alt="kindzma_0-1722955701646.png" /&gt;&lt;/span&gt;
&lt;P&gt;... which means not all crashes will get noticed - at least in our env - only ones that fail to start after 2 retries.&lt;/P&gt;
&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;After we updated Cortex XDR to 8.5 across the board (200+ servers and workstations or so), the only immediate adverse impact (crashed print spoolers) was on those specific types of servers, and then - not all of them - about 5 initially, with 5 more joining the party a week later. We still have about 10 of them with Cortex XDR 8.5 that do not exhibit any crashes, and don't have those application errors mentioning both&amp;nbsp;cyvrtrap.dll and spoolsv.exe. (I know, a mystery.&amp;nbsp;&lt;SPAN&gt;🤷)&lt;/SPAN&gt;&lt;/SPAN&gt;&lt;/LI&gt;
&lt;LI&gt;&lt;SPAN&gt;When downgraded to 8.4, there may be &lt;EM&gt;one&lt;/EM&gt; application error like the above - yet the service recovers if it's configured to auto-retry, and then the errors seem to go away. I.e. so far (knock on wood) 8.4 fixes the issue.&lt;/SPAN&gt;&lt;/LI&gt;
&lt;/UL&gt;</description>
      <pubDate>Tue, 06 Aug 2024 15:06:47 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594152#M7038</guid>
      <dc:creator>kindzma</dc:creator>
      <dc:date>2024-08-06T15:06:47Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594400#M7048</link>
      <description>&lt;P&gt;I've 6500 devices with 8.5...only print servers have the issue when upgrade to version 8.5.0.&lt;BR /&gt;&lt;BR /&gt;But another mystery, I've one server on lab, with 8.5.0 and disable exploit module, and problem disappear...right know my question for support is, what is the root cause ...because i don't see any alert or incident??&lt;/P&gt;</description>
      <pubDate>Thu, 08 Aug 2024 17:06:59 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/594400#M7048</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-08-08T17:06:59Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/596560#M7135</link>
      <description>&lt;P&gt;solutions is "&lt;SPAN class="ng-star-inserted"&gt;Disable PrintMonitor for the Windows Spooler service" exploit module.&lt;BR /&gt;&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Mon, 02 Sep 2024 16:38:42 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/596560#M7135</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-09-02T16:38:42Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/596561#M7136</link>
      <description>&lt;P&gt;... or downgrade to 8.4? ("Downgrading" isn't quite the right term as it seems to require a full re-install of the XDR agent?)&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;Is there a doc on how to do this?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;BLOCKQUOTE&gt;&lt;HR /&gt;&lt;a href="https://live.paloaltonetworks.com/t5/user/viewprofilepage/user-id/307134"&gt;@tlmarques&lt;/a&gt;&amp;nbsp;wrote:&lt;BR /&gt;
&lt;P&gt;solutions is "&lt;SPAN class="ng-star-inserted"&gt;Disable PrintMonitor for the Windows Spooler service" exploit module.&lt;BR /&gt;&lt;/SPAN&gt;&lt;/P&gt;
&lt;HR /&gt;&lt;/BLOCKQUOTE&gt;</description>
      <pubDate>Mon, 02 Sep 2024 18:36:31 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/596561#M7136</guid>
      <dc:creator>kindzma</dc:creator>
      <dc:date>2024-09-02T18:36:31Z</dc:date>
    </item>
    <item>
      <title>Re: cyvrtrap.dll causing spoolsv.exe crashes?</title>
      <link>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/596646#M7138</link>
      <description>&lt;P&gt;Yes, there's no downgrade option in XDR... The only option is to remove the agent (uninstall) via the tenant and then install version 8.4.&lt;BR /&gt;&lt;BR /&gt;to do exception, import the json file and insert the same on rules...&lt;BR /&gt;&lt;BR /&gt;&lt;A href="https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Support-Exception-Rule" target="_blank"&gt;https://docs-cortex.paloaltonetworks.com/r/Cortex-XDR/Cortex-XDR-Pro-Administrator-Guide/Add-a-Support-Exception-Rule&lt;/A&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 03 Sep 2024 19:40:28 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/cortex-xdr-discussions/cyvrtrap-dll-causing-spoolsv-exe-crashes/m-p/596646#M7138</guid>
      <dc:creator>tlmarques</dc:creator>
      <dc:date>2024-09-03T19:40:28Z</dc:date>
    </item>
  </channel>
</rss>

