<?xml version="1.0" encoding="UTF-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:rdf="http://www.w3.org/1999/02/22-rdf-syntax-ns#" xmlns:taxo="http://purl.org/rss/1.0/modules/taxonomy/" version="2.0">
  <channel>
    <title>topic Re: cytray.exe  &amp;quot;bad image&amp;quot; errors following Agent update in Advanced Threat Prevention Discussions</title>
    <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579307#M2111</link>
    <description>&lt;P&gt;Seems we are reliant on Palo Alto to help with this. Response from Parallels - "This issue is unrelated to the Parallels RAS issue, so we suggest reaching out to Palo Alto support for further clarification and assistance."&lt;/P&gt;</description>
    <pubDate>Tue, 05 Mar 2024 14:44:26 GMT</pubDate>
    <dc:creator>AndyHartwell</dc:creator>
    <dc:date>2024-03-05T14:44:26Z</dc:date>
    <item>
      <title>cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579085#M2104</link>
      <description>&lt;P&gt;Following the Cortex XDR Windows agent update to 8.3.0.49434 we started to see the following error affecting some application DLLs.&lt;/P&gt;
&lt;P&gt;Clicking Ok makes the message go away and the application keeps working. TAC case was logged and an temporary Support Exception was added and applied to some affected hosts. This seemed to stop the error.&lt;/P&gt;
&lt;P&gt;Wondering if anyone else is experiencing the same or similar issue? This affects approx. 2 DLLs on two separate applications of ours. I'd like to see a fix come in the form of an update to the Cortex XDR client, as applying a temporary support exception doesn't seem like a viable long term solution.&lt;/P&gt;</description>
      <pubDate>Sun, 03 Mar 2024 23:11:18 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579085#M2104</guid>
      <dc:creator>cskoien</dc:creator>
      <dc:date>2024-03-03T23:11:18Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579090#M2105</link>
      <description>&lt;P&gt;We see same issue in several customer's environments. As far as I know, PAN will plan to fix the issue within 8.3.1 and 8.4.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 02:19:56 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579090#M2105</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2024-03-04T02:19:56Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579135#M2106</link>
      <description>&lt;P&gt;Same issues here, with a specific application (Parallels)&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 12:36:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579135#M2106</guid>
      <dc:creator>Gerry_Fahy</dc:creator>
      <dc:date>2024-03-04T12:36:44Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579208#M2108</link>
      <description>&lt;P&gt;Information from TAC:&lt;/P&gt;
&lt;P&gt;"This is caused by a new feature enabled in 8.3, where we check the signature level of every DLL loaded into cytray.exe. The application's DLL must be unsigned or with a lower trusted level, which will result in the DLL being blocked by us and this pop-up to show. hence we have provided the SUEX to disable the feature.&lt;BR /&gt;&lt;BR /&gt;At the moment the engineering team does not consider this issue as an actual bug inside the product, but rather a by-design behavior.&lt;BR /&gt;&lt;BR /&gt;I would like to inform you that it might be fixed in the upcoming version of the XDR Agent, but we do not have an ETA for this."&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;I'd argue that its a bug. Its not an error handled by cytray.exe. Windows is throwing an error due to the action.&lt;/P&gt;</description>
      <pubDate>Mon, 04 Mar 2024 23:05:21 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579208#M2108</guid>
      <dc:creator>cskoien</dc:creator>
      <dc:date>2024-03-04T23:05:21Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579297#M2109</link>
      <description>&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AndyHartwell_0-1709642134320.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58056iC12415A7E7D11ECC/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AndyHartwell_0-1709642134320.png" alt="AndyHartwell_0-1709642134320.png" /&gt;&lt;/span&gt;&amp;nbsp; &amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="AndyHartwell_1-1709642200546.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58057iFC7757745AE6E3C2/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="AndyHartwell_1-1709642200546.png" alt="AndyHartwell_1-1709642200546.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;We are also having problems with Parallels RAS.&amp;nbsp; The DLL Cytray is complaining about appears to be signed OK.&lt;/P&gt;
&lt;P&gt;Interested to hear how you work around this. Parallels seem to think it is not a problem for them to fix.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 12:38:58 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579297#M2109</guid>
      <dc:creator>AndyHartwell</dc:creator>
      <dc:date>2024-03-05T12:38:58Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579298#M2110</link>
      <description>&lt;P&gt;I raised an issue with support and they applied a test exception profile in Cortex dashboard. However, I'm still seeing this issue on some machines even though the exception has been applied.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 12:43:36 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579298#M2110</guid>
      <dc:creator>Gerry_Fahy</dc:creator>
      <dc:date>2024-03-05T12:43:36Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579307#M2111</link>
      <description>&lt;P&gt;Seems we are reliant on Palo Alto to help with this. Response from Parallels - "This issue is unrelated to the Parallels RAS issue, so we suggest reaching out to Palo Alto support for further clarification and assistance."&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 14:44:26 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579307#M2111</guid>
      <dc:creator>AndyHartwell</dc:creator>
      <dc:date>2024-03-05T14:44:26Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579313#M2112</link>
      <description>&lt;P&gt;Do you think its worth compiling a list of applications that we believe to be affected ?&amp;nbsp; At the moment PaloAlto don't seem to be at all interested but that may change if a long list of applications that they have broken were put together ?&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 15:33:39 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579313#M2112</guid>
      <dc:creator>AndyHartwell</dc:creator>
      <dc:date>2024-03-05T15:33:39Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579374#M2113</link>
      <description>&lt;P&gt;Andy - The statement I got from Palo was "This is caused by a new feature enabled in 8.3, where we check the signature level of every DLL loaded into cytray.exe. The application's DLL must be unsigned or with a lower trusted level, which will result in the DLL being blocked by us and this pop-up to show. hence we have provided the SUEX to disable the feature."&lt;BR /&gt;&lt;BR /&gt;I agree in that its not a problem for Parallels to fix. If its a feature of Cortex XDR then there should be some alerting/incidents relating to the block in the console, but there is nothing. Blanket disabling a newly introduced feature is not a solution.&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 22:46:06 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579374#M2113</guid>
      <dc:creator>cskoien</dc:creator>
      <dc:date>2024-03-05T22:46:06Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579375#M2114</link>
      <description>&lt;P&gt;Andy - I am waiting to hear back today with further information. I'm receiving mixed messages on whether Palo Alto plan to fix it in the next agent release. One response stated "late March" but had not firm release timeline.&lt;/P&gt;</description>
      <pubDate>Tue, 05 Mar 2024 22:48:41 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579375#M2114</guid>
      <dc:creator>cskoien</dc:creator>
      <dc:date>2024-03-05T22:48:41Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579469#M2115</link>
      <description>&lt;P&gt;Same here with DLL belonging to Teamviewer:&amp;nbsp;"C:\Program Files (x86)\TeamViewer\tv_x64.dll"&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 14:30:01 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579469#M2115</guid>
      <dc:creator>Jurriaan</dc:creator>
      <dc:date>2024-03-06T14:30:01Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579538#M2116</link>
      <description>&lt;P&gt;Received confirmation that this issue will be resolved in the next release of the agent, tentative release date being late March 2024.&lt;/P&gt;</description>
      <pubDate>Wed, 06 Mar 2024 23:51:13 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579538#M2116</guid>
      <dc:creator>cskoien</dc:creator>
      <dc:date>2024-03-06T23:51:13Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579547#M2117</link>
      <description>&lt;P&gt;Yes,it's not a good solution.&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 01:09:50 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579547#M2117</guid>
      <dc:creator>huangyz</dc:creator>
      <dc:date>2024-03-07T01:09:50Z</dc:date>
    </item>
    <item>
      <title>Betreff: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579573#M2120</link>
      <description>&lt;P&gt;Hello,&lt;/P&gt;
&lt;P&gt; ZoomText&amp;nbsp;&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="Screenshot 2024-03-07 075638.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58130i1E010BFA901E3F29/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="Screenshot 2024-03-07 075638.png" alt="Screenshot 2024-03-07 075638.png" /&gt;&lt;/span&gt;&lt;/P&gt;</description>
      <pubDate>Thu, 07 Mar 2024 07:26:08 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579573#M2120</guid>
      <dc:creator>StephanRuediger</dc:creator>
      <dc:date>2024-03-07T07:26:08Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579811#M2121</link>
      <description>&lt;P&gt;Not an issue my a$$ .. Ever since 8.3.0 we get multiple alerts from a monitoring software that the Cortex XDR service has stopped. Digging into PC's and laptop's event logs, it appears it's cysvc.dll itself which is crashing; we see the same event log entry in all the the computers which reported the issue.&lt;/P&gt;
&lt;P&gt;&lt;span class="lia-inline-image-display-wrapper lia-image-align-inline" image-alt="DovToren_0-1709918634451.png" style="width: 400px;"&gt;&lt;img src="https://live.paloaltonetworks.com/t5/image/serverpage/image-id/58174i55F2C3D236819E05/image-size/medium/is-moderation-mode/true?v=v2&amp;amp;px=400" role="button" title="DovToren_0-1709918634451.png" alt="DovToren_0-1709918634451.png" /&gt;&lt;/span&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;</description>
      <pubDate>Fri, 08 Mar 2024 17:28:51 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/579811#M2121</guid>
      <dc:creator>DovToren</dc:creator>
      <dc:date>2024-03-08T17:28:51Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580069#M2122</link>
      <description>&lt;P&gt;Would you know where one would obtain this "&lt;SPAN&gt;SUEX&amp;nbsp;"?&lt;BR /&gt;&lt;BR /&gt;Cheers&lt;BR /&gt;jc&lt;/SPAN&gt;&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 13:40:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580069#M2122</guid>
      <dc:creator>JLamb17</dc:creator>
      <dc:date>2024-03-12T13:40:24Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580079#M2123</link>
      <description>&lt;P&gt;1) On effected machines, downgraded from 8.3.0 to 8.2.1&lt;/P&gt;
&lt;P&gt;2) In CortexXDR Console created a policy preventing agent to be upgraded&lt;/P&gt;
&lt;P&gt;3) Added effected machines to the policy&lt;/P&gt;
&lt;P&gt;No more annoying popups. Waiting for new version.&lt;/P&gt;</description>
      <pubDate>Tue, 12 Mar 2024 15:36:48 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580079#M2123</guid>
      <dc:creator>Jurriaan</dc:creator>
      <dc:date>2024-03-12T15:36:48Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580709#M2126</link>
      <description>&lt;P&gt;&lt;A href="https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008XKOCA2" target="_blank"&gt;https://knowledgebase.paloaltonetworks.com/KCSArticleDetail?id=kA14u0000008XKOCA2&lt;/A&gt;&lt;/P&gt;
&lt;P&gt;&amp;nbsp;&lt;/P&gt;
&lt;P&gt;FYI : The new KB posted which related to this issue.&lt;/P&gt;</description>
      <pubDate>Mon, 18 Mar 2024 05:15:44 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580709#M2126</guid>
      <dc:creator>emr_1</dc:creator>
      <dc:date>2024-03-18T05:15:44Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580942#M2130</link>
      <description>&lt;P&gt;The PAN article says:&lt;/P&gt;
&lt;OL&gt;
&lt;LI&gt;To resolve the issue, please whitelist Cortex XDR Agent process on the affected 3rd party application to disable injection into Cortex XDR Agent process.&lt;/LI&gt;
&lt;/OL&gt;
&lt;P&gt;But no indication is given how to do that, so it is not helpful.&lt;/P&gt;</description>
      <pubDate>Tue, 19 Mar 2024 18:06:45 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/580942#M2130</guid>
      <dc:creator>LCMember40912</dc:creator>
      <dc:date>2024-03-19T18:06:45Z</dc:date>
    </item>
    <item>
      <title>Re: cytray.exe  "bad image" errors following Agent update</title>
      <link>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/581030#M2131</link>
      <description>&lt;P&gt;The whitelisting workaround works if there is a security product injecting DLLs in Cortex processes. But in case it is for example TeamViewer or another software's DLL, this is unfeasible because they do not have a whitelist to configure.&lt;/P&gt;</description>
      <pubDate>Wed, 20 Mar 2024 11:43:24 GMT</pubDate>
      <guid>https://live.paloaltonetworks.com/t5/advanced-threat-prevention/cytray-exe-quot-bad-image-quot-errors-following-agent-update/m-p/581030#M2131</guid>
      <dc:creator>GrazianoG</dc:creator>
      <dc:date>2024-03-20T11:43:24Z</dc:date>
    </item>
  </channel>
</rss>

