IMPORTANT ANNOUNCEMENT: On May 6, 2024, Carbon Black User eXchange (UeX) and Case Management will move to a new platform!
The Community will be in read-only mode starting April 19th, 7:00 AM PDT. Check out the blog post!
You will still be able to use the case portal to create and interact with your support cases until the transition, view more information here!

Endpoint Standard: Shadow Copy Service Hangs During Backup Process

Endpoint Standard: Shadow Copy Service Hangs During Backup Process

Environment

  • Carbon Black Cloud Sensor: Version 3.6.0.1897 and higher
  • Microsoft Windows: All Supported Versions
    • Shadow Copy Service

Symptoms

When Shadow Copy service is running may hang during backup

Cause

  • Sensor is hooking into VSS

Resolution

  • 3.6 fix released in sensor version 3.6.0.2127
  • The 3.7 version of the fix is in sensor version 3.7.0.1411

Additional Notes

Workaround until sensor upgrade is possible:
  1. Open C:\Windows\System32
  2. Copy and Paste svchost.exe to the same folder, rename the copy version to svchostswprv.exe
  3. Open regedit.exe (Registry Editor)
  4. Navigate to Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\swprv
  5. Edit the value of ImagePath to "%SystemRoot%\System32\svchostswprv.exe -k swprv"
  6. Log into the Carbon Black Cloud Console
  7. Navigate to the Policy in place for the affected Devices
  8. Add a Permission Rule with the following values
    Process/Applications at Path: **\System32\svchostswprv.exe
    Operation Attempt: Performs any API operation
    Action: Bypass
  9. Reboot the Device and run backup process to test function

Related Content


Was this article helpful? Yes No
67% helpful (2/3)
Article Information
Author:
Creation Date:
‎02-09-2021
Views:
1744
Contributors