Threat Report: Exposing Malware in Linux-Based Multi-Cloud Environments | Download Now

VMware vShield Endpoint driver (vsepflt) interoperability with Bit9 agent

VMware vShield Endpoint driver (vsepflt) interoperability with Bit9 agent

Version

All.

 

Issue

Virtual machine hangs after installing Bit9 Agent.

 

Symptoms

The virtual machine hangs. Parity Agent service memory usage spikes up to 100%. The virtual machine is inaccessible via remote desktop, but it is still responding to ping.

 

Cause

VMware vShield Endpoint driver (vsepflt) is causing system deadlock in the presence of other filter drivers like Bit9’s Parity Driver. The vShield driver also locks the call that Bit9 makes when trying to normalize file path.

 

Solution

Disable the vShield driver in an elevated command prompt:

sc config vsepflt start= disabled

Labels (1)
Was this article helpful? Yes No
No ratings
Article Information
Author:
Creation Date:
‎11-20-2014
Views:
1651
Contributors