DLP EDPA and WDP services crashing immediately
search cancel

DLP EDPA and WDP services crashing immediately

book

Article ID: 277582

calendar_today

Updated On:

Products

Data Loss Prevention Data Loss Prevention Endpoint Prevent

Issue/Introduction

You installed the DLP agent and both EDPA and WDP services are crashing immediately. In the EDPA logs you see the below information:

12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Network Connector
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Detection Post Processor
12/04/2023 09:57:32 | 71068 | WARNING | CoreServices.ProcessActivity | Failed to repair rtam driver binary. Error: Failed to repair driver binary, for driver: vrtam. CopyFile() failed with error: 32
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ProcessActivity | Agent Tamper Protection for registry is disabled
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ProcessActivity | RTAM driver version: 
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: RTAM Connector
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Message Service Logger
12/04/2023 09:57:32 | 71068 | INFO    | Discover.DiscoverController | There are no scan definitions in the discover database.
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Discover
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Agent Store Configuration Listener
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Browser Content Analyzer
12/04/2023 09:57:32 | 71068 | INFO    | Incidents.IncidentEvictor | Incident Evictor started successfully.
12/04/2023 09:57:32 | 71068 | INFO    | Incidents.TwoTierEvictor | Two Tier Evictor started successfully.
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Incident Handler
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: IE Connector
12/04/2023 09:57:32 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Hook Manager
12/04/2023 09:57:33 | 71068 | ADMIN   | AgentServices.SystemEventLogger | Category: agent_event.category.chrome_extension_status, SubCategory: agent_event.subcategory.chrome_extension_loaded, Extended Value: Successfully loaded
12/04/2023 09:57:33 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Chrome Connector
12/04/2023 09:57:33 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: UI Proxy
12/04/2023 09:57:33 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: System Resource Manager
12/04/2023 09:57:33 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Telemetry Collector
12/04/2023 09:57:33 | 71068 | INFO    | CoreServices.ComponentManager | Agent component started: Unexpected Error Handler
12/04/2023 09:57:33 | 71068 | WARNING | FileSystem.FileSystemConnector | Failed to repair filesystem driver binary. Error: Failed to repair driver binary, for driver: vfsmfd. CopyFile() failed with error: 32
12/04/2023 09:57:33 | 71068 | INFO    | FileSystem.FileSystemConnector | File System driver version: 16.0.10000.60135
12/04/2023 09:57:33 | 71068 | INFO    | FileSystem.DriverCommunication | File system driver communication port thread priority is THREAD_PRIORITY_ABOVE_NORMAL Number Of Listener Threads :1
12/04/2023 09:57:33 | 71068 | WARNING | FileSystem.ApplicationChecklist | Failed in getting explorer path (shell), err:2

Environment

15.X/16.0

Cause

The DLP agent is unable to initiate its drivers as it fails to determine the path to the Windows shell.

Resolution

Make sure that under HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon you have Shell (REG_SZ) entry in your registry. If missing, create it with explorer.exe as the Data value.