Endpoint Standard: "CrashDumpEnabled" Registry Configuration Changes on System Restart
book
Article ID: 290893
calendar_today
Updated On:
Products
Carbon Black Cloud Endpoint Standard (formerly Cb Defense)
Issue/Introduction
The value of key: HKLM\System\CurrentControlSet\Control\CrashControl\CrashDumpEnabled is being changed forcefully to "1" after a re-start when the value is being modified to "7".
If a change to "Write debugging information" is made in Backup and Recover advanced settings, a Windows reboot always results in that setting reverting to "Complete Memory Dump"
Environment
Endpoint Standard: All supported versions
Microsoft Windows: All supported versions
Cause
The above behaviour is by default so that if a crash occurs a dump is saved for diagnostic purposes.
Resolution
This setting can be disabled in 2 ways:
At the time of install by specifying AUTO_CONFIG_MEM_DUMP=0 on the msiexec command line
Post-install:
Put the sensor into Bypass mode
Edit C:\Program Files\Confer\cfg.ini file
Add the following:
ConfigureMemoryDumpSettings=0
Reboot the endpoint
Take the sensor out of bypass mode
Additional Information
Must also have the following setting enabled in the Windows Operating System taken from the related KB: https://community.carbonblack.com/t5/Knowledge-Base/Carbon-Black-Cloud-Pagefile-grows-when-3-4-0-1097-or-higher/ta-p/88627
Go to Advanced System Settings > Advanced > Startup & Recovery >Settings > Write Debug Info