Hello,
I am running into a bit of an issue and I can't find anymore information regarding it.
We have no more use for Sysmon on our network and I am working through uninstalling it from our Windows 10 devices.
After uninstalling v15.14 with the recommended steps (including -u, deleting the service reg keys, and deleting the actual objects in the windows folder) it is gone for about 30-40 minutes until I notice that sysmon has returned only its version 9.01. And after uninstalling that it just keeps reappearing every so often.
I looked in event viewer for any installation history happening after my uninstall and I can see the following
Event ID: 7045
A service was installed in the system.
Service Name: Sysmon
Service File Name: C:\windows\Sysmon.exe
Service Type: user mode service
Service Start Type: auto start
Service Account: LocalSystem
I can see the same for sysmondrv.sys as well as Event ID 6 for the service registering with Filter Manager.
I should say, v9.01 was the old version before I upgraded to v15.14. Is there some sort of remnant files or services I am missing to delete from my old version? Why does this version of Sysmon keep reappearing even after a "scorched-earth" uninstall?
I have already looked at our policies applied to these workstations and to scheduled tasks as well as SCCM and I cannot find this version of sysmon pushing to machines, it just reappears on them for some reason, am I crazy or has this behavior been documented?