Unable to disable CRL checking via configuration xml once it has been enabled
Once CRL checking has been enabled, you can only disable CRL checking through reinstall or by configuration reset via hidden "sysmon -c --" command. Please add support to explicitly disable CRL checking via the CheckRevocation flag in…
What is the HLK package for certifying eMMC storage device for Windows 10
Hi, What is the HLK package for certifying eMMC storage device for Windows 10. Server : Windows 10 2012 ServerR2 Client: Windows10 20H1 Media for test : eMMC storage device Thanks
System State backup fails in Windows server 2019
Windws Server backup log: Error in deletion of [C:\Sysmon] while pruning the target VHD: Error [0x80070020] The process cannot access the file because it is being used by another process. The backup succeeds a few times (3-4) and then fails. If i…
Error Message sending bug report to syssite@microsoft.com
For everyone that received an error sending an email to SYSSITE@MICROSOFT.COM these days, like The problem has been solved. You can send your bug report or change request to that address as before. Thanks -mario
Sysinternals Date Stamp file updates
Hello, Would it be possible to keep the date stamp file, found at https://live.sysinternals.com/, updated. Above link shows Autoruns with date stamp of: Monday, April 6, 2020 4:39 AM 755576 Autoruns.exe However, Autoruns specific web page…
Process Explorer (16.32) terminates on Windows 10
On my Windows 10 64bit system (10.0.19041) I'm encountering difficulties runing Sysinsternals ProcessExplorer (16.32). No matter if I run procexp.exe or procexp64.exe both applications are terminating after a few seconds. I can see only the UI shortly…
How to verify the integrity of Windows/Sysinternals tools
Hi, Does Microsoft publish checksum values for Windows/Sysinternals tools? I want to verify the integrity after downloading. Thanks. Marcel
Autorunsc STILL cannot save .ARN
I found this archived post: https://social.technet.microsoft.com/Forums/windows/en-US/dbe40f1c-9b5b-4612-a9a2-2270f379c245/merge-supported-export-formats-for-autoruns-autorunsc?forum=autoruns while researching a problem I was having - I couldn't…
Process explorer cpu overview only shows 64 cores on a 96 cors machine!
Process explorer cpu overview only shows 64 cores on a 96 cors machine!
Isolate the error or issue in Windows troubleshooting
Hello, My question is how do I isolate whether issue exists in user account or in local user profile or in roaming user profile or in local machine while troubleshooting? Is there any Microsoft official or simple isolation technique to pinpoint the…
Bug in <Snapshot Time> field
It seems that I have found a "bug" in the BGInfo 4.28 Built 2019/9/19 program. The <Snapshot Time> field is only updated once (in fact, the first time) when you have making changes or modifications with the program open. Once all the…
Application performance Issues
Hi all Hope you lovely people can help. The problem We have an application called EROS which is supported by a company called IDOX, that used to take 4-5 mins to load, now is taking 30+mins to run. Also, when moving from field to field…
Error communicating with PsExec service on PC0236206
For the first time, I could able to run the application remotely using PsExec utility tool. A day after, the same application could not able to run remotely using PsExec Utility tool. Then i tried to get some answers and followed few steps sc.exe…
Autoruns broken rendering on HDPI screen
Autoruns, when started on my 4K screen zoomed at 200%, looks like this:
COM question, how to corelate a COM server(EXE) created by a client request.
I have a COM server(EXE) and when I access the object first time using CoCreateInstance/Ex the EXE starts running. However the parent for this process seems to be svchost.exe , not the client application that asked for the Object Activation. I verified…
ProcMon does not show executable
Hello, When executing ProcMon not all executables are showing up in the activity window. The executable I am interested in shows up in TaskMgr but not ProcMon. I've ensured all filters are off. Please advise. Thank you. Randall Princeton
Autoruns does not search for menu handlers in all locations
Hello. I came up with a problem with possibility to disable an explorer menu handler for one of my apps. The app is called "chomikbox" - here is the link do download: https://chomikuj.pl/chomikbox. It's an app to download files from…
How to troubleshoot interoperability issues using process monitor
How to troubleshoot interoperability issues using process monitor Issues such as, application (Edge, Chrome, Adobe, etc.) slow, application hung, when a security software is running. It works fine if the security software is disabled (security…
Sysmon 12.03 not logging EventID:2 (file creation time modified)
Hello, I just made a test with Sysmon 9.1.0 on a VM and I was able to get file creation time modification events. Upgrading to 12.03 with the same configuration allows to get all the other events except this one. Test was made using a ps1 script that…