That's a really old Sysmon running there, v5.02. Just manually delete it and then switch to v15.0. Also look in the Registry under ControlSet001
:
- Remove the reference to the service and driver from the Registry:
-
Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Sysmon[64]
-
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Sysmon[64]
-
Computer\HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\SysmonDrv
-
Computer\HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\SysmonDrv
-
- Reboot and delete the binaries
C:\Windows\sysmon[64].exe
,C:\Windows\SysmonDrv.exe
. - Install the new v15.0 client which should work.