Sysmon v9.01 shows up after uninstalling v15.14

Seth Anders 0 Reputation points
2024-06-27T18:47:17.3+00:00

Hello,

I am running into a bit of an issue and I can't find anymore information regarding it.

We have no more use for Sysmon on our network and I am working through uninstalling it from our Windows 10 devices.

After uninstalling v15.14 with the recommended steps (including -u, deleting the service reg keys, and deleting the actual objects in the windows folder) it is gone for about 30-40 minutes until I notice that sysmon has returned only its version 9.01. And after uninstalling that it just keeps reappearing every so often.

I looked in event viewer for any installation history happening after my uninstall and I can see the following

Event ID: 7045 A service was installed in the system. Service Name: Sysmon Service File Name: C:\windows\Sysmon.exe Service Type: user mode service Service Start Type: auto start Service Account: LocalSystem

I can see the same for sysmondrv.sys as well as Event ID 6 for the service registering with Filter Manager.

I should say, v9.01 was the old version before I upgraded to v15.14. Is there some sort of remnant files or services I am missing to delete from my old version? Why does this version of Sysmon keep reappearing even after a "scorched-earth" uninstall?

I have already looked at our policies applied to these workstations and to scheduled tasks as well as SCCM and I cannot find this version of sysmon pushing to machines, it just reappears on them for some reason, am I crazy or has this behavior been documented?

Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,984 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,116 questions
{count} votes

1 answer

Sort by: Most helpful
  1. Seth Anders 0 Reputation points
    2024-06-28T14:56:48.4666667+00:00

    Run Process Monitor and set a filter for "Path contains sysmon.exe". Also in the filter entries, uncheck the entry for "Process name is system (Exclude)". That should lead you to the process that is reinstalling it. Double click any event that it catches and in the Process tab, check the program and the command line that it was launched with. Also note the parent PID and see what that program is.

    Thanks so much. Found in Procmon.exe there was a CCM script somewhere that was calling to sysmon.exe in a central location, ".olded" it and I am looking for the script now. I appreciate the help!

    0 comments No comments