Microsoft Q&A

Windows Sysinternals

873 questions

A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.

Browse all Windows tags

873 questions with Windows Sysinternals tags

Sort by: Updated
1 answer One of the answers was accepted by the question author.

I would like to virtualise an install on Windows 2016 server but the drive is a GPT and virtual PC wont boot GPT drives how do I get around this

I have made a VHDx file from a working Windows 2016 server but cant get it to boot in Virtual PC, it seems its because of the GPT drive. How can I virtualise the server?

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-25T10:59:09.1833333+00:00
Mark Cooper 0 Reputation points
commented 2023-03-25T11:51:31.6933333+00:00
Mark Cooper 0 Reputation points
1 answer

Why does my computer have session 0 (Operating System Space) and session 2 but not session 1 (user space)?

Hello, I was experimenting with the Windows Sysinternal Tools and learned that typically speaking there are two sessions in Windows OS, Session 0 and Session 1. Session 0 is allocated to the Operating System and Session 1 is allocated to the User space.…

Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
4,085 questions
Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-24T00:39:21.6666667+00:00
Iziren Okhamafe 6 Reputation points
answered 2023-03-24T04:48:04.7233333+00:00
Castorix31 68,671 Reputation points
0 answers

Process > Suspend/Resume menu text swap "sticks"

In Process Explorer, when performing the action Process > Suspend, the a text for that menu action changes to Resume. However, in v17.02 of the app, this menu text change "sticks": the menu item will switch to the text for the opposite of…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-23T00:55:15.1566667+00:00
Ben Sorensen 0 Reputation points
2 answers

Remote Desktop Connection Manager

I'm facing a problem with Remote Desktop Connection Manager. I have added 2 remote connections to two different PCs (VMs). I connect to one connection and open AnyDesk. I give access to someone via AnyDesk. Everything works normally but while RDCM's…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-20T09:37:04.68+00:00
Nick Angelopoulos 41 Reputation points
answered 2023-03-21T14:39:57.2666667+00:00
Nejo1978 0 Reputation points
0 answers

Autoruns v 14.09 Painfully Slow

As the thread title, I have an Intel 8700k with ssd. To scan (open program): Version - 14.09, 120s Version - 13.5, 5s To close: Version - 14.09, >120s Version - 13.5, <1s Any ideas why this maybe the case? Thanks,

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2022-02-18T19:15:30.457+00:00
Van Dammesque 6 Reputation points
commented 2023-03-19T19:02:32.2566667+00:00
Wim Cossement 6 Reputation points
0 answers

Process Explorer does not start minimized any more

I'm currently using Process Explorer 17.02. Normally it could be started into System Tray by using command line parameter '/t'. This was working on older versions perfectly. After switching to 17.02 Process Explorer starts allways with full window,…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-18T13:48:41.94+00:00
H. Helbig 0 Reputation points
2 answers

Looking for sysmon64.exe version 13.01

I'm looking for previous versions of sysmon64.exe (v13.01). Might anyone know where I can get my hands on it? I need it for testing purposes.

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-16T16:48:37.9+00:00
Masashi Asao 0 Reputation points Microsoft Employee
answered 2023-03-17T13:30:43.12+00:00
Eugene P 11 Reputation points
1 answer

RDCman 2.83 memory leak on reconnect

Hi! After applying updates to a server and restarting it, I drag it from the recent list to the reconnect folder after the automatic logoff/disconnect. RDCman then tries to reconnect very rapidly and the private and working set bytes shoot up rapidly…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2022-01-12T07:03:19.08+00:00
Christian Arnold 1 Reputation point
commented 2023-03-17T01:41:01.1+00:00
Martin Martinec 0 Reputation points
2 answers

Autoruns appears(?) to not detect all startup items (even Microsoft ones).

Hello, I am uncertain if this is a "bug" (< or at least "omission") or user error (mine), but it appears that Autoruns does not comprehensively detect startup items - at least it does not appear to detect MS Teams where said…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2022-05-13T19:15:39.717+00:00
David Durlach 6 Reputation points
commented 2023-03-16T22:02:27.5833333+00:00
John 0 Reputation points
3 answers

Missing sysinternalssuite.zip on live sysinternals.com

There is no files/sysinternalssuite.zip in live sysinternals after January 15, 2021. I know that I can download the latest version from https://download.sysinternals.com/files/SysinternalsSuite.zip, but it used to be available from…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2021-01-18T23:42:58.597+00:00
かずお 山内 1 Reputation point MVP
answered 2023-03-14T18:15:11.34+00:00
Andrii 0 Reputation points
3 answers

Update for BGinfo in Windows 11

Hello, Do you know if/when BGinfo will be updated for Windows 11?

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
4,085 questions
asked 2021-11-19T04:01:05.387+00:00
Jared 16 Reputation points
commented 2023-03-14T15:28:53.35+00:00
Thomas Persson 0 Reputation points
0 answers

Sysmon for old system 2003 SP2

Hi all, we installed sysmon 3.21 in old windows server 2003 SP2. Customer refer me that theare are unexpected restarts after sysmon installation. We read that sysmon 3.21 it's last one supported version for windows 2003 and 2008 from this link…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-14T15:22:29.28+00:00
Cristian Bullo 0 Reputation points
0 answers

disk2vhd hangs on exFAT disk

disk2vhd hangs without message and without visible application window on lauch when a large external exFAT disk (30Tb) is connected. After reformatting the disk to NTFS, disk2vhd could be used without a problem.

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-14T14:06:47.31+00:00
Pieter Janssens 0 Reputation points
0 answers

Allow for the disabling of the termination of Process Explorer when Esc key is pressed

Unless there is already an option to "Not exit Process Explorer when the user hits the <Esc> key," this option really needs to get added to the application. Way too often does one hit <Esc> one time too many to exit some window or…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-14T13:49:12.34+00:00
Michael Goldshteyn 0 Reputation points
0 answers

Disable Filesystem Cache/File Direct write to Disk

Hi All, I am doing a testing inside disk(SSD FW) level. Whenever the files are copy/written from the windows it doesn't come to disk immediately, it cached the file write operation and written the disk as bulk. Eg: I am trying write 5000 files(each…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2021-12-06T08:43:37.883+00:00
Raja 6 Reputation points
edited a comment 2023-03-14T12:57:14.2233333+00:00
Aida Amir 0 Reputation points
8 answers

Process Explorer - ProcExp152.sys Driver Flagged As Vulnerable

Hello- We are leveraging a new security solution in our environment that adds protection to our endpoints. The XDR solution has a rule that is detecting the driver ProcExp152.sys as being "vulnerable". I have asked our security vendor to…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2022-08-31T17:36:54.77+00:00
Marc Denman 51 Reputation points
answered 2023-03-13T13:47:13.0566667+00:00
Dennis Seyersdahl 0 Reputation points
5 answers

Clicking on load filter does nothing!

Clicking/hovering on load filter does nothing! I Am using Process Monitor x64 ver: 3.61. I Am launched as admin...

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2022-04-14T15:32:53.517+00:00
empleat 121 Reputation points
answered 2023-03-12T21:24:47.45+00:00
Dav3ywrx 1 Reputation point
1 answer

How to detect what spins up my disk?

I am seriously trying to figure out what is spinning up one of my disks. I tried using filemon but it doesn't catch the issue. I am trying with DiskMon, but due to many disks in the system, the event log if flooded and unusable. Is there a way to detect…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-11T13:30:15.17+00:00
Bernhard 0 Reputation points
commented 2023-03-11T23:06:07.2233333+00:00
Bernhard 0 Reputation points
0 answers

Sdelete overwrite function should avoid the letter Z as an extension overwrite function

The Sysinternals Sdelete utility has a secure overwrite function which will rename the files 26 times wherein each character in the file name will go from foo.bar to AAA.AAA, then BBB.BBB, and so on. However, if the file being overwritten happens to…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
asked 2023-03-11T15:30:20.6866667+00:00
Stoute, Jason /US 0 Reputation points
5 answers One of the answers was accepted by the question author.

Sysmon Event ID 22

Hello, I'm using newest version of sysmon with config i get from https://github.com/SwiftOnSecurity/sysmon-config/blob/master/sysmonconfig-export.xml I have a problem with Event 22 DNS query. It doesn`t generate the events with the domains I am…

Windows Sysinternals
Windows Sysinternals
A website that offers technical information and advanced system utilities to manage, troubleshoot, and diagnose Windows systems and applications.
873 questions
Microsoft Edge
Microsoft Edge
A Microsoft cross-platform web browser that provides privacy, learning, and accessibility tools.
1,451 questions
asked 2023-02-15T09:57:13.8766667+00:00
THAN VAN TRONG 20 Reputation points
accepted 2023-03-10T03:03:20.9866667+00:00
THAN VAN TRONG 20 Reputation points