Unable to stop Sysmon 15.0
Hello, After we migrate Sysmon to v15.0, everything works fine as expected, but it is unstoppable. During patching cycles or some other maintenance window, we need to stop Sysmon for a short duration. When we try to stop it through Services with…
Why does BGInfo show the 'Host Name' in capital letters only?
I realized that BGInfo shows the 'Host Name' in capital letters only, even if the host name under system control and in several registry keys is case sensitive. Does anybody know how to solve this. VBscript was already tried without success.
One bit more of the modification for bypassing two qualifications, please.
In testing anew the MoSetup modification by way of a VHDX Win 11 environment, I have discovered the reg-word with numbering (1) at the 'AllowUpgradesWithUnsupportedTPMOrCPU' recreated DWORD, was only enough to bypass the CPU unsupported limitation; the…
What is this hardware error?
Mid game computer had shutdown/crash on it's own. Im guessing overheating issue, though if it is.. i don't know if its a CPU or GPU issue. A problem with your hardware caused Windows to stop working correctly. Problem signature Problem Event…
Running BGInfo64 with /ALL parameter from batch file is unable to relaunch as a service even if the batch file is run As Administrator
If I run the command line from an elevated command prompt, it is able to relaunch as a service so that all users see the same background information text. If I run the batch file as administrator, or even run the batch file from an elevated command…
Procexp152.sys Driver cannot load due to security setting
Can anyone at Sysinternals please help? I am suddenly getting a Program Compatibility Assistant error which states, "A driver cannot load on this device" and points at the ProcExp152.sys driver, saying that a security setting has detected this…
autolog.exe login fail with command line
hi there I use autologon.exe on commandline per script for configuring autlogon on domain computer. Command: autologon.exe /AcceptEula username@mydomain.com mydomain.com Password after Reboot the computer, I see that the autologon user can not to…
Minimizing RDCMan immediately causes Unknown diconnection reason 3336
For a long time I've been using the older version of RDCMan which got discontinued, with no issues. Now that RDCMan is a live again, finally downloaded the latest v2.92. Thank you for bringing it back!! However, I'm having a serious issue with it. No…
ZoomIT Live zoom Missing Cursor after Windows 11 upgrade
Hi, I've never had any problem with ZoomIT before, but after Windows 11 upgrade the cursor is missing in Live Zoom mode which makes it very hard to navigate.. Anyone else have the same issue? Im running lates official build of Windows 11…
How to provision a Wi-Fi profile via a website ?
Reference - https://learn.microsoft.com/en-us/windows/win32/nativewifi/prov-wifi-profile-via-website Context - We are trying to implement a feature in our system using the above concept. Basically, we have a website with an anchor tag (<a>) that…
psinfo reports incorrect information about physical memory
I'd like to raise again the bug that exists in psinfo v1.78 (published on June 29, 2016). As reported in a post on the archived forums psinfo (both 32-bit and 64-bit version) reports incorrect information about physical memory above 4 GB. It's quite…
Process explorer systray / taskbar / tray icons lost on explorer.exe (shell) restart
If you use the process explorer graphs in your systray when explorer restarts all systray icons for process explorer are lost. Has been this way for quite awhile (probably ever? at least years?). It is a bit annoying as you must also kill the old one…
rdcman Failed to decrypt using
Hi people! I love RDCMAN, but suddenly I'm having a lot of Failed to decrypt using when launched it. Can this be fixed?
How do you stop Sysmon64.exe so that the program can be uninstalled / upgraded
We have an issue with Sysmon 15.12 causing Windows Server 2022 VM's (ESX 7) to unexpectedly reboot. Microsoft Unified Support informed us to upgrade to Sysmon 15.14 however I am unable to stop the service despite having highest priveledges. What is the…
BGInfo native ARM64
Just wondering if BGInfo will be ported to be a native ARM version to support upcoming hardware?
Zoomit - Magnification 1.0
Zoomit is very useful but I would like to draw on snips (rectangles, lines, etc). I found a workaround which is zoom first Ctrl+1, draw, then snip Ctrl+6. The only thing is that there is no way to zoom with 1.0 magnification because I just want a…
mstsc works but RDCman doesnt
Hi all, I'd like to use RDCMan again after seeing this is being maintained again. I can remote onto a server using MSTSC without a problem but as soon as the same server connection is attempted via RDCMan it cannot be connected to. It's 2022 DC OS, with…
how to get the loaded assemblies of a process programatically
Reference to this old question : https://stackoverflow.com/questions/36431220/getting-a-list-of-dlls-currently-loaded-in-a-process-c-sharp I am writing a security application where we are monitoring our in house developed software (EPD) which is composed…
Bug in the latest RAMMAP version (v1.61)
There is a bug in RAMMAP v1.61. This bug doesn't crash the program. But it's VERY annoying and needs to be fixed in the next version of RAMMAP. Start the program and open the "Processes" tab. Then you'll see that the program will only displays…
Is sdbinst.exe malware if it is using options not listed in MS documentation?
I am using Sysmon and sending the logs to Wazuh for threat detection. It shows a level 12 event that pertains to sdbinst.exe. The event data command line was C:\WINDOWS\System32\sdbinst.exe -m -bg but according to MS documentation the options used by…