Software Request for Sysmon 13.34
Hi team, I'm from SCCM support team(Land o Lakes) I'm requesting you to share the link to install Sysmon 13.34 for one of my user , user has requested for this application and Im unable to find the link , Kindly assist ASAP, thanks Regards Mohamed Ashiq

Whois is partially broken
Recently I found that the whois utility in SysinternalsSuite fails to lookup for domains in .tw TLD, giving a message "%ERROR:101: no entries found", while other online whois services e.g. IANA WHOIS (https://www.iana.org/whois) work well to…
should pendmoves (and movefile) be updated to comply to the "new" syntax of PendingFileRenameOperations?
It appears that at least in Win10, the PendingFileRenameOperations registry value is now being populated using a slightly different syntax, which prepends "*1" or "*2" to the usual renaming/deleting patterns. Can at least pendmoves be…
Sysmon unable to handle removal of Alternate data stream
Hi, I'm currently testing sysmon 15.15 with the configuration from (Olaf Hartong) sysmonconfig-with-filedelete.xml and we came across a issue with unblocking downloads (zone.identifier alternate data stream). Is this a problem on how sysmon handles file…

Sysprep fails on Windows 11 version 24H2
2025-02-15 10:04:55, Info SYSPRP Entering SysprepGeneralizeValidate (Appx) - validating whether all apps are also provisioned. 2025-02-15 10:04:55, Error power 2025-02-15 10:04:55, Error SYSPRP Failed to…
How to reinstall bluetooth driver
My bluetooth has completely disappeared and even a tech support wasn't able to reinstall it, can you help?
Sysinternals Process Explorer - BUG REPORT: Column Headers overwrite sorting Caret
On the Process Explorer regular/home screen, you can (of course) order/sort the processes displayed by clicking on the column header. This works fine. HOWEVER the CARET (^) which displays the "order-this-column-is-now-sorted" is OVERWRITTEN…
Procexp152.sys Driver cannot load due to security setting
Can anyone at Sysinternals please help? I am suddenly getting a Program Compatibility Assistant error which states, "A driver cannot load on this device" and points at the ProcExp152.sys driver, saying that a security setting has detected this…

What does "The specified network name is no longer available" mean in psping?
"The specified network name is no longer available" is displayed if I include a -l in the command: C:\IT\PSTools>psping -l 32 52.96.110.34:443 PsPing v2.12 - PsPing - ping, latency, bandwidth measurement utility Copyright (C) 2012-2023 Mark…

Process Monitor doesn't seem to "work" with dev drives?
I recently moved over to using a Windows Dev Drive. I've become accustomed to using Process Monitor with File tracking to find open files but I can't seem to do this with Dev Drives?
BUG: SDelete 2.05 prints contradictory message for switch -z.
When sdelete 2.05 runs with the switch -z switch it prints a progress message "Cleaning free space on...". When finished, it prints "... drive cleaned." I expected the messages to indicate that it was Zeroing, and had zeroed, the…
Sysinternals - ZoomIt v8.01 - Multi Screen Support - Feedback
Hello, I am a bit surprised by how difficult it is to find good/simple windows screen zooming tools. In a multiple monitor scenario I want zoom one monitors screen. I don't want scale, I don't want a magnifier window gobbling more screen space,…
How/where does autoruns get startup info for a specific user? Seems broken.
Autoruns is returning data for wrong user: It is returning contents of /users/USER-1/appdata/roaming/microsoft/windows/start menu/programs/startup when USER is set to USER-2, not USER-1 in the dropdown USER option, and when logged in as USER-2 USER-2 who…
Process Monitor is showing impossibly old Timestamps for modules under \Windows\SysWOW64
When viewing process modules, I have noticed that many modules under C:\Window\SysWOW64 have impossibly old Timestamps, yet if you view the properties of a modules, they appear normal. I observed this on my test VM and also a customer's computer who sent…

Remote Desktop Connection Manager v 2.93.1431.0 won't start; crashing with KERNELBASE.dll module
I'm hoping there's an easy solution to my problem. Attempting to run Remote Desktop Connection Manager (2.93.1431.0) under Windows 11 Pro (23H2, OS Build 22631.4751). Event viewer shows it crashing with the following: Faulting application name:…
BGInfo - Needs Support for Windows Server 2025
The latest version available of BGInfo does not have support for the new Windows Server 2025.
Column sort not working on Process Monitor 4.1
Windows 7/Ent/32-bit: Column sort does not work on Process Monitor 4.1. I don't mean it isn't correctly configured. I mean it's not working. I can filter the log (PML) file and work on individual entries, but clicking on the column head does nothing.
How to securely use PSEXEC with a remote user and password from a batch file?
I use PSEXEC to administer many embedded Windows systems (no KVM) that are not part of our domain. (Think of a thermostat or freezer.) They use their own user/password that does not exist in our domain or locally. I use "PSEXEC -u user -p…
Troubleshooting memory access violation in external module acroPDF.dll
Hello. I am experiencing apparently "random" crashes in a program, where the crash dump logs (analyed with WindDbg) indicate an memory access violation occuring in AcroPDF.dll. The last four function calls in the call stack are always…

ADMINISTRATION PROBLEM
So my mother originally set up an account on my computer which gives her administration. There are some applications I can't download or delete without permission, but the problem is: She forgot the password to it, and she said she can't reset it. I…