Process Monitor doesn't seem to "work" with dev drives?
I recently moved over to using a Windows Dev Drive. I've become accustomed to using Process Monitor with File tracking to find open files but I can't seem to do this with Dev Drives?
BUG: SDelete 2.05 prints contradictory message for switch -z.
When sdelete 2.05 runs with the switch -z switch it prints a progress message "Cleaning free space on...". When finished, it prints "... drive cleaned." I expected the messages to indicate that it was Zeroing, and had zeroed, the…
What does "The specified network name is no longer available" mean in psping?
"The specified network name is no longer available" is displayed if I include a -l in the command: C:\IT\PSTools>psping -l 32 52.96.110.34:443 PsPing v2.12 - PsPing - ping, latency, bandwidth measurement utility Copyright (C) 2012-2023 Mark…
Sysinternals - ZoomIt v8.01 - Multi Screen Support - Feedback
Hello, I am a bit surprised by how difficult it is to find good/simple windows screen zooming tools. In a multiple monitor scenario I want zoom one monitors screen. I don't want scale, I don't want a magnifier window gobbling more screen space,…
How/where does autoruns get startup info for a specific user? Seems broken.
Autoruns is returning data for wrong user: It is returning contents of /users/USER-1/appdata/roaming/microsoft/windows/start menu/programs/startup when USER is set to USER-2, not USER-1 in the dropdown USER option, and when logged in as USER-2 USER-2 who…
Process Monitor is showing impossibly old Timestamps for modules under \Windows\SysWOW64
When viewing process modules, I have noticed that many modules under C:\Window\SysWOW64 have impossibly old Timestamps, yet if you view the properties of a modules, they appear normal. I observed this on my test VM and also a customer's computer who sent…
![](https://techprofile.blob.core.windows.net/images/_5e-jRvlCkWlkMrV8cdbJg.png?8D8365)
Remote Desktop Connection Manager v 2.93.1431.0 won't start; crashing with KERNELBASE.dll module
I'm hoping there's an easy solution to my problem. Attempting to run Remote Desktop Connection Manager (2.93.1431.0) under Windows 11 Pro (23H2, OS Build 22631.4751). Event viewer shows it crashing with the following: Faulting application name:…
BGInfo - Needs Support for Windows Server 2025
The latest version available of BGInfo does not have support for the new Windows Server 2025.
Column sort not working on Process Monitor 4.1
Windows 7/Ent/32-bit: Column sort does not work on Process Monitor 4.1. I don't mean it isn't correctly configured. I mean it's not working. I can filter the log (PML) file and work on individual entries, but clicking on the column head does nothing.
How to securely use PSEXEC with a remote user and password from a batch file?
I use PSEXEC to administer many embedded Windows systems (no KVM) that are not part of our domain. (Think of a thermostat or freezer.) They use their own user/password that does not exist in our domain or locally. I use "PSEXEC -u user -p…
Troubleshooting memory access violation in external module acroPDF.dll
Hello. I am experiencing apparently "random" crashes in a program, where the crash dump logs (analyed with WindDbg) indicate an memory access violation occuring in AcroPDF.dll. The last four function calls in the call stack are always…
![](https://techprofile.blob.core.windows.net/images/_5e-jRvlCkWlkMrV8cdbJg.png?8D8365)
ADMINISTRATION PROBLEM
So my mother originally set up an account on my computer which gives her administration. There are some applications I can't download or delete without permission, but the problem is: She forgot the password to it, and she said she can't reset it. I…
ZoomIt turn off system color inversion and lack multi-monitor support.
Means it don't support Windows Accessibility Color filter. It turn it off and draw only for current monitor
Sysinternals TCPVIEW [Time Wait] what is it?
Hi all; decided to check out TCPVIEW from sysinternals today and discovered a ton of [Time Wait] i have found 0 answers online or anyone talking about this so i'm asking here; what does this mean?
![](https://techprofile.blob.core.windows.net/images/bpqI_wINOUGg4BYYipkUVA.png?8D827C)
Procmon: When you filter to a registry path, do you need to specify the exact value?
In procmon, if you filter to a registry path like so: HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Services\Spooler Then change a value in this path, such as the "start" value, this change is not captured in Procmon. However, if you filter…
ZoomIt 7.2 to 9.0: The mouse pointer disappears when I try to exit from the "Draw" mode while using "LiveZoom"
The mouse pointer disappears when I try to exit from the the "Draw" mode while using "LiveZoom". By double-clicking the right mouse button, the display exits both the Draw mode and the LiveZoom mode, returning to the normal…
shellrunas : error launching application: Parameter is incorrect
After changing local policy to allow logon as a service for user account, shellrunas still errors: shellrunas : error launching application: Parameter is incorrect
![](https://techprofile.blob.core.windows.net/images/_5e-jRvlCkWlkMrV8cdbJg.png?8D8365)
Collecting msDS-LastSuccessfulInteractiveLogonTime Without Displaying Logon Data
How can the msDS-LastSuccessfulInteractiveLogonTime attribute be collected without enabling the "Display information about previous logons during user logon" Group Policy? This attribute is important for gathering interactive logon times for…
![](https://techprofile.blob.core.windows.net/images/87ESmqZrLUGA2Ockp7wKAw.png?8D848E)
RDCMan with ts_redir will never disconnect
I'm having an issue with RDCMan when the remote system is a gateway and issues a redirect. Once RDCMan gets the redirect it will work, but I cannot disconnect. Any attempts to log out or disconnect result in RDCMan immediately reconnecting back to the…
![](https://techprofile.blob.core.windows.net/images/YY4C0NjBC06ZXLiDnLHJFA.png?8D8974)
![](https://techprofile.blob.core.windows.net/images/YY4C0NjBC06ZXLiDnLHJFA.png?8D8974)
Odd Sysmon Version numbers question, have you seen this before?
Hey Everyone, I've got a weird one to ask about today. We have Sysmon feeding into our SIEM, and when looking at the file version information the SIEM receives, we see some differing results that we are confused about. Some of the results for the…