How to securely use PSEXEC with a remote user and password from a batch file?
I use PSEXEC to administer many embedded Windows systems (no KVM) that are not part of our domain. (Think of a thermostat or freezer.) They use their own user/password that does not exist in our domain or locally. I use "PSEXEC -u user -p…
Process Monitor Not Picking Up Any Events When "Drop Filtered Events" is toggeled?
I am trying to troubleshoot an issue with Sever 2022 becoming unable to RDP into it after some time, and I'm trying to use Process Monitor to monitor the key HKLM\SYSTEM\CurrentControlSet\Control\Terminal Server\fDenyTSConnections. However, when I toggle…
How can I limit or delete the folder content of Sysmon folder?
I have Sysmon installed in all of our Servers 2019 and 2022. It piles up the logs in C:/Sysmon folder. The folder is owned by TrustedInstaller so generally I cannot delete the content. I have used PSexec but whenever I try to run that it gives an error…
Sysmon 15 is not able to start service in timely manner?
Sysmon v15.0 installation failed during StartService operation and it tried to clean up machine by uninstalling it automatically, but uninstall operation failed as well and left the System in bad state so reinstallation is not working either. System…
Sysmon 13.01 Prevent ArchiveDirectory creation and file delete backup
Is there a way with Sysmon 13.01 to prevent the creation of the Archive Directory (default is C:\Sysmon) and prevent file deletions from saving the file to the local filesystem?
Sysinternals - ZoomIt v8.01 - Multi Screen Support - Feedback
Hello, I am a bit surprised by how difficult it is to find good/simple windows screen zooming tools. In a multiple monitor scenario I want zoom one monitors screen. I don't want scale, I don't want a magnifier window gobbling more screen space,…
Process Explorer does not respond when starting
On many windows servers I have when I start Process Explorer x64, the screen shows the list of processes but Process Explorer is not responding (for example scrolling down the process list does not do anything). The status bar continues to update showing…
Sysmon - Non-ASCII character in the ParentUser and ParentCommandLine field
Has anyone seen this behavior with Sysmon: getting non-ASCII characters in the ParentUser, and ParentCommandLine fields? Sometimes it looks like another language character set, other times it is WingDings or some other non-sensical characters. …
verified signer
In Process Explorer I clicked Options > Verify Image Signatures. Several show no signer and "The system cannot find the specified file". If I attempt to kill the process it reports "Error Opening process: Access is denied'". If I…
How to remove (none) from BGInfo output?
Computers these days have so many network connection options the BGInfo is providing useless info for network adapters that are not being used. As seen here this PC is only using one network connection but because it has a WiFi adapter, Ble and…
sigcheck: non-ASCII characters in output are being replaced with question marks
For example, for this (https://www.virustotal.com/gui/file/6279b309469c10b8c478c49ad6cf06b7f7307079bd90f00bbe3b292d5c6a52e5/details) sample I get the following output: Verified: Signed Signing date: 12:05 PM 7/4/2024 Publisher: ??????????? ... I…
no filename completion with remote cmd.exe started with psecex
When running a remote cmd.exe with psexec, why doesn't filename completion and the cls, Title and color commands not work there? Win 10/64, PsExec v2.43
process explorer app in system tray
how to place process explorer app in system tray
Output of GFlags "Show Loader Snaps" not visible in DebugView
"Show Loader Snaps" is a very useful GFlag to investigate dependency issue of an application. When using it, I will get the debug output of this flag in the Debug Output windows of Visual Studio 2022 - that is nice. But when using the famous…
Problem with Process Explorer Windows 10 "a device attached to the system is not functioning"
When I attempt to bulk check for all processes in Process Explorer with VirusTotal, This error show up "a device attached to the system is not functioning". I have already attempted to resolve the issue by deleting it from the registry and…
sysinternals zoomit recording suddently started giving an error
I'm using zoomit from sysinternals, and one of the most used features I used was the screen recording. I don't know what happened, but it suddently stopped working giving the following error: ZoomIt Error starting recording: Invalid pointer OK …
RDCMan mouse cursor jumps to the left
I am using RDCMan v2.90 on a Windows 10 laptop. When my mouse cursor is inside RDCMan's window, the cursor jumps to the left on its own every few minutes. If I move my cursor to anywhere outside RDCMan's window, the cursor becomes normal. Regular…
Sysmon v9.01 shows up after uninstalling v15.14
Hello, I am running into a bit of an issue and I can't find anymore information regarding it. We have no more use for Sysmon on our network and I am working through uninstalling it from our Windows 10 devices. After uninstalling v15.14 with the…
bginfo - logon desktop (screen) for console users - does this work in windows 10?
I'm trying to get some info appear on the logon screen. It doesn't seem to work. Am I understanding this feature wrong? I have win 10 enterprise. Only setting this registry entry gets results: HKLM\SOFTWARE\Policies\Microsoft\Windows\Personalization…
BgInfo support for PowerShell commands and scripts
Please add PowerShell command and script support to BgInfo. BgInfo currently supports many legacy methods for data collection such as environment variables, registry value, WMI query and VB scripts. Modern system administrators and IT professionals…