1,103 questions with Sysinternals-related tags

Sort by: Updated
0 answers

procdump: bug when using perf.counter as perf.threshold for when a process has been running at Y% usage for X amount of time

I'm trying to use ProcDump to create a memdump when my process has been using basically 100% of a single core for over an hour. Here's the problem though; when using the parameter -p "\Process(processname)\% Processor Time" value (Performance…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-03-15T13:36:39.0766667+00:00
Patrik Mattsson 0 Reputation points
edited the question 2024-03-15T13:57:59.5533333+00:00
Patrik Mattsson 0 Reputation points
4 answers

[Sysmon 15.12] Server crashes from time to time with Sysmon v15.12

We had a crash after 20 minutes of the installation of Sysmon 15.12. In the system event log we've found this message: The computer has rebooted from a bugcheck.  The bugcheck was: 0x00000139 (0x0000000000000003, 0xffff928901305000, 0xffff928901304f58,…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-05T16:34:48.0566667+00:00
Joe Doe 156 Reputation points
commented 2024-03-12T08:41:38.2866667+00:00
Alex Mihaiuc 176 Reputation points Microsoft Employee
0 answers

My processexplorer icon is set as a cpu monitor, but sometimes my laptop freezes for long periods, and all I see are a couple of red dots at the bottom of the icon, can I put it into a different mode that will show me some sort of indication?

I have Process Explorer running with the status bar icon. It's set as a cpu monitor. I've been using PE for a long time. I've set it up on this new laptop, but for some reason the PE icon is only showing anything happening in about the last pixel row of…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-03-11T23:56:39.5933333+00:00
KARR, DAVID 6 Reputation points
0 answers

Sysmon DNS Query Logs - QueryResults Field

How do I display type: 1 for Type A DNS logs in the QueryResults field of Sysmon Event ID 22 DNS Query logs? I tried generating the logs using the below XML format: <Sysmon schemaversion="4.90">  <EventFiltering>  <DnsQuery…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,807 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,844 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,780 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,414 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-03-11T04:05:38.8966667+00:00
1357A 0 Reputation points
1 answer

How can I make Cacheset appear on the taskbar when it's running?

When I'm running Cacheset 1.2.0.1 on windows 11 home 22H2 it doesn't show up on the taskbar. How can I make it show up?

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-03-07T12:50:06.1866667+00:00
K Damstra 0 Reputation points
answered 2024-03-09T12:56:48.8233333+00:00
RLWA32 40,946 Reputation points
0 answers

Procmon scan smb request

Hello, I have an issue on a fileshare server, users are complaining about latency, especially when transferring files to the fileshare server,opening files, or modifying files. I want to launch a procmon on the user workstation to see what what…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-03-05T16:53:35.69+00:00
Mohamed jihad bayali 1,121 Reputation points
3 answers

when running using procmon /terminate log is corrupted

Hello Guys, I'm configuring procmon to run as a scheduled task and then also using another schedule task to terminate it. Both tasks are configured to run with System. Start task has the following arguments: /AcceptEula /LoadConfig…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2020-12-31T12:37:44.237+00:00
Miguel Gomes 1 Reputation point
commented 2024-03-04T15:06:48.6233333+00:00
Brad Parham 0 Reputation points
1 answer

Bug in BGInfo - Wrong background with correct text or wrong text on correct background

We have BGInfo being run for all users logging on to our RDS environment using a company background generating some custom info. All servers are virtual. RDS servers use FSLogix. It works most of the time BUT some times BGInfo will: not load the…

Windows Server 2019
Windows Server 2019
A Microsoft server operating system that supports enterprise-level management updated to data storage.
3,505 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-01-11T16:03:31.0966667+00:00
Nicolaj Rasmussen 0 Reputation points
commented 2024-03-01T21:11:42.2166667+00:00
Stink Bait 0 Reputation points
1 answer

Sysmon archive folder too big

Hi all. I'm using sysmon with a lot of rules and I'm having a problem, which has been previously exposed here: The archive folder is getting way too big and I can't find any relevant information on how we should clean this folder. Keeping in mind…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-29T14:28:45.9733333+00:00
radw 0 Reputation points
answered 2024-02-29T15:12:01.31+00:00
Michael Taylor 49,246 Reputation points
3 answers

Remote Desktop connection manager client screen is not aligned with screen size in windows 11 Laptop

Remote Desktop
Remote Desktop
A Microsoft app that connects remotely to computers and to virtual apps and desktops.
4,290 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2022-07-26T12:55:00.667+00:00
Nagaraju Thiriveedhi 6 Reputation points Microsoft Employee
commented 2024-02-29T12:54:28.3733333+00:00
Bates, Chris 5 Reputation points
1 answer One of the answers was accepted by the question author.

Stable Sysmon 15.x version.

We deployed sysmon v15.12 and ran into an issue with random crash with windows servers. Can you recommend a stable version of sysmon which has a fix to CVE-2023-29343 & CVE-2022-41120. TIA

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-21T18:49:30.3166667+00:00
sreejesh chethil 40 Reputation points
accepted 2024-02-28T18:53:10.7+00:00
sreejesh chethil 40 Reputation points
5 answers One of the answers was accepted by the question author.

BSOD DRIVER_OVERRAN_STACK_BUFFER when attaching to w3wp.exe process with VS2019

Recently (as of 2 days ago), every time I try to attach to the IIS process w3wp.exe with Visual Studio 2019 (running on Windows 10), I get the blue screen of death with the DRIVER_OVERRAN_STACK_BUFFER error. Several other people at my organization have…

Internet Information Services
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2021-08-12T20:16:38.343+00:00
Elisabeth D 111 Reputation points
answered 2024-02-27T18:01:18.81+00:00
Patrick, Keith 0 Reputation points
2 answers

New startup registry key in Windows 10/11, NOT captured within autoruns

Hi All, While researching the startup behavior of Windows Container (Windows Metro) Apps , like the ones installed through Microsoft Store or native to System (xbox/phone, etc), I came across a new registry key location (different from the known…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2022-10-17T07:21:39.64+00:00
Rahat Sanghoi 1 Reputation point
answered 2024-02-26T15:41:46.04+00:00
Ricardo Almada 5 Reputation points
5 answers

400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer"

On one specific server I have 400% difference in CPU usage between "Task Manager" and "Sysinternal's Process Explorer" (both picture taken on the same screenshot, so at the exact same time). What can be the cause of this…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2022-10-07T08:24:13.33+00:00
Bertrand K 51 Reputation points
commented 2024-02-26T15:27:16.83+00:00
Brok3n Cogniti0n 15 Reputation points
0 answers

What to do If window Dosn't Open In window 11

Help With Window 11 Is There anybody to Fix Problem

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-25T21:47:37.5+00:00
DILIPBHAI PATEL 0 Reputation points
commented 2024-02-25T21:55:43.7733333+00:00
Reza-Ameri 16,836 Reputation points
1 answer One of the answers was accepted by the question author.

Can someone help me fix this BGInfo error?

Hello, I'm having a problem. I'm the IT specialist of a company. Then a host turns on a computer it gets an error message "Cannot find the configuration file 'C:\BGInfo\bginfo2.bgi/SILENT.bgi' do you want to create a new file". And when I press…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2021-02-17T14:49:38.397+00:00
Domantas Orentas | FITSOUT 21 Reputation points
commented 2024-02-24T15:09:08.32+00:00
Sharma, Gourav 0 Reputation points
0 answers

Process Explorer v17.05 Issue: TCP/IP Properties Tab Blank

Trying to troubleshoot a few issues, however unable to view information in Process Explorer v17.05 When I right click to view properties of a process, parent or child I run into this Issue: TCP/IP Properties Tab Blank TCP View shows limited data as well,…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-21T11:16:19.1133333+00:00
Neil 0 Reputation points
0 answers

Bug Report: tcpview bad IPv6 name resolution

TCPView v4.19 on Windows 11 With "Resolve names" OFF, tcpview displays the local and remote IPv6 addresses. With "Resolve names" ON, it produces spurious "names" that look like IPv4 addresses, and then attempts to resolve…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-20T22:16:58.6+00:00
James Garrison 236 Reputation points
0 answers

Sysmon DNS Query Support

I have been trying to generate Sysmon Event ID 22 DNS Query logs using the below xml format  <Sysmon schemaversion="4.90">  <EventFiltering>  <DnsQuery onmatch="exclude" />  </EventFiltering>…

Windows 10
Windows 10
A Microsoft operating system that runs on personal computers and tablets.
10,807 questions
Windows
Windows
A family of Microsoft operating systems that run across personal computers, tablets, laptops, phones, internet of things devices, self-contained mixed reality headsets, large collaboration screens, and other devices.
4,844 questions
Windows 10 Security
Windows 10 Security
Windows 10: A Microsoft operating system that runs on personal computers and tablets.Security: The precautions taken to guard against crime, attack, sabotage, espionage, or another threat.
2,780 questions
Windows 11
Windows 11
A Microsoft operating system designed for productivity, creativity, and ease of use.
8,414 questions
Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-01-17T12:14:49.9433333+00:00
1357A 0 Reputation points
edited the question 2024-02-19T06:30:25.0166667+00:00
1357A 0 Reputation points
0 answers

Fvevol.sys blue screen + Critical_process_died blue screen error

Hey there, I went to turn on my computer today (It is a lenovo legion that has been working since christmas windows 11), and within seconds of logging in I got a Fvevol.sys blue screen error. After restarting I got a blue screen immediately after boot…

Sysinternals
Sysinternals
Advanced system utilities to manage, troubleshoot, and diagnose Windows and Linux systems and applications.
1,103 questions
asked 2024-02-18T23:48:19.5733333+00:00
Brandon Krupka 0 Reputation points
edited the question 2024-02-18T23:49:28.7033333+00:00
Brandon Krupka 0 Reputation points