INACCESSIBLE BOOT DEVICE - after WinPE-installed Windows 11 on Qemu-KVM
Hi guys. I have winpe-deployed - over iPXE - win11 pro 24H2, whose installation works a ok, meaning installer reports no issues and then - very first time installer reboots - win11 fails to boot with the error as per title. WinPE is rendered wholly on…
Sysinternals
How to delete HKEY_LOCAL-MACHINE\Software\wow6432node\avast without re installing windows
Sysinternals
How to fix Security Health Systray.exe - bad image
Hi I have had this error For a couple of days, I haven't downloaded anything weird recently. Yesterday I had my laptop go into bit locker mode, which i eventually fixed with a system restore. This error persists. I have tried almost every fix I can…
Sysinternals
Procexp152.sys Driver cannot load due to security setting
Can anyone at Sysinternals please help? I am suddenly getting a Program Compatibility Assistant error which states, "A driver cannot load on this device" and points at the ProcExp152.sys driver, saying that a security setting has detected this…
Sysinternals
Windows for business | Windows Client for IT Pros | User experience | Other
CLR profiling: Trying to understand how to fetch variables.
I have been experimenting with a .NET CLR profiler for the purposes of building a powershell monitoring AV tool. I wanted to intercept powershell code (IL) using the profiler right before it is JIT compiled using API functions like JITCompilationStarted,…
Sysinternals
SYSMON and Windows Event ID
I am looking for data on specific Windows Event IDs in SYSMON data. Is there any way to get the Windows Event ID from SYSMON data?
Sysinternals
What are the SYSMON codes above 255?
I am looking at SYSMON data and it is grouped by SYSMON event code. However, there is Other data that has event codes above 255. Where can I find documentation on these codes and what they mean?
Sysinternals
Autorun Search on line option not working
I am not able to use the Search Online feature in the drop-down box in Autorun from Sysinternals. nothing happens been laid up a while do not know when problem started Edition Windows 11 Home Version 24H2 Installed on 1/12/2025 OS…
Sysinternals
how to us sysinternal DU along with doskey or findstr?
how to use sysinternal DU along with doskey or findstr?
Sysinternals
Systernals ZoomIt vs Power Toys ZoomIt
I know that Power Toys ZoomIt came from Sysinternals Zoom It. However I am not sure they now have feature/bug parity. I saw Power Toys had an update for ZoomIt that did a few things and Sysinternals had an update with the screen smoothing that the other…
Sysinternals
RDCMan 3.1 - Recent folder does not populate
I recently updated RDCMan from 2.81.1408 to 3.1.0. The Recent folder no longer populates with servers I connect to. I have it enabled/showing and set to keep 5 recent entries. Is this a known issue? Besides this minor issue, I am loving the new version…
Sysinternals
Sysmon EventCode 15 records content of the primary data stream
I recently installed Sysmon version 15.15 on multiple Windows 11 machines using a custom configuration file with no filtering on EventCode 15. From my understanding, EventCode 15 should be generated whenever an alternate data stream (ADS) of a file is…
Sysinternals
PsExec: Logon failure: the user has not been granted the requested logon type at this computer.
Hello, I am trying to run the following command within a domain using an account with Domain Admin on to computers within the domain: psexec64 @Anonymous .txt -u domain\adminaccount "\server\share\file.cmd" I enter the password…
Sysinternals
ZoomIT Live zoom Missing Cursor after Windows 11 upgrade
Hi, I've never had any problem with ZoomIT before, but after Windows 11 upgrade the cursor is missing in Live Zoom mode which makes it very hard to navigate.. Anyone else have the same issue? Im running lates official build of Windows 11…
Sysinternals
Procdump not work with custom dump option (-mc)
Hi, With WER, I can use with dumpType = 0, and CustomDumpFlags = 0, to generate small crash dump file enough to trace (1~2MB). When use procdump -e -mc 0, it doesn't work, it generates ~30MB crash dump size, then I test with procdump -e -mc 2 (for full…
Sysinternals
How to fix “An administrator has restricted sign in.”
I got my microsoft account hacked and now i got the account back but when i try to log into my laptop it just shows this. now i don’t know what to do. I tried to get into recovery mode by holding shift and pressing restart but it doesn’t work and if i…
Sysinternals
sysinternals/sdelete
The DOD 5220.22-M method is considered deprecated -- will sdelete be update using current standards?
Sysinternals
Network driver missing during reboot
Hi, I’m reinstalling Windows 11 Pro on an HP ZBook Power 15.6 G9 using a USB installer. The setup says I’m not connected to a network, and I can’t connect because no network drivers are found. I downloaded HP’s network drivers: 23H2 version → Windows…
Sysinternals
Logonsessions.Exe - Sysinternals
I had downloaded Sysinternals, never used it or opened it, and then deleted it. I noticed it was in the trash bin in OneDrive. I then decided to find out what the file was and if it could be deleted. I came across this article that says: "No,…
Sysinternals
Event id 2511 in Windows Server 2016 Standard
My Server have 8TB, 32GB RAM but prolong the time of load the data existing. At times some files or folder are missing and the people cry. I share a file or folder with another users but they don't found the file or folder: I must share the path of…
Sysinternals