Autoruns v14.06 and Sysmon v13.30

Published Oct 26 2021 12:45 PM 4,047 Views
Microsoft

Autoruns v14.06

This Autoruns release fixes a crash happening for scheduled tasks containing spaces.
 

Sysmon v13.30

This Sysmon update adds user fields for events, fixes a series of crash-causing bugs - for example with the Visual Studio debugger - and improves memory usage and management in the driver.
 
14 Comments
%3CLINGO-SUB%20id%3D%22lingo-sub-2887598%22%20slang%3D%22en-US%22%3EAutoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2887598%22%20slang%3D%22en-US%22%3E%3CDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsysinternals%2Fdownloads%2Fautoruns%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%3EAutoruns%20v14.06%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3E%3CSPAN%3EThis%20Autoruns%20release%20fixes%20a%20crash%20happening%20for%20scheduled%20tasks%20containing%20spaces.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Fdocs.microsoft.com%2Fen-us%2Fsysinternals%2Fdownloads%2Fsysmon%22%20target%3D%22_self%22%20rel%3D%22noopener%20noreferrer%22%3E%3CSPAN%3ESysmon%20v13.30%3C%2FSPAN%3E%3C%2FA%3E%3C%2FP%3E%0A%3CDIV%3E%3CSPAN%3EThis%20Sysmon%20update%20adds%20user%20fields%20for%20events%2C%20fixes%20a%20series%20of%20crash-causing%20bugs%20-%20for%20example%20with%20the%20Visual%20Studio%20debugger%20-%20and%20improves%20memory%20usage%20and%20management%20in%20the%20driver.%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3CDIV%3E%26nbsp%3B%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-BODY%3E%3CLINGO-TEASER%20id%3D%22lingo-teaser-2887598%22%20slang%3D%22en-US%22%3E%3CDIV%3E%0A%3CDIV%3E%3CSPAN%3ELearn%20about%20the%20latest%20updates%20to%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FSPAN%3E%3C%2FDIV%3E%0A%3C%2FDIV%3E%3C%2FLINGO-TEASER%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2887948%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2887948%22%20slang%3D%22en-US%22%3E%3CP%3EIn%20the%20Sysmon%20zip%20file%2C%20Sysmon64.exe%20shows%20a%20file%20and%20product%20version%20of%2013.30.%20However%2C%20upon%20installation%2C%20it%20displays%20v13.24.%20Additionally%2C%20once%20installed%2C%20C%3A%5CWindows%5CSysmon64.exe%20displays%20a%20file%20and%20product%20version%20of%2013.24%2C%20as%20does%20the%20C%3A%5CWindows%5CSysmonDrv.sys.%20Is%20this%20the%20latest%20version%20of%2013.30%3F%20Or%20is%20the%20product%20version%20incorrectly%20listed%20on%20install%20and%20post-install%3F%26nbsp%3B%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2888983%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2888983%22%20slang%3D%22en-US%22%3E%3CP%3EAutoruns%20is%20still%20broken%26nbsp%3B%3CIMG%20class%3D%22lia-deferred-image%20lia-image-emoji%22%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Fhtml%2F%40FE3C8A5543DEF164D4C09E9B7F45E1A4%2Fimages%2Femoticons%2Ffacepalm_40x40.gif%22%20alt%3D%22%3Afacepalm%3A%22%20title%3D%22%3Afacepalm%3A%22%20%2F%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2889814%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2889814%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1196854%22%20target%3D%22_blank%22%3E%40JosephMy%3C%2FA%3E%26nbsp%3BIt%20appears%20you%20have%20a%20mix%20between%20v13.24%20and%20v13.30.%20I%20think%20that%20in%20your%20case%20the%20previous%20version%20was%20not%20fully%20uninstalled%20before%20getting%20to%20v13.30.%20Completely%20remove%20sysmon%20with%3A%3C%2FP%3E%0A%3CPRE%20class%3D%22lia-code-sample%20language-powershell%22%3E%3CCODE%3Esysmon64%20-u%20force%3C%2FCODE%3E%3C%2FPRE%3E%0A%3CP%3Ethen%20make%20sure%20that%20C%3A%5CWindows%5Csysmon64.exe%20doesn't%20exist%20anymore%20and%20start%20again%20v13.30.%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1143778%22%20target%3D%22_blank%22%3E%40hqqddy%3C%2FA%3E%26nbsp%3Bis%20this%20still%20the%20crash%20with%20rundll%20entries%20containing%20spaces%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2889901%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2889901%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F776036%22%20target%3D%22_blank%22%3E%40Alex_Mihaiuc%3C%2FA%3E%26nbsp%3Bwell%20it's%20failed%20to%20disable%20components%20is%20Installed%20components%20for%20i.e.%20Is%20it%20new%20normal%20behaviour%3F%20We%20(ok%20I%20am)%20look%20at%20builds%20v13.x%20and%20it%20works%20fine.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2890520%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2890520%22%20slang%3D%22en-US%22%3E%3CP%3EOh%2C%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1143778%22%20target%3D%22_blank%22%3E%40hqqddy%3C%2FA%3E%2C%20I%20saw%20such%20problems%20with%20v14%20and%20I%20thought%20they%20were%20all%20fixed.%20I%20would%20owe%20you%20one%20if%20you%20could%20provide%20a%20more%20detailed%20description%20so%20I%20can%20get%20a%20fix%20out.%20Either%20here%20or%20via%20mail%20at%20%22syssite%22.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2890876%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2890876%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F776036%22%20target%3D%22_blank%22%3E%40Alex_Mihaiuc%3C%2FA%3E%26nbsp%3Bit's%26nbsp%3B%20looks%20like%20this.%20is%20it%20normal%3F%20I%20saw%20it%20start%20from%20first%20v14.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-left%22%20image-alt%3D%2201.png%22%20style%3D%22width%3A%20999px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F320460i688B87B85BD5DC67%2Fimage-size%2Flarge%3Fv%3Dv2%26amp%3Bpx%3D999%22%20role%3D%22button%22%20title%3D%2201.png%22%20alt%3D%2201.png%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2890900%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2890900%22%20slang%3D%22en-US%22%3E%3CP%3E14.06%20is%20still%20broken.%20Open%20-%26gt%3B%20Save%20%26gt%3B%20and%20Compare%20still%20cannot%20load%20the%20saved%20.arn%20file%20with%20Win7%20ESU%2C%20Win%208.1%20and%20Win10%20LTSB.%20Works%20okay%20with%20Win11%20and%20some%20newer%20W10%20builds.%3C%2FP%3E%3CP%3E%3CSPAN%20class%3D%22lia-inline-image-display-wrapper%20lia-image-align-inline%22%20image-alt%3D%222021-10-27_162649.jpg%22%20style%3D%22width%3A%20319px%3B%22%3E%3CIMG%20src%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fimage%2Fserverpage%2Fimage-id%2F320464i51BAAC88671BA17B%2Fimage-size%2Fmedium%3Fv%3Dv2%26amp%3Bpx%3D400%22%20role%3D%22button%22%20title%3D%222021-10-27_162649.jpg%22%20alt%3D%222021-10-27_162649.jpg%22%20%2F%3E%3C%2FSPAN%3E%3C%2FP%3E%3CP%3EHas%20no%20one%20tested%20this%3F%3CBR%20%2F%3EAm%20I%20the%20only%20one%20with%20this%20problem%3F%3CBR%20%2F%3EIt%20would%20be%20nice%20if%20someone%20could%20confirm.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2890931%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2890931%22%20slang%3D%22en-US%22%3E%3CP%3EHi%26nbsp%3B%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F776036%22%20target%3D%22_blank%22%3E%40Alex_Mihaiuc%3C%2FA%3E%2C%26nbsp%3Bthanks%20for%20the%20reply.%26nbsp%3B%3CSPAN%3EI%20did%20try%20the%20-u%20force%20command%2C%20it%20appears%20that%20the%20executable%20persists%20in%20C%3A%5CWindows%20although%20the%20output%20says%20that%20it's%20the%20Sysmon64%20service%20is%20stopped%20and%20and%20Sysmon64%20is%20removed.%20As%20a%20workaround%2C%20I'm%20running%20-u%20force%2C%20then%20deleting%20the%20executable.%20Thanks.%3C%2FSPAN%3E%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2890951%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2890951%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1196854%22%20target%3D%22_blank%22%3E%40JosephMy%3C%2FA%3E%26nbsp%3Bthe%20fact%20that%20we%20don't%20properly%20handle%20this%20common%20upgrade%20path%20is%20very%20useful%20feedback%20in%20itself%2C%20thanks!%3C%2FP%3E%0A%3CP%3E%26nbsp%3B%3C%2FP%3E%0A%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1186628%22%20target%3D%22_blank%22%3E%40click-click%3C%2FA%3E%26nbsp%3Breally%20weird%20it's%20regressing%20on%20the%20older%20systems%2C%20I'll%20have%20a%20look%20and%20get%20back%20to%20you%20with%20a%20fix.%3C%2FP%3E%3C%2FLINGO-BODY%3E%3CLINGO-SUB%20id%3D%22lingo-sub-2891037%22%20slang%3D%22en-US%22%3ERe%3A%20Autoruns%20v14.06%20and%20Sysmon%20v13.30%3C%2FLINGO-SUB%3E%3CLINGO-BODY%20id%3D%22lingo-body-2891037%22%20slang%3D%22en-US%22%3E%3CP%3E%3CA%20href%3D%22https%3A%2F%2Ftechcommunity.microsoft.com%2Ft5%2Fuser%2Fviewprofilepage%2Fuser-id%2F1143778%22%20target%3D%22_blank%22%3E%40hqqddy%3C%2FA%3E%26nbsp%3B-%20getting%20that%20error%20while%20trying%20to%20disable%20one%20of%20the%20%22%3F%3F%3F%3F%3F%22%20entries%20towards%20the%20bottom%20of%20the%20list%2C%20is%20that%20correct%3F%3C%2FP%3E%3C%2FLINGO-BODY%3E
Co-Authors
Version history
Last update:
‎Oct 26 2021 12:45 PM
Updated by: