Following yesterday’s Sysmon 6 release, Microsoft Sysinternals has announced new releases of Autoruns, Process Explorer, Process Monitor, AccessChk, LiveKD and BgInfo. Autoruns now lists print monitors, the DLLs responsible for sending data from the Windows print spooler to the kernel mode print driver. We tried this on a Windows 10 laptop and found 10 installed monitors, mostly relating to PDF and other virtual printers. Unfortunately, Autoruns listed every monitor DLL as a "file not found", even for standard Windows files which definitely existed, and were stored in the usual locations. This could be a bug: if you see the same…
[Continue Reading]