Giter Site home page Giter Site logo

sysinternals's Introduction

sysinternals's People

Stargazers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

Watchers

 avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar  avatar

sysinternals's Issues

WHOIS v1.20 Issue

C:\Windows\System32>whois godaddy.com

Whois v1.20 - Domain information lookup
Copyright (C) 2005-2017 Mark Russinovich
Sysinternals - www.sysinternals.com

Connecting to COM.whois-servers.net...

WHOIS Server: whois.godaddy.com
   Registrar URL: http://www.godaddy.com
   Updated Date: 2014-04-09T04:15:36Z
   Creation Date: 1999-03-02T05:00:00Z
   Registry Expiry Date: 2021-11-01T11:59:59Z
   Registrar: GoDaddy.com, LLC
   Registrar IANA ID: 146
   Registrar Abuse Contact Email: [email protected]
   Registrar Abuse Contact Phone: 480-624-2505
   Domain Status: clientDeleteProhibited https://icann.org/epp#clientDeleteProhibited
   Domain Status: clientRenewProhibited https://icann.org/epp#clientRenewProhibited
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Domain Status: clientUpdateProhibited https://icann.org/epp#clientUpdateProhibited
   Domain Status: serverDeleteProhibited https://icann.org/epp#serverDeleteProhibited
   Domain Status: serverTransferProhibited https://icann.org/epp#serverTransferProhibited
   Domain Status: serverUpdateProhibited https://icann.org/epp#serverUpdateProhibited
   Name Server: A1-245.AKAM.NET
   Name Server: A11-64.AKAM.NET
   Name Server: A20-65.AKAM.NET
   Name Server: A6-66.AKAM.NET
   Name Server: A8-67.AKAM.NET
   Name Server: A9-67.AKAM.NET
   Name Server: CNS1.GODADDY.COM
   Name Server: CNS2.GODADDY.COM
   Name Server: CNS3.GODADDY.COM
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of whois database: 2018-01-09T06:23:04Z <<<

For more information on Whois status codes, please visit https://icann.org/epp

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.

Connecting to whois.godaddy.com...

Domain Name: GODADDY.COM
Registrar URL: http://www.godaddy.com
Registrant Name: Domain Administrator
Registrant Organization: Go Daddy Operating Company, LLC
Name Server: CNS1.GODADDY.COM
Name Server: CNS2.GODADDY.COM
Name Server: CNS3.GODADDY.COM
Name Server: A11-64.AKAM.NET
Name Server: A1-245.AKAM.NET
Name Server: A20-65.AKAM.NET
Name Server: A6-66.AKAM.NET
Name Server: A8-67.AKAM.NET
Name Server: A9-67.AKAM.NET
DNSSEC: unsigned

For complete domain details go to:
http://who.godaddy.com/whoischeck.aspx?domain=GODADDY.COM

The data contained in GoDaddy.com, LLC's WhoIs database,
while believed by the company to be reliable, is provided "as is"
with no guarantee or warranties regarding its accuracy.  This
information is provided for the sole purpose of assisting you
in obtaining information about domain name registration records.
Any use of this data for any other purpose is expressly forbidden without the prior written
permission of GoDaddy.com, LLC.  By submitting an inquiry,
you agree to these terms of usage and limitations of warranty.  In particular,
you agree not to use this data to allow, enable, or otherwise make possible,
dissemination or collection of this data, in part or in its entirety, for any
purpose, such as the transmission of unsolicited advertising and
and solicitations of any kind, including spam.  You further agree
not to use this data to enable high volume, automated or robotic electronic
processes designed to collect or compile this data for any purpose,
including mining this data for your own personal or commercial purposes.

Please note: the registrant of the domain name is specified
in the "registrant" section.  In most cases, GoDaddy.com, LLC
is not the registrant of domain names listed in this database.

Connecting to ODADDY.COM...

When doing a WHOIS lookup for godaddy.com for example, it properly redirects to whois.godaddy.com but then for some reason does a redirect to "odaddy.com".

When using some software, SYSMON's CPU usage and IO will increase abnormally.

When I use an Android simulator, Sysmon's CPU usage and IO will increase abnormally.
image
image

Software download url:https://www.yeshen.com/

Stack:
ntoskrnl.exe!KiCpuId+0xaa
ntoskrnl.exe!KeReleaseSpinLock+0x612
ntoskrnl.exe!KeWaitForMutexObject+0x1a3
ntoskrnl.exe!KeQueryActiveProcessorCountEx+0x218
ntoskrnl.exe!RtlNumberOfSetBitsUlongPtr+0x10cd
ntoskrnl.exe!KiCpuId+0x2553
ntoskrnl.exe!RtlFindClearBits+0x2f0
ntoskrnl.exe!ExDeleteNPagedLookasideList+0x2edab
ntoskrnl.exe!ExReleaseSpinLockSharedFromDpcLevel+0xec
ntoskrnl.exe!ExAllocatePoolWithTag+0x82e
ntoskrnl.exe!ExAllocatePoolWithQuotaTag+0x55
ntoskrnl.exe!NtQueryVolumeInformationFile+0x10df
ntoskrnl.exe!NtDeviceIoControlFile+0x56
ntoskrnl.exe!longjmp+0x5b93
ntdll.dll!ZwDeviceIoControlFile+0xa
KERNELBASE.dll!SystemTimeToTzSpecificLocalTimeEx+0x1322
kernel32.dll!DeviceIoControl+0x7f
Sysmon64.exe+0xdc5b
Sysmon64.exe+0xa1871
kernel32.dll!BaseThreadInitThunk+0xd
ntdll.dll!RtlUserThreadStart+0x1d

After closing the software:
image

junction - errorlevel is 0 on failed delete

The junction tool returns errorlevel 0 on failed delete:

test.bat

@echo off
junction  -nobanner -d c:\this_doesnt_exist 
echo Errorlevel: %errorlevel%
echo ^^ This should be anything but 0

outputs

Error deleting c:\this_doesnt_exist: The system cannot find the file specified.

Errorlevel: 0
^ This should be anything but 0

Sysmon: Performance considerations

Q1: Does Sysmon evaluate rules in a sequential way?
If yes. Would it make sense to re-order the policy and move the most frequently used rules to the top so we get a hit as fast as possible?

Q2: Image Condition
Someone mentioned in the sysinternals (now technet) forums that the performance hit is reduced when the filter "image" ist used instead of "is". Could you please clarify whether you expect a noticable difference.
calc.exe.. vs. calc.exe

sigcheck64.exe in batch problem

Hello, I want to use the sigcheck64.exe in a batch file on a new clean OS to verify product version numbers. When used in the batch with the -nobanner option it always returned empty. After starting it one time manually and agreeing the EULA, it worked also in the batch.
Is there an option to pass the agreement as option to be able to use it in the batch witout starting it manually?
Thanks,
Andreas.

Sigcheck supplies dummy signing date

When scanning a signed executable with a missing signature timestamp, sigcheck will silently substitute it with the current machine time. The objective of this substitution is unclear while it misleads users.

Interestingly, when run with option -i then the signature timestamp is correctly reported as n/a.

PS C:\> sigcheck64.exe bbflbk5*

Sigcheck v2.60 - File version and signature viewer
Copyright (C) 2004-2017 Mark Russinovich
Sysinternals - www.sysinternals.com

C:\bbflbk5.exe:
	Verified:	Signed
	Signing date:	6:36 PM 6/7/18
	Publisher:	Blueberry Software Ltd
	Company:	Blueberry Software (UK) Ltd.
	Description:	n/a
	Product:	FlashBack Pro 5
	Prod version:	5.31.0.4361
	File version:	5.31.0.4361
	MachineType:	32-bit

PS C:\> sigcheck64.exe bbflbk5*

Sigcheck v2.60 - File version and signature viewer
Copyright (C) 2004-2017 Mark Russinovich
Sysinternals - www.sysinternals.com

C:\bbflbk5.exe:
	Verified:	Signed
	Signing date:	6:37 PM 6/7/18
	Publisher:	Blueberry Software Ltd
	Company:	Blueberry Software (UK) Ltd.
	Description:	n/a
	Product:	FlashBack Pro 5
	Prod version:	5.31.0.4361
	File version:	5.31.0.4361
	MachineType:	32-bit

PS C:\> sigcheck64.exe -i bbflbk5*

Sigcheck v2.60 - File version and signature viewer
Copyright (C) 2004-2017 Mark Russinovich
Sysinternals - www.sysinternals.com

C:\bbflbk5.exe:
	Verified:	Signed
	Link date:	1:19 PM 2/24/12
	Signing date:	n/a
	Catalog:	C:\bbflbk5.exe
	Signers:
	   Blueberry Software Ltd
		Cert Status:	Valid
		Valid Usage:	Code Signing
		Cert Issuer:	COMODO RSA Code Signing CA
		Serial Number:	62 F6 DD E4 D6 02 D4 82 F8 30 41 79 B2 1D 42 70
		Thumbprint:	D68E7377F726BB5D5E467DFCEE9CE53B80EE1260
		Algorithm:	sha256RSA
		Valid from:	6:00 PM 8/31/17
		Valid to:	5:59 PM 8/31/20
	   COMODO RSA Code Signing CA
		Cert Status:	Valid
		Valid Usage:	Code Signing
		Cert Issuer:	COMODO RSA Certification Authority
		Serial Number:	2E 7C 87 CC 0E 93 4A 52 FE 94 FD 1C B7 CD 34 AF
		Thumbprint:	B69E752BBE88B4458200A7C0F4F5B3CCE6F35B47
		Algorithm:	sha384RSA
		Valid from:	6:00 PM 5/8/13
		Valid to:	5:59 PM 5/8/28
	   COMODO SECURE?
		Cert Status:	Valid
		Valid Usage:	Server Auth, Client Auth, Email Protection, Code Signing, Timestamp Signing, EFS, IPSEC Tunnel, IPSEC User
		Cert Issuer:	COMODO RSA Certification Authority
		Serial Number:	4C AA F9 CA DB 63 6F E0 1F F7 4E D8 5B 03 86 9D
		Thumbprint:	AFE5D244A8D1194230FF479FE2F897BBCD7A8CB4
		Algorithm:	sha384RSA
		Valid from:	6:00 PM 1/18/10
		Valid to:	5:59 PM 1/18/38
	Company:	Blueberry Software (UK) Ltd.
	Description:	n/a
	Product:	FlashBack Pro 5
	Prod version:	5.31.0.4361
	File version:	5.31.0.4361
	MachineType:	32-bit

Sdelete 2.01 has become very dangerous to execute potentially leading to data loss

Sdelete 2.01 has become very dangerous to execute
Command line parameter interpretation is ambiguous and can lead to data loss.

As per man page:

SDelete v2.01 - Secure file delete
Copyright (C) 1999-2018 Mark  Russinovich
Sysinternals - www.sysinternals.com

usage: sdelete [-p passes] [-r] [-s] [-q] <file or directory> [...]
       sdelete [-p passes] [-z|-c [percent free]] <drive letter [...]>
       sdelete [-p passes] [-z|-c] <physical disk number>
   -c         Clean free space. Specify an option amount of space
              to leave free for use by a running system.
   -p         Specifies number of overwrite passes (default is 1)
   -r         Remove Read-Only attribute
   -s         Recurse subdirectories
   -z         Zero free space (good for virtual disk optimization)
   -nobanner  Do not display the startup banner and copyright message.

Disks must not have any volumes in order to be cleaned.

The example below command intention should be zero-filling the E: drive leaving 1% disk space free.
Instead this command "cleaned" disk 1 and wiped everything off including the disk signature. The access denied is given because there where volumes on this disk 1. The command also did not do anything with target E: drive as it seems to be unable to find it.

C:\sysint>sdelete.exe -z 1 e:

SDelete v2.01 - Secure file delete
Copyright (C) 1999-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.

Cleaning disk 1:
Pass 0 progress: 0% (0.00 MB/s)
Error cleaning disk 1:
Access is denied.


Make sure that the disk has no file system volumes.


Cleaning disk e::

Error opening disk e::
The system cannot find the file specified.

I figured I must be wrong and tried the following command. This resulted in the drive being zero-filled, however the 50% free is not applied. It filled the drive until 0 percent free space.

C:\sysint>sdelete.exe -z50 e:

SDelete v2.01 - Secure file delete
Copyright (C) 1999-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.
Free space cleaned on E:\
1 drive cleaned.

C:\sysint>

The following command does do the intended zero-filling of free space, however there won't be any free space left during the process:

C:\sysint>sdelete -z e:

SDelete v2.01 - Secure file delete
Copyright (C) 1999-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.
Free space cleaned on E:\
1 drive cleaned.

There zero fill disk command (when removed all volumes from the drive) runs as expected:

C:\sysint>sdelete.exe -z 3

SDelete v2.01 - Secure file delete
Copyright (C) 1999-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.

Cleaning disk 3:
Disk 3 cleaned.

sdelete: Cleaning vs Zeroing?

If you use sdelete to cleaning or zeroing the disk space, the output is not correct.
Start with Zeroing:

C:\Programm\SDelete>sdelete -p 1 -c C:

SDelete v2.0 - Secure file delete
Copyright (C) 1999-2016 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.
Zeroing free space on C:\: 0%

and then after 1% switches to Cleaning:

C:\Programm\SDelete>sdelete -p 1 -c C:

SDelete v2.0 - Secure file delete
Copyright (C) 1999-2016 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.
Cleaning free space on C:\: 1%

also for "-z":

C:\Programm\SDelete>sdelete -p 1 -z C:

SDelete v2.0 - Secure file delete
Copyright (C) 1999-2016 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.
Zeroing free space on C:\: 0%

after a few seconds:

C:\Programm\SDelete>sdelete -p 1 -z C:

SDelete v2.0 - Secure file delete
Copyright (C) 1999-2016 Mark Russinovich
Sysinternals - www.sysinternals.com

SDelete is set for 1 pass.
Cleaning free space on C:\: 2%

and if run through sdelete64 the result will be the same.

How to determine which mode is working now and what is the difference in the -z or -c commands?

[NANO SERVER 1809] PsList

Hi All,

The pslist64.exe -accepteula -m dont working in container mcr.microsoft.com/windows/nanoserver:1809

I receive the following error:

Failed to take process snapshot on B953D67866FA.
Make sure that the Remote Registry service is running on the remote system, that you have
firewall ports allow RPC access, and your account has read access the following key on the remote system:
HKLM\Software\Microsoft\Windows NT\CurrentVersion\Perflib

More dump types are needed to add for ProcDump v9.0

https://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-178-Sysinternals-ProcDump-v90

•-mc Write a 'Custom' dump file. Include memory defined by the specified MINIDUMP_TYPE mask (Hex). -md Write a 'Callback' dump file. Include memory defined by the MiniDumpWriteDump callback routine named MiniDumpCallbackRoutine of the specified DLL
•-mk Also write a 'Kernel' dump file. Includes the kernel stacks of the threads in the process. OS doesn't support a kernel dump (-mk) when using a clone (-r). When using multiple dump sizes, a kernel dump is taken for each dump size

Handle V4.21 cannot match fully specified file name anymore

The versions V4.11 and V4.21 behave differently. Whereas 4.11 does find the PID of a file given (fully specified), V4.21 fails to do so:

V4.11:

C:\Temp> handle_v411.exe -u AFX5723.tmp

Nthandle v4.11 - Handle viewer
Copyright (C) 1997-2017 Mark Russinovich
Sysinternals - www.sysinternals.com

Skdaemon.exe pid: 10044 type: File DOMAIN\user.name 224: C:\Temp\AFX5723.tmp

V4.21:

C:\Temp> handle_v421.exe -u AFX5723.tmp

Nthandle v4.21 - Handle viewer
Copyright (C) 1997-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

No matching handles found.

but if 4.21 gets only a part of the filename, it will find the corresponding handle!

C:\Temp> handle_v421.exe -u AFX5723.tm

Nthandle v4.21 - Handle viewer
Copyright (C) 1997-2018 Mark Russinovich
Sysinternals - www.sysinternals.com

Skdaemon.exe pid: 10044 type: File DOMAIN\user.name 224: C:\Temp\AFX5723.tmp

Sigcheck lacks exit codes

It seems that sigcheck uses exit codes to communicate some issues with files. E.g. 1 seems to indicate files that are unsigned (gleaned from the web). I have an exit code of 4, but without docs I'm unable to know what that means. Please add docs for exit codes to this and I'd assume other tools.

Typo in EULA for regjump

When I ran RegJump for the first time, I noticed the name of Sysinternals is spelled incorrectly as "Systinternals.com"

I also noticed this for Process Explorer, which leads me to believe this may be present in many of the tools.

BG Info 4.22 not working with scripts

BG info crashes when running vbs scripts.
here is a simple script for ip info in a format that allows multiple nics.
Thit crashes the latest version

``
strMsg = ""
strComputer = "."

Set objWMIService = GetObject("winmgmts:" & "{impersonationLevel=impersonate}!\" & strComputer & "\root\cimv2")
Set IPConfigSet = objWMIService.ExecQuery("Select IPAddress, description from Win32_NetworkAdapterConfiguration WHERE IPEnabled = 'True'")

For Each IPConfig in IPConfigSet

If Not IsNull(IPConfig.IPAddress) Then
For i = LBound(IPConfig.IPAddress) To UBound(IPConfig.IPAddress)
If Not Instr(IPConfig.IPAddress(i), ":") > 0 Then
If UBound(IPConfig.IPAddress) = 1 then
strMsg = strMsg & " (" & IPConfig.IPAddress(0) & ") & (" & IPConfig.IPAddress(1) & ")" & vbCrLf
Else
strMsg = strMsg & " (" & IPConfig.IPAddress(0) & ") & (Disabled)" & vbCrLf
End If
Exit For
ElseIf Not Instr(IPConfig.IPAddress(i), ".") > 0 Then
If UBound(IPConfig.IPAddress) = 1 then
strMsg = strMsg & " (" & IPConfig.IPAddress(0) & ") & (" & IPConfig.IPAddress(1) & ")" & vbCrLf
Else
strMsg = strMsg & " (Disabled) & (" & IPConfig.IPAddress(0) & ")" & vbCrLf
End If
Exit For
End If
Next
End If
Next
If Right(strmsg,2) = vbCrLf Then
strmsg = Left(strmsg,Len(strmsg)-2)
End If

if len(strMsg) = 0 Then
strMsg = " (No IpAddresses)"
End if

Echo strMsg
``

Symbol download failed when use process monitor

Hi,

We only push pdb file in my company's symbol server.
i find the process monitor can't show the function in UI. I checked the dbghelp log, i find the tool first download the excute file from symbol server, when it fail, it search in the local, and it success. it start find the pdb file, but it don't search from symbol server, it only find the local, so it failed.

May this tool support search the pdb file from symbol server when search the execute file from symbol server failed?
Thank you.

Sysmon parsing issue when empty field in forwardedevents

Using Sysmon in conjunction with Windows event forwarding, when a field is empty in a Sysmon log (for example SourcePortName in EventID 3) the windows event viewer can't parse the event correctly. For the local sysmon logs everything is ok, but in the forwarded events on the WEC all fields are shifted.
example:

SourcePortName: false
DestinationIsIpv6: 40.113.200.201
DestinationIp: microsoft.com
DestinationHostname: 443
DestinationPort: %16
DestinationPortName: %17

Process Explorer: crashes when environment variable name length is 264 characters or more

To reproduce the bug, set environment variable in cmd.exe and open Process Properties->Environment tab for the process
set nnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnnn=Crash

Sysmon TCP SYN

Whether the network monitoring of SYSMON supports the behavior of trying to connect, for example, only sending the SYN packet, and the connection is not established. thx

ZoomIt PenWidth Stays on 367580

Whatever I do (use left CTRL + mouse, left CTRL + down arrow or changing the value directly in the registry) my PenWidth always stays at or comes back to 367580. Using draw with that size colors my complete screen and I have no way of actually drawing anything. Deleting ZoomIt and downloading it again produces the same problem.

grafik

Sysmon 6 and 7 Locking Up Trend Officescan and Entire Server on Server 2008R2

We have been having issues with our Server 2008R2 machines locking up for the last 2 years, after much research and working with Trend it appears that this is an issue caused by sysmon and they refuse to fix it.

Here is there responses.

Hi All,

Good day! so I did ask our Developers if they have a plan to release a hotfix and this is what they said.

"It is SysmonDrv.sys that blocks the IPC operation in Ntrtscan as previous update shows.We will not have plan to release hotfix for this issue.
Actually, customer should contact Microsoft for the further investigation as removing sysmon driver resolve the issue"

Based on the Dump files It is the SysmonDrv.sys that is blocking the IPC operationg in the Ntrtscan (Real time Scan). So it is not actually the Trend Micro OfficeScan that has the problem it is the SysmonDrv.sys that is causing the conflict.

As per the suggestion of the Developers you need to contact the Microsoft for the further investigation since we prove that removing the Sysmon actually fix the issue

add note that contig64 is broken

Please add a note on the contig sysinternals page that the 64-bit version contig64 is broken. I was consistently receiving STATUS_ALREADY_COMMITTED. The problem is shared by others, as per Google.

This isn't a bugfix request. But a note not to use the 64-bit version would save others after me a lot of pain. I was for a long time convinced it can't be made to work. See background.


Background:

I'm using a 2TB partition for bulk data storage. Bundled Windows defrag utility hangs while analyzing it.

A third-party defrag program skips over two 100 GB files, being preallocated VM disks. The files had lots of small fragments and a great amount of fragments in total.

More mistakes in sysinternals/sysinternals/downloads/sysmon.md

First problem
In the picture:
image
It says, "Do not log process termination", but the value of "onmatch" is "include". It should be "exclude".

Second problem
The example of "RuleGroup" can not work.
When I write them to a file "example.xml" as follows:

<Sysmon schemaversion="4.20">
    <!-- Capture all hashes -->
    <HashAlgorithms>*</HashAlgorithms>
    <EventFiltering>
        <Group name="group 1" groupRelation="and">
            <ProcessCreate onmatch="include">
                <Image condition="contains">timeout.exe</Image>
                <CommandLine condition="contains">100</CommandLine>
            </ProcessCreate>
        </Group>
        <Group groupRelation="or">
            <ProcessTerminate onmatch="include"/>
            <Image condition="contains">timeout.exe</Image>
            <Image condition="contains">ping.exe</Image>
        </Group>
        <ImageLoad onmatch="include"/>
    </EventFiltering>
</Sysmon>

And I use a command like this:
sysmon -c example.xml
Then the output is:

Error: Incorrect XML configuration: example.xml
Reason: ????? 'EventFiltering' ???????? 'Group' ??????
??: RuleGroup, ProcessCreate, FileCreateTime, NetworkConnect, ProcessTerminate, DriverLoad, ImageLoad, CreateRemoteThread, RawAccessRead, ProcessAccess, FileCreate, RegistryEvent, FileCreateStreamHash, PipeEvent, WmiEvent?

Who can help me?

Autoruns / Space in executable path to hide from autoruns

Looks like autoruns can be fooled by inserting a space in a executable path since Command and Arguments attribute get concatenated with a space in between. Interesting corner case but would be great if autoruns would check for this condition.

Details:
TL;DR; Creating a scheduled task with a space in the file path will “hide” the executable from Autoruns. The file path is split on the space, the first part becomes the scheduled task’s command and the second part is treated as the command’s arguments. Autoruns uses the command as the image (executable) path for scheduled tasks. Tested on Windows 7, 2012, and 10. The task only ran on Windows 2012 and 10.

https://medium.com/@jdferrell3/scheduled-task-command-with-space-hides-the-file-from-autoruns-1c7bfe38a67c

Sysmon memory leak

I faced a bug in Sysmon (ver. 7.01 and 7.03) - Sysmon's driver (SysmonDrv.sys) consumes new area in Nonpaged pool memory every time configuration reloads, but driver does not free old area in Nonpaged pool memory. As a result, We can see memory leak. I found this problem on my VM, which had only 4GB RAM and more than 180 uptime days.
I used this script to reproduce bug:
$sleep = 0
$ErrorActionPreference = "SilentlyContinue"
$iterationPeriod = New-TimeSpan -Seconds 2
$scriptDuration = New-TimeSpan -Hours 1
$scriptStopWatch = [System.Diagnostics.Stopwatch]::StartNew()
while($scriptStopWatch.ElapsedMilliseconds -le $scriptDuration.TotalMilliseconds)
{
if($sleep -gt 0){Start-Sleep -Milliseconds $sleep }
$iterationStopWatch = [System.Diagnostics.Stopwatch]::StartNew()
Invoke-Expression 'C:\Windows\Sysmon64.exe -c "C:\Windows\SysmonConfig.xml"' |Out-Null
$iterationStopWatch.Stop()
$iterationTime = $iterationStopWatch.Elapsed
$sleep = $iterationPeriod.TotalMilliseconds - $iterationTime.TotalMilliseconds
}
$scriptStopWatch.Stop()

SysR is Sysmon driver tag, as you see, it took 252313744 Bytes (240 MBytes)

Portmon compatibility

The issue was created by @PeterMortensen from MicrosoftDocs/feedback#287 (comment)

https://docs.microsoft.com/en-us/sysinternals/downloads/portmon fails to mention on which newer versions of Windows it works, including the bitness of the operating system (e.g. not working on Windows 7 64-bit and Windows 10 64-bit, but working on Windows 7 32-bit, etc. - I am not sure which of these are correct).
It should explicitly list where it works and where it doesn't. A table would be fine.
It seems like the information has not been updated since 2012, and as a result a lot of users end up beeing very frustrated.
E.g. ref.: https://superuser.com/questions/927948/portmon-portmsys-sys-not-found/927969#927969

BGInfo and BGInfo64 v4.23 crash when adding/using certain custom fields

When adding a custom field that utilizes certain options, the program crashes after clicking the final OK button.

File contents: crashes
WMI query: crashes

Sample WMI query used: SELECT CurrentClockSpeed FROM Win32_Processor WHERE DeviceID='CPU0'

Additionally, it is unable to open any .BGI saved that utilizes any custom fields. Curiously, attempting to open said .BGI files does not cause a crash, it just reverts back to the main screen.

Event Log: Event ID 1000
Faulting application name: BGInfo64.exe, version: 4.23.0.0, time stamp: 0x5a2c885b
Faulting module name: BGInfo64.exe, version: 4.23.0.0, time stamp: 0x5a2c885b
Exception code: 0xc0000409
Fault offset: 0x000000000025119c
Faulting process id: 0x8e8
Faulting application start time: 0x01d373b92b0d50d6
Faulting application path: C:\UTILS\BGInfo\BGInfo64.exe
Faulting module path: C:\UTILS\BGInfo\BGInfo64.exe
Report Id: c2aa43d5-9106-4ac2-ab0e-ef836581b402
Faulting package full name:
Faulting package-relative application ID:

Event Log: Event ID 1001
Fault bucket 1809349670476882291, type 5
Event Name: BEX64
Response: Not available
Cab Id: 0

Problem signature:
P1: BGInfo64.exe
P2: 4.23.0.0
P3: 5a2c885b
P4: BGInfo64.exe
P5: 4.23.0.0
P6: 5a2c885b
P7: 000000000025119c
P8: c0000409
P9: 0000000000000008
P10:

Attached files:
\?\C:\ProgramData\Microsoft\Windows\WER\Temp\WER474E.tmp.WERInternalMetadata.xml

These files may be available here:
C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_BGInfo64.exe_fc378249c91358d2c47ae6bd5e66bf6f2622b9_aeba361a_03ac81c7

Analysis symbol:
Rechecking for solution: 0
Report Id: c2aa43d5-9106-4ac2-ab0e-ef836581b402
Report Status: 0

BGInfo /TIMER:0 doesn't work, creates zombie process.

On the Dec 12th version, on Server 2016, if I run "bginfo.exe /timer:0" -- nothing seems to happen. I see there is a bginfo process running in taskmanager. And, if I press "c" the "user defined fields" pops up, so it's like interface is running invisibly. Consequently, this version doesn't work through GPO and such, and fills systems with zombie copies of bgingo processes. It does the same thing with bginfo and bginfo64.

Got black screen in VMware® Workstation 11.1.3 build-3206955

Perhaps a message about this problem could be added in the documentation (could produce black screen on start up of VMware clients!?) Didn't know where to tell this case. (Both machines are Windows 7). Worked again after reboot of the host with disabled Desktops.

VMware Log:

2017-09-04T09:15:36.019+02:00| mks| I120: MKS-SWB: Window #0 validation failed: no valid host window or host surface.
2017-09-04T09:15:36.019+02:00| mks| I120: GDI-Backend: successfully started by HWinMux to do window composition.
2017-09-04T09:15:36.019+02:00| mks| I120: MKS-HWinCompMux: Started GDI presentation backend
2017-09-04T09:15:36.019+02:00| mks| W110: MKSWin32_CreateWindow: Failed to create window: Unknown error 1400 (0x578) (1400)
2017-09-04T09:15:36.019+02:00| mks| I120: MKS-HWinCompMux: Failed PreDefineWindow
2017-09-04T09:15:36.019+02:00| mks| W110: MKS-SWB: HWin failed to define window.
2017-09-04T09:15:36.019+02:00| mks| W110: MKSWin32_CreateWindow: Failed to create window: Unknown error 1400 (0x578) (1400)
2017-09-04T09:15:36.019+02:00| mks| I120: MKS-HWinCompMux: Failed PreDefineWindow
2017-09-04T09:15:36.019+02:00| mks| W110: MKS-SWB: HWin failed to define window.
2017-09-04T09:15:36.035+02:00| vmx| I120: Vix: [5788 mainDispatch.c:4790]: VMAutomationProcessMessage: Postpone the command. MSG in progress (opcode 151)

Best Regards,
Mayra

Mistakes in sysinternals/sysinternals/downloads/sysmon.md

Current sysmon.md does not match what is output by the command "sysmon.exe -? config".
Current sysmon.md:
You can use both include and exclude rules for the same tag, where exclude rules override include rules. Within a rule, filter conditions on the same field have OR behavior, whereas conditions on different fields have AND behavior. In the sample configuration shown earlier, the networking filter uses both an include and exclude rule to capture activity to port 80 and 443 by all processes except those that have iexplore.exe in their name.

"sysmon.exe -? config":
You can use both include and exclude rules for the same tag, where exclude rules override include rules.
Within a rule, filter conditions have OR behavior. In the sample configuration shown earlier, the networking filter uses both an include and exclude rule to capture activity to port 80 and 443 by all processes except those that have iexplore.exe in their name.

There is the same mistake above "Condition - Description" table:
Each filter can include zero or more rules. Each tag under the filter tag is a field name from the event. Rules that specify a condition for the same field name behave as OR conditions, and ones that specify different field name behave as AND conditions. Field rules can also use conditions to match a value. The conditions are as follows (all are case insensitive):

Whois v1.14

Whois v1.14 is no longer properly redirecting to the registrar's WHOIS server for Verisign TLDs such as .com and .net. I believe this is because the WHOIS format was changed from "Whois Server:" to "Registrar WHOIS Server:" somewhat recently.

Bugcheck code 00000050

0: kd> .bugcheck
Bugcheck code 00000050
Arguments ffffb288402043fa 0000000000000000 fffff80c42651285 0000000000000002
0: kd> kv
*** Stack trace for last set context - .thread/.cxr resets it

Child-SP RetAddr : Args to Child : Call Site

00 fffff28282c7b978 fffff80c426532b8 : 0000000000000000 0000000000000000 0000000000000000 0000000000000000 : PROCMON23+0x1285
01 fffff28282c7b980 fffff80c42653795 : ffffc90beeb55100 ffffc90bfe99efb0 ffffc90bf58b4080 ffffc90beeb55100 : PROCMON23+0x32b8
02 fffff28282c7b9e0 fffff80c42652f84 : ffffc90bfe99ee00 ffffc90bfe99eee0 ffffc90bfe99eef8 00000000000000c0 : PROCMON23+0x3795
03 fffff28282c7ba30 fffff80c3ecd6a8a : 00000000c0000000 ffffc90bfe99ee00 ffffc90bfe99ef80 ffffc90b00000154 : PROCMON23+0x2f84
04 fffff28282c7ba80 fffff80c3ecd6246 : ffffc90bed5a7000 fffff8002f64cc00 0000000000000000 0000000000000000 : FLTMGR!FltpPerformPostCallbacks+0x47a
05 fffff28282c7bb60 fffff80c3ecd5ffc : fffff987eca7aaf0 fffff8002f972bc0 ffffc90bfeb8f960 ffffc90bfc6d9ac0 : FLTMGR!FltpPassThroughCompletionWorker+0x76
06 fffff28282c7bbd0 fffff8002fdc2ce0 : ffffc90bfeb8f9c8 fffff8002f972bc0 ffffc90bfeb8f960 ffffc90bfc6d9ac0 : FLTMGR!FltpPassThroughCompletion+0xc
07 fffff28282c7bc00 fffff8002fdc2f9c : fffff8002f972bd0 fffff8002f972bc0 0000000000000080 fffff8002fdc2f70 : nt!ViPendingCompleteAfterWait+0xe8
08 fffff28282c7bc50 fffff8002f6d3967 : ffffc90bed5a7040 0000000000000080 fffff8002fdc2f70 0000080800000000 : nt!ViPendingWorkerThread+0x2c
09 fffff28282c7bc90 fffff8002f791fb6 : fffff8002dfae180 ffffc90bed5a7040 fffff8002f6d3920 0065007000790054 : nt!PspSystemThreadStartup+0x47
0a fffff28282c7bce0 0000000000000000 : fffff28282c7c000 fffff28282c76000 0000000000000000 0000000000000000 : nt!KiStartSystemThread+0x16
0: kd> r
Last set context:
rax=ffffb288402042aa rbx=0000000000000000 rcx=ffffc90beeb55250
rdx=ffffe97c516af1aa rsi=0000000000000000 rdi=0000000000000000
rip=fffff80c42651285 rsp=fffff28282c7b978 rbp=0000000000080009
r8=0000000000000154 r9=ffffc90beeb55100 r10=0000000000001001
r11=ffffc90beeb55100 r12=0000000000000000 r13=0000000000000000
r14=0000000000000000 r15=0000000000000000
iopl=0 nv up ei ng nz na po nc
cs=0010 ss=0018 ds=0000 es=0000 fs=0000 gs=0000 efl=00010286
PROCMON23+0x1285:
fffff80c42651285 8b040a mov eax,dword ptr [rdx+rcx] ds:ffffb288402043fa=????????
0: kd> lm vm procmon23
Browse full module list
start end module name
fffff80c42650000 fffff80c42669000 PROCMON23 (no symbols)
Loaded symbol image file: PROCMON23.SYS
Image path: PROCMON23.SYS
Image name: PROCMON23.SYS
Browse all global symbols functions data
Timestamp: Sun Sep 10 13:52:05 2017 (59B5A5F5)
CheckSum: 0001E54E
ImageSize: 00019000
Translations: 0000.04b0 0000.04e4 0409.04b0 0409.04e4
Information from resource tables:

https://correy.webs.com

Sigcheck supplies dummy signing date (still)

I am still observing issue #91 in the latest version, 2.72.
(Github does not allow me to re-open the original issue.)


C:\>sigcheck64 -vr bbflbk5.exe

Sigcheck v2.72 - File version and signature viewer
Copyright (C) 2004-2019 Mark Russinovich
Sysinternals - www.sysinternals.com
C:\bbflbk5.exe:
        Verified:       Signed
        Signing date:   10:07 AM 5/21/19
        Publisher:      Blueberry Software Ltd
        Company:        Blueberry Software (UK) Ltd.
        Description:    n/a
        Product:        FlashBack Pro 5
        Prod version:   5.36.0.4417
        File version:   5.36.0.4417
        MachineType:    32-bit
        VT detection:   0/70
        VT link:        https://www.virustotal.com/file/1d3c37f04a6e13eb1e7e1375fb49d650afb3eb42b04999fd337e39520d4ff527/analysis/

C:\>sigcheck64 -vr bbflbk5.exe

Sigcheck v2.72 - File version and signature viewer
Copyright (C) 2004-2019 Mark Russinovich
Sysinternals - www.sysinternals.com

C:\bbflbk5.exe:
        Verified:       Signed
        Signing date:   10:11 AM 5/21/19
        Publisher:      Blueberry Software Ltd
        Company:        Blueberry Software (UK) Ltd.
        Description:    n/a
        Product:        FlashBack Pro 5
        Prod version:   5.36.0.4417
        File version:   5.36.0.4417
        MachineType:    32-bit
        VT detection:   0/70
        VT link:        https://www.virustotal.com/file/1d3c37f04a6e13eb1e7e1375fb49d650afb3eb42b04999fd337e39520d4ff527/analysis/

C:\>

Whois V1.20 loops outputting the whois information over and over

When using whois from a cmd prompt in Windows 7 Ultimate 64 bit I find it often loops outputting the whois information over and over, only stopping then I use Ctrl/C.
e.g.

C:\Users\Brian G>whois namecheap.com

Whois v1.20 - Domain information lookup
Copyright (C) 2005-2017 Mark Russinovich
Sysinternals - www.sysinternals.com

Connecting to COM.whois-servers.net...

WHOIS Server: whois.enom.com
   Registrar URL: http://www.enom.com
   Updated Date: 2017-06-16T21:53:04Z
   Creation Date: 2000-08-11T16:15:25Z
   Registry Expiry Date: 2025-08-11T16:15:25Z
   Registrar: eNom, Inc.
   Registrar IANA ID: 48
   Registrar Abuse Contact Email:
   Registrar Abuse Contact Phone:
   Domain Status: clientTransferProhibited https://icann.org/epp#clientTransferProhibited
   Name Server: A1.VERISIGNDNS.COM
   Name Server: A2.VERISIGNDNS.COM
   Name Server: A3.VERISIGNDNS.COM
   DNSSEC: unsigned
   URL of the ICANN Whois Inaccuracy Complaint Form: https://www.icann.org/wicf/
>>> Last update of whois database: 2018-03-19T20:03:44Z <<<

For more information on Whois status codes, please visit https://icann.org/epp

NOTICE: The expiration date displayed in this record is the date the
registrar's sponsorship of the domain name registration in the registry is
currently set to expire. This date does not necessarily reflect the expiration
date of the domain name registrant's agreement with the sponsoring
registrar.  Users may consult the sponsoring registrar's Whois database to
view the registrar's reported date of expiration for this registration.

TERMS OF USE: You are not authorized to access or query our Whois
database through the use of electronic processes that are high-volume and
automated except as reasonably necessary to register domain names or
modify existing registrations; the Data in VeriSign Global Registry
Services' ("VeriSign") Whois database is provided by VeriSign for
information purposes only, and to assist persons in obtaining information
about or related to a domain name registration record. VeriSign does not
guarantee its accuracy. By submitting a Whois query, you agree to abide
by the following terms of use: You agree that you may use this Data only
for lawful purposes and that under no circumstances will you use this Data
to: (1) allow, enable, or otherwise support the transmission of mass
unsolicited, commercial advertising or solicitations via e-mail, telephone,
or facsimile; or (2) enable high volume, automated, electronic processes
that apply to VeriSign (or its computer systems). The compilation,
repackaging, dissemination or other use of this Data is expressly
prohibited without the prior written consent of VeriSign. You agree not to
use electronic processes that are automated and high-volume to access or
query the Whois database except as reasonably necessary to register
domain names or modify existing registrations. VeriSign reserves the right
to restrict your access to the Whois database in its sole discretion to ensure
operational stability.  VeriSign may restrict or terminate your access to the
Whois database for failure to abide by these terms of use. VeriSign
reserves the right to modify these terms at any time.

The Registry database contains ONLY .COM, .NET, .EDU domains and
Registrars.

Connecting to whois.enom.com...

WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2017-01-13T05:52:52.00Z
Creation Date: 2000-08-11T12:15:25.00Z
Registrar Registration Expiration Date: 2025-08-11T16:15:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP, INC
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: NAMECHEAP.COM NAMECHEAP.COM
Registrant Organization: NAMECHEAP, INC
Registrant Street: 4600 EAST WASHINGTON STREET, SUITE 305
Registrant City: PHOENIX
Registrant State/Province: AZ
Registrant Postal Code: 85034
Registrant Country: US
Registrant Phone: +1.6613102107
Registrant Phone Ext:
Registrant Fax: +1.6613102107
Registrant Fax Ext:
Registrant Email: [email protected]
Registry Admin ID:
Admin Name: NAMECHEAP.COM NAMECHEAP.COM
Admin Organization: NAMECHEAP, INC
Admin Street: 4600 EAST WASHINGTON STREET, SUITE 305
Admin City: PHOENIX
Admin State/Province: AZ
Admin Postal Code: 85034
Admin Country: US
Admin Phone: +1.6613102107
Admin Phone Ext:
Admin Fax: +1.6613102107
Admin Fax Ext:
Admin Email: [email protected]
Registry Tech ID:
Tech Name: NAMECHEAP.COM NAMECHEAP.COM
Tech Organization: NAMECHEAP, INC
Tech Street: 4600 EAST WASHINGTON STREET, SUITE 305
Tech City: PHOENIX
Tech State/Province: AZ
Tech Postal Code: 85034
Tech Country: US
Tech Phone: +1.6613102107
Tech Phone Ext:
Tech Fax: +1.6613102107
Tech Fax Ext:
Tech Email: [email protected]
Name Server: A1.VERISIGNDNS.COM
Name Server: A2.VERISIGNDNS.COM
Name Server: A3.VERISIGNDNS.COM
DNSSEC: unSigned
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4252982646
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2017-01-13T05:52:52.00Z <<<

For more information on Whois status codes, please visit https://icann.org/epp


The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us.

We reserve the right to modify these terms at any time. By submitting
this query, you agree to abide by these terms.
Version 6.3 4/3/2002

Get Noticed on the Internet!  Increase visibility for this domain name by listing it at www.whoisbusinesslistings.com
Connecting to whois.enom.com...

WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2017-01-13T05:52:52.00Z
Creation Date: 2000-08-11T12:15:25.00Z
Registrar Registration Expiration Date: 2025-08-11T16:15:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP, INC
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: NAMECHEAP.COM NAMECHEAP.COM
Registrant Organization: NAMECHEAP, INC
Registrant Street: 4600 EAST WASHINGTON STREET, SUITE 305
Registrant City: PHOENIX
Registrant State/Province: AZ
Registrant Postal Code: 85034
Registrant Country: US
Registrant Phone: +1.6613102107
Registrant Phone Ext:
Registrant Fax: +1.6613102107
Registrant Fax Ext:
Registrant Email: [email protected]
Registry Admin ID:
Admin Name: NAMECHEAP.COM NAMECHEAP.COM
Admin Organization: NAMECHEAP, INC
Admin Street: 4600 EAST WASHINGTON STREET, SUITE 305
Admin City: PHOENIX
Admin State/Province: AZ
Admin Postal Code: 85034
Admin Country: US
Admin Phone: +1.6613102107
Admin Phone Ext:
Admin Fax: +1.6613102107
Admin Fax Ext:
Admin Email: [email protected]
Registry Tech ID:
Tech Name: NAMECHEAP.COM NAMECHEAP.COM
Tech Organization: NAMECHEAP, INC
Tech Street: 4600 EAST WASHINGTON STREET, SUITE 305
Tech City: PHOENIX
Tech State/Province: AZ
Tech Postal Code: 85034
Tech Country: US
Tech Phone: +1.6613102107
Tech Phone Ext:
Tech Fax: +1.6613102107
Tech Fax Ext:
Tech Email: [email protected]
Name Server: A1.VERISIGNDNS.COM
Name Server: A2.VERISIGNDNS.COM
Name Server: A3.VERISIGNDNS.COM
DNSSEC: unSigned
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4252982646
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2017-01-13T05:52:52.00Z <<<

For more information on Whois status codes, please visit https://icann.org/epp


The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us.

We reserve the right to modify these terms at any time. By submitting
this query, you agree to abide by these terms.
Version 6.3 4/3/2002

Get Noticed on the Internet!  Increase visibility for this domain name by listing it at www.whoisbusinesslistings.com
Connecting to whois.enom.com...

WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2017-01-13T05:52:52.00Z
Creation Date: 2000-08-11T12:15:25.00Z
Registrar Registration Expiration Date: 2025-08-11T16:15:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP, INC
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: NAMECHEAP.COM NAMECHEAP.COM
Registrant Organization: NAMECHEAP, INC
Registrant Street: 4600 EAST WASHINGTON STREET, SUITE 305
Registrant City: PHOENIX
Registrant State/Province: AZ
Registrant Postal Code: 85034
Registrant Country: US
Registrant Phone: +1.6613102107
Registrant Phone Ext:
Registrant Fax: +1.6613102107
Registrant Fax Ext:
Registrant Email: [email protected]
Registry Admin ID:
Admin Name: NAMECHEAP.COM NAMECHEAP.COM
Admin Organization: NAMECHEAP, INC
Admin Street: 4600 EAST WASHINGTON STREET, SUITE 305
Admin City: PHOENIX
Admin State/Province: AZ
Admin Postal Code: 85034
Admin Country: US
Admin Phone: +1.6613102107
Admin Phone Ext:
Admin Fax: +1.6613102107
Admin Fax Ext:
Admin Email: [email protected]
Registry Tech ID:
Tech Name: NAMECHEAP.COM NAMECHEAP.COM
Tech Organization: NAMECHEAP, INC
Tech Street: 4600 EAST WASHINGTON STREET, SUITE 305
Tech City: PHOENIX
Tech State/Province: AZ
Tech Postal Code: 85034
Tech Country: US
Tech Phone: +1.6613102107
Tech Phone Ext:
Tech Fax: +1.6613102107
Tech Fax Ext:
Tech Email: [email protected]
Name Server: A1.VERISIGNDNS.COM
Name Server: A2.VERISIGNDNS.COM
Name Server: A3.VERISIGNDNS.COM
DNSSEC: unSigned
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4252982646
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2017-01-13T05:52:52.00Z <<<

For more information on Whois status codes, please visit https://icann.org/epp


The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us.

We reserve the right to modify these terms at any time. By submitting
this query, you agree to abide by these terms.
Version 6.3 4/3/2002

Get Noticed on the Internet!  Increase visibility for this domain name by listing it at www.whoisbusinesslistings.com
Connecting to whois.enom.com...

WHOIS Server: whois.enom.com
Registrar URL: www.enom.com
Updated Date: 2017-01-13T05:52:52.00Z
Creation Date: 2000-08-11T12:15:25.00Z
Registrar Registration Expiration Date: 2025-08-11T16:15:00.00Z
Registrar: ENOM, INC.
Registrar IANA ID: 48
Reseller: NAMECHEAP, INC
Domain Status: clientTransferProhibited https://www.icann.org/epp#clientTransferProhibited
Registry Registrant ID:
Registrant Name: NAMECHEAP.COM NAMECHEAP.COM
Registrant Organization: NAMECHEAP, INC
Registrant Street: 4600 EAST WASHINGTON STREET, SUITE 305
Registrant City: PHOENIX
Registrant State/Province: AZ
Registrant Postal Code: 85034
Registrant Country: US
Registrant Phone: +1.6613102107
Registrant Phone Ext:
Registrant Fax: +1.6613102107
Registrant Fax Ext:
Registrant Email: [email protected]
Registry Admin ID:
Admin Name: NAMECHEAP.COM NAMECHEAP.COM
Admin Organization: NAMECHEAP, INC
Admin Street: 4600 EAST WASHINGTON STREET, SUITE 305
Admin City: PHOENIX
Admin State/Province: AZ
Admin Postal Code: 85034
Admin Country: US
Admin Phone: +1.6613102107
Admin Phone Ext:
Admin Fax: +1.6613102107
Admin Fax Ext:
Admin Email: [email protected]
Registry Tech ID:
Tech Name: NAMECHEAP.COM NAMECHEAP.COM
Tech Organization: NAMECHEAP, INC
Tech Street: 4600 EAST WASHINGTON STREET, SUITE 305
Tech City: PHOENIX
Tech State/Province: AZ
Tech Postal Code: 85034
Tech Country: US
Tech Phone: +1.6613102107
Tech Phone Ext:
Tech Fax: +1.6613102107
Tech Fax Ext:
Tech Email: [email protected]
Name Server: A1.VERISIGNDNS.COM
Name Server: A2.VERISIGNDNS.COM
Name Server: A3.VERISIGNDNS.COM
DNSSEC: unSigned
Registrar Abuse Contact Email: [email protected]
Registrar Abuse Contact Phone: +1.4252982646
URL of the ICANN WHOIS Data Problem Reporting System: http://wdprs.internic.net/
>>> Last update of WHOIS database: 2017-01-13T05:52:52.00Z <<<

For more information on Whois status codes, please visit https://icann.org/epp


The data in this whois database is provided to you for information
purposes only, that is, to assist you in obtaining information about or
related to a domain name registration record. We make this information
available "as is," and do not guarantee its accuracy. By submitting a
whois query, you agree that you will use this data only for lawful
purposes and that, under no circumstances will you use this data to: (1)
enable high volume, automated, electronic processes that stress or load
this whois database system providing you this information; or (2) allow,
enable, or otherwise support the transmission of mass unsolicited,
commercial advertising or solicitations via direct mail, electronic
mail, or by telephone. The compilation, repackaging, dissemination or
other use of this data is expressly prohibited without prior written
consent from us.

We reserve the right to modify these terms at any time. By submitting
this query, you agree to abide by these terms.
Version 6.3 4/3/2002

Get Noticed on the Internet!  Increase visibility for this domain name by listing it at www.whoisbusinesslistings.com
Connecting to whois.enom.com...
^C
C:\Users\Brian G>

Recommend Projects

  • React photo React

    A declarative, efficient, and flexible JavaScript library for building user interfaces.

  • Vue.js photo Vue.js

    🖖 Vue.js is a progressive, incrementally-adoptable JavaScript framework for building UI on the web.

  • Typescript photo Typescript

    TypeScript is a superset of JavaScript that compiles to clean JavaScript output.

  • TensorFlow photo TensorFlow

    An Open Source Machine Learning Framework for Everyone

  • Django photo Django

    The Web framework for perfectionists with deadlines.

  • D3 photo D3

    Bring data to life with SVG, Canvas and HTML. 📊📈🎉

Recommend Topics

  • javascript

    JavaScript (JS) is a lightweight interpreted programming language with first-class functions.

  • web

    Some thing interesting about web. New door for the world.

  • server

    A server is a program made to process requests and deliver data to clients.

  • Machine learning

    Machine learning is a way of modeling and interpreting data that allows a piece of software to respond intelligently.

  • Game

    Some thing interesting about game, make everyone happy.

Recommend Org

  • Facebook photo Facebook

    We are working to build community through open source technology. NB: members must have two-factor auth.

  • Microsoft photo Microsoft

    Open source projects and samples from Microsoft.

  • Google photo Google

    Google ❤️ Open Source for everyone.

  • D3 photo D3

    Data-Driven Documents codes.