From Wikipedia, the free encyclopedia
Winternals Software LP
GenreSoftware development
Founded1996; 28 years ago (1996)
FounderBryce Cogswell and Mark Russinovich

Windows Sysinternals is a website that offers technical resources and utilities to manage, diagnose, troubleshoot, and monitor a Microsoft Windows environment.[1] Originally, the Sysinternals website (formerly known as ntinternals[2]) was created in 1996 and was operated by the company Winternals Software LP,[1] which was located in Austin, Texas. It was started by software developers Bryce Cogswell and Mark Russinovich.[1] Microsoft acquired Winternals and its assets on July 18, 2006.[3]

The website featured several freeware tools to administer and monitor computers running Microsoft Windows. The software can now be found at Microsoft. The company also sold data recovery utilities and professional editions of their freeware tools.

Winternals Software LP[edit]

Winternals Software LP was founded by Bryce Cogswell and Mark Russinovich, who sparked the 2005 Sony BMG CD copy protection scandal in an October 2005 posting to the Sysinternals blog.[4]

On July 18, 2006, Microsoft Corporation acquired the company and its assets. Russinovich explained that Sysinternals will remain active until Microsoft agrees on a method of distributing the tools provided there.[5] However, NT Locksmith, a Windows password recovery utility, was immediately removed.[citation needed] Most of the source that Sysinternals provided was also removed. Currently, the Sysinternals website is moved to the Windows Sysinternals website and is a part of Microsoft Docs.[1]

In late 2010, Bryce Cogswell retired from Sysinternals.[6]


Windows Sysinternals supplies users with numerous free utilities, most of which are being actively developed by Mark Russinovich and Bryce Cogswell,[7] such as Process Explorer, an advanced version of Windows Task Manager,[8] Autoruns, which Windows Sysinternals claims is the most advanced manager of startup applications,[9] RootkitRevealer, a rootkit detection utility,[10] Contig, PageDefrag and a total of 65 other utilities.[11] NTFSDOS, which allowed NTFS volumes to be read by Microsoft's MS-DOS operating system, is now discontinued and is no longer available for download.[11] A larger number of these utilities are nowadays bundled by the publishers for the sake of simpler downloading of all, or most, current versions in the so-called Sysinternals Suite.

Previously available for download was the Winternals Administrator Pak which contained ERD Commander 2005, Remote Recover 3.0, NTFSDOS Professional 5.0, Crash Analyzer Wizard, FileRestore 1.0, Filemon Enterprise Edition 2.0, Regmon Enterprise Edition 2.0, AD Explorer Insight for Active Directory 2.0, and TCP Tools.

On May 18, 2010 Sysinternals released its first new utility since its acquisition by Microsoft. Named RAMMap, it is a diagnostic utility similar to the memory tab of Windows Resource monitor, but more advanced. RAMMap runs only on Windows Vista and later.[12] A system event monitoring tool, Sysmon, was released in 2014, which can collect and publish system events that are helpful for security analysis into the Windows Event Log.[13][14]

In November 2018, Microsoft confirmed it is porting Sysinternals tools, including ProcDump and ProcMon, to Linux.[15]

Licensing issue with Best Buy[edit]

In April 2006, Geek Squad, a tech support company working in cooperation with Best Buy, was accused of using unlicensed versions of the ERD Commander software. Winternals supplied Best Buy with copies of its software so that Best Buy could evaluate the software while conducting contract negotiations for using it on a permanent basis. When contract talks broke down Best Buy did not notify its Geek Squad Agents to stop using the software and discard all copies. A judge granted a restraining order on April 14, requiring that use of all unlicensed software be stopped, and forcing Best Buy to turn over all copies of Winternals software within 20 days.[16] After settlement, a version of the Winternals software was released to be used by Geek Squad.[17]

See also[edit]


  1. ^ a b c d "Windows Sysinternals". Microsoft Docs. Microsoft Corporation. August 12, 2009. Retrieved August 15, 2009.
  2. ^ Mark Russinovich (May 9, 2011). Podnutz Episode #64 - Mark Russinovich Talks Tech (Flash) (Podcast). Podnutz. Event occurs at 0:02:01. Retrieved June 18, 2011. ...that's when Sysinternals started, originally called ntinternals...
  3. ^ "Microsoft Acquires Winternals Software". Company Press Releases. Winternals Software. July 18, 2006. Archived from the original on March 14, 2007. Retrieved March 14, 2007.
  4. ^ Mark Russinovich (October 31, 2005). "Sony, Rootkits and Digital Rights Management Gone Too Far". Sysinternals Blog. Retrieved December 18, 2006.
  5. ^ Mark Russinovich (July 18, 2006). "On My Way to Microsoft!". Sysinternals Blog. Retrieved December 18, 2006.
  6. ^ "Mark Russinovich Discusses Windows Azure", Windows IT Pro. Retrieved on April 16, 2011.
  7. ^ "What is new (August 5, 2009)". Windows Sysinternals. Microsoft Corporation. August 15, 2009. Retrieved August 15, 2009.
  8. ^ "Process Explorer v11.33". Windows Sysinternals. Microsoft Corporation. February 4, 2009. Retrieved August 15, 2009.
  9. ^ "Autoruns for Windows v9.53". Windows Sysinternals. Microsoft Corporation. August 12, 2009. Retrieved August 15, 2009.
  10. ^ "RootkitRevealer v1.71". Windows Sysinternals. Microsoft Corporation. November 1, 2006. Retrieved August 15, 2009.
  11. ^ a b "Sysinternals Utilities Index". Windows Sysinternals. Microsoft Corporation. August 12, 2009. Retrieved August 15, 2009.
  12. ^ Russinovich, Mark; Cogswell, Bryce (May 18, 2011). "RAMMap v1.11". Windows Sysinternals. Microsoft. Retrieved June 12, 2011.
  13. ^ Russinovich, Mark; Garnier, Thomas (June 28, 2019). "Sysmon v10.2". Windows Sysinternals. Microsoft Corporation. Retrieved July 24, 2019.
  14. ^ Russinovich, Mark; Richards, Andrew; Garnier, Thomas (September 29, 2014). "Defrag Tools #108 - Sysinternals SysMon - Mark Russinovich". Windows Sysinternals. Microsoft Corporation. Retrieved July 24, 2019.
  15. ^ Cimpanu, Catalin (November 5, 2018). "Microsoft working on porting Sysinternals to Linux". ZDNet. CBS Interactive. Retrieved November 5, 2018.
  16. ^ "Best Buy's Geek Squad Accused of Pirating Software", FOX News. Retrieved on December 16, 2006.
  17. ^ "Winternals & Best Buy/Geek Squad Settle Federal Lawsuit", Winternals press release. Retrieved on December 16, 2006. Archived March 14, 2007, at the Wayback Machine

External links[edit]