Gutcheck
0.11
Gutcheck - an honest look inside a slow or unstable Windows PC. Performance and stability diagnostics for Windows clients, driven by data-defined Checks. A technician runs one command at a customer site and reads the report on the spot.
Minimum PowerShell version
5.1
Installation Options
Owners
Copyright
(c) 2026 MERLIN. Licensed under the MIT License.
Package Details
Author(s)
- MERLIN
Tags
Windows Diagnostics Performance Support Troubleshooting Helpdesk Hardware Reporting
Functions
PSEditions
Dependencies
This module has no dependencies.
Release Notes
0.11 - The User, and what changed.
- The Report says who the User is in terms of the machine, under a new heading
"Benutzer": since when they are signed in and what their Session holds; what kind of
User Profile they have, how large its folders are and how long it takes to load;
where Desktop and Documents lie; their proxy, default printer, autostart, monitors
and Offline Files.
- Every Session and every User Profile on the machine is listed, with a warning for a
disconnected Session that holds memory and a count of User Profiles nobody has used
for half a year. Of other Users only account, state, times, memory, kind and size.
- A timeline of what Windows logged as changed in the last 30 days - programs, updates,
drivers, services, restarts - with the account. A crash Finding says so where the
crashes began shortly after such a Change.
- Gutcheck reads state and logged Changes and never what a User did: no file names, no
usage, no content.
- A Run that is not in the User's Session says so and leaves the User's part unread.
0.10 - Every running program.
- A new Check looks at every running program, not only at the applications that have a
Check of their own: a table of all of them with memory, handles, GDI and USER objects,
and a Finding for one near the limit of 10,000 GDI or USER objects or holding
unusually many handles. The programs of other accounts are read with admin rights;
what stays unread is said to be unread.
- A status of Windows or a WinHTTP error Gutcheck has no wording for is said as Windows
says it; each print service error has its own meaning; four sign-in errors of
Microsoft Entra ID are worded as Microsoft documents them.
- Where a program was found is one Finding per application, and a shortcut to a program
on a share is information, not a warning.
0.9.1 - No code without what it means.
- A status or an error code is no longer shown bare: service exit codes, print and Group
Policy errors, HTTP statuses, certificate errors, sign-in errors of Windows and of
Microsoft Entra ID, add-in settings and the antivirus and printer states say what they
mean, with the code behind it. The evidence tables are headed in German.
- The Report says who ran the Run and with what rights, and gives the evidence more room.
- Fewer false alarms: a remote desktop session's display adapter is no outdated graphics
driver; a printer whose queues report offline is one printer and is not called
outdated; a virtual disk is not failed for calling itself an HDD; the add-ins Office
installs itself do not count as many add-ins.
- Failed connections that are a program going through the network address by address
are recognised as that, and the Report says what to look for.
- An elevated window of an account that has no lesser rights is not offered a restart.
0.9 - What the Findings point to together.
- "Verdacht": where two Findings observed two different things that point to one cause,
the Report says so before anything else - a failing drive, failing memory, the graphics
driver, this machine's network connection, or one Server. It names the Findings it
rests on, says once what to do, and says what would have supported it and was not
checked. It is no Finding and is in no count.
- A Finding says what it means ("Bedeutung") apart from what to do about it ("Was tun"),
for the Findings of Stability, Network and Outlook that can warn or fail.
- What a Hint assumes about the machine is found out once and stated at the top of the
Report: connected by cable, Wi-Fi or VPN, notebook or desktop, docked, on battery, in a
domain. No docking station is named on a desktop, and a slow measurement says when it
was taken on battery.
- A Finding links to the evidence to read with it and to the Findings that belong with
it, and every piece of evidence says which Findings it belongs to.
- findings.csv has new columns at the end: References, Signals, Meaning, Subject,
Unobserved. The graphics driver and its date are a Finding of their own.
0.8.3 - Hints that fit the machine, and a Run in the right session.
- A Run started "as administrator" says so before it examines anything and asks whether
to start again in the logged-on user's session, where it asks for the rights itself.
Started in another account it would read the wrong profile; in the user's own it would
not see the user's network drives. -NoUserSwitch keeps a Run where it was started.
- What to do about a lossy ping or a slow Server follows how the machine reaches it: by
cable, Wi-Fi or VPN, inside its own network or beyond. A machine at a cable is no
longer told to try a cable. One lost ping is a WARN and not a FAIL.
- Blue screens and live kernel events say what the code means and what to do about it,
where "2: 0x193 x2" said neither.
- Scheduled tasks that are not Windows' own are listed with account, trigger, last run
and how it ended. A program a task starts from a share says so and points there.
- An ODBC data source is named with whose driver it uses, which is as near to the
program as a data source gets.
- Every Finding in the Report has a button that copies it as text, for a ticket.
- The Report says "Notiz" where it said "Was tun".
0.8.2 - A stress test that loads the machine.
- The stress test could not load a processor fully: its load was PowerShell loops, which
reach about three quarters of a healthy machine, and the Report then said that
something was limiting the CPU. The load is compiled threads now and reaches 100 %.
"Lasttest: Durchsatz" is on another scale; numbers from earlier Reports do not compare.
- A Server that lost its connection or could not be reached is named by name and by
address, and the evidence sets apart which of the two the machine asked for.
- An example in a code comment no longer uses a name from a real machine.
0.8.1 - What four machines in one afternoon showed.
- Disk errors name the drive: which disk or volume, how many events, and when. Errors on
a drive the machine no longer has - a memory stick, an external disk - no longer fail
the machine, and with admin rights the drive is named by model and serial number.
- A connection to a Server that was lost and one that never came about are two Findings.
A retired server that something still asks for at every start is no longer listed among
the Servers whose connection dropped.
- Two antivirus products are confirmed by asking Defender itself: listed as active in
Security Center, and passive by its own account, it is not a second scanner.
- A Run started in another account than the user's says so in a banner under the
machine's box, and puts its folder on the Desktop all users share.
- A Run that was given admin rights reads the network adapters' power management in the
admin part; "nicht gelesen: Get-NetAdapterPowerManagement" appeared in spite of them.
Versions 0.1 to 0.8: https://github.com/kort3x/gutcheck/blob/main/docs/release-notes-earlier.md
FileList
- Gutcheck.nuspec
- Definitions\checks.json
- Gutcheck.psd1
- Gutcheck.psm1
- Invoke-GutcheckElevated.ps1
- Private\Account.ps1
- Private\AppSelection.ps1
- Private\Autoupdate.ps1
- Private\Code.ps1
- Private\Console.ps1
- Private\Data.ps1
- Private\Definition.ps1
- Private\Elevation.ps1
- Private\Finding.ps1
- Private\KeepSignIn.ps1
- Private\Kind.ps1
- Private\Kinds\App.ps1
- Private\Kinds\AppConnection.ps1
- Private\Kinds\AppLog.ps1
- Private\Kinds\AppRuntime.ps1
- Private\Kinds\Autodiscover.ps1
- Private\Kinds\Battery.ps1
- Private\Kinds\BootPerformance.ps1
- Private\Kinds\Change.ps1
- Private\Kinds\Cpu.ps1
- Private\Kinds\CrashDump.ps1
- Private\Kinds\DiskHealth.ps1
- Private\Kinds\DiskTest.ps1
- Private\Kinds\DotNet.ps1
- Private\Kinds\FolderSize.ps1
- Private\Kinds\GroupPolicy.ps1
- Private\Kinds\HttpsEndpoint.ps1
- Private\Kinds\ImageIntegrity.ps1
- Private\Kinds\Memory.ps1
- Private\Kinds\Network.ps1
- Private\Kinds\NetworkDependency.ps1
- Private\Kinds\NetworkDisruption.ps1
- Private\Kinds\Odbc.ps1
- Private\Kinds\OfficeAddins.ps1
- Private\Kinds\OutlookAuth.ps1
- Private\Kinds\OutlookData.ps1
- Private\Kinds\Power.ps1
- Private\Kinds\Printing.ps1
- Private\Kinds\Program.ps1
- Private\Kinds\ProgramElevated.ps1
- Private\Kinds\Security.ps1
- Private\Kinds\Server.ps1
- Private\Kinds\Service.ps1
- Private\Kinds\Session.ps1
- Private\Kinds\SessionElevated.ps1
- Private\Kinds\Stability.ps1
- Private\Kinds\Startup.ps1
- Private\Kinds\Storage.ps1
- Private\Kinds\Stress.ps1
- Private\Kinds\System.ps1
- Private\Kinds\Temperature.ps1
- Private\Kinds\Updates.ps1
- Private\Kinds\UserProfile.ps1
- Private\Kinds\UserProfileElevated.ps1
- Private\Kinds\UserProfileOther.ps1
- Private\Kinds\UserSetting.ps1
- Private\Lead.ps1
- Private\Parameter.ps1
- Private\Probe.ps1
- Private\Progress.ps1
- Private\PublishedDefinitions.ps1
- Private\QrCode.ps1
- Private\Reading.ps1
- Private\Report.ps1
- Private\Sampling.ps1
- Private\Section.ps1
- Private\Signal.ps1
- Private\Situation.ps1
- Private\Text.ps1
- Private\TokenCache.ps1
- Public\Invoke-Gutcheck.ps1
Version History
| Version | Downloads | Last updated |
|---|---|---|
| 0.11.1 | 8 | 10/10/2026 |
| 0.11 (current version) | 5 | 10/10/2026 |
| 0.10 | 5 | 10/10/2026 |
| 0.9.1 | 10 | 10/10/2026 |
| 0.9 | 8 | 10/10/2026 |
| 0.8.3 | 5 | 10/9/2026 |
| 0.8.2 | 4 | 10/9/2026 |
| 0.8.1 | 3 | 10/9/2026 |
| 0.8 | 3 | 10/9/2026 |
| 0.7.2 | 4 | 10/9/2026 |
| 0.7.1 | 5 | 10/9/2026 |
| 0.6.2 | 6 | 10/8/2026 |
| 0.6.1 | 5 | 10/8/2026 |
| 0.6 | 4 | 10/8/2026 |
| 0.5.2 | 6 | 10/7/2026 |
| 0.5.1 | 8 | 10/7/2026 |
| 0.5 | 5 | 10/7/2026 |
| 0.4 | 19 | 9/25/2026 |
| 0.3 | 7 | 9/25/2026 |
| 0.2 | 7 | 9/24/2026 |