For system administrators

Deploying in an organisation

Everything needed to install Personal IT Guy on computers you manage: a managed installation that runs in the background and connects to the monitoring dashboard by itself, a one-command silent install, Intune and GPO, how to check the file is ours, and exactly what is installed on the computer.

Version 1.0.415 Signed by Personal IT Guy (PelegSoft) Windows 10/11 x64

1 Two ways to install

One installer, one program. At the start of the installation you choose how it behaves on the computer:

Full installation

  • The whole app: checks, repairs, tools and the AI assistant
  • Shortcuts on the desktop and in the Start menu
  • Remote monitoring only if the user switches it on

Managed - monitoring only

  • Runs in the background with no window, for every user who signs in
  • Connects to the monitoring dashboard by itself with the enrolment code
  • An icon by the clock: who manages the computer and what is sent - the user always knows
  • The helper service is installed at once - updates and admin actions with no prompt
  • No desktop shortcut; the full app is one press away from the icon

2 Verify the file

Before deploying, make sure the file you downloaded is exactly the one we published - its fingerprint (SHA-256) and its signature:

SHA-256 of version 1.0.41566D43570A62E9879F5FE2259207FE42DE9B0FEECA4BD5C190E4DB79E1BA8F7D5
Signing certificate thumbprintD8D1F005B697EA2CC458B95136B7B4EF3D20EEA2
The file's fingerprint (PowerShell)
Get-FileHash .\PersonalITGuy-Setup.exe -Algorithm SHA256
Who signed the file
(Get-AuthenticodeSignature .\PersonalITGuy-Setup.exe).SignerCertificate | Format-List Subject, Thumbprint

On a computer that does not trust the certificate yet, Windows shows the signature status as unverified (UnknownError) - that is expected. What matters is that the signer's thumbprint matches the one above.

3 Trust the publisher (recommended in an organisation)

The software is signed with Personal IT Guy's own certificate, not a commercial one. When the organisation's computers trust it, Windows shows "Personal IT Guy" as a verified publisher in the installer and the permission prompt, and the software can be allowed by publisher in policy (AppLocker, WDAC, Defender). It is done once, for every computer.

The certificate is limited to code signing only - it cannot be used for websites or anything else. Valid until 01-10-2036.

With a GPO

  1. Download the certificate (the button above) and save it to a shared folder.
  2. Computer Configuration > Policies > Windows Settings > Security Settings > Public Key Policies
  3. Import it into Trusted Root Certification Authorities and into Trusted Publishers.

With Intune

Devices > Configuration > Create > Windows 10 and later > Templates > Trusted certificate, with the certificate for the Computer certificate store - Root. For Trusted Publishers, run the PowerShell command below (its second line) through Devices > Scripts.

On one computer (PowerShell as administrator)

Import-Certificate -FilePath .\pitguy-codesign.cer -CertStoreLocation Cert:\LocalMachine\Root
Import-Certificate -FilePath .\pitguy-codesign.cer -CertStoreLocation Cert:\LocalMachine\TrustedPublisher

4 Managed installation

  1. Get an enrolment code for each computer. Codes are created in the service admin screen (Admin > Remote monitoring); if a provider runs the service for you, ask them for codes. Each code connects one computer.
  2. Run the installer and choose "Managed installation - monitoring only". Enter the code and the organisation name shown to the user, and confirm you are authorised to install monitoring on the computer.
  3. When it finishes, the app starts in the background, connects, and the computer appears on the dashboard within a minute.

The organisation's responsibility: a managed installation switches monitoring on without the user approving it themselves. Whoever installs it represents that the organisation is authorised to monitor the computer and undertakes that its users will receive clear notice of the monitoring, its scope and its purpose, and that it will be used in accordance with all applicable law - including the law on monitoring employees. The software itself always shows the user that the computer is managed and what is sent. Terms of use

Silent installation

Managed, with a code and an organisation name
PersonalITGuy-Setup.exe /S /MANAGED /CODE=XXXXXXXX /ORG="IT Solutions"
Managed without a code - you or the user enter it later in the window by the clock
PersonalITGuy-Setup.exe /S /MANAGED
Back to a full installation on a managed computer
PersonalITGuy-Setup.exe /S /FULL
SwitchMeaning
/SSilent - no windows. Installed for every user, in Program Files.
/MANAGEDManaged installation.
/CODE=The enrolment code from the dashboard (8 characters, dashes do not matter).
/ORG=The name shown to the user: "Managed by ...".
/FULLA full installation (and the end of managed mode).

An update, including one started remotely from the dashboard, keeps the computer's current mode.

5 Deploying with Intune, a GPO or an RMM tool

Intune - Win32 app

Package the installer with IntuneWinAppUtil and set:

Install command (Install behavior: System)
PersonalITGuy-Setup.exe /S /MANAGED /CODE=XXXXXXXX /ORG="IT Solutions"
Uninstall command
"C:\Program Files\PelegSoft\Personal-IT-Guy\Uninstall pitguy.exe" /S
Detection rule (Registry, 64-bit)
HKEY_LOCAL_MACHINE\SOFTWARE\PelegSoft\Personal IT Guy\Managed  ·  Mode  =  managed

An enrolment code connects one computer. For several computers create a code per computer, or install without one and enter it later in the window by the clock.

GPO - computer startup script

if (-not (Test-Path 'C:\Program Files\PelegSoft\Personal-IT-Guy\pitguy.exe')) {
  & '\\server\share\PersonalITGuy-Setup.exe' /S /MANAGED /ORG="IT Solutions"
}

A GPO script runs as SYSTEM: the app starts at the next user sign-in. The installer runs as SYSTEM in Intune and RMM tools too - that is expected.

6 Microsoft Defender

Software that manages a computer remotely, runs in the background and takes actions from a server behaves much like malicious tools - so antivirus may be suspicious of it, especially a new version with no reputation yet. If Defender blocks it:

  1. Make sure the file is genuine - its fingerprint and signer (section 2).
  2. In Microsoft Defender for Endpoint: Settings > Endpoints > Indicators > File hashes - add the SHA-256 of the version as Allow. Each new version adds its own.
  3. On computers that already trust the certificate (section 3) you can also try Indicators > Certificates with the .cer file - the allowance then covers every version.
  4. Tell us - we will submit the version to Microsoft as legitimate software.

Excluding a whole folder from scanning is not recommended; allowing by certificate is narrower and safer.

7 Network and firewall

All traffic goes out from the computer (no inbound port), over HTTPS:

AddressWhyRequired
pitguy.com:443Monitoring, dashboard actions and updatesYes
generativelanguage.googleapis.com:443Repair with AI, only if AI was switched on in the appNo
speed.cloudflare.com:443Internet speed test from the dashboardNo
timestamp.digicert.comNot needed on the computer - only to check the signature's timestamp, if Windows checksNo

8 What is installed on the computer

FolderC:\Program Files\PelegSoft\Personal-IT-Guy
Processpitguy.exe --windowless
Windows servicePersonal IT Guy (PersonalITGuy) · LocalSystem · Automatic
Start at sign-inHKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Run · PersonalITGuyManaged
Managed-mode settingsHKLM\SOFTWARE\PelegSoft\Personal IT Guy\Managed · Mode, Code, Org
Service data and logs%ProgramData%\Personal IT Guy
User settings%AppData%\personal-it-guy

What is sent and what the administrator can do is set out in the privacy policy, section 4.8, and shown to the user in the window by the clock. No files, browsing history, passwords, document contents or screenshots are sent. Privacy policy

9 Removal

Silent uninstall
"C:\Program Files\PelegSoft\Personal-IT-Guy\Uninstall pitguy.exe" /S

Uninstalling removes the software, the helper service, the start at sign-in and the managed-mode settings. The computer is removed from the dashboard on its page there.

Known limit: the monitoring connection is kept for the first user who signs in. On a computer several people use, reporting runs while that account is signed in.

Remote monitoring