Page 1 of 1

Sysinternals Process Monitor: New Sysinternals Tool!

Posted: Tue Nov 07, 2006 5:59 pm
by ClausValca
New tool offered by the fine folks formerly known as Sysinternals:

Process Monitor v1.0: http://www.microsoft.com/technet/sysint ... nitor.mspx

Quoting:

"Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit."

"Process Monitor runs on Windows 2000 SP4 with Update Rollup 1, Windows XP SP2, Windows Server 2003, and Windows Vista as well as x64 versions of Windows XP, Windows Server 2003 and Windows Vista."

It seems to unpack, run and execute very similar to Process Explorer. Thus it can be ported easily and doesn't seem to make any more demands on registry entries than Process Explorer does. Shouldn't be too difficult to consider "portable" but I haven't thoroughly vetted it with with RegWatcher yet.

Looks to be very useful. I've enjoyed playing with it this afternoon at work.

Posted: Tue Nov 07, 2006 6:26 pm
by Erind
Can you search for Handles, etc with it? Or better yet, have you noticed anything that Process Explorer does that this doesn't do?

Posted: Thu Nov 09, 2006 9:36 pm
by Andrew Lee
Posted to the database. Thanks!

Process Monitor

Posted: Sun Sep 27, 2020 10:40 pm
by lwc
Andrew Lee wrote: Thu Nov 09, 2006 9:36 pm Posted to the database. Thanks!
It's stated in the database that:
2. Delete Eula.txt and Procmon64a.exe
What is Procmon64a.exe supposed to do? If I try to run it in Windows 10 64-bit, then I get an error.

Sysinternals Process Monitor: New Sysinternals Tool!

Posted: Mon Sep 28, 2020 12:04 am
by SYSTEM
lwc wrote: Sun Sep 27, 2020 10:40 pm What is Procmon64a.exe supposed to do? If I try to run it in Windows 10 64-bit, then I get an error.
I think it's an ARM version for computers which have an ARM processor, such as Microsoft Surface Pro X.

Re: Sysinternals Process Monitor: New Sysinternals Tool!

Posted: Mon Sep 28, 2020 1:44 pm
by vevy
SYSTEM wrote: Mon Sep 28, 2020 12:04 am
lwc wrote: Sun Sep 27, 2020 10:40 pm What is Procmon64a.exe supposed to do? If I try to run it in Windows 10 64-bit, then I get an error.
I think it's an ARM version...
Correct. You can examine the executable with sigcheck, another Sysinternals tool:

Code: Select all

MachineType:    64-bit ARM

Re: Sysinternals Process Monitor: New Sysinternals Tool!

Posted: Mon Mar 01, 2021 8:56 pm
by webfork
If you've been interested in finding Windows tweaks, learning about the registry, or other testing, I have to say Process Monitor has a lot to offer. As I've been digging further into Windows software testing, I found a detailed breakdown on the program:

Using Process Monitor to Troubleshoot and Find Registry Hacks
https://www.howtogeek.com/school/sysint ... o/lesson5/

Re: Sysinternals Process Monitor: New Sysinternals Tool!

Posted: Mon Mar 01, 2021 10:16 pm
by Mike.S.G.
Here's a few more tidbits about Windows processes using Sysinternals Tools - videos #s 7-12 are very techy but also very good... hang in there, some good stuff.
-> https://www.youtube.com/playlist?list=P ... DwNdEebYGC