Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit.
Reviewing 2.7 (Oct 5, 2009)
Starting this program will merely start harddisk and registry activity ad infinity by itself, thus it is worthless at actually finding out what is happening.
Reviewing 2.5 (Jul 26, 2009)
wow, streamentry! makes live more interesting, immediately.
Reviewing 2.02 (Oct 30, 2008)
I use Filemon and Regmon as well, but only because they're much easier and faster to use when I only want to watch FSO or registry activity.
Reviewing 2.01 (Oct 18, 2008)
Very good and usefull !
But I still need to use the "old" FileMon and RegMon because ProcessMonitor now only work starting Win2K SP4 Rollup 1 (SP4 seems not enought) and it crashes on machines running Kaspersky anti-virus whenever you disable it, you must fully uninstall, may be because klif.sys driver is still started if you only disable/quit Kasperske (I have seen other poeple with same problem on sysinternals forum).
Reviewing 2.01 (Oct 17, 2008)
It just the answer to the question: what's going on right now?
Useful and indispensable.
No comments yet