09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

Chapter 3 Process Explorer 79<br />

The second field in the Image tab serves as a Verified Signer field, showing the company<br />

name from the version resource or the subject name from the verified signing certificate. If<br />

signature verification has not been attempted, you can click the Verify button to perform<br />

that verification. See the “Verifying Image Signature” section in this chapter for more<br />

information.<br />

If the process owns a visible window on the current desktop, clicking the Bring To Front<br />

button brings it to the foreground. If the process owns more than one top-level window,<br />

Bring To Front brings the one closest to the top of the z-order to the foreground.<br />

Clicking the Kill Process button forcibly terminates the process. By default, Procexp will<br />

prompt you for confirmation before terminating the process. You can disable that prompt by<br />

clearing the Confirm Kill check box in the Options menu.<br />

Warning Forcibly terminating a process does not give the process an opportunity to shut down<br />

cleanly and can cause data loss or system instability. In addition, Procexp does not provide extra<br />

warnings if you try to terminate a system-critical process such as Csrss.exe. Terminating a systemcritical<br />

process results in an immediate <strong>Windows</strong> blue screen crash.<br />

You can add a comment for a process in the Comment field. Comments are visible in the<br />

process list if you display the Comment column or, if you do not have the Comment column<br />

selected, in the tooltip for the process. Comments apply to all processes with the same path<br />

and are remembered for future executions of Procexp. Note that administrative rights are<br />

required to identify the executable image path for processes running in other accounts. If the<br />

image path cannot be identified, the process name is used instead. That means, for example,<br />

that a comment entered for a svchost.exe process while running Procexp with administrative<br />

rights might be associated with “C:\<strong>Windows</strong>\System32\svchost.exe”, while a comment<br />

entered for the same process when running without administrative rights will be associated<br />

with “svchost.exe”, and the comment associated with the full path will not be displayed.<br />

Procexp saves comments under the same registry key as its other configuration settings<br />

(HKCU\Software\Sysinternals\Process Explorer).<br />

Performance Tab<br />

The Performance tab, shown in Figure 3-27, reports metrics for CPU usage, virtual memory,<br />

physical memory (working set), I/O, kernel object handle count, and window manager handle<br />

counts. All the data on the tab is updated at the Procexp refresh interval.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!