09.02.2014 Views

Windows sysinternals

You also want an ePaper? Increase the reach of your titles

YUMPU automatically turns print PDFs into web optimized ePapers that Google loves.

118 Part II Usage Guide<br />

without permanently removing it by clearing its check box. To enable the rule again, simply<br />

select its check box again and click OK or Apply.<br />

To reset the filter to default settings, click the Reset button in the Filter dialog box. You can<br />

reset the filter from the Procmon main window by pressing Ctrl+R.<br />

FIGURE 4-11 Process Monitor Filter dialog box.<br />

Procmon ORs together all the filter rules for a particular attribute and ANDs filters for<br />

different attributes. For example, if you specify Process Name “include” filters for Notepad.<br />

exe and Cmd.exe, and a Path “include” filter for C:\<strong>Windows</strong>, Procmon displays only events<br />

involving C:\<strong>Windows</strong> that originated from Notepad or Command Prompt. It doesn’t show<br />

any other events involving other paths or other processes.<br />

Another powerful way to add filter criteria is by right-clicking an event and selecting criteria<br />

from the context menu. Figure 4-12 shows just the context menu from Figure 4-8 and<br />

illustrates the available choices.<br />

First, the context menu offers quick-filter entries for the value on which you click. For<br />

example, the fourth and fifth items in Figure 4-12 show Include and Exclude quick filters<br />

for registry path “HKCR\.exe\OpenWithProgids”. The Exclude Events Before option hides<br />

all events preceding the selected one by adding a rule based on the event’s Date & Time<br />

attribute; similarly, Exclude Events After hides all events following the selected one. Finally,<br />

the Include and Exclude submenus (the second and third items from the bottom) list most<br />

available filter attributes. Pick an attribute name from one of these submenus and the<br />

corresponding value from the selected event will be added to the filter. You can also add a<br />

filter based on the collection of values from multiple events simultaneously: select the events,<br />

right-click, and select an attribute name from the Include or Exclude submenu. Doing this<br />

configures a filter for all the unique values contained in the selected events.<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!