09.02.2014 Views

Windows sysinternals

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

444<br />

events<br />

events (continued)<br />

filtering and highlighting in<br />

Procmon, 116–122<br />

finding, 115<br />

Load Image events, 104<br />

Process Profiling events, 114<br />

Procmon-captured, 104–116,<br />

138<br />

profiling events, 114<br />

reporting on, 305<br />

searching online, 116<br />

sequence number, 298<br />

Thread Profiling events, 114<br />

time of day, 104<br />

viewing associated events, 303<br />

Events report, 305<br />

Events with Details reports, 305<br />

Exchange Server<br />

CPU spikes, troubleshooting,<br />

423–424<br />

high item count folders, 425<br />

troubleshooting problems<br />

with, 420–426<br />

EXE files, 26<br />

description and publisher<br />

information, 169<br />

hijacks of, 161<br />

executable code, functions,<br />

24–26<br />

executable files, 21<br />

details about, 265<br />

digital signatures on, 262<br />

EXE or DLL, 26<br />

properties of, 90<br />

scanning for, 265<br />

verification of, 72<br />

executable images, 54<br />

DLLs loaded as, 255<br />

path to, 54, 432<br />

in process address space, 112<br />

properties of, 78–79<br />

verifying, 91–92<br />

execution on remote<br />

computers, PsExec for,<br />

176–184<br />

exit codes, 177, 198<br />

of PsInfo, 188<br />

Explorer.exe, autostart entries<br />

related to, 155<br />

export tables, 26<br />

exporting<br />

event logs, 195<br />

from VMMap, 212<br />

external storage devices,<br />

removing, 339<br />

F<br />

F5 key, 46<br />

FAT drives, changing ID number,<br />

350<br />

file access<br />

delays, troubleshooting,<br />

415–419<br />

redirecting, 394–395<br />

file activity<br />

summary of, 136–137<br />

viewing, 102. See also Process<br />

Monitor (Procmon)<br />

file associations, changing, 161<br />

File Errors dialog box, 341<br />

file extensions<br />

of EXEs and DLLs, 26<br />

file and folder operations,<br />

listing by, 137<br />

file fragmentation, display of,<br />

342<br />

file handles, 256–257<br />

file hashes, calculating, 261–286<br />

file locations, jumping to,<br />

115–116<br />

file management utilities,<br />

325–334<br />

file mapping objects, 22, 257<br />

file mappings<br />

listing, 71<br />

mapped views of, 216<br />

Filemon, 102<br />

filtering capabilities, 116<br />

file names, overwriting, 286<br />

“File not found” autostart<br />

entries, 169–170<br />

file objects, sharing mode, 76<br />

file reads<br />

noncached, 417<br />

re-reads, 418<br />

file and registry virtualization,<br />

disabling, 20<br />

file shares<br />

enumerating, 277–278<br />

permissions on, changing, 278<br />

security settings on, 277<br />

violations of, 401–404<br />

file signatures, verifying, 149–<br />

150, 169<br />

File Summary dialog box,<br />

136–137<br />

file system<br />

activity, capturing, 104<br />

autostart locations, 145<br />

file system buffers, flushing to<br />

disk, 339<br />

file system objects, reporting,<br />

326–328<br />

file utilities, 5<br />

files<br />

alternate data streams, 326<br />

attributes of, 109–110<br />

clusters, locating, 343<br />

defragmentation of, 344–345<br />

deleting securely, 284–286<br />

effective permissions on, 267<br />

in-use, identifying, 256–260<br />

mapping into memory, 365<br />

moving, renaming, and<br />

deleting, scheduling, 334<br />

multiple paths to, 328<br />

opened remotely, listing,<br />

184–185<br />

properties of, viewing, 71<br />

searching for, 71<br />

searching for strings in, 325<br />

Filter dialog box, 117–118<br />

filtered access tokens, 18<br />

filtering<br />

AdInsight data, 303–304<br />

advanced output, 120–121<br />

boot logging and, 129<br />

configuring, 117–119<br />

context menu options,<br />

118–119<br />

debug output, 242–243<br />

Drop Filtered Events option,<br />

129<br />

events in Procmon, 116–122<br />

resetting filters, 118<br />

rule sets, importing, 131<br />

rules, adding, 117<br />

rules, editing and removing,<br />

117–118<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!