09.02.2014 Views

Windows sysinternals

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

446<br />

HKLM\System\CurrentControlSet\Control\Print\Monitors<br />

HKLM\System\<br />

CurrentControlSet\Control\<br />

Print\Monitors, 164<br />

HKLM\System\<br />

CurrentControlSet\<br />

Control\Session Manager\<br />

KnownDlls, 162<br />

HKLM\System\<br />

CurrentControlSet\Services<br />

drivers in subkeys of, 159<br />

services in subkeys of, 158<br />

HKLM\System\<br />

CurrentControlSet\Services\<br />

EventLog, 195<br />

Host Process for <strong>Windows</strong><br />

Services (Svchost.exe), 158<br />

hotfixes, information about, 188<br />

hotkeys<br />

for switching desktops, 318<br />

for ZoomIt, 320–321<br />

HTML-formatted reports of<br />

AdInsight captured events,<br />

305<br />

hung windows, process file<br />

dumps on, 231<br />

Hyper-V guest virtual machines,<br />

debugging, 249, 251<br />

Hyper-V host, running<br />

debugger on, 249<br />

I<br />

iexplore.exe process<br />

infinite loops,<br />

troubleshooting, 405–407<br />

listing, 255<br />

illegal operations, 159<br />

Image File Execution Options<br />

(IFEO) subkeys, 161<br />

image files<br />

searching for strings in, 325<br />

viewing, 69<br />

Image Hijacks, 161–162<br />

Image memory, 216<br />

image names, terminating<br />

processes by, 189<br />

image pages, excluding from<br />

dumps, 234<br />

image signatures, verifying, 72,<br />

91–92<br />

image signer information, 261<br />

image strings, 72, 85<br />

impersonation, 84, 179<br />

in-use files and folders,<br />

identifying, 256–260<br />

Include Process From Window<br />

option, 117<br />

infinite loops, troubleshooting,<br />

405–407<br />

ini-file APIs, 394<br />

IniFileMapping, 394–395<br />

input/output control (IOCTL)<br />

commands, logging,<br />

353–357<br />

insertion strings, 192<br />

installation, Sysinternals utilities<br />

and, 171<br />

installation programs, move and<br />

delete requests, 333<br />

installation type, 187<br />

installer detection, 19<br />

instrumented processes<br />

memory allocations, viewing,<br />

221–224<br />

of memory snapshots,<br />

218–219<br />

symbols and, 222<br />

integrity labels, 272–273<br />

integrity level (IL) of processes,<br />

35, 55<br />

interactive desktops as terminal<br />

server sessions, 238<br />

interactive logon type, 183<br />

interactive services, 199, 204<br />

Interactive Services Detection<br />

service (UI0Detect), 33<br />

interactive sessions, one at a<br />

time, 31<br />

Internet<br />

running utilities from, 10<br />

unblocking downloads from,<br />

8–9<br />

Internet Explorer<br />

autostarts related to, 157–158<br />

extensibility of, 157<br />

Protected Mode, 20, 184<br />

internode access costs, 367<br />

Interrupts pseudo-process, 49,<br />

190<br />

invalid pages, 58<br />

I/O<br />

disk I/O metrics, 63–64<br />

graph of, 65, 81<br />

metrics on, 95<br />

private I/O counts, 61–62<br />

I/O prioritization, 62<br />

ipconfig, running remotely, 176<br />

IPsec with ESP (Encapsulating<br />

Security Payload), 179<br />

IPv4 endpoints, viewing,<br />

351–353<br />

IPv6 endpoints, viewing,<br />

351–353<br />

IsDebuggerPresent API, 231<br />

IsProcessorFeaturePresent<br />

function, 369<br />

J<br />

Jackson, Chris, 410<br />

job objects, 51<br />

jobs, 21–22<br />

details about, viewing, 88<br />

in process list, 44<br />

Jump To feature, 35<br />

Junction, 329–330<br />

junctions, 328–330<br />

K<br />

Kd.exe, 251<br />

kernel build numbers, 187<br />

kernel debuggers, 249–253<br />

kernel memory<br />

dump files, 249–253<br />

metrics on, 94<br />

kernel mode, 22–23<br />

illegal operations in, 159<br />

processes, code access of, 359<br />

kernel-mode core, 23<br />

kernel-mode debug output, 237<br />

capturing, 241–242<br />

at system startup, 241<br />

kernel-mode stack, 22<br />

kernel-mode stack frames, 112<br />

kernel objects, viewing, 67–77<br />

kernel service functions, 23<br />

kernel symbol files,<br />

downloading, 250<br />

keyboard activity, simulating, 35<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!