09.02.2014 Views

Windows sysinternals

Create successful ePaper yourself

Turn your PDF publications into a flip-book with our unique Google optimized e-Paper software.

458<br />

Sysinternals utilities<br />

Sysinternals utilities (continued)<br />

LogonSessions, 280–283<br />

malware blocking access to,<br />

427–429<br />

Microsoft support, 3, 14<br />

MoveFile, 334<br />

new features, utilities, and<br />

bug fixes, 3<br />

number of copies, 14<br />

overview, 3–6<br />

PageDefrag, 345–346<br />

PendMoves, 333–334<br />

PipeList, 374–375<br />

Portmon, 353–358<br />

ProcDump, 227–237<br />

process state, viewing with,<br />

211–260<br />

ProcFeatures, 369–370<br />

RAMMap, 359–367<br />

RegDelNull, 378–379<br />

RegJump, 377<br />

running from Web, 10<br />

SDelete, 283–286<br />

ShareEnum, 277–278<br />

ShellRunAs, 278–280<br />

SigCheck, 261–267<br />

single executable images, 11<br />

Streams, 326–328<br />

Strings, 325–326<br />

symbolic information, 28–30<br />

Sync, 339–340<br />

TCPView, 351–353<br />

32-bit and 64-bit system<br />

support, 11<br />

VMMap, 211–227<br />

VolumeID, 350<br />

Web site, 6–13<br />

Whois, 353<br />

WinObj, 370–373<br />

ZoomIt, 320–324<br />

Sysinternals Web site, 6–13<br />

SysinternalsBluescreen.scr, 379<br />

System account, executing<br />

programs in, 176, 182<br />

system activity<br />

boot activity, logging,<br />

127–128<br />

log of, 123–126<br />

system clock, current resolution,<br />

375<br />

System Configuration Utility<br />

(msconfig.exe), 145–146<br />

System.Diagnostics.Debug class,<br />

237<br />

System.Diagnostics.Trace class,<br />

237<br />

System event log<br />

displaying records of, 192<br />

PsShutdiown errors, 205<br />

system files, defragmenting,<br />

345–346<br />

system hangs and crashes,<br />

troubleshooting, 127<br />

System Idle Process, 48<br />

system information, 187–188<br />

desktop wallpaper, displaying<br />

as, 309–318<br />

memory usage, monitoring,<br />

355<br />

viewing, 92–95<br />

System Information dialog box,<br />

92–94<br />

system information utilities, 6,<br />

359–376<br />

system performance<br />

KnownDLLs and, 162<br />

noncached reads impact on,<br />

417–418<br />

on-access virus scans and,<br />

418–419<br />

troubleshooting, 405–426<br />

system performance metrics,<br />

92–95<br />

System process<br />

high CPU usage,<br />

troubleshooting, 408–410<br />

logging activity of, 128<br />

system processes, 43, 48<br />

system requirements for PsTools<br />

utilities, 208–209<br />

system resources, access to,<br />

15–20<br />

system shutdown, logging<br />

activity of, 127–129<br />

System start drivers, load order,<br />

373<br />

system-start services, 200<br />

system startup, kernel-mode<br />

debug output at, 241<br />

system uptime, 187<br />

system volumes, capturing<br />

images of, 336<br />

systemwide commit charge, 65<br />

T<br />

tab-delimited text, saving<br />

Autoruns scans as, 166<br />

target processes<br />

directory for, 183<br />

interactive running, 182<br />

limited rights execution, 183<br />

priority of, setting, 180<br />

process tree of, 189<br />

runtime environment,<br />

181–184<br />

scheduling on multiprocessor<br />

systems, 181<br />

secure Winlogon desktop<br />

environment, 182–183<br />

terminating, 188–189<br />

tracing, 214<br />

Task Manager<br />

CPU usage calculation, 41<br />

vs. Process Explorer, 96–97<br />

processes, viewing in, 39<br />

replacing and restoring,<br />

96–97<br />

Show Processes From All Users<br />

option, 431–432<br />

Users tab, 97<br />

Task Scheduler, 146, 158<br />

Taskkill.exe, 189<br />

TCP endpoints, viewing, 82,<br />

351–353<br />

TCP operations, metrics on,<br />

62–63<br />

TCP port 2020 connections, 248<br />

TCPView, 351–353<br />

connected endpoints, viewing,<br />

352<br />

Resolve Addresses option, 352<br />

update options, 351–352<br />

Whois lookups, 352<br />

tdx driver (NetIO Legacy TDI<br />

Support Driver), 200<br />

TechEd presentations, 13<br />

terminal server sessions<br />

capturing output of, 240–241<br />

interactive desktops as, 238<br />

www.it-ebooks.info

Hooray! Your file is uploaded and ready to be published.

Saved successfully!

Ooh no, something went wrong!