Process Monitor 3.33 绿色版_可以监视进程线程文件注册表变化简介:
这是一个高级的Windows监视工具,不但可以监视进程/线程,还可以关注到文件系统,注册表的变化.它包含2个Sysinternals遗留组件:Filemon 和 Regmon,并添加了大量功能,有兴趣的可以去再关注一下.
Process Monitor is an advanced monitoring tool for Windows that shows realtime file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and nondestructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit
专用区按钮让你决定是否要“显示注册表活动”,“显示文件系统活动”,“显示网络活动”,“显示进程和线程活动”或“显示剖析事件”,让您停用任何人只是按他们。
此外,该工具允许您自定义的信息栏,让你可以查看“应用程序详细信息”,“事件详细信息”或“流程管理”有关每个条目的数据。这可以从“选项”菜单来完成。
Procmon.exe就是它了,经典的名字,熟悉的名字吧。