Windows Vista Tips

Windows Vista Tips > Newsgroups > Windows Vista General Discussion > Using Process Explorer...

Reply
Thread Tools Display Modes

Using Process Explorer...

 
 
Ross M. Greenberg
Guest
Posts: n/a

 
      12-05-2008
I'm trying to use Process Explorer to capture and then examine all registry reads and/or rights by a single process. How do I go about displaying only those reads/writes to a process that begins with "fred"? I'm sure I'm going to use Filters, but how specifically?

Thanks!

Ross

 
Reply With Quote
 
 
 
 
Ross M. Greenberg
Guest
Posts: n/a

 
      12-05-2008
Thank you for wasting my time... I see you got through the filter...

"Brontosaurus Burger AKA Vista!" <> wrote in message news:493951c4$...
> Fred no... Frank possible though.. just apply the "douche bag" filter and
> you will see Franks processes.


 
Reply With Quote
 
Poutnik
Guest
Posts: n/a

 
      12-05-2008
In article <POb_k.4254$>,
says...>
> I'm trying to use Process Explorer to capture
> and then examine all registry reads and/or rights by a single process.


> How do I go about displaying only those reads/writes to a process that
> begins with "fred"? I'm sure I'm going to use Filters, but how
> specifically?
>


You definitely wanted to say Process Monitor ( ProcMon.exe ),
follower and union of FileMon and RegMon.
Because Process Explorer ( ProcExp.exe ) is counterpart to task manager.

Run ProcMon and filter dialog displays.
Using filters is quite strait forward:

ProcessName begins with fred include
Event class is registry include
Operation is RegSetValue include
Operation is RegQueryValue include
( more operations possible )

You will learn quicly by browsing items and their possible values.
 
Reply With Quote
 
Poutnik
Guest
Posts: n/a

 
      12-05-2008
In article <MPG.23a3a3b66491e1b09896ab@127.0.0.1>,
says...>
>
> You definitely wanted to say Process Monitor ( ProcMon.exe ),
> follower and union of FileMon and RegMon.
> Because Process Explorer ( ProcExp.exe ) is counterpart to task manager.
>
> Run ProcMon and filter dialog displays.
> Using filters is quite strait forward:
>
> ProcessName begins with fred include
> Event class is registry include
> Operation is RegSetValue include
> Operation is RegQueryValue include
> ( more operations possible )
>
> You will learn quicly by browsing items and their possible values.


Easier way is set default ( or reseted ) setting,
and by right clicking chosing includes to filter.

In both ways the approach is this:
when no includes are present,
all but excluded items are displayed.

when includes are present,
only included but excluded items are listed.
 
Reply With Quote
 
Ross M. Greenberg
Guest
Posts: n/a

 
      12-05-2008
So I tried the below, have got an empty screen when I okayed the filter the first time. I tried it again and got an Out Of Memory error.

Ross

"Poutnik" <> wrote in message news:MPG.23a3a3b66491e1b09896ab@127.0.0.1...
> In article <POb_k.4254$>,
> says...>
>> I'm trying to use Process Explorer to capture
>> and then examine all registry reads and/or rights by a single process.

>
>> How do I go about displaying only those reads/writes to a process that
>> begins with "fred"? I'm sure I'm going to use Filters, but how
>> specifically?
>>

>
> You definitely wanted to say Process Monitor ( ProcMon.exe ),
> follower and union of FileMon and RegMon.
> Because Process Explorer ( ProcExp.exe ) is counterpart to task manager.
>
> Run ProcMon and filter dialog displays.
> Using filters is quite strait forward:
>
> ProcessName begins with fred include
> Event class is registry include
> Operation is RegSetValue include
> Operation is RegQueryValue include
> ( more operations possible )
>
> You will learn quicly by browsing items and their possible values.

 
Reply With Quote
 
DanS
Guest
Posts: n/a

 
      12-05-2008
"Ross M. Greenberg" <> wrote in
news:0rh_k.4298$:

> So I tried the below, have got an empty screen when I okayed the
> filter the first time. I tried it again and got an Out Of Memory
> error.
>
> Ross


Aha ha ha ha ha ha .....

I was wondering how long it would take MS to completely ruin some of the
SysInternals utilites they purchased........

That just goes to prove a point. Some 3rd party developers are far more
capable programming for Windows that actual MS programmers themselves.
 
Reply With Quote
 
Rick Rogers
Guest
Posts: n/a

 
      12-06-2008
Seeing as they hired the author as well as buying the software, any failings
can still be attributed to him. Having met Mark, I doubt he would allow
anyone to cripple his software.

--
Best of Luck,

Rick Rogers, aka "Nutcase" - Microsoft MVP
http://mvp.support.microsoft.com/
Windows help - www.rickrogers.org
My thoughts http://rick-mvp.blogspot.com

"DanS" <> wrote in message
news:Xns9B6BC06713F25thisnthatroadrunnern@85.214.1 05.209...
> "Ross M. Greenberg" <> wrote in
> news:0rh_k.4298$:
>
>> So I tried the below, have got an empty screen when I okayed the
>> filter the first time. I tried it again and got an Out Of Memory
>> error.
>>
>> Ross

>
> Aha ha ha ha ha ha .....
>
> I was wondering how long it would take MS to completely ruin some of the
> SysInternals utilites they purchased........
>
> That just goes to prove a point. Some 3rd party developers are far more
> capable programming for Windows that actual MS programmers themselves.


 
Reply With Quote
 
 
 
Reply

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are Off


Similar Threads
Thread Thread Starter Forum Replies Last Post
Explorer.exe process at ~100% Kemper Windows Vista Performance 8 04-07-2009 02:56 AM
Explorer process engross 50-60% CPU yxq Windows Vista General Discussion 1 10-20-2008 12:37 AM
Process Explorer AliceZ Windows Vista General Discussion 6 07-10-2008 05:10 AM
Process Explorer AliceZ Windows Vista General Discussion 2 08-19-2007 11:26 PM
SysInternal's Process Explorer MICHAEL Windows Vista General Discussion 5 07-13-2006 04:31 AM



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28 29 30 31 32 33 34 35 36 37 38 39 40 41 42 43 44 45 46 47 48 49 50 51 52 53 54 55 56 57 58 59