document updated 16 years ago, on May 14, 2008
Different kinds of monitors can be installed:
HOWTO log with existing applications
- File creation: Use procmon, capture everything. After capture, Tools>Unique values, Column=Process Name, click Show, double-click all involved processes, close dialog. (note that all events listed are now just for the Tools>File summmary, sort by number of writes.
(NOTE: does NOT hilight files created with zero bytes, or directories created)
- Registry creation: Same as "file creation", but use Tools>Registry summmary, and sort by number of writes.