Troubleshooting with the windows sysinternals tools 2nd edition

Название: Troubleshooting with the Windows Sysinternals Tools (2nd Edition)Автор: Mark E. Russinovich, Aaron MargosisИздательство: Microsoft PressГод: 2016Страниц: 688Формат: PDFРазмер: 31 MbЯзык: EnglishOptimize Windows system reliability and performance with SysinternalsIT pros and power users

Troubleshooting with the Windows Sysinternals Tools (2nd Edition)

Автор: bhaer от 24-10-2016, 21:37, Коментариев: 0

Категория: КНИГИ » ОС И БД

Troubleshooting with the Windows Sysinternals Tools (2nd Edition)

Название: Troubleshooting with the Windows Sysinternals Tools (2nd Edition)
Автор: Mark E. Russinovich, Aaron Margosis
Издательство: Microsoft Press
Год: 2016
Страниц: 688
Формат: PDF
Размер: 31 Mb
Язык: English

Optimize Windows system reliability and performance with Sysinternals

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.
Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:
Use Process Explorer to display detailed process and system information
Use Process Monitor to capture low-level system events, and quickly filter the output to narrow down root causes
List, categorize, and manage software that starts when you start or sign in to your computer, or when you run Microsoft Office or Internet Explorer

Verify digital signatures of files, of running programs, and of the modules loaded in those programs

Use Autoruns, Process Explorer, Sigcheck, and Process Monitor features that can identify and clean malware infestations
Inspect permissions on files, keys, services, shares, and other objects
Use Sysmon to monitor security-relevant events across your network
Generate memory dumps when a process meets specified criteria
Execute processes remotely, and close files that were opened remotely
Manage Active Directory objects and trace LDAP API calls
Capture detailed data about processors, memory, and clocks
Troubleshoot unbootable devices, file-in-use errors, unexplained communication, and many other problems
Understand Windows core concepts that aren’t well-documented elsewhere


Нашел ошибку? Есть жалоба? Жми!
Пожаловаться администрации

Уважаемый посетитель, Вы зашли на сайт как незарегистрированный пользователь.
Мы рекомендуем Вам зарегистрироваться либо войти на сайт под своим именем.

Информация
Посетители, находящиеся в группе Гости, не могут оставлять комментарии к данной публикации.

Содержание

  1. Troubleshooting with the Windows Sysinternals Tools
  2. Ordering the Book
  3. Description of the Book
  4. Sample Chapter
  5. Table of Contents
  6. Errata
  7. Sysinternals Resources
  8. Books
  9. Articles
  10. Videos and Webcasts
  11. Sysinternals
  12. Sysinternals@25:В A special anniversary event
  13. Sysinternals Live
  14. What’s New
  15. What’s New (October 26, 2022)
  16. What’s New (October 14, 2022)
  17. What’s New (August 18, 2022)
  18. What’s New (July 27, 2022)
  19. What’s New (June 22, 2022)
  20. What’s New (May 25, 2022)
  21. What’s New (April 21, 2022)
  22. Troubleshooting with the Windows Sysinternals Tools, 2nd Edition
  23. eBook
  24. Book + eBook
  25. Online Sample Chapter
  26. Sample Pages
  27. Table of Contents
  28. Features
  29. Скрытые инструменты Microsoft: лучшие утилиты для Windows 10
  30. Что такое Sysinternals Suite
  31. Основные возможности Sysinternals
  32. Как запустить Sysinternals в проводнике Windows
  33. Как использовать Sysinternals Tools в браузере
  34. Что появилось в последнем обновлении Sysinternals Suite
  35. Как автоматически обновлять Sysinternals

Troubleshooting with the Windows Sysinternals Tools

An update to Windows Sysinternals Administrator’s Reference
By Mark Russinovich and Aaron Margosis
Troubleshooting with the Windows Sysinternals Tools is the official book on the Sysinternals tools, written by tool author and Sysinternals cofounder Mark Russinovich, and Windows expert Aaron Margosis. The book covers all 65+ tools in detail, with full chapters on the major tools like Process Explorer, Process Monitor, and Autoruns. In addition to tips and tricks in the tool chapters, it includes 45 «Case of the Unexplained…» examples of the tools used by users to solve real-world problems. Buy the book today and take your Windows troubleshooting and systems management skills to the next level.

Ordering the Book

You can purchase the book from these online retailers:

You can also read it online through Safari.

Description of the Book

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and expert Windows consultant Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

Sample Chapter

You can read samples from the book at this link on Amazon.com.

Table of Contents

Errata

See the Errata & Updates tab on the Microsoft Press web site

Источник

Sysinternals Resources

Books

Windows Internals Book
The official updates and errata page for the definitive book on Windows internals, by Mark Russinovich and David Solomon.

Troubleshooting with the Windows Sysinternals Tools
The official guide to the Sysinternals utilities by Mark Russinovich and Aaron Margosis, including descriptions of all the tools, their features, how to use them for troubleshooting, and example real-world cases of their use.

Articles

Videos and Webcasts

Defrag Tools Shows
Episodes 1 – 12 of the Defrag Tools shows focus on Sysinternals tools. Each episode covers a specific tool used on the tech support show Defrag, covering when and why to use the tools, and providing tips on how to get the most out of them:

Mark’s Webcasts
Two dozen of Mark’s top-rated presentations on Sysinternals, Windows internals, and Windows Azure are available for on-demand viewing. Get tips and techniques on using the Sysinternals tools to troubleshoot directly from their author.

TWC: Sysinternals Primer: TechEd 2014 Edition
The latest edition of the popular Sysinternals Primer series with Aaron Margosis, Mark Russinovich’s co-author of The Windows Sysinternals Administrator’s Reference. The Sysinternals utilities are vital tools for any computer professional on the Windows platform. Mark Russinovich’s popular “Case Of The Unexplained” demonstrates some of their capabilities in advanced troubleshooting scenarios. This complementary tutorial series focuses primarily on the utilities themselves, deep-diving into as many features as time allows. Expect to see some advanced analysis, such as manipulating Procmon results with Windows PowerShell, and interesting/useful new features.

Sysinternals Primer: Autoruns, Disk2Vhd, ProcDump, BgInfo and AccessChk
The Sysinternals utilities are vital tools for any computer professional on the Windows platform. Mark Russinovich’s popular «Case Of The Unexplained» demonstrates some of their capabilities in advanced troubleshooting scenarios. This complementary tutorial session focuses primarily on the utilities themselves, giving you tips and techniques for using their full functionality for troubleshooting and systems management. This session follows the same format as last year’s highly-rated delivery, and covers a different set of the most useful Sysinternals tools.

Unintended Consequences of Security Lockdowns (uses Sysinternals utilities a lot)
Security-conscious organizations often lock down their systems based on prescriptive guidance from Microsoft, US Federal government agencies or other security organizations. Sometimes these settings can lead to unpleasant surprises and unexpected side effects. This session describes and demonstrates some of the common issues that can arise, and whether and how those settings actually help or hurt. Is there benefit to not granting Administrators the “Debug” privilege? Does “Hide mechanisms to remove zone information” break anything? Is the “Require trusted path for credential entry” setting worth the inconvenience? Come see!

Windows Sysinternals Primer: Process Explorer, Process Monitor and More
The Sysinternals utilities are vital tools for any computer professional on the Windows platform. Mark Russinovich’s popular «Case Of The Unexplained» demonstrates some of their capabilities in advanced troubleshooting scenarios. This complementary tutorial session by Aaron Margosis and Tim Reckmeyer focuses primarily on the utilities, deep-diving into as many features as time will allow. Learn tips and tricks that will make you more effective with the Sysinternals utilities.

Источник

sysinternals
Sysinternals

The Sysinternals web site was created in 1996 by Mark Russinovich to host his advanced system utilities and technical information. Whether you’re an IT Pro or a developer, you’ll find Sysinternals utilities to help you manage, troubleshoot and diagnose your Windows systems and applications.

Sysinternals@25:В
A special anniversary event

Sysinternals Live

You can view the entire Sysinternals Live tools directory in a browser at https://live.sysinternals.com/.

What’s New rss

What’s New (October 26, 2022)

What’s New (October 14, 2022)

Install Sysinternals Suite from the Microsoft Store
Sysinternals Suite is now available in the Microsoft Store and Windows Package Manager (winget).

Sysmon for Linux
Sysmon is now available as an open source project for Linux.

What’s New (August 18, 2022)

Candid talk from the man behind your favorite Windows tools
Mark talks with Larry Seltzer about the history and future of Sysinternals.

Autoruns v14.0
Autoruns, a utility for monitoring startup items, is the latest Sysinternals tool to receive a UI overhaul including a dark theme.

What’s New (July 27, 2022)

What’s New (June 22, 2022)

What’s New (May 25, 2022)

Process Monitor v3.80
Process Monitor is the latest tool to integrate with the new Sysinternals theme engine, giving it dark mode support.

Sysmon v13.20
This update to Sysmon, an advanced system security monitor, adds » not begin with » and » not end with » filter conditions and fixes a regression for rule include/exclude logic.

TCPView v4.10
This update to TCPView, a TCP/UDP endpoint query tool, adds the ability to filter connections by state.

Process Explorer v16.40
This update to Process Explorer, an advanced process, DLL and handle viewing utility, adds process filtering support to the main display and reports process CET (shadow stack) support.

What’s New (April 21, 2022)

Process Monitor v3.70
This update to Process Monitor allows constraining the number of events based on a requested number minutes and/or size of the events data, so that older events are dropped if necessary. It also fixes a bug where the Drop Filtered Events option wasn’t always respected and contains other minor bug fixes and improvements.

Sysmon v13.10
This update to Sysmon adds a FileDeleteDetected rule that logs when files are deleted but doesn’t archive, deletes clipboard archive if event is excluded and fixes an ImageLoad event bug.

Theme Engine
This update to the theme engine uses a custom title bar in dark mode, similar to MS Office black theme. WinObj and TCPView have been updated. Expect more tools using the theme engine in the near future!

Источник

Troubleshooting with the Windows Sysinternals Tools, 2nd Edition

Register your book to access additional benefits.

This eBook includes the following formats, accessible from your Account page after purchase:

EPUB The open industry format known for its reflowable content and usability on supported mobile devices.

MOBI The eBook format compatible with the Amazon Kindle and Amazon Kindle applications.

PDF The popular standard, which reproduces the look and layout of the printed page.

This eBook requires no passwords or activation to read. We customize your eBook by discreetly watermarking it with your name, making it uniquely yours.

eBook

This eBook includes the following formats, accessible from your Account page after purchase:

EPUB The open industry format known for its reflowable content and usability on supported mobile devices.

MOBI The eBook format compatible with the Amazon Kindle and Amazon Kindle applications.

PDF The popular standard, which reproduces the look and layout of the printed page.

This eBook requires no passwords or activation to read. We customize your eBook by discreetly watermarking it with your name, making it uniquely yours.

Book + eBook

This eBook includes the following formats, accessible from your Account page after purchase:

EPUB The open industry format known for its reflowable content and usability on supported mobile devices.

MOBI The eBook format compatible with the Amazon Kindle and Amazon Kindle applications.

PDF The popular standard, which reproduces the look and layout of the printed page.

This eBook requires no passwords or activation to read. We customize your eBook by discreetly watermarking it with your name, making it uniquely yours.

This eBook includes the following formats, accessible from your Account page after purchase:

EPUB The open industry format known for its reflowable content and usability on supported mobile devices.

MOBI The eBook format compatible with the Amazon Kindle and Amazon Kindle applications.

PDF The popular standard, which reproduces the look and layout of the printed page.

This eBook requires no passwords or activation to read. We customize your eBook by discreetly watermarking it with your name, making it uniquely yours.

Optimize Windows system reliability and performance with Sysinternals

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

Online Sample Chapter

Sample Pages

Download the sample pages (includes Chapter 4 and the Index.)

Table of Contents

Features

If you find an error, you can report it to us through our Submit errata page.

Источник

Скрытые инструменты Microsoft: лучшие утилиты для Windows 10

Windows 10 предлагает очень мало профессиональных инструментов, однако можно открыть дополнительные возможности с помощью Sysinternals Tools. Недавно появилось обновление для данного пакета утилит — рассказываем о нем подробнее.

fit 300 200 false crop 1553 874 183 0 q90 457722 cac1c6435e095c4aa7cc65ae8

fit 960 530 false crop 1553 874 183 0 q90 457722 cac1c6435e095c4aa7cc65ae8

Что такое Sysinternals Suite

Windows 10 оснащена огромным количеством инструментов, но профессионалам их всё равно не хватает. Поэтому Microsoft выпускает дополнительные утилиты для продвинутых пользователей. В пакете Sysinternals вы можете найти целых 74 инструмента, которые помогут познакомиться со всеми даже самыми скрытыми компонентами Windows. Новые функции позволят заглянуть в саму систему и добавлять возможности, отсутствующие в основном наборе. Они отображают каждую деталь об автозапуске, запущенных программах, файловых системах или сетевом трафике.

Скачать пакет инстументов Sysinternals Suite можно на официальном сайте Microsoft. Это ZIP-папка размером около 35 Мбайт, которую вам нужно будет распаковать. В ней вы найдете все прилагаемые инструменты. Установка не требуется ни для одного из них, поэтому вы сможете легко скопировать папку на USB-накопитель и брать ее с собой.

Скачать пакет Sysinternals Tools с сайта Microsoft

Внимание: хотя каждый инструмент может быть безопасно запущен, сначала стоит узнать, что делает каждый из них по отдельности. Потому что программы глубоко проникают в систему и могут вызвать проблемы при неправильном обращении.

Основные возможности Sysinternals

Контроль над автозапуском. Autoruns — это идеальный инструмент для контроля за процессом запуска Windows. Например, в нем перечислены все сведения об автоматически запускаемых объектах. На вкладке программы можно просмотреть, что запускается при загрузке Windows и что именно происходит при старте системы, какие сервисы загружаются автоматически, а также какие драйверы и кодеки начинают работать. При желании с помощью флажков вы можете деактивировать отдельные элементы. Но здесь следует быть осторожным, а не просто отключать все подряд объекты запуска.

fit 960 530 false crop 1280 765 0 87 q90 457712 b0d2e1fe55835440014643e6e

Лучше, чем диспетчер задач. В Windows 10 разработчики Microsoft уже и так очень неплохо поработали над диспетчером задач. Но в пакете Sysinternals есть еще один очень классный инструмент — своего рода замена диспетчера задач с множеством дополнительных функций — это Process Explorer. Конечно, с Process Explorer необходимо сначала как следует разобраться, но вот маленький совет — нажмите в разделе «Options» на «Tray Icons». Там поставьте флажки рядом с «CPU-History», а также «I/O-History», «GPU-History» и «Physical Memory History». После этого на панели задач появятся небольшие диаграммы, на которых вы увидите, с какой нагрузкой используется система.

Как запустить Sysinternals в проводнике Windows

Microsoft подготовила еще одну классную новинку под названием Sysinternals Live — сервис, который позволяет запускать Sysinternals Tools прямо из локальной сети. Для этого в проводнике Windows введите \live.sysinternals.comtools. Что особенно удобно: вы также можете подключить Sysinternals Live как сетевой диск: тогда инструменты всегда будут появляться, например, как диск S. Это можно сделать через вкладку «Компьютер» — «Подключить сетевой диск».

В принципе, у вас больше не будет необходимости сохранять пакет Sysinternals на USB-накопитель, если вы имеете доступ в интернет на своем компьютере. Потому что через браузер также можно открыть пакет инструментов: для этого надо зайти на страницу https://live.sysinternals.com.

В приложениях Edge Legacy и Internet Explorer достаточно просто кликнуть по инструменту, который вы выбрали, и нажать на «Выполнить». Другие браузеры, такие как Chrome или Firefox, загружают соответствующий exe-файл отдельно — к сожалению, то же самое делает и новый Microsoft Edge.

fit 960 530 false crop 1185 694 0 0 q90 457702 f9916d8fec42c061c5c6dc68e

Что появилось в последнем обновлении Sysinternals Suite

Sysmon 13.00: Sysmon является мощным инструментом для мониторинга системы Windows. В новой версии он может сообщить о тех происходящих в системе процессах, которые подверглись неким вредоносным манипуляциям. Кроме того, в обновлениях были исправлены некоторые незначительные ошибки.

Process Monitor 3.61: Process Monitor — это инструмент мониторинга, который наблюдает за активностью файловой системы, реестра и процессов/потоков. В новой версии он работает и с функциями API RegSaveKey, RegLoadKey и RegRestoreKey.

Как автоматически обновлять Sysinternals

Те, кто подружился с инструментами Sysinternals, на практике сталкиваются с одной очень раздражающей проблемой: обновления. Да, существуют регулярные апдейты для инструментов, но, к сожалению, нет механизма для автоматических обновлений. С помощью Sysinternals Updater вы получите очень полезный инструмент, в котором вам просто нужно будет указать папку Sysinternals Suite.

Затем Sysinternals Updater сравнивает версию файла в папке с текущей версией на серверах Microsoft и загружает обновления. Что удобно: вы сможете скачивать апдейты только для отдельных инструментов или сразу всего пакета.

Источник

K9 User Guide S3azonaws

K9 User Guide S3azonaws
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with k9 user guide s3azonaws.

More information

Windows Ce 3 0 WordPress

Windows Ce 3 0 WordPress
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with windows ce 3 0 wordpress.

More information

Vmware Vsphere Optimize And Scale

Vmware Vsphere Optimize And Scale
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with vmware vsphere optimize

More information

Microsoft Word 2016 Step By Step

Microsoft Word 2016 Step By Step
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with microsoft word 2016

More information

Epson 7600 Repair Manual

Epson 7600 Repair Manual
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with epson 7600 repair manual.

More information

My Windows 10 Computer For Seniors

My Windows 10 Computer For Seniors
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with my windows 10 computer

More information

Latest Cisco Dumps Surepassexam

Latest Cisco Dumps Surepassexam
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with latest cisco 400 101

More information

Hp Envy 4500 E All In One Series

Hp Envy 4500 E All In One Series
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with hp envy 4500 e all in

More information

Os X El Capitan Guida Alluso

Os X El Capitan Guida Alluso
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with os x 10 11 el capitan

More information

Excel 2016 In Easy Steps

Excel 2016 In Easy Steps
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with excel 2016 in easy steps.

More information

Microsoft Publisher 98 For Dummies

Microsoft Publisher 98 For Dummies
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with microsoft publisher

More information

Learn Microsoft Publisher 98

Learn Microsoft Publisher 98
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with learn microsoft publisher

More information

Ipad At Work In Easy Steps

Ipad At Work In Easy Steps
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with ipad at work in easy

More information

Cisco Ccna 3 Lab Answers

Cisco Ccna 3 Lab Answers
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with cisco ccna 3 lab answers.

More information

Adobe Photoshop 7 User Guide

Adobe Photoshop 7 User Guide
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with adobe photoshop 7 user

More information

Open Office 3 User Guide File Type

Open Office 3 User Guide File Type
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with open office 3 user guide

More information

Digital Camera Repair Manual

Digital Camera Repair Manual
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with digital camera repair

More information

Netacad Chapter 3 Answers

Netacad Chapter 3 Answers
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with netacad chapter 3 answers.

More information

Adobe Photoshop 7 User Guide

Adobe Photoshop 7 User Guide
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with adobe photoshop 7 user

More information

Iomega Storcenter Ix4 Manual

Iomega Storcenter Ix4 Manual
We have made it easy for you to find a PDF Ebooks without any digging. And by having access to our ebooks online or by storing it on your computer, you have convenient answers with iomega storcenter ix4

More information

Optimize Windows system reliability and performance with Sysinternals

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

  • Use Process Explorer to display detailed process and system information
  • Use Process Monitor to capture low-level system events, and quickly filter the output to narrow down root causes
  • List, categorize, and manage software that starts when you start or sign in to your computer, or when you run Microsoft Office or Internet Explorer
  • Verify digital signatures of files, of running programs, and of the modules loaded in those programs
  • Use Autoruns, Process Explorer, Sigcheck, and Process Monitor features that can identify and clean malware infestations
  • Inspect permissions on files, keys, services, shares, and other objects
  • Use Sysmon to monitor security-relevant events across your network
  • Generate memory dumps when a process meets specified criteria
  • Execute processes remotely, and close files that were opened remotely
  • Manage Active Directory objects and trace LDAP API calls
  • Capture detailed data about processors, memory, and clocks
  • Troubleshoot unbootable devices, file-in-use errors, unexplained communication, and many other problems
  • Understand Windows core concepts that aren’t well-documented elsewhere

Optimize Windows system reliability and performance with Sysinternals

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

  • Use Process Explorer to display detailed process and system information
  • Use Process Monitor to capture low-level system events, and quickly filter the output to narrow down root causes
  • List, categorize, and manage software that starts when you start or sign in to your computer, or when you run Microsoft Office or Internet Explorer
  • Verify digital signatures of files, of running programs, and of the modules loaded in those programs
  • Use Autoruns, Process Explorer, Sigcheck, and Process Monitor features that can identify and clean malware infestations
  • Inspect permissions on files, keys, services, shares, and other objects
  • Use Sysmon to monitor security-relevant events across your network
  • Generate memory dumps when a process meets specified criteria
  • Execute processes remotely, and close files that were opened remotely
  • Manage Active Directory objects and trace LDAP API calls
  • Capture detailed data about processors, memory, and clocks
  • Troubleshoot unbootable devices, file-in-use errors, unexplained communication, and many other problems
  • Understand Windows core concepts that aren’t well-documented elsewhere

Optimize Windows system reliability and performance with Sysinternals

IT pros and power users consider the free Windows Sysinternals tools indispensable for diagnosing, troubleshooting, and deeply understanding the Windows platform. In this extensively updated guide, Sysinternals creator Mark Russinovich and Windows expert Aaron Margosis help you use these powerful tools to optimize any Windows system’s reliability, efficiency, performance, and security. The authors first explain Sysinternals’ capabilities and help you get started fast. Next, they offer in-depth coverage of each major tool, from Process Explorer and Process Monitor to Sysinternals’ security and file utilities. Then, building on this knowledge, they show the tools being used to solve real-world cases involving error messages, hangs, sluggishness, malware infections, and much more.

Windows Sysinternals creator Mark Russinovich and Aaron Margosis show you how to:

  • Use Process Explorer to display detailed process and system information
  • Use Process Monitor to capture low-level system events, and quickly filter the output to narrow down root causes
  • List, categorize, and manage software that starts when you start or sign in to your computer, or when you run Microsoft Office or Internet Explorer
  • Verify digital signatures of files, of running programs, and of the modules loaded in those programs
  • Use Autoruns, Process Explorer, Sigcheck, and Process Monitor features that can identify and clean malware infestations
  • Inspect permissions on files, keys, services, shares, and other objects
  • Use Sysmon to monitor security-relevant events across your network
  • Generate memory dumps when a process meets specified criteria
  • Execute processes remotely, and close files that were opened remotely
  • Manage Active Directory objects and trace LDAP API calls
  • Capture detailed data about processors, memory, and clocks
  • Troubleshoot unbootable devices, file-in-use errors, unexplained communication, and many other problems
  • Understand Windows core concepts that aren’t well-documented elsewhere

background image

Моим коллегам —  

специалистам по устранению неполадок Windows.

 Никогда не отступайте и не сдавайтесь!

– Марк Руссинович

Элизе, благодаря ей сбываются самые прекрасные мечты! 

(И она гораздо круче меня!)

– Аарон Маргозис

SIN_Titul.indd   I

29.12.2011   13:41:15

background image

Марк Руссинович

Аарон Маргозис

Предисловие Дэвида Соломона

Справочник

администратора

2012

Утилиты

Sysinternals

SIN_Titul.indd   III

29.12.2011   13:41:15

background image

УДК 004.738.5
ББК 32.973.202

P89

Руссинович Марк, Маргозис Аарон

P89   Утилиты Sysinternals. Справочник администратора. / Пер. с англ. — М. : 

Издательство «Русская редакция» ; СПб. : БХВ-Петербург, 2012. — 480 стр. : ил.

ISBN 978-5-7502-0411-3 («Русская редакция») 
ISBN 978-5-9775-0826-1  («БХВ-Петербург»)

Эта книга — исчерпывающее руководство по использованию утилит Sysin-

ternals. Авторы книги — создатель утилит Sysinternals Марк Руссинович и при-
знанный эксперт по Windows Аарон Маргозис — подробно разбирают многочис-
ленные функции утилит для диагностики и управления файлами, дисками, си-
стемой безопасности и встроенным инструментарием Windows. Рекомендации 
авторов проиллюстрированы многочисленными примерами из реальной жизни. 
Изучив их, вы сможете справиться с неполадками в ИТ-системах так, как это 
делают настоящие профессионалы.

Книга состоит из 18 глав и предметного указателя. Она предназначена для 

ИТ-специалистов и опытных пользователей Windows, которые хотят применять 
утилиты Sysinternals с максимальной эффективностью.

УДК 004.738.5

ББК 32.973.202

  © 2011-2012, Translation Russian Edition Publishers.  
Authorized Russian translation of the English edition of Windows® Sysinternals Administrator’s Reference, ISBN 978-
0-7356-5672-7  © Aaron Margosis and Mark Russinovich.  
This translation is published and sold by permission of O’Reilly Media, Inc., which owns or controls all rights to publish 
and sell the same.    
© 2012, перевод ООО «Издательство «Русская редакция», издательство «БХВ-Петербург».  
Авторизованный перевод с английского на русский язык произведения Windows® Sysinternals Administrator’s 
Reference, ISBN 978-0-7356-5672-7  © Aaron Margosis and Mark Russinovich. 
Этот перевод оригинального издания публикуется и продается с разрешения O’Reilly Media, Inc., которая владеет 
или распоряжается всеми правами на его публикацию и продажу.    
© 2012, оформление и подготовка к изданию, ООО «Издательство «Русская редакция», издательство «БХВ-
Петербург».  
Microsoft, а также товарные знаки, перечисленные в списке, расположенном по адресу: 
http://www.microsoft.com/about/legal/en/us/IntellectualProperty/Trademarks/EN-US.aspx являются товарными 
знаками или охраняемыми товарными знаками корпорации Microsoft в США и/или других странах. Все другие 
товарные знаки являются собственностью соответствующих фирм.  
Все названия компаний, организаций и продуктов, а также имена лиц, используемые в примерах, вымышлены и 
не имеют никакого отношения к реальным компаниям, организациям, продуктам и лицам.    

SIN_Titul.indd   IV

29.12.2011   13:41:15

Like this post? Please share to your friends:
  • Tropico 2 вылетает на windows 10
  • Tropico 2 pirate cove windows 10
  • Tron evolution не запускается на windows 10
  • Tron evolution вылетает при запуске windows 10
  • Trojan win32 zpevdo b как удалить windows 10