Skip to Content
Troubleshooting with the Windows Sysinternals Tools
book

Troubleshooting with the Windows Sysinternals Tools

by Mark Russinovich, Aaron Margosis
October 2016
Intermediate to advanced
688 pages
21h 41m
English
Microsoft Press
Content preview from Troubleshooting with the Windows Sysinternals Tools

Chapter 18. Crashes

This chapter demonstrates the use of Sysinternals utilities to troubleshoot crashes. Procmon and ProcDump are the primary utilities here: Procmon primarily to show the file and registry operations that led up to the crash, and ProcDump to capture a detailed snapshot of the process’ state at the time of the crash. Autoruns is used to resolve a case in which the crash occurred during startup. The upcoming “Troubleshooting crashes” section describes general techniques for solving crashes, after which the following cases will illustrate those and other techniques:

Image The Case of the Failed AV Update demonstrates Autoruns’ Analyze ...

Become an O’Reilly member and get unlimited access to this title plus top books and audiobooks from O’Reilly and nearly 200 top publishers, thousands of courses curated by job role, 150+ live events each month,
and much more.
Start your free trial

You might also like

Windows Internals, Part 1: System architecture, processes, threads, memory management, and more, Seventh Edition

Windows Internals, Part 1: System architecture, processes, threads, memory management, and more, Seventh Edition

Pavel Yosifovich, Alex Ionescu, Mark E. Russinovich, David A. Solomon

Publisher Resources

ISBN: 9780133986549Purchase book