"Masen Loy" <Masen.Loy.firstname.lastname@example.org.Win7heads.com> wrote in message
> I downloaded ProcMon, and ran it, but I really don't know what to do
> from there. All I really see from it are a bunch of processes from
> -explorer- and -firefox-.
> What exactly am I supposed to be doing with this program? (sorry for
> the incompetence)
Well, to show only what msnmsgr.exe is doing, for example, you could
right-click, Include Process Name on one of its trace entries. Then you
could find file management records which involved a write operation and
perhaps highlight those. So, Ctrl-h Operation Contains Write to
highlight all such records. If one of those writes seemed interesting to
you you could use the Jump command (Ctrl-j). Etc.