Is there any way i can get some kind of fairly low-level breakdown of what it's doing?
Eu encontrei os utilitários SysInternals muito úteis para isso. Particularmente, os antigos filemon
e regmon
- embora pareçam ter sido substituídos por process monitor
.
Process Monitor is an advanced monitoring tool for Windows that shows real-time file system, Registry and process/thread activity. It combines the features of two legacy Sysinternals utilities, Filemon and Regmon, and adds an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, simultaneous logging to a file, and much more. Its uniquely powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit.
Espero que process explorer
também valha a pena tentar
Ever wondered which program has a particular file or directory open? Now you can find out. Process Explorer shows you information about which handles and DLLs processes have opened or loaded.