IRPMon
IRPMon copied to clipboard
IRPMon: not connected
Hello,
did you run the program as administrator?
Checking the Monitoring | Capture events should connect to the driver.
Also, you may look at this tutorial Keyboard Monitoring
I hope to release new version during this weekend.
i follow this steps:
-
(run it on administrator)none - ok

-
gui

It seems the driver is not loaded.
Do you have Secure Boot disabled? Unfortunately, I am currently not able to make the driver load when the Secure Boot is enabled (I do not own necessary EV certificate yet).
i run it on virtual machine. It should not have a secure boot by default.

i wanna monitor all driver irp code then i need know who(application) connected it.
Well, I tried to connect to the driver and all seems to be OK. I did the following:
- I downloaded the v1.0 RC2 release, the installer,
- I installed the program (with Run IRPMon server on startup unchecked),
- I run the program as administrator,
- in the Connect to the driver window, I selected Device and pressed Ok,
- now, I can connect to the driver via Monitoring | Capture events.
Since I have 64-bit version of Windows, I run 64-bit version of IRPMon (be careful with that since both versions are installed).
-
step 1

-
step 2

-
step 3

-
step 4: (run
IRPMon 64-Biton administrator)none - ok -
still can't work
- new vmos:
winx64 10.0.17763.737
Do not start the IRPMon server service (although it is strange because it seems it is not running anyway). The IRPMon application connects directly to the driver, not the server. The server may be used if you wish to have the GUI on machine other than the driver is... and it is quite unreliable.
I changed step 3 to this, still not work

Well, that all seems very strange. Can you provide me with a log from Sysinternals DbgView?
Run DbgView as administrator. You may do it before running the IRPMon installer. The following items need to be checked in the Capture menu:
- Capture Win32,
- Capture Global Win32,
- Capture Kernel,
- Enable verbose kernel output,
- Capture kernel.
Before installing IRPMon, uninstall it first (it should have its entry in the Control Panel).
After you run the IRPMon 64-bit application as administrator and see the main window (where you should see the list view for displaying individual requests), you may save the debug log to a file and upload it either here, or send it to me via email ([email protected]).
Alternatively, if the VM is not too big nad your internet connection is strong enough, you may upload it somewhere and I will attemt to reproduce your problem.
