Skip to main content

Fix: Can’t Enable Boot Logging in Process Monitor on Windows 10

Process Monitor is an advanced monitoring tool for Windows users that is capable of monitoring file system, Registry and process/thread activity, all in real-time. Process Monitor is a lightweight yet brilliant little program that has some extremely handy features, including Boot Logging – enabling which allows Process Monitor to generate thread profiling events that capture the state of all running applications at a regular interval. Unfortunately, many Windows 10 users have reported being unable to enable Process Monitor’s Boot Logging feature even though it worked perfectly for them on older versions of the Windows Operating System. When a Windows 10 user affected by this issue tries to enable Boot Logging, they see an error message that states:
Unable to write PROCMON23.SYSMake sure that you have permission to write to the %%SystemRoot%%\System32\Drivers directory.

PRO TIP: If the issue is with your computer or a laptop/notebook you should try using Reimage Plus which can scan the repositories and replace corrupt and missing files. This works in most cases, where the issue is originated due to a system corruption. You can download Reimage by Clicking Here
The error message doesn’t provide affected users with a lot of information, only that Process Monitor was unable to create or write to a file named PROCMON23.sys and that the cause may be the user not having permission to write to the directory in which this file is located or is supposed to be located. In actuality, Windows 10 already has a file titled PROCMON23.sys in the same directory, so when Process Monitor tries to create the file in that very directory, it fails and consequently displays the error message described above. This issue has been confirmed to affect all currently available builds of Windows 10, which makes it all the more significant. Thankfully, though, this problem can be fixed pretty easily – all you need to do is:
  1. Press the Windows Logo key + R to open a Run
  2. Type the following into the Run dialog and press Enter:
%SystemRoot%\System32\Drivers\
  1. In the File Explorer window that opens up next, locate a file named sys, right-click on it and click on Rename.
  2. Rename the file to PROCMON23_old.sys and press Enter to save the name.
  3. If you are asked to confirm the action or provide your password to give the administrative action the go-ahead, do whatever is asked of you. If you are not asked to confirm the action or provide authentication, simply skip this step.
  4. Restart your computer.
  5. When the computer boots up, launch Process Monitor, click on Options Enable Boot Logging and click on OK in the resulting popup, and Process Monitor should be able to successfully enable Boot Logging this time.

Comments

Popular posts from this blog

How to Fix Windows 10 Pin Issues when Logging In

Windows 10 provide a very convenient way of logging in to your Windows using a pin code. However, some users are experiencing problems with the Windows 10 pin login. After a Windows Update, users can’t sign in using their previous pin code. And this isn’t related to users forgetting their pin codes. It seems like their old pin code has been removed from the Windows and their PCs aren’t recognising it. Now, there are a lot of scenarios of this. Some people can’t sign in because the system doesn’t recognise their PIN. On the other hand, some people can’t even enter their pin because there isn’t a pin option available for them. What Causes the Pin to Stop Working? Here is a list of things that can cause this issue A bug in the Windows Update that might have broken the PIN sign in option Corrupt files in the Ngc folder Usually it happens after a Windows Update so it’s a bug that breaks the PIN sign in option. Tips Before you dive deep in to the methods given below...

How to Fix the ‘Failed to Acquire the VirtualBox COM Object’ Error

Several users are reporting that they are unable to launch VirtualBox. The critical error message that comes up is  “Failed to acquire the VirtualBox COM object. The application will terminate”.  In some cases, the error is also accompanied by a second error message pointing towards the problem. The issue does not seem to be specific to a certain Windows version since it’s confirmed to occur on both Windows 8.1 and Windows 10. Failed to acquire the VirtualBox COM object. The application will now terminate. What is causing the ‘Failed to Acquire the VirtualBox COM Object’ error? We investigated this issue by looking at various user reports and the repair strategies that are commonly deployed successfully in this particular scenario. As it turns out, there are multiple culprits that might end up triggering this issue: VirtualBox is not installed with admin access  – Virtualbox is one of those software products that will require you to install them with a...

Fix: System Found Unauthorized Changes on the Firmware, Operating System or UEFI Drivers

Several users are struggling with the  System found unauthorized changes on the firmware error  at every startup or when trying to take their computer out of hibernation mode. Most affected users report that the issue started occurring after they installed some pending Windows updates. The issue is mostly encountered on Windows 7. The system found unauthorized changes on the firmware, operating system or UEFI drivers. Press [OK] to run the next boot device, or enter directly to BIOS Setup if there are no other boot devices installed. What is causing the System found unauthorized changes on the firmware error We investigated this particular issue by looking at various user reports. This error will occur whenever your system is checking the firmware one some computer hardware parts as part of a new security feature. To be precise, the error is occurring because not all Windows versions will support this new security feature. As it turns out, there are sev...