ProcMon (Windows)

To get an idea of what programs are accessing your file, please grab a ProcMon trace and send it over for review. 


You can extract this in the Downloads folder and run it from there. The Agent may have provided a path to check; if not, we will want to scan the domains folder and the root install folder in general. Run procmon.exe as an Administrator 

Here, you will want to add the filters. 


  • PATH -> CONTAINS -> C:\SMARTERMAIL -> Include
  • PATH -> CONTAINS -> C:\PROGRAM FILES (X86)\SMARTERTOOLS\SMARTERMAIL -> Include
When you click "Ok" the process will start. The first thing to do is to stop the capture and drop filtered events. 
  1. Stop the capture
  2. Drop Filtered events ( Important: as this will keep the process from consuming all of your resources. )
Here are some alternative filters you can add if requested. ( Only do this if we request it of you please. )
  1. PROCESS NAME -> IS -> MAILSERVICE.EXE -> Exclude
  2. PROCESS NAME -> IS -> W3WP.EXE -> Exclude
  3. PROCESS NAME -> IS -> CLAMD.EXE -> Exclude
  4. PROCESS NAME -> IS -> EXPLORER.EXE -> Exclude
When done, you can go to File > Save. The default options are good. When done, zip up the results and send them over in the open ticket you have with support.