When an app fails with a vague file-not-found error, guessing which DLL or configuration file it wanted often wastes time. Microsoft's Sysinternals Process Monitor records real-time file system, Registry and process activity, including paths and results. The useful method is a short capture around one reproduction, filtered to the exact process, then examining the sequence that precedes the failure. A NAME NOT FOUND entry is not automatically the bug; many apps probe optional locations normally.
Before you start
Download Process Monitor only from Microsoft's Sysinternals site. Keep a copy of the error and know the app executable name. Capture on a test or personal PC with enough free disk space; traces can grow and may include usernames, paths and sensitive document names. On a work PC, follow support policy before sharing a trace.Do it step by step
- Start Process Monitor and stop live capture immediately while setting up filters. Filter Process Name to the affected executable and optionally limit Operation to relevant file events.
- Clear previous events, start capture and reproduce the error once. Stop capture as soon as the message appears to keep the data small and relevant.
- Find the last events from the affected process and inspect path, result and detail. Compare a failed lookup with nearby successful paths; a missing optional file may be expected.
- If a particular path appears causal, confirm whether the file should exist by checking the vendor's installer, configuration and permissions. Do not copy a random DLL from the Internet.
- Test a supported repair or reinstall of that app and repeat the capture. Compare whether the same path failure disappears and the app now works.
- Save a filtered trace only when needed for vendor support, review it for sensitive data and remove local copies after the case is resolved.