NoVirusThanks PE Capture is a portable tool which captures and saves non-system PE images - executables, DLLs, drivers - as they're loaded.
There's no setup involved, no configuration required: just run PE Capture and watch the display.
As processes run in the background, you'll see the relevant DLL or EXE listed, along with its execution time.
To prove this works, launch some other application of your own - Google Chrome should generate some hits.
Browse to your \pe_capture_portable\PORTABLE\Intercepted\xx-xx-2016 folder at any time, and you'll see all the captured files.
The images are renamed to their file hashes, which can be annoying. But if you're concerned about malware, you can at least scan the folder with your antivirus tool for a speedy verdict.
Verdict:
An easy way to capture the executables launched on a PC. Pity they're renamed to their MD5 file hashes, though.
Your Comments & Opinion
Analyse any Windows executable for signs of malware
Explore executables on disk/ in RAM
Search for disguised executables
A feature-packed file analysis tool
Log executable files as they're created on your system
Detect and remove browser hijackers, adware, more
Track and recover your lost or stolen laptop with this free tool
The secure chat app is now available everywhere
The secure chat app is now available everywhere
A powerful security tool to monitor data sent from your computer