<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Comment Feed for Channel 9 - Defrag Tools: #8 - Mark Russinovich</title>
	<atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich/RSS"></atom:link>
	<image>
		<url>http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_220.jpg</url>
		<title>Channel 9 - Defrag Tools: #8 - Mark Russinovich</title>
		<link></link>
	</image>
	<description>Mark Russinovich joins Andrew Richards and Larry&amp;nbsp;Larsen on&amp;nbsp;this episode of Defrag Tools to talk about the history of Sysinternals, his involvement with the Windows Internals book series and&amp;nbsp;advice on Cybersecurity. Learn about new tools, retired tools and tools that never got completed.&amp;nbsp; Get advice on troubleshooting.&amp;nbsp;Get advice on how to survive a cyber attack. And much much more... Write a comment before 24th Sept. for a chance to win a signed copy of Trojan Horse! Blog:Mark&#39;s Blog&amp;nbsp;(TechNet) - http://blogs.technet.com/b/markrussinovich/Mark&#39;s Web Site - http://www.russinovich.com/Sysinternals&amp;nbsp;Web Site - http://www.sysinternals.com Videos:All of Mark&#39;s videos on Channel 9 and talks&amp;nbsp;at conferences. Of note:* Case of the Unexplained...* Mysteries of Memory Management Revealed&amp;nbsp;- Part 1, Part 2* Malware Hunting with the Sysinternals Tools* RSA Conference 2012&amp;nbsp;-- Zero Day: A Non-Fiction View* Inside Windows 7* Inside Windows 7&amp;nbsp;Redux* Windows 7 and Windows Server 2008 R2 Kernel Changes* Windows Vista and Windows Server 2008 Kernel Changes Books:Sysinternals Administrator&#39;s Reference - [Amazon]Windows Internals&amp;nbsp;books:* 4th Edition - Windows XP and Windows Server 2003 - [Amazon]* 5th Edition - Windows Vista and Windows Server 2008 - [Amazon]* 6th Edition - Windows 7 and Windows Server 2008 R2 - [Amazon:&amp;nbsp;Part 1,&amp;nbsp;Part 2]Cybersecurity novels:* Zero Day - A Novel - [Amazon]* Trojan Horse - A Novel - [Amazon]* Operation Desolation - A Short Story - [Amazon] Timeline:[00:00] - How did Sysinternals start?[02:20] - Tools that never got released and tool retirement[03:55] - The most complex tool - Process Explorer[04:51] - Favorite tool - ZoomIt[07:01] - Windows Internals books[10:54] - What&#39;s the best way to learn how to troubleshoot?[12:47] - Do traditional techniques work when analyzing viruses?[13:49] - Cybersecurity awareness[14:40] - Cybersecurity novels[16:28] - Cybersecurity advice for corporations and individuals[20:25] - White Listing[22:53] - User Account Control (UAC)[29:55] - Winternals vs Sysinternals vs Windows Internals[31:08] - New&amp;nbsp;Windows 8 features/support in the Sysinternals tools:*&amp;nbsp;Process Explorer v15.1*&amp;nbsp;Process Monitor v3.0* ProcDump v5.0* RAMMap v1.2*&amp;nbsp;DebugView&amp;nbsp;v4.78* AccessChk v5.1[33:57] - Windows Internals 7th edition (for Windows 8)? Windows Azure Internals?[36:47] -&amp;nbsp;New tools - PsPing, RAMMap, VMMap[40:33] - Win a signed copy of Trojan Horse! </description>
	<link></link>
	<language>en</language>
	<pubDate>Fri, 24 May 2013 13:58:43 GMT</pubDate>
	<lastBuildDate>Fri, 24 May 2013 13:58:43 GMT</lastBuildDate>
	<generator>Rev9</generator>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Fantastic work guys. Great that you could get Mark on.<br><br>Love the show.<p>posted by Scott</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834950270515867</link>
		<pubDate>Mon, 17 Sep 2012 16:10:27 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834950270515867</guid>
		<dc:creator>Scott</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Great information, love the channel&#33;  Awesome to see Mark on the show, he is a genius&#33;<p>posted by Jesse H</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834970133400560</link>
		<pubDate>Mon, 17 Sep 2012 16:43:33 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834970133400560</guid>
		<dc:creator>Jesse H</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Thank you Mark,</p><p>You expertise has improved the general security within the operating system and a great foundation for Azure.&nbsp;I am currently ready Zero Day and having been enjoying so much that my wife had to remind of the time and to turn off the light so she could sleep.</p><p>&nbsp;</p><p>posted by skarnis</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834981392630790</link>
		<pubDate>Mon, 17 Sep 2012 17:02:19 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834981392630790</guid>
		<dc:creator>skarnis</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Mark your my hero man&#33; Zero Day rocked. and Just started to read Trojan Horse. - Zero Day while fictional really open my eyes. I have spend the last 9 months learning Malware RE.  I can honestly say your work inspire where I want my career to go.  Hope to meet you one day.<p>posted by Juan</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834994397957710</link>
		<pubDate>Mon, 17 Sep 2012 17:23:59 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634834994397957710</guid>
		<dc:creator>Juan</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Great show! Great talk and always new stuff to learn.</p><p>I have Windows Internals 5 and I need another book to make a pair. And a signed one that would perfection! Need to order Zero Day and Trojan Horse, because in Portugal, book stores don't have it or is waiting to get it. It is hard to get really good books. Oh, Windows Internals 5... I waited like 4 months or so to get it. Anyway, I have to order both it and just wait.</p><p>Also, this is an awesome comment. It is awesome cause it has the word awesome at least 3 times and it says comment too.</p><p>&nbsp;</p><p>posted by AdelinoAraujo</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835000212386420</link>
		<pubDate>Mon, 17 Sep 2012 17:33:41 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835000212386420</guid>
		<dc:creator>AdelinoAraujo</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Mark, I like your shirt.</p><p>Do I win? </p><p>posted by Smoker65</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835003335899297</link>
		<pubDate>Mon, 17 Sep 2012 17:38:53 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835003335899297</guid>
		<dc:creator>Smoker65</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Always love the talks from Russinovich, because he talks about the meat, the technology, the stuff under the hood for MS products, which a lot people seem to be quiet about. Also, cybersecurity - legit!</p><p>The sheer knowledge you possess is just inspiring!</p><p>&nbsp;</p><p>posted by AgnisM</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835004968290453</link>
		<pubDate>Mon, 17 Sep 2012 17:41:36 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835004968290453</guid>
		<dc:creator>AgnisM</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[great stuff&#33; i really liked the information about the history of sysinternals. thanks&#33; <p>posted by bertge</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835006785205203</link>
		<pubDate>Mon, 17 Sep 2012 17:44:38 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835006785205203</guid>
		<dc:creator>bertge</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835003335899297">Smoker65</a>: lol!</p><p>posted by Mark Russinovich</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835012064715315</link>
		<pubDate>Mon, 17 Sep 2012 17:53:26 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835012064715315</guid>
		<dc:creator>Mark Russinovich</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[This one is really superb &#33; Keep going &#33; <p>posted by HUssain</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835012108295439</link>
		<pubDate>Mon, 17 Sep 2012 17:53:30 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835012108295439</guid>
		<dc:creator>HUssain</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>&quot;When in doubt run process monitor!&quot;</p><p>... life is so much easier now <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p>posted by zico</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835042507158650</link>
		<pubDate>Mon, 17 Sep 2012 18:44:10 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835042507158650</guid>
		<dc:creator>zico</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Oh now after watching the video I understand why &#34;Prompt for elevation for non-Windows binaries&#34; was introduced for Windows 7 UAC. But then why aren&#39;t all Windows binaries signed, at least why not some important ones like cmd or regedit&#63;<p>posted by Gaurav</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835071884343806</link>
		<pubDate>Mon, 17 Sep 2012 19:33:08 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835071884343806</guid>
		<dc:creator>Gaurav</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Hey guys,</p><p>I like how you go through all the sysinternals tools but how about some logging stuff? I'm a SharePoint (soon to be ex-)&nbsp;developer and becoming a SharePoint admin, so I embrace ULS Viewer <a href="http://archive.msdn.microsoft.com/ULSViewer">http://archive.msdn.microsoft.com/ULSViewer</a>. Logging is helluva important here and it's actually the first thing I go to when someone tells me there's a problem.</p><p>Do you know of any other log viewer/dig-througer (I tried logparse <a href="http://en.wikipedia.org/wiki/Logparser">http://en.wikipedia.org/wiki/Logparser</a>&nbsp;but it's kinda too rough for me) that can show me different logs like ULS, IIS, system, event viewer in real time with filtering, additional data (associated process information, correlation id, stack trace etc.)&nbsp;and stuff?</p><p>I've also&nbsp;heard of some 'watson' log system, but it's kinda cryptic to me (only saw uls&nbsp;log entries like 'Error encountered, commencing Dr.&nbsp;Watson' or something). Is it relevant or ancient technology?</p><p>Any hints on other useful logging toys?</p><p>posted by siodmy</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835072429930779</link>
		<pubDate>Mon, 17 Sep 2012 19:34:02 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835072429930779</guid>
		<dc:creator>siodmy</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835072429930779">siodmy</a>: We are going to do a big series on xPerf&nbsp;which will cover logging for all applications.&nbsp; I'll add Logparser to the list of applications to be covered in a future episode.</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835091351072046</link>
		<pubDate>Mon, 17 Sep 2012 20:05:35 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835091351072046</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835071884343806">Gaurav</a>: We didn't want to let ISVs easily cheat by leveraging cmd or regedit to modify the system for their apps with admin rights without a prompt.&nbsp;</p><p>posted by Mark Russinovich</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835134383255272</link>
		<pubDate>Mon, 17 Sep 2012 21:17:18 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835134383255272</guid>
		<dc:creator>Mark Russinovich</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Big guns came out blazing today. Enjoyed the talk. Thanks.</p><p>posted by samhmaria</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835184000147762</link>
		<pubDate>Mon, 17 Sep 2012 22:40:00 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835184000147762</guid>
		<dc:creator>samhmaria</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Great video.&nbsp; Thanks Mark and thanks Defrag team.</p><p>I'm still chomping at the bit for part two of Win Internals 6th ed.&nbsp; I have to admit, I felt a pang of sadness when you said you wouldn't be working on another edition of Windows Internals.&nbsp; Not that anyone could blame you, as I know you're all about Azure now, and there's no doubt the Azure team&nbsp;is better for that.</p><p>The 6th edition has been my first edition, and I felt like I got here late to the party, just as it was ending, as this book has been solid gold to me.&nbsp; It's been exactly the kind of material that I soak up like a sponge.&nbsp; I just really hope that someone can fill your shoes, pick up where you left off, and carry the torch of explicating the next generation of Windows Internals for the masses!</p><p>That said, I'm also super excited to see what innovations Azure brings to the market.&nbsp;I'm a huge fan of cloud technologies, and they're keeping me employed right now, so&nbsp;I'm always looking for the newest and most exciting developments to come out of this industry.</p><p>I also know that you will not stop writing tools.&nbsp; Wherever you are, you'll keep writing tools to make&nbsp;whatever space you're in&nbsp;a better, more efficient, more informative,&nbsp;all around cooler&nbsp;place to be.</p><p>After all, making tools is what really separates us from animals!</p><p>posted by RyanRies</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835299100434341</link>
		<pubDate>Tue, 18 Sep 2012 01:51:50 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835299100434341</guid>
		<dc:creator>RyanRies</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Does anyone remember the commercial Gatorade did about Michael Jordan&#63;&#63;&#63; &#34;Sometimes I dream... that he is me... you know that&#39;s how I dream to be... like Mark... If I could be like Mark&#33;&#34; Seriously though, what he is doing, and has done, is analogous to what Jordan did  with the game of basketball. He seems to be operating on a different plane. When I finished high school I really didn&#39;t have a much idea what I was going to do with my life. I worked for awhile, attended my local University for awhile, slowly working on a mathematics degree &#40;I&#39;ve always loved math&#41; and as part of that I had to take a class in C&#43;&#43; programming. Well, while working on that, my brother mentioned that I should read about this genius that now works at Microsoft named Mark Russinovich. Well, I did, and it was then that I decided... that&#39;s what I want to do. Well, I am now a computer tech at a major retail outfit and am beginning my third year of study in Computer Engineering. I have read Zero Day &#40;twice&#41; and am half way through Trojan Horse and if you, like me, enjoy reading stories where you think to yourself, &#34;this could really happen&#34; then these books are for you. Anyway, I&#39;d just like to take this opportunity to say thanks to Mark for being an incredible inspiration. Also, to say how cool it is that the public is finally beginning to understand the value of his work and to appreciate Mr. Russinovich not just as a computer scientist but as an engineer, a mathematician, an author, and as an all around artist.   <p>posted by Court Oakes</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835341187285995</link>
		<pubDate>Tue, 18 Sep 2012 03:01:58 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835341187285995</guid>
		<dc:creator>Court Oakes</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835299100434341">RyanRies</a>: 6th edition Part 2 RTMed today, so it will be printed and available soon.</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835425430630517</link>
		<pubDate>Tue, 18 Sep 2012 05:22:23 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835425430630517</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>I really hope Zero Day and Trojan Horse are released as audiobooks at some point. But until then I want to win Trojan Horse <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p>posted by sialivi</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835436148421861</link>
		<pubDate>Tue, 18 Sep 2012 05:40:14 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835436148421861</guid>
		<dc:creator>sialivi</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Also, it was mentioned that the UAC prompt doesn&#39;t show the cmd line but why not&#63; Why is that single line hidden and user have to click &#34;Show details&#34; to view it every single time&#63; Is there any way to always show details&#63;<p>posted by Gaurav</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835533212316360</link>
		<pubDate>Tue, 18 Sep 2012 08:22:01 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835533212316360</guid>
		<dc:creator>Gaurav</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Thank you Mr Russinovich, I always have a dedicated monitor assigned to Process Explorer, even run it inside VM's and one day might get around to slip-streaming it into our Windows images as it's installed right after the first app 7-Zip. Process Monitor analysis should be forced labour for reformed hackers, though when you find the problem, you luckily forget the K's of lines and filters you've gone through. BUT! (oops caps-lock, apparently the visual studio design team also re-keyed that caps lock key!) Can we please have the Process Explorer graphs reset (<a href="http://forum.sysinternals.com/graph-height-reset_topic28345.html">http&#58;&#47;&#47;forum.sysinternals.com&#47;graph-height-reset_topic28345.html</a>) and better network graphs? Is the computer working? No, don't stare at the hdd light, look at the process explorer graphs!</p><p>posted by N2Cheval</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835671345489288</link>
		<pubDate>Tue, 18 Sep 2012 12:12:14 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835671345489288</guid>
		<dc:creator>N2Cheval</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p><span>Another great episode of defrag tools ... with legend of Mark R.</span></p><p><span>I wolud like to share one &quot;trojan&quot; with you guys from my first flight ... and I hope that I'll get the real thing....real TROJAN HORSE <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' />) :</span></p><p><span>A distinguished young woman on a flight from</span><br><span>Croatia asked the priest beside her, &quot;Father, may I ask a favor?&quot;</span><br><br><span>&quot;Of course. What may I do for you?&quot;</span></p><p><span>&quot;Well, I bought an expensive electronic hair dryer</span><br><span>that is well over the Customs limits and I'm afraid they'll confiscate</span><br><span>it. Is there anyway you could carry it through Customs for me?</span><br><span>Under your robes perhaps?&quot;</span><br><br><span>&quot;I would love to help you, dear, but I must warn you: I will not lie.&quot;</span><br><br><span>&quot;With your honest face, Father, no one will question you.&quot;</span><br><br><span>When they got to Customs, she let the priest go ahead of her.</span><br><span>The official asked, &quot;Father, do you have anything to declare?&quot;</span><br><br><span>&quot;From the top of my head down to my waist, I have nothing to declare.&quot;</span><br><br><span>The official thought this answer strange, so asked, &quot;And what do you</span><br><span>have to declare from your waist to the floor?&quot;</span><br><br><span>&quot;I have a marvelous little instrument designed to be</span><br><span>used on a woman, but which is, to date, unused.&quot;</span><br><br><span>Roaring with laughter, the official said, &quot;Go ahead, Father. Next!&quot;</span></p><p><span>&nbsp;</span></p><p><span>God bless defrag tools..... !!!</span></p><p>posted by mivancev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835700548452669</link>
		<pubDate>Tue, 18 Sep 2012 13:00:54 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835700548452669</guid>
		<dc:creator>mivancev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Thanks Mark and Channel 9 for the very interesting talk!</p><p>And yes: Process Explorer is excellent!</p><p>@Mark: It would be great if you could make Sysinternals tools open-source (e.g. sharing the source on CodePlex), so the community could both <strong>learn</strong> advanced Windows native programming techniques from your code and also <strong>contribute</strong> to code with additional features.</p><p>Moreover, an analysis with <a title="Dependency Walker" href="http://www.dependencywalker.com/" target="_blank">depends.exe</a> shows that <em>Linker Ver</em> field for procexp.exe is 9.0, meaning that Visual Studio 2008 (VC9) was used to build this tool. I'm curious why do you use this particular toolset (e.g. to support older OS'es like Windows 2000)?</p><p>Thanks, and please keep up your excellent work on Sysinternals tools.</p><p>posted by C64</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835831181266247</link>
		<pubDate>Tue, 18 Sep 2012 16:38:38 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835831181266247</guid>
		<dc:creator>C64</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835831181266247">C64</a>: Visual Studio 2008 SP1 is used to compile the tools so that the tools use MSVCRT v9.0 - which is shipped with Windows XP/Windows 2003.</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835847317503041</link>
		<pubDate>Tue, 18 Sep 2012 17:05:31 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835847317503041</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p></p><blockquote><div class="quoteText"><p></p><p><a class="permalink" title="Comment Permalink" href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835847317503041">5 minutes&nbsp;ago</a>, <a href="/Niners/windev">windev</a> wrote</p><p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835831181266247">C64</a>: Visual Studio 2008 SP1 is used to compile the tools so that the tools use MSVCRT v9.0 - which is shipped with Windows XP/Windows 2003.</p><p></p></div></blockquote><p></p><p>I can be wrong, but using Dependency Walker I see no dependency of PROCEXP.EXE on MSVCR90.DLL, so I thought Sysinternals tools used <em>static linking</em> to CRT (which to me makes sense, to make tools deployment easier).</p><p>&nbsp;</p><p>posted by C64</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835853005993632</link>
		<pubDate>Tue, 18 Sep 2012 17:15:00 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835853005993632</guid>
		<dc:creator>C64</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>A very interesting Markinternals interview about the backstage of Sysinternals. An excellent wrap up of the series of Sysinternals Tools on C9. Unless there's more... <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /></p><p>posted by StanS</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835913268754109</link>
		<pubDate>Tue, 18 Sep 2012 18:55:26 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835913268754109</guid>
		<dc:creator>StanS</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835913268754109">StanS</a>: There are a few more and then on to non-Mark tools.</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835967706272968</link>
		<pubDate>Tue, 18 Sep 2012 20:26:10 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634835967706272968</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>As a software developer, I use PerfMon and ProcessExplorer a lot. Especially useful when trying to figure out when something doesn't work.</p><p>Recently my team and I were trying to solve an issue with IIS AppPool because of high CPU usage. First think I thought of &quot;Is there a tool which can take memory dump when these conditions occurs?&quot;. Then I checked Sysinternals and the tool was there, waiting for me. I somehow knew it will be there. Plus little bit of WinDbg, but that is different story <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-2.gif?v=c9' alt='Big Smile' /> </p><p>&nbsp;</p><p>Thanks Mark for these great tools! They're making life a lot easier.</p><p>posted by Tomas_Voracek</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836029065251305</link>
		<pubDate>Tue, 18 Sep 2012 22:08:26 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836029065251305</guid>
		<dc:creator>Tomas_Voracek</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[The more information your tools show, the less I know .. you know&#63;<p>posted by JosephL</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836558162579461</link>
		<pubDate>Wed, 19 Sep 2012 12:50:16 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836558162579461</guid>
		<dc:creator>JosephL</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Mark,&nbsp;long time fan here,&nbsp;when we can expect the <strong>psping</strong> tool to be released. It would be of great use in network troubleshooting in organization I work for. We&nbsp;run VPN network layer on top of the WAN network topology&nbsp;which&nbsp;unfortunately&nbsp;hides a lot of the WAN network properties and makes performance planning and tunning hard (e.g. VPN layer makes the network hierarchy flat, in a way that&nbsp;the distance between all&nbsp;sites is always one hop, regardless of the physical network topology). I could run <strong>psping</strong> between&nbsp;endpoints in different sites&nbsp;to&nbsp;find&nbsp;the bottlenecks, it would help us a lot!</p><p>posted by bukem</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836617673564719</link>
		<pubDate>Wed, 19 Sep 2012 14:29:27 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836617673564719</guid>
		<dc:creator>bukem</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836617673564719">bukem</a>: It's great to hear you'll find psping useful. I'll be posting it in a couple of weeks.&nbsp;</p><p>posted by Mark Russinovich</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836670287666034</link>
		<pubDate>Wed, 19 Sep 2012 15:57:08 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836670287666034</guid>
		<dc:creator>Mark Russinovich</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836670287666034">Mark Russinovich</a>:That's great news! And thank you for all the efforts you have made to keep the sysinternals tools up-to-date and moreover free.</p><p>&nbsp;</p><p>posted by bukem</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836701698250652</link>
		<pubDate>Wed, 19 Sep 2012 16:49:29 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836701698250652</guid>
		<dc:creator>bukem</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634836670287666034">Mark Russinovich</a>:BTW, it was nice to see you at <a title="TWIT" href="http://www.youtube.com/watch?v=BkerZWFuMeQ&amp;feature=plcp" target="_self">TWIT</a> finally!</p><p>posted by bukem</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837276857359715</link>
		<pubDate>Thu, 20 Sep 2012 08:48:05 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837276857359715</guid>
		<dc:creator>bukem</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Spoiler Alert:&nbsp; don't read this if you haven't read the Zero Day book.&nbsp;</p><p>Mark, since the infection Jeff worked on was triggered by an incorrect date on the system, why couldn't he just reset the system with the correct date and then reinstall from backup?&nbsp; Even if the backup was infected, it wouldn't be triggered until the trigger date (09/11).&nbsp; Doing this would have allowed his client to get back up and running at least for a while.&nbsp;</p><p>Even if Jeff wasn't aware that the infection had been triggered by an incorrect date, when the system was rebuilt the first time, Sue (or even Jeff) should have set the rebuilt system to a correct date.&nbsp; If the date was for some reason still wrong after the system was rebuilt, it should have raised a huge red flag and given them troubleshooting options.&nbsp;</p><p>posted by Jamezs</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837558898869204</link>
		<pubDate>Thu, 20 Sep 2012 16:38:09 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837558898869204</guid>
		<dc:creator>Jamezs</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Spoiler Alert Part II - Don't read this if you haven't read the Zero Day book.&nbsp;</p><p>After figuring out that the infection had been triggered by an incorrect date, a quick workaround would have been to rebuild the system, set the date to a time after 09/11, and then restore the data from backup.&nbsp; Obviously Time Stamp issues would be a concern, but at least the system would be up and running and the data would be accessible, etc.&nbsp; That would give Jeff's client breathing room until a patch becomes available from the Vendors.&nbsp; Does that seem technically sound for a quick workaround?&nbsp; Or am I missing something?&nbsp;</p><p>Thanks,</p><p>posted by Jamezs</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837562924244184</link>
		<pubDate>Thu, 20 Sep 2012 16:44:52 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837562924244184</guid>
		<dc:creator>Jamezs</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Wow- I can't believe that no one&nbsp;took this name before I did.</p><p>Spoiler Alert Part III</p><p>@Jamezs.&nbsp;It seems like your second scenario (Setting the date past 9/11) would work unless the trigger parameter&nbsp;was&nbsp;<em>greater than</em> or equal to 9/11.</p><p>My questions are: Am I correct in assuming that the time settings are being provided to the&nbsp;client machines by the server(s).&nbsp;How could a company like&nbsp;Fischerman, Platt &amp; Cohen&nbsp;not notice that the time settings were wrong on <strong>all</strong> of their workstations?</p><p>posted by Superphreak</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837578679630901</link>
		<pubDate>Thu, 20 Sep 2012 17:11:07 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837578679630901</guid>
		<dc:creator>Superphreak</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Hey.</p><p>This DefragTools series is just ubercool (and hopefully never-ending) <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /> </p><p>I've given all my co-workers an heads-up about this series, (and Mark's Case of the unexplained talks at TechEd, and other Sysinternals talks there), and their just amazed. There's tons of stuff to learn here. Some of us know the tools and use them, but some don't. Seeing them demonstrated by an experts is just 100 times better than just reading about them and trying by yourself.</p><p>I hope You also can do a series focused on troubleshooting different scenarios, why You choose to use a specific tool, and how You use it. That's what so cool about the TechEd shows. It's a great way to learn the tools, and also the OS.&nbsp; Especially an evolving one like Windows.&nbsp; Can't get enough of that stuff...</p><p>Hopefully Mark and You others on the team will continue posting bloggpost like the &quot;Pushing the limits of Windows&quot; series also. That one and talks like &quot;Mysteries of Windows memory management&quot; are packet with helpful insight into the inner workings of Windows.</p><p>Don't stop, You're not finished... You're never finished. Go on... go on... go on...&nbsp; <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-5.gif?v=c9' alt='Wink' /> </p><p>posted by geirendre</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837666804462500</link>
		<pubDate>Thu, 20 Sep 2012 19:38:00 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837666804462500</guid>
		<dc:creator>geirendre</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[I just finished watching a talk about the payloads left to be decrypted inside flame, then I watched this one.....<br><br>http&#58;&#47;&#47;www.drdobbs.com&#47;windows&#47;windows-nt-system-call-hooking&#47;184410109&#63;pgno&#61;1<br><br>&#34;Since each thread&#39;s TEB has its own Service Table List pointer, it is possible that every thread could also have its own unique table of OS services. However, in practice, the list and tables are globally shared. Simply changing an entry in either the NTOSKRNL or WIN32K service tables to point to a new hook routine in a device driver is all that is needed.&#34;<br><br>I know someone else would have done it if you hadn&#39;t, but did you have any idea of the size of the pandoras box you were opening at the time&#63;<p>posted by Crispin Wright</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837838850881016</link>
		<pubDate>Fri, 21 Sep 2012 00:24:45 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837838850881016</guid>
		<dc:creator>Crispin Wright</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Mark - loving your work&#33;  I was a Unix advocate until yours &#40;&#38; Bryse&#39;s&#41; books and talks got me interested in the internals of Windows. The fact that Microsoft now employs you gives me renewed respect for the organisation.<p>posted by Bashingdinosaurs</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837853274410684</link>
		<pubDate>Fri, 21 Sep 2012 00:48:47 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634837853274410684</guid>
		<dc:creator>Bashingdinosaurs</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[Trojan Horse, now thats a book I would like to win a copy off, and its signed by Mark too - awesome&#33;<p>posted by Philip Churchill</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634838248697220305</link>
		<pubDate>Fri, 21 Sep 2012 11:47:49 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634838248697220305</guid>
		<dc:creator>Philip Churchill</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@DeepInsideTheDeathStar: Great series, great show! Keep it up guys! I´d really like to see a bit about malware hunting with the Sysinternals tools.</p><p>@Mark: I really don´t know how you manage to keep all the balls in the air ... just astounding! &quot;Zero Day&quot; &amp; &quot;Trojan Horse&quot; = movie material! Am still a little annoyed though that i can´t purchase &quot;Operation Desolation&quot; for my kindle. Still says &quot;<span>Not currently available&quot; (seems that Amazon doesn´t like to sell in Germany?!?!)<br><br>Cheers and all the best!</span></p><p>posted by r4m3u5</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839440670701797</link>
		<pubDate>Sat, 22 Sep 2012 20:54:27 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839440670701797</guid>
		<dc:creator>r4m3u5</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Rolling rolling rolling. Keep the books a flowin'.&nbsp;</p><p>posted by ababcock1</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839471066705842</link>
		<pubDate>Sat, 22 Sep 2012 21:45:06 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839471066705842</guid>
		<dc:creator>ababcock1</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>Mark. I can't say enough good stuff about the sysinternal tools. They've been saving my sanity for years.</p><p>Hey... If you're thinking about a fun new project (like you don't have enough on your plate), that Audiobook idea that Sailivi mentioned would be super cool. And I bet it would be ultra-awesome if you were the Narrator.&nbsp; Cheers!</p><p>posted by Rob Patterson</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839475426397792</link>
		<pubDate>Sat, 22 Sep 2012 21:52:22 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839475426397792</guid>
		<dc:creator>Rob Patterson</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[When in doubt, . . . run Process Explorer. . okay just kidding.<br><br>However one legitimate question. . . Is there any chance that future Sysinternals tools could make their way into the PowerShell world&#63;<br><br>At a minimum tab completing params and inbuilt help and examples in the PowerShell standard format would be awesome. <br><br>E.g. psping as a powershell cmdlet would be very sweet. I know old tools don&#39;t change much, however that is an example of a new one. <br><br>As an ITPro I don&#39;t have an understanding about the effort required to make the transition, however I understand some of the benefits in discoverability of the tools and consuming the data returned.<p>posted by BRWILKINSON</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839548988318076</link>
		<pubDate>Sat, 22 Sep 2012 23:54:58 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839548988318076</guid>
		<dc:creator>BRWILKINSON</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>I like the Sysinternals tools, my favorit is the Process Explorer <img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-1.gif?v=c9' alt='Smiley' /> <br>Here are some questions about the tools.<br>Why has the System Idle Process a Working Set and is counted in the sum of processes? Is there a real process behind?<br>Is it possible to extend Process Explorer to show the app (process) history like the task manager in Windows 8? Is the history API public?<br>Is it possible to extend the Process Dump tool to flush a ETW log in the case of a dump?</p><p>posted by SteffenZeidler</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839765646135089</link>
		<pubDate>Sun, 23 Sep 2012 05:56:04 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839765646135089</guid>
		<dc:creator>SteffenZeidler</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634839765646135089">SteffenZeidler</a>: each core has a thread for idle processing. These are represented by PID 0 (which doesn't really exist). The threads consume working set as the threads need to be paged in to work.</p><p>Process Explorer has history support. New history columns were added about a year ago. Instead of being numbers they are graphs. There is no explicit api that gives you&nbsp;the history. The closest thing is being an&nbsp;ETW consumer and polling the system with the tooltip32 API.</p><p>ProcDump is designed to not change the state&nbsp;of the target. If you wrote your own MiniDumpCallback DLL (-d &lt;dll&gt;)&nbsp;you might be able to force the&nbsp;flush of the ETW buffers &nbsp;- it'd only work&nbsp;if the target didn't needed to execute any of it's threads (as they will be all suspended).</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840410162568334</link>
		<pubDate>Sun, 23 Sep 2012 23:50:16 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840410162568334</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[So interetig to hear Mark talking... The systernal tools have helped thru the years and have made mike life easier<p>posted by Rodolfo</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840472238366900</link>
		<pubDate>Mon, 24 Sep 2012 01:33:43 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840472238366900</guid>
		<dc:creator>Rodolfo</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840410162568334">windev</a>: Thanks. By &quot;app history&quot; I mean the sum of resource usage of a process since a certain date.<br><a href="http://blogs.msdn.com/b/tparks/archive/2012/07/05/tripp-s-tiny-tips-4.aspx">http://blogs.msdn.com/b/tparks/archive/2012/07/05/tripp-s-tiny-tips-4.aspx</a></p><p>posted by SteffenZeidler</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840667131615464</link>
		<pubDate>Mon, 24 Sep 2012 06:58:33 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840667131615464</guid>
		<dc:creator>SteffenZeidler</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[I have never used the advanced tools of the SysInternals, however, simple tools such as ZoomIt, Autoruns and Autologon have made my work easier for many years. Thanks Mark&#33; <p>posted by Gaizka</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840745932468750</link>
		<pubDate>Mon, 24 Sep 2012 09:09:53 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840745932468750</guid>
		<dc:creator>Gaizka</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[I&#39;d like a copy<p>posted by Michael</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840919413821253</link>
		<pubDate>Mon, 24 Sep 2012 13:59:01 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840919413821253</guid>
		<dc:creator>Michael</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@<a href="/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840667131615464">SteffenZeidler</a>: Use&nbsp;the&nbsp;ETW and Tooltip32&nbsp;APIs to get this data.</p><p>posted by windev</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840967654976584</link>
		<pubDate>Mon, 24 Sep 2012 15:19:25 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634840967654976584</guid>
		<dc:creator>windev</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>The winner of the show's signed book giveaway is - fittingly enough - Superphreak! @Superphreak, email your mailing address to <a href="mailto:markruss@microsoft.com">markruss@microsoft.com</a> and I'll send out the book. Congrats,&nbsp;Superphreak,&nbsp;and thanks everyone for the comments and feedback!</p><p>posted by Mark Russinovich</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634842011119639542</link>
		<pubDate>Tue, 25 Sep 2012 20:18:31 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634842011119639542</guid>
		<dc:creator>Mark Russinovich</dc:creator>
	</item>
	<item>
		<title>Re: Defrag Tools: #8 - Mark Russinovich</title>
		<description>
			<![CDATA[<p>@Mark Russinovich, thanks for choosing my comment from among the other great posts on this page. It's an honor to receive a signed copy of Trojan Horse. I promise not to use its powers for 3vil. &gt;<img src='http://ecn.channel9.msdn.com/o9/content/images/emoticons/emotion-2.gif?v=c9' alt='Big Smile' /></p><p>posted by Superphreak</p>]]>
		</description>
		<link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634843019720160957</link>
		<pubDate>Thu, 27 Sep 2012 00:19:32 GMT</pubDate>
		<guid isPermaLink="true">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#c634843019720160957</guid>
		<dc:creator>Superphreak</dc:creator>
	</item>
</channel>
</rss>