<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" media="screen" href="/styles/xslt/rss.xslt"?>
<rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:trackback="http://madskills.com/public/xml/rss/module/trackback/" xmlns:wfw="http://wellformedweb.org/CommentAPI/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:media="http://search.yahoo.com/mrss/" xmlns:itunes="http://www.itunes.com/dtds/podcast-1.0.dtd" xmlns:c9="http://channel9.msdn.com">
<channel>
	<title>Channel 9 - Entries tagged with sysinternals</title>
    <atom:link rel="self" type="application/rss+xml" href="http://channel9.msdn.com/Tags/sysinternals/RSS"></atom:link>
    <itunes:summary></itunes:summary>
    <itunes:author>Microsoft</itunes:author>
    <itunes:subtitle></itunes:subtitle>
    <image>
      <url>http://mschnlnine.vo.llnwd.net/d1/Dev/App_Themes/C9/images/feedimage.png</url>
      <title>Channel 9 - Entries tagged with sysinternals</title>
      <link>http://channel9.msdn.com/Tags/sysinternals</link>
    </image>
    <itunes:image href=""></itunes:image>
    <itunes:category text="Technology"></itunes:category>
    <description>Channel 9 keeps you up to date with the latest news and behind the scenes info from Microsoft that developers love to keep up with. From LINQ to SilverLight – Watch videos and hear about all the cool technologies coming and the people behind them.</description>
    <link>http://channel9.msdn.com/Tags/sysinternals</link>
    <language>en</language>
    <pubDate>Tue, 21 May 2013 10:23:08 GMT</pubDate>
    <lastBuildDate>Tue, 21 May 2013 10:23:08 GMT</lastBuildDate>
    <generator>Rev9</generator>
    <c9:totalResults>32</c9:totalResults>
    <c9:pageCount>2</c9:pageCount>
    <c9:pageSize>25</c9:pageSize>
  <item>
      <title>Defrag Tools: #32 - Desktops</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew Richards, Chad Beeder and Larry Larsen walk you through <strong>Sysinternals Desktops</strong>. Desktops allows you to organize your applications on up to four virtual desktops. We go under the covers and show how Desktops fits in to the Session, Window Station and Desktop object/security model.</p><p><strong>** I didn't do a great job&nbsp;explaining Sessions/Window Stations/Desktops -- If you want to know about those concepts in detail, I suggest you watch <a href="http://channel9.msdn.com/events/TechEd/Europe/2012/SIA311">Sysinternals Primer: Gems</a> instead.</strong></p><p><strong>Resources:</strong><br><a href="http://technet.microsoft.com/en-us/sysinternals/cc817881.aspx">Sysinternals Desktops</a><br><a href="http://technet.microsoft.com/en-us/sysinternals/bb896657.aspx">Sysinternals WinObj</a><br><a href="http://technet.microsoft.com/en-us/sysinternals/bb896769.aspx">Sysinternals LogonSessions</a><br><a href="http://blogs.msdn.com/b/aaron_margosis/archive/2012/07/18/tssessions-utility.aspx">Aaron Margosis' TSSessions</a><br>Sysinternals Administrator's Reference - [<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]<br>Sysinternals Primer: Gems [<a href="http://channel9.msdn.com/events/TechEd/Europe/2012/SIA311">TechEd EMEA 2012 @13:45</a>]<br>Malware Hunting with the Sysinternals Tools [<a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/SIA302">TechEd USA 2012 @ 44:30</a>]</p><p><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=01m05s">[01:05]</a> - Sysinternals Desktops<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=04m50s">[04:50]</a> - Sessions, Window Stations and Desktops<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=05m13s">[05:13]</a> - Sysinternals WinObj<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=05m43s">[05:43]</a> - Sessions<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=06m40s">[06:40]</a> - Window Stations<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=09m00s">[09:00]</a> - Enumeration (Standard User)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=10m11s">[10:11]</a> - Desktops<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=11m38s">[11:38]</a> - Local Security Authority (LSA) - Sessions via Logons *<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=12m16s">[12:16]</a> -&nbsp;Enumeration (Elevated User)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=15m20s">[15:20]</a> - psexec -sid cmd.exe<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=16m38s">[16:38]</a> - Enumeration (NT Authority\SYSTEM)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=17m15s">[17:15]</a> - Sessions via Logons (NT Authority\SYSTEM)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops#time=18m26s">[18:26]</a> - Media Center Extender example</p><p>* You can enumerate sessions directly via the <a href="http://msdn.microsoft.com/en-us/library/windows/desktop/aa383833.aspx">Remote Desktop Services</a>&nbsp;API.</p><p><strong>Exercises:<br></strong></p><p>Use <strong>Sysinternals LogonSessions</strong> to view the logon sessions.<br>Use Aaron Margosis' <strong>TSSessions</strong> to view the Sessions/Window Stations/Desktops (and much more).</p><p>Session: 0<br>&nbsp; WinStation: WinSta0<br>&nbsp;&nbsp;&nbsp; Desktop: Default<br>&nbsp;&nbsp;&nbsp; Desktop: Disconnect<br>&nbsp;&nbsp;&nbsp;&nbsp;Desktop: Winlogon<br>&nbsp; WinStation: Service-0x0-3e4$<br>&nbsp;&nbsp;WinStation: Service-0x0-3e5$<br>&nbsp;&nbsp;WinStation: Service-0x0-3e7$<br>&nbsp;&nbsp;WinStation: msswindowstation<br>&nbsp;&nbsp; &nbsp;&nbsp;Desktop: mssrestricteddesk<br>Session: 1<br>&nbsp; WinStation: WinSta0<br>&nbsp;&nbsp;&nbsp; Desktop: Default<br>&nbsp;&nbsp;&nbsp; Desktop: Disconnect<br>&nbsp;&nbsp;&nbsp; Desktop: Winlogon<br>...</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:f260cfb41f30418db546a17b003729ca">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew Richards, Chad Beeder and Larry Larsen walk you through Sysinternals Desktops. Desktops allows you to organize your applications on up to four virtual desktops. We go under the covers and show how Desktops fits in to the Session, Window Station and Desktop object/security model. ** I didn&#39;t do a great job&amp;nbsp;explaining Sessions/Window Stations/Desktops -- If you want to know about those concepts in detail, I suggest you watch Sysinternals Primer: Gems instead. Resources:Sysinternals DesktopsSysinternals WinObjSysinternals LogonSessionsAaron Margosis&#39; TSSessionsSysinternals Administrator&#39;s Reference - [Amazon]Sysinternals Primer: Gems [TechEd EMEA 2012 @13:45]Malware Hunting with the Sysinternals Tools [TechEd USA 2012 @ 44:30] Timeline:[01:05] - Sysinternals Desktops[04:50] - Sessions, Window Stations and Desktops[05:13] - Sysinternals WinObj[05:43] - Sessions[06:40] - Window Stations[09:00] - Enumeration (Standard User)[10:11] - Desktops[11:38] - Local Security Authority (LSA) - Sessions via Logons *[12:16] -&amp;nbsp;Enumeration (Elevated User)[15:20] - psexec -sid cmd.exe[16:38] - Enumeration (NT Authority\SYSTEM)[17:15] - Sessions via Logons (NT Authority\SYSTEM)[18:26] - Media Center Extender example * You can enumerate sessions directly via the Remote Desktop Services&amp;nbsp;API. Exercises: Use Sysinternals LogonSessions to view the logon sessions.Use Aaron Margosis&#39; TSSessions to view the Sessions/Window Stations/Desktops (and much more). Session: 0&amp;nbsp; WinStation: WinSta0&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop: Default&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop: Disconnect&amp;nbsp;&amp;nbsp;&amp;nbsp;&amp;nbsp;Desktop: Winlogon&amp;nbsp; WinStation: Service-0x0-3e4$&amp;nbsp;&amp;nbsp;WinStation: Service-0x0-3e5$&amp;nbsp;&amp;nbsp;WinStation: Service-0x0-3e7$&amp;nbsp;&amp;nbsp;WinStation: msswindowstation&amp;nbsp;&amp;nbsp; &amp;nbsp;&amp;nbsp;Desktop: mssrestricteddeskSession: 1&amp;nbsp; WinStation: WinSta0&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop: Default&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop: Disconnect&amp;nbsp;&amp;nbsp;&amp;nbsp; Desktop: W</itunes:summary>
      <itunes:duration>1252</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops</link>
      <pubDate>Mon, 18 Mar 2013 22:20:50 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.mp3" expression="full" duration="1252" fileSize="20042817" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.mp4" expression="full" duration="1252" fileSize="118455740" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.webm" expression="full" duration="1252" fileSize="40135996" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.wma" expression="full" duration="1252" fileSize="10134519" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.wmv" expression="full" duration="1252" fileSize="60519917" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32_high.mp4" expression="full" duration="1252" fileSize="259508221" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32_mid.mp4" expression="full" duration="1252" fileSize="181251630" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32_Source.wmv" expression="full" duration="1252" fileSize="139161396" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.ism/manifest" expression="full" duration="1252" fileSize="6046" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/075a/a62999be-6e31-426b-a001-23b2dc57075a/DefragTools32.wmv" length="60519917" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>12</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-32-Desktops/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Troubleshooting</category>
    </item>
  <item>
      <title>Defrag Tools: #31 - ZoomIt</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew Richards, Chad Beeder and Larry Larsen walk you through <strong>Sysinternals ZoomIt</strong>. ZoomIt is a screen zoom and annotation tool for technical presentations that include application demonstrations. ZoomIt runs unobtrusively in the tray and activates with customizable hotkeys to zoom in on an area of the screen, move around while zoomed, and draw on the zoomed image.</p><p><strong>Resources:</strong><br><a href="http://technet.microsoft.com/en-us/sysinternals/bb897434.aspx">Sysinternals ZoomIt</a><br>Sysinternals Administrator's Reference - [<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]</p><p><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=00m00s">[00:00]</a> - Overview<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=01m42s">[01:42]</a> - Windows Magnifier (Win-&#43;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=03m35s">[03:35]</a> - Ctrl-1 - Static Zoom<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=05m30s">[05:30]</a> - Ctrl-2&nbsp;- Draw<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=06m38s">[06:38]</a> - Ctrl-4&nbsp;-&nbsp;Live Zoom<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=08m12s">[08:12]</a> - File Save *<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt#time=10m05s">[10:05]</a> - Ctrl-3&nbsp;- Break Timer</p><p>* Zoomed to 480x300 on a 1920x1200 screen, the file sizes are:</p><ul><li>Zoomed -&nbsp;1920x1200 </li><li>Actual -&nbsp;480x300 </li></ul> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:9a571b07cef94dca98f6a17b0036fe37">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew Richards, Chad Beeder and Larry Larsen walk you through Sysinternals ZoomIt. ZoomIt is a screen zoom and annotation tool for technical presentations that include application demonstrations. ZoomIt runs unobtrusively in the tray and activates with customizable hotkeys to zoom in on an area of the screen, move around while zoomed, and draw on the zoomed image. Resources:Sysinternals ZoomItSysinternals Administrator&#39;s Reference - [Amazon] Timeline:[00:00] - Overview[01:42] - Windows Magnifier (Win-&amp;#43;)[03:35] - Ctrl-1 - Static Zoom[05:30] - Ctrl-2&amp;nbsp;- Draw[06:38] - Ctrl-4&amp;nbsp;-&amp;nbsp;Live Zoom[08:12] - File Save *[10:05] - Ctrl-3&amp;nbsp;- Break Timer * Zoomed to 480x300 on a 1920x1200 screen, the file sizes are: Zoomed -&amp;nbsp;1920x1200 Actual -&amp;nbsp;480x300 </itunes:summary>
      <itunes:duration>754</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt</link>
      <pubDate>Mon, 11 Mar 2013 20:27:38 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.mp3" expression="full" duration="754" fileSize="12068574" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.mp4" expression="full" duration="754" fileSize="72226438" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.webm" expression="full" duration="754" fileSize="26796386" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.wma" expression="full" duration="754" fileSize="6106155" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.wmv" expression="full" duration="754" fileSize="42995297" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31_high.mp4" expression="full" duration="754" fileSize="157390026" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31_mid.mp4" expression="full" duration="754" fileSize="110140096" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31_Source.wmv" expression="full" duration="754" fileSize="110604286" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.ism/manifest" expression="full" duration="754" fileSize="6046" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/638d/0e5f8e26-2188-4c3a-9481-a1c70518638d/DefragTools31.wmv" length="42995297" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>6</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-31-ZoomIt/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Troubleshooting</category>
    </item>
  <item>
      <title>Defrag Tools: #23 - Windows 8 SDK</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew Richards and Larry Larsen upgrade the software we downloaded in <a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive">Episode #1</a>&nbsp;to the <strong>Windows 8</strong> (x86 &amp;x64) and<strong> Windows RT</strong>&nbsp;(ARM) versions.</p><p><strong>Resources: <br></strong><a href="http://msdn.microsoft.com/en-us/windows/hardware/hh852363.aspx">Windows Software Development Kit (SDK) for Windows 8</a><br><a href="http://www.sysinternals.com/">Sysinternals</a><br><a href="http://www.datapro.net/products/usb-3-0-super-speed-a-a-cable-crossover-strict.html">USB3 Debugging Cable</a><br>- Note, you must use&nbsp;a USB3 A-A cable designed for debugging, otherwise it will fry your box!<br><br><span><span><strong>Timeline: <br></strong></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=00m00s">[00:00]</a> - Table tablets and 4K screens at <a href="http://www.cesweb.org/">CES 2013</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=02m30s">[02:30]</a> - Time to upgrade our tools to the Windows 8\Windows RT versions!</span></span><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=03m20s">[03:20]</a> - <a href="http://www.sysinternals.com/">www.sysinternals.com</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=05m34s">[05:34]</a> -&nbsp;Win7SP1 and Win8RTM folders<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=06m16s">[06:16]</a> -&nbsp;Bing: &quot;Windows 8 SDK&quot;<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=06m53s">[06:53]</a> - Bing: &quot;</span></span><span><span>Debugging Tools for Windows&quot;<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=07m25s">[07:25]</a> - New web installer does installation or download.<br></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=10m02s">[10:02]</a> - MSI files are in the ..\Windows Kits\8.0\StandaloneSDK\Installers<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=13m00s">[13:00]</a> - Sync your 'My' folder with <a href="https://skydrive.live.com/">SkyDrive</a> so it is always available!<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=13m30s">[13:30]</a> - Install the <strong>Debugging Tools for Windows</strong> to gather the files for xcopy deployment<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=15m33s">[15:33]</a> - <a href="http://www.microsoft.com/visualstudio/">Visual Studio 2012</a> builds&nbsp;PDBs with <strong>Inline Frame</strong> information<br></span></span></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=17m23s">[17:23]</a> - <a href="http://www.microsoft.com/visualstudio/">Visual Studio 2012</a> builds&nbsp;PDBs with <strong>Local Variable</strong> information<br><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=18m55s">[18:55]</a> - <strong>Windows 8</strong> supports <strong>Network</strong> and <strong>USB3</strong> kernel debugging<br></span></span></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=21m10s">[21:10]</a> - <a href="http://www.microsoft.com/visualstudio/">Visual Studio 2012</a> now supports both the VS and DbgEng debugger engines</span></span></span></span><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK#time=21m40s">[21:40]</a> - Keep posting questions and sending email to <a href="mailto:defragtools@microsoft.com">defragtools@microsoft.com</a>!</span></span></span></span></p><p><span><span><span><span><strong>CES 2013: </strong><br><a href="http://www.pixelsense.com/">Microsoft PixelSense</a><br><a href="http://www.youtube.com/watch?v=1sqFkd-wHKs">The Hobbit - Production Diary #4</a> - Film shot at 5K 48fps 3D</span></span></span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:387bcb9f54184e3b949ca1410153f614">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew Richards and Larry Larsen upgrade the software we downloaded in Episode #1&amp;nbsp;to the Windows 8 (x86 &amp;amp;x64) and Windows RT&amp;nbsp;(ARM) versions. Resources: Windows Software Development Kit (SDK) for Windows 8SysinternalsUSB3 Debugging Cable- Note, you must use&amp;nbsp;a USB3 A-A cable designed for debugging, otherwise it will fry your box!Timeline: [00:00] - Table tablets and 4K screens at CES 2013[02:30] - Time to upgrade our tools to the Windows 8\Windows RT versions![03:20] - www.sysinternals.com[05:34] -&amp;nbsp;Win7SP1 and Win8RTM folders[06:16] -&amp;nbsp;Bing: &amp;quot;Windows 8 SDK&amp;quot;[06:53] - Bing: &amp;quot;Debugging Tools for Windows&amp;quot;[07:25] - New web installer does installation or download.[10:02] - MSI files are in the ..\Windows Kits\8.0\StandaloneSDK\Installers[13:00] - Sync your &#39;My&#39; folder with SkyDrive so it is always available![13:30] - Install the Debugging Tools for Windows to gather the files for xcopy deployment[15:33] - Visual Studio 2012 builds&amp;nbsp;PDBs with Inline Frame information[17:23] - Visual Studio 2012 builds&amp;nbsp;PDBs with Local Variable information[18:55] - Windows 8 supports Network and USB3 kernel debugging[21:10] - Visual Studio 2012 now supports both the VS and DbgEng debugger engines[21:40] - Keep posting questions and sending email to defragtools@microsoft.com! CES 2013: Microsoft PixelSenseThe Hobbit - Production Diary #4 - Film shot at 5K 48fps 3D </itunes:summary>
      <itunes:duration>1424</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK</link>
      <pubDate>Mon, 14 Jan 2013 16:57:44 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.mp3" expression="full" duration="1424" fileSize="22798842" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.mp4" expression="full" duration="1424" fileSize="138475813" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.webm" expression="full" duration="1424" fileSize="54452243" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.wma" expression="full" duration="1424" fileSize="11528375" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.wmv" expression="full" duration="1424" fileSize="82817405" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23_high.mp4" expression="full" duration="1424" fileSize="303676181" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23_mid.mp4" expression="full" duration="1424" fileSize="212208860" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23_Source.wmv" expression="full" duration="1424" fileSize="456649207" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.ism/manifest" expression="full" duration="1424" fileSize="7646" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/3547/f0238ffe-fb9e-4bd9-8872-f53ce8d33547/DefragTools23.wmv" length="82817405" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>16</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-23-Windows-8-SDK/RSS</wfw:commentRss>
      <category>Debugging</category>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #22 - WinDbg - Memory Kernel Mode</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew Richards, Chad Beeder and Larry Larsen continue looking at the <strong>Debugging Tools for Windows</strong> (in particular <strong>WinDbg</strong>). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer.</p><p>This installment goes over the commands used to show the memory used in a kernel mode debug session. We cover these commands:</p><ul><li>!vm </li><li>!vm 1 </li><li>!memusage 8 </li><li>!poolused 2 </li><li>!poolused 4 </li><li>!poolfind &lt;tag&gt; </li><li>!pool &lt;addr&gt; </li><li>!pool &lt;addr&gt; 2 </li><li>!pte </li></ul><p>Make sure you watch <a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive">Defrag Tools Episode #1</a> for instructions on how to get the <strong>Debugging Tools for Windows</strong> and how to set the required environment variables for symbols and source code resolution.</p><p><strong>Resources:</strong><br><a href="http://www.microsoft.com/en-us/download/details.aspx?id=8279">Microsoft Windows SDK for Windows 7 and .NET Framework 4</a> <br><a href="http://technet.microsoft.com/en-us/sysinternals/bb897415">Sysinternals LiveKD</a><br><a href="http://technet.microsoft.com/en-us/sysinternals/ff700229">Sysinternals RAMMap</a></p><p><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=00m45s">[00:45]</a> - Sysinternals LiveKD debug of the machine<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=01m47s">[01:47]</a> - Virtual Memory summary (!vm 1)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=05m10s">[05:10]</a> - Sysinternals LiveKD live kernel dump (livekd.exe -m -o kernel.dmp)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=09m30s">[09:30]</a> - Sysinternals RAMMap<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=11m10s">[11:10]</a> - <span><span>Memory List summary (!memusage 8)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=16m15s">[16:15]</a> - Pool Usage by Non-Paged Pool (!poolused 2)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=20m16s">[20:16]</a> - Pool Tags (c:\debuggers\triage\pooltag.txt)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=28m06s">[28:06]</a> - Pool Usage by Paged Pool (!poolused 4)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=29m27s">[29:27]</a> - Pool issues lead to Bugchecks<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=34m00s">[34:00]</a> - Find Pool by Address&nbsp;(!pool &lt;addr&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=36m05s">[36:05]</a> - Find Pool by Tag (!poolfind &lt;tag&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=40m30s">[40:30]</a> - Page Table Entry (PTE) and Page Frame Number (PFN) (!pte &lt;addr&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode#time=42m45s">[42:45]</a> - Sometimes it is a physical hardware failure<br></span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:9d64ee25af2049528afba118015367e3">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew Richards, Chad Beeder and Larry Larsen continue looking at the Debugging Tools for Windows (in particular WinDbg). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer. This installment goes over the commands used to show the memory used in a kernel mode debug session. We cover these commands: !vm !vm 1 !memusage 8 !poolused 2 !poolused 4 !poolfind &amp;lt;tag&amp;gt; !pool &amp;lt;addr&amp;gt; !pool &amp;lt;addr&amp;gt; 2 !pte Make sure you watch Defrag Tools Episode #1 for instructions on how to get the Debugging Tools for Windows and how to set the required environment variables for symbols and source code resolution. Resources:Microsoft Windows SDK for Windows 7 and .NET Framework 4 Sysinternals LiveKDSysinternals RAMMap Timeline:[00:45] - Sysinternals LiveKD debug of the machine[01:47] - Virtual Memory summary (!vm 1)[05:10] - Sysinternals LiveKD live kernel dump (livekd.exe -m -o kernel.dmp)[09:30] - Sysinternals RAMMap[11:10] - Memory List summary (!memusage 8)[16:15] - Pool Usage by Non-Paged Pool (!poolused 2)[20:16] - Pool Tags (c:\debuggers\triage\pooltag.txt)[28:06] - Pool Usage by Paged Pool (!poolused 4)[29:27] - Pool issues lead to Bugchecks[34:00] - Find Pool by Address&amp;nbsp;(!pool &amp;lt;addr&amp;gt;)[36:05] - Find Pool by Tag (!poolfind &amp;lt;tag&amp;gt;)[40:30] - Page Table Entry (PTE) and Page Frame Number (PFN) (!pte &amp;lt;addr&amp;gt;)[42:45] - Sometimes it is a physical hardware failure </itunes:summary>
      <itunes:duration>2723</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode</link>
      <pubDate>Mon, 07 Jan 2013 20:31:31 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_512.jpg" height="287" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.mp3" expression="full" duration="2723" fileSize="43581059" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.mp4" expression="full" duration="2723" fileSize="261773779" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.webm" expression="full" duration="2723" fileSize="98532116" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.wma" expression="full" duration="2723" fileSize="22030359" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.wmv" expression="full" duration="2723" fileSize="159186527" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_high.mp4" expression="full" duration="2723" fileSize="574752123" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_mid.mp4" expression="full" duration="2723" fileSize="401111464" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22_Source.wmv" expression="full" duration="2723" fileSize="759477032" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.ism/manifest" expression="full" duration="2723" fileSize="7646" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/128a/6cf46ae7-4ba9-42e7-beca-3e5a3770128a/DefragTools22.wmv" length="159186527" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>5</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-22-WinDbg-Memory-Kernel-Mode/RSS</wfw:commentRss>
      <category>Drivers</category>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #14 - WinDbg - SOS</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew Richards and Larry Larsen continue looking at the <strong>Debugging Tools for Windows</strong> (in particular <strong>WinDbg</strong>). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer.</p><p>This installment shows how you can view the user mode call stack and stack variables in a native, managed (.NET) or Silverlight process. We&nbsp;use these commands:</p><ul><li>dv </li><li>dt </li><li>!sos.dumpstack </li><li>!sos.dumpstackobjects / !sos.dso </li><li>!sos.dumpobj / !sos.do </li><li>!sos.printexception / !sos.pe </li><li>.frame </li><li>.f&#43; </li><li>.f- </li><li>.load </li><li>.unload </li><li>.loadby </li><li>.chain </li><li>lm / lmm / lmvm </li><li>.extmatch </li><li>.prefer_dml 1 </li><li>.lines </li><li>.ecxr </li><li>.cls </li></ul><p>Make sure you watch <a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive">Defrag Tools Episode #1</a> for instructions on how to get the <strong>Debugging Tools for Windows</strong> and how to set&nbsp;the required environment variables for symbols and source code resolution.</p><p><strong>Resources:<br></strong><a href="http://www.microsoft.com/en-us/download/details.aspx?id=8279">Microsoft Windows SDK for Windows 7 and .NET Framework 4</a><br><a href="http://technet.microsoft.com/en-us/sysinternals/dd996900.aspx">Sysinternals ProcDump</a><strong><br></strong><a href="http://www.silverlight.net/downloads">Silverlight Developer Runtime</a></p><p><span><span><strong>Timeline:<br></strong></span></span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=01m05s">[01:05]</a> - Native vs. Managed variables<br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=02m35s">[02:35]</a> - Display Variables (dv) and Display Type (dt)</span></span><br><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=03m38s">[03:38]</a> - Debugger Extensions (.chain, .load, .unload)</span></span><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=05m43s">[05:43]</a> - Extension Match (.extmatch)</span></span><br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=07m08s">[07:08]</a> - ProcDump v5.1 captures a .NET 2 and .NET 4 exception<br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=08m46s">[08:46]</a> - .NET engines versus .NET releases</span></span><br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=10m34s">[10:34]</a> - Loading &quot;Son of Strike&quot; for .NET 2 engine applications (.loadby sos.dll <em>mscorwks</em>)<br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=13m44s">[13:44]</a> - Loading &quot;Son of Strike&quot; for .NET 4 engine applications (.loadby sos.dll <em>clr</em>)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=15m24s">[15:24]</a> - Dump Call Stack (!sos.dumpstack)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=16m32s">[16:32]</a> - Dump Stack Objects (!sos.dumpstackobjects / !sos.dso)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=17m30s">[17:30]</a> - Dump Object (!sos.dumpobject / !sos.do)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=17m51s">[17:51]</a> - Enable DML (.prefer_dml 1)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=20m14s">[20:14]</a> - Toggling Line display (.lines)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=20m52s">[20:52]</a> - Current Frame Context (.frame, .f&#43;, .f-); Note, registers do not change<br></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=22m58s">[22:58]</a> - ProcDump v5.1 misses Silverlight exceptions<br></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=24m50s">[24:50]</a> - Silverlight Developer Runtime (dbgshim.dll &amp; sos.dll)<br></span></span></span></span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=26m10s">[26:10]</a> - ProcDump v5.1 captures a Silverlight exception<br></span></span></span></span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=28m10s">[28:10]</a> - Loading &quot;Son of Strike&quot; for Silverlight applications (.loadby sos.dll <em>coreclr</em>)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=30m47s">[30:47]</a> - Missed: </span></span>Exceptions can also be displayed with !sos.printexception / !sos.pe<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS#time=31m29s">[31:29]</a> -&nbsp;Episode review and next week... Kernel debugging</span></span></span></span></span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:91aa3622a9a54585ba84a0e101206ed8">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew Richards and Larry Larsen continue looking at the Debugging Tools for Windows (in particular WinDbg). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer. This installment shows how you can view the user mode call stack and stack variables in a native, managed (.NET) or Silverlight process. We&amp;nbsp;use these commands: dv dt !sos.dumpstack !sos.dumpstackobjects / !sos.dso !sos.dumpobj / !sos.do !sos.printexception / !sos.pe .frame .f&amp;#43; .f- .load .unload .loadby .chain lm / lmm / lmvm .extmatch .prefer_dml 1 .lines .ecxr .cls Make sure you watch Defrag Tools Episode #1 for instructions on how to get the Debugging Tools for Windows and how to set&amp;nbsp;the required environment variables for symbols and source code resolution. Resources:Microsoft Windows SDK for Windows 7 and .NET Framework 4Sysinternals ProcDumpSilverlight Developer Runtime Timeline:[01:05] - Native vs. Managed variables[02:35] - Display Variables (dv) and Display Type (dt)[03:38] - Debugger Extensions (.chain, .load, .unload)[05:43] - Extension Match (.extmatch)[07:08] - ProcDump v5.1 captures a .NET 2 and .NET 4 exception[08:46] - .NET engines versus .NET releases[10:34] - Loading &amp;quot;Son of Strike&amp;quot; for .NET 2 engine applications (.loadby sos.dll mscorwks)[13:44] - Loading &amp;quot;Son of Strike&amp;quot; for .NET 4 engine applications (.loadby sos.dll clr)[15:24] - Dump Call Stack (!sos.dumpstack)[16:32] - Dump Stack Objects (!sos.dumpstackobjects / !sos.dso)[17:30] - Dump Object (!sos.dumpobject / !sos.do)[17:51] - Enable DML (.prefer_dml 1)[20:14] - Toggling Line display (.lines)[20:52] - Current Frame Context (.frame, .f&amp;#43;, .f-); Note, registers do not change[22:58] - ProcDump v5.1 misses Silverlight exceptions[24:50] - Silverlight Developer Runtime (dbgshim.dll &amp;amp; sos.dll)[26:10] - ProcDump v5.1 captures a Silverlight exception[28:10] - Loading &amp;quot;Son of Strike&amp;quot; for Silverlight applica</itunes:summary>
      <itunes:duration>2056</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS</link>
      <pubDate>Mon, 12 Nov 2012 18:24:02 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.mp3" expression="full" duration="2056" fileSize="32908019" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.mp4" expression="full" duration="2056" fileSize="201196413" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.webm" expression="full" duration="2056" fileSize="76403289" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.wma" expression="full" duration="2056" fileSize="16635175" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.wmv" expression="full" duration="2056" fileSize="114768893" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14_high.mp4" expression="full" duration="2056" fileSize="437649034" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14_mid.mp4" expression="full" duration="2056" fileSize="306507271" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14_Source.wmv" expression="full" duration="2056" fileSize="305411411" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.ism/manifest" expression="full" duration="2056" fileSize="10034" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/f9f0/c1047a76-2158-4998-803f-2c2db849f9f0/DefragTools14.wmv" length="114768893" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>26</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-14-WinDbg-SOS/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: Live - //build/ 2012</title>
      <description><![CDATA[<p><span>Mark Russinovich joins Larry Larsen and Andrew Richards for a live version of Defrag Tools where they take questions about troubleshooting Windows 8, the changes to the Sysinternals Tools, Driver support, VHD support, Security, and much more.</span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:35ffc0be4db24fdeba54a0fd014eb334">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Live-Build2012</comments>
      <itunes:summary>Mark Russinovich joins Larry Larsen and Andrew Richards for a live version of Defrag Tools where they take questions about troubleshooting Windows 8, the changes to the Sysinternals Tools, Driver support, VHD support, Security, and much more. </itunes:summary>
      <itunes:duration>2676</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Live-Build2012</link>
      <pubDate>Tue, 06 Nov 2012 17:50:16 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Live-Build2012</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.mp3" expression="full" duration="2676" fileSize="1" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.mp4" expression="full" duration="2676" fileSize="1" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.webm" expression="full" duration="2676" fileSize="1" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.wma" expression="full" duration="2676" fileSize="1" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.wmv" expression="full" duration="2676" fileSize="1" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive_high.mp4" expression="full" duration="2676" fileSize="1" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive_mid.mp4" expression="full" duration="2676" fileSize="1" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive_Source.wmv" expression="full" duration="2676" fileSize="1" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.ism/manifest" expression="full" duration="2676" fileSize="1" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/2f81/f5f653e0-a64e-40c1-8766-ea72311d2f81/DefragToolsLive.wmv" length="0" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Mark Russinovich, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Mark Russinovich, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>2</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Live-Build2012/RSS</wfw:commentRss>
      <category>Security</category>
      <category>sysinternals</category>
      <category>Tech Support</category>
      <category>Build</category>
    </item>
  <item>
      <title>Defrag Tools: #13 - WinDbg</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew Richards and Larry Larsen start walking you through the <strong>Debugging Tools for Windows</strong> (in particular <strong>WinDbg</strong>). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer.</p><p>This first WinDbg installment configures the system to open dumps files via an adjusted Context Menu. It&nbsp;shows how to set WinDbg as the (AeDebug) postmortem debugger, and how to use <strong>ProcDump v5.1</strong> to do the same but capture the process as a dump file. It then starts to explain some basic concepts of debugging: call stacks (k), registers (r) and&nbsp;exception context records (.ecxr).</p><p>Make sure you watch <a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive">Defrag Tools Episode #1</a> for instructions on how to get the <strong>Debugging Tools for Windows</strong> and how to set&nbsp;the required environment variables for symbols and source code resolution.</p><p><strong>Resources:<br></strong><a href="http://www.microsoft.com/en-us/download/details.aspx?id=8279">Microsoft Windows SDK for Windows 7 and .NET Framework 4</a><br><a href="http://technet.microsoft.com/en-us/sysinternals/dd996900.aspx">Sysinternals ProcDump</a></p><p><span><span><strong>Timeline:<br></strong></span></span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=00m00s">[00:00]</a> - Windows 8 General Availability (GA)<br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=02m45s">[02:45]</a> - WinDbg -IA&nbsp;- Register File Associations</span></span><br><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=05m45s">[05:45]</a> - Custom Context Menu</span></span><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=10m15s">[10:15]</a> - WinDbg -I - Register Postmortem Debugger</span></span><br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=11m07s">[11:07]</a> - Custom AeDebug: -c &quot;.jdinfo %p&quot;<br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=15m00s">[15:00]</a> - ProcDump v5.1: -i &lt;folder&gt;<br></span></span></span></span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=18m00s">[18:00]</a> - Internals of Windows Error Reporting<br><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=21m48s">[21:48]</a> - Registers (r)<br><span><span><span><span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=29m50s">[29:50]</a> - Exception Context Record (.ecxr)<br></span></span></span></span></span></span><span><span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=32m01s">[32:01]</a> - Examples - NT Debugging Blog<br></span></span><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=34m02s">[34:02]</a> -&nbsp;MSJ Magazine - Under The Hood<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=35m20s">[35:20]</a> - <a href="http://www.intel.com/content/www/us/en/processors/architectures-software-developer-manuals.html">Intel Developer's Manual</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg#time=38m40s">[38:40]</a> - Next week, Call Stacks, Locals and .NET/Silverlight extensions</span></span></span></span></span></span></p><p><strong>MSJ (MSDN) Magazine:</strong></p><p><em>Assembly Language<br></em><a href="http://www.microsoft.com/msj/0298/hood0298.aspx" target="_blank">http://www.microsoft.com/msj/0298/hood0298.aspx</a><br><a href="http://www.microsoft.com/msj/0797/hood0797.aspx" target="_blank">http://www.microsoft.com/msj/0797/hood0797.aspx</a></p><p><strong>NT Debugging Blog:</strong>&nbsp;&nbsp;<a href="http://blogs.msdn.com/b/ntdebugging/">http://blogs.msdn.com/b/ntdebugging/</a></p><p><em>Debugging Techniques<br></em><a href="http://blogs.msdn.com/b/ntdebugging/archive/2007/06/13/hung-window-no-source-no-problem-part-1.aspx">http://blogs.msdn.com/b/ntdebugging/archive/2007/06/13/hung-window-no-source-no-problem-part-1.aspx</a><br><a href="http://blogs.msdn.com/ntdebugging/archive/2007/06/15/hung-window-no-source-no-problem-part-2.aspx">http://blogs.msdn.com/b/ntdebugging/archive/2007/06/15/hung-window-no-source-no-problem-part-2.aspx</a><br><a href="http://blogs.msdn.com/ntdebugging/archive/2007/06/15/this-button-doesn-t-do-anything.aspx">http://blogs.msdn.com/b/ntdebugging/archive/2007/06/15/this-button-doesn-t-do-anything.aspx</a></p><p><em>Fundamentals<br></em><a href="http://blogs.msdn.com/b/ntdebugging/archive/tags/fundamentals&#43;exercise/">http://blogs.msdn.com/b/ntdebugging/archive/tags/fundamentals&#43;exercise/</a></p><p><em>Puzzles<br></em><a href="http://blogs.msdn.com/b/ntdebugging/archive/tags/puzzler/">http://blogs.msdn.com/b/ntdebugging/archive/tags/puzzler/</a></p><p><strong>Custom&nbsp;Context Menu (WinDbg -IA):</strong></p><p><pre class="brush: text">
Windows Registry Editor Version 5.00
[HKEY_CLASSES_ROOT\.dmp]
@=&quot;WinDbg.DumpFile.1&quot;
 
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1]
@=&quot;WinDbg Post-Mortem Dump File&quot;
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1\DefaultIcon]
@=&quot;\&quot;C:\\debuggers\\windbg.exe\&quot;,-3002&quot;
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1\shell]
@=&quot;Open&quot;
 
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1\shell\Open]
@=&quot;Open x&amp;64&quot;
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1\shell\Open\command]
@=&quot;\&quot;C:\\debuggers\\windbg.exe\&quot; -z \&quot;%1\&quot; -c \&quot;.prefer_dml 1\&quot;&quot;
 
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1\shell\Open_x86]
@=&quot;Open x&amp;86&quot;
[HKEY_CLASSES_ROOT\WinDbg.DumpFile.1\shell\Open_x86\command]
@=&quot;\&quot;C:\\debuggers_x86\\windbg.exe\&quot; -z \&quot;%1\&quot; -c \&quot;.prefer_dml 1\&quot;&quot;
</pre></p><p><strong>Custom AeDebug&nbsp;(WinDbg -I):</strong></p><p><pre class="brush: text">
Windows Registry Editor Version 5.00
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AeDebug]
&quot;Auto&quot;=&quot;1&quot;
&quot;Debugger&quot;=&quot;\&quot;C:\\debuggers\\windbg.exe\&quot; -p %ld -e %ld -c \&quot;.jdinfo %p\&quot;&quot;
 
[HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows NT\CurrentVersion\AeDebug]
&quot;Auto&quot;=&quot;1&quot;
&quot;Debugger&quot;=&quot;\&quot;C:\\debuggers_x86\\windbg.exe\&quot; -p %ld -e %ld -c \&quot;.jdinfo %p\&quot;&quot;
</pre></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:265f33f3fd1246f58eeea0e101204051">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew Richards and Larry Larsen start walking you through the Debugging Tools for Windows (in particular WinDbg). WinDbg is a debugger that supports user mode debugging of a process, or kernel mode debugging of a computer. This first WinDbg installment configures the system to open dumps files via an adjusted Context Menu. It&amp;nbsp;shows how to set WinDbg as the (AeDebug) postmortem debugger, and how to use ProcDump v5.1 to do the same but capture the process as a dump file. It then starts to explain some basic concepts of debugging: call stacks (k), registers (r) and&amp;nbsp;exception context records (.ecxr). Make sure you watch Defrag Tools Episode #1 for instructions on how to get the Debugging Tools for Windows and how to set&amp;nbsp;the required environment variables for symbols and source code resolution. Resources:Microsoft Windows SDK for Windows 7 and .NET Framework 4Sysinternals ProcDump Timeline:[00:00] - Windows 8 General Availability (GA)[02:45] - WinDbg -IA&amp;nbsp;- Register File Associations[05:45] - Custom Context Menu[10:15] - WinDbg -I - Register Postmortem Debugger[11:07] - Custom AeDebug: -c &amp;quot;.jdinfo %p&amp;quot;[15:00] - ProcDump v5.1: -i &amp;lt;folder&amp;gt;[18:00] - Internals of Windows Error Reporting[21:48] - Registers (r)[29:50] - Exception Context Record (.ecxr)[32:01] - Examples - NT Debugging Blog[34:02] -&amp;nbsp;MSJ Magazine - Under The Hood[35:20] - Intel Developer&#39;s Manual[38:40] - Next week, Call Stacks, Locals and .NET/Silverlight extensions MSJ (MSDN) Magazine: Assembly Languagehttp://www.microsoft.com/msj/0298/hood0298.aspxhttp://www.microsoft.com/msj/0797/hood0797.aspx NT Debugging Blog:&amp;nbsp;&amp;nbsp;http://blogs.msdn.com/b/ntdebugging/ Debugging Techniqueshttp://blogs.msdn.com/b/ntdebugging/archive/2007/06/13/hung-window-no-source-no-problem-part-1.aspxhttp://blogs.msdn.com/b/ntdebugging/archive/2007/06/15/hung-window-no-source-no-problem-part-2.aspxhttp://blogs.msdn.com/b/ntdebugging/archive/2007/06/15/this-butt</itunes:summary>
      <itunes:duration>2353</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg</link>
      <pubDate>Mon, 22 Oct 2012 18:34:59 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.mp3" expression="full" duration="2353" fileSize="37657291" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.mp4" expression="full" duration="2353" fileSize="226726860" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.webm" expression="full" duration="2353" fileSize="87951889" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.wma" expression="full" duration="2353" fileSize="19035371" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.wmv" expression="full" duration="2353" fileSize="129041363" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13_high.mp4" expression="full" duration="2353" fileSize="497056615" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13_mid.mp4" expression="full" duration="2353" fileSize="347427817" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13_Source.wmv" expression="full" duration="2353" fileSize="461080264" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.ism/manifest" expression="full" duration="2353" fileSize="6046" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/cd7e/12ef0c28-6d0e-4c78-a0fb-03fd49f9cd7e/DefragTools13.wmv" length="129041363" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>11</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-13-WinDbg/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #11 - ProcDump - Windows 8 &amp; Process Monitor</title>
      <description><![CDATA[<p>In this 3 part episode of <strong>Defrag Tools</strong>, Andrew Richards&nbsp;and&nbsp;Larry Larsen walk you through <strong>Sysinternals ProcDump</strong>. ProcDump allows you to capture the memory of a process running on the computer. The dump file can be of varying size and can be taken with varying outage durations. Dumps can be triggered immediately or can be triggered by a variety of events including CPU utilization, Memory utilization, a Performance Counter, a Hung Window and/or Native/Managed exceptions.</p><p><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump">Part 1</a> covers what the tool captures and the outage durations that can be expected.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers">Part 2</a> goes through the wide variety of triggering options; in particular 1st and 2nd chance exceptions.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor">Part 3</a> (this week) goes through Windows 8 Modern Application support and Process Monitor logging support.</p><p><strong>Resources:<br></strong><a href="http://technet.microsoft.com/en-us/sysinternals/dd996900.aspx">Sysinternals ProcDump</a></p><p><span><span><strong>Timeline:<br></strong><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=00m00s">[00:00]</a> - Overview of Windows 8 Modern Applications<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=01m09s">[01:09]</a> - ProcDump v5.0 vs. PLMDebug<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=01m38s">[01:38]</a> - Registry - Package and Application Names (AppUserModeId)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=02m00s">[02:00]</a> - Activation and Monitoring (-x &lt;folder&gt; &lt;appusermodeid&gt;)&nbsp;<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=04m42s">[04:42]</a> - User created ProcDump<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=05m21s">[05:21]</a> - Registry changes - DebugInformation<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=05m40s">[05:40]</a> - PLM created ProcDump<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=06m53s">[06:53]</a> - Process Monitor - Debug Output Profile events<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=09m50s">[09:50]</a> - PLM behaviour for Attach vs. Launch<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor#time=11m17s">[11:17]</a> - And that's it for ProcDump!</span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:881f8b317c124e1e95a0a0d20141cbba">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor</comments>
      <itunes:summary>In this 3 part episode of Defrag Tools, Andrew Richards&amp;nbsp;and&amp;nbsp;Larry Larsen walk you through Sysinternals ProcDump. ProcDump allows you to capture the memory of a process running on the computer. The dump file can be of varying size and can be taken with varying outage durations. Dumps can be triggered immediately or can be triggered by a variety of events including CPU utilization, Memory utilization, a Performance Counter, a Hung Window and/or Native/Managed exceptions. Part 1 covers what the tool captures and the outage durations that can be expected.Part 2 goes through the wide variety of triggering options; in particular 1st and 2nd chance exceptions.Part 3 (this week) goes through Windows 8 Modern Application support and Process Monitor logging support. Resources:Sysinternals ProcDump Timeline:[00:00] - Overview of Windows 8 Modern Applications[01:09] - ProcDump v5.0 vs. PLMDebug[01:38] - Registry - Package and Application Names (AppUserModeId)[02:00] - Activation and Monitoring (-x &amp;lt;folder&amp;gt; &amp;lt;appusermodeid&amp;gt;)&amp;nbsp;[04:42] - User created ProcDump[05:21] - Registry changes - DebugInformation[05:40] - PLM created ProcDump[06:53] - Process Monitor - Debug Output Profile events[09:50] - PLM behaviour for Attach vs. Launch[11:17] - And that&#39;s it for ProcDump! </itunes:summary>
      <itunes:duration>727</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor</link>
      <pubDate>Mon, 08 Oct 2012 16:42:46 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.mp3" expression="full" duration="727" fileSize="11646017" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.mp4" expression="full" duration="727" fileSize="74268382" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.webm" expression="full" duration="727" fileSize="25322057" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.wma" expression="full" duration="727" fileSize="5892871" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.wmv" expression="full" duration="727" fileSize="40873655" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11_high.mp4" expression="full" duration="727" fileSize="159902285" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11_mid.mp4" expression="full" duration="727" fileSize="112404576" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11_Source.wmv" expression="full" duration="727" fileSize="141061648" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.ism/manifest" expression="full" duration="727" fileSize="6046" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/26e7/9f39d624-f9aa-434b-a1da-41545a5a26e7/DefragTools11.wmv" length="40873655" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>4</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #10 - ProcDump - Triggers</title>
      <description><![CDATA[<p>In this 3 part episode of <strong>Defrag Tools</strong>, Andrew Richards and Larry Larsen walk you through <strong>Sysinternals ProcDump</strong>. ProcDump allows you to capture the memory of a process running on the computer. The dump file can be of varying size and can be taken with varying outage durations. Dumps can be triggered immediately or can be triggered by a variety of events including CPU utilization, Memory utilization, a Performance Counter, a Hung Window and/or Native/Managed exceptions.</p><p><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump">Part 1</a> covers what the tool captures and the outage durations that can be expected.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers">Part 2</a> (this week) goes through the wide variety of triggering options; in particular 1st and 2nd chance exceptions.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor">Part 3</a> goes through Windows 8 Modern Application support and Process Monitor logging support.<br><br><strong>Resources:&nbsp;<br></strong><a href="http://technet.microsoft.com/en-us/sysinternals/dd996900.aspx">Sysinternals ProcDump</a></p><p><span><span><strong>Timeline:<br></strong><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=00m27s">[00:27]</a> - WinDbg -IA - Register File Associations<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=00m58s">[00:58]</a> - WinDbg -I - Postmortem Debugger (AeDebug) **<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=04m48s">[04:48]</a> - Triggers<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=05m13s">[05:13]</a> - Breakpoints (-b)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=06m03s">[06:03]</a> - CPU (-c) and Uniprocessor scale (-u) [<a href="http://blogs.technet.com/b/markrussinovich/archive/2010/08/24/3351213.aspx">Compound Case of the Outlook Hangs</a>]<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=11m06s">[11:06]</a> - Count (-n)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=11m42s">[11:42]</a> - Examples (-? -e)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=12m02s">[12:02]</a> - Performance Counters (-p &lt;counter&gt; &lt;value&gt;) *<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=13m20s">[13:20]</a> - Hung window (-h)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=13m36s">[13:36]</a> - Wait (-w &lt;process&gt;) and Execute (-x &lt;folder&gt; &lt;process&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=14m28s">[14:28]</a> - Crashes (e.g. procdump -e -x c:\dumps notepad) ***<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=16m45s">[16:45]</a> - Memory Commit (-m &lt;Mb&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=18m25s">[18:25]</a> - Timed (-n &lt;count&gt; -s &lt;seconds&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=21m30s">[21:30]</a> - Process Name vs PID<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=22m24s">[22:24]</a> - Exceptions; C&#43;&#43; (msc) vs CLR vs OS<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=23m35s">[23:35]</a> - Crashes &amp; Recovery - aka 2nd Chance Exceptions (-e)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=28m40s">[28:40]</a> - 1st Chance Exceptions (-e 1)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=31m07s">[31:07]</a> - Exception Filtering (-f &lt;filter&gt;)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=33m30s">[33:30]</a> - Exception Names<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=34m50s">[34:50]</a> - <a href="http://msdn.microsoft.com/en-us/library/windows/desktop/ms681381.aspx">System Error Codes</a> and <strong>!error</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=36m30s">[36:30]</a> - Ignore transistion to .NET 4&nbsp;managed debugging (-g)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers#time=38m07s">[38:07]</a> - Next time... Windows 8 Modern Applications and Process Monitor Logging<br></span></span></p><p><span><span>*&nbsp;The Performance Counter (-p) trigger does&nbsp;use the seconds (-s) parameter.<br></span></span><span><span>**&nbsp;<strong>ProcDump v5.1</strong> (not yet released) adds <strong>procdump.exe -i &lt;folder&gt;</strong> support to set ProcDump as the postmortem debugger for both x64 and x86 applications (includes a JIT context).<br>*** If you are using <strong>ProcDump v5.0</strong> as the postmortem debugger (<em>doesn't</em> include a JIT context), use these AeDebug settings:<br>Auto&nbsp;= &quot;1&quot;<br>Debugger = &quot;C:\my\sysinternals\procdump.exe %ld -ma c:\dumps&quot;</span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:bb227dfcdaba44ad94bfa0d201418ecb">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers</comments>
      <itunes:summary>In this 3 part episode of Defrag Tools, Andrew Richards and Larry Larsen walk you through Sysinternals ProcDump. ProcDump allows you to capture the memory of a process running on the computer. The dump file can be of varying size and can be taken with varying outage durations. Dumps can be triggered immediately or can be triggered by a variety of events including CPU utilization, Memory utilization, a Performance Counter, a Hung Window and/or Native/Managed exceptions. Part 1 covers what the tool captures and the outage durations that can be expected.Part 2 (this week) goes through the wide variety of triggering options; in particular 1st and 2nd chance exceptions.Part 3 goes through Windows 8 Modern Application support and Process Monitor logging support.Resources:&amp;nbsp;Sysinternals ProcDump Timeline:[00:27] - WinDbg -IA - Register File Associations[00:58] - WinDbg -I - Postmortem Debugger (AeDebug) **[04:48] - Triggers[05:13] - Breakpoints (-b)[06:03] - CPU (-c) and Uniprocessor scale (-u) [Compound Case of the Outlook Hangs][11:06] - Count (-n)[11:42] - Examples (-? -e)[12:02] - Performance Counters (-p &amp;lt;counter&amp;gt; &amp;lt;value&amp;gt;) *[13:20] - Hung window (-h)[13:36] - Wait (-w &amp;lt;process&amp;gt;) and Execute (-x &amp;lt;folder&amp;gt; &amp;lt;process&amp;gt;)[14:28] - Crashes (e.g. procdump -e -x c:\dumps notepad) ***[16:45] - Memory Commit (-m &amp;lt;Mb&amp;gt;)[18:25] - Timed (-n &amp;lt;count&amp;gt; -s &amp;lt;seconds&amp;gt;)[21:30] - Process Name vs PID[22:24] - Exceptions; C&amp;#43;&amp;#43; (msc) vs CLR vs OS[23:35] - Crashes &amp;amp; Recovery - aka 2nd Chance Exceptions (-e)[28:40] - 1st Chance Exceptions (-e 1)[31:07] - Exception Filtering (-f &amp;lt;filter&amp;gt;)[33:30] - Exception Names[34:50] - System Error Codes and !error[36:30] - Ignore transistion to .NET 4&amp;nbsp;managed debugging (-g)[38:07] - Next time... Windows 8 Modern Applications and Process Monitor Logging *&amp;nbsp;The Performance Counter (-p) trigger does&amp;nbsp;use the seconds (-s) parameter.**&amp;nbsp;ProcDump v5.1 (not yet released) adds procdump</itunes:summary>
      <itunes:duration>2328</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers</link>
      <pubDate>Mon, 01 Oct 2012 16:46:14 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.mp3" expression="full" duration="2328" fileSize="37256048" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.mp4" expression="full" duration="2328" fileSize="225067168" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.webm" expression="full" duration="2328" fileSize="84265021" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.wma" expression="full" duration="2328" fileSize="18834103" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.wmv" expression="full" duration="2328" fileSize="122258453" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10_high.mp4" expression="full" duration="2328" fileSize="493719698" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10_mid.mp4" expression="full" duration="2328" fileSize="345801399" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10_Source.wmv" expression="full" duration="2328" fileSize="336773081" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.ism/manifest" expression="full" duration="2328" fileSize="6046" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/2a60/9b7af1cb-f19b-4316-a59b-50d520222a60/DefragTools10.wmv" length="122258453" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>5</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #9 - ProcDump</title>
      <description><![CDATA[<p>In this 3 part episode of <strong>Defrag Tools</strong>, Andrew Richards and Larry Larsen walk you through <strong>Sysinternals ProcDump</strong>. ProcDump allows you to capture the memory of a process running on the computer. The dump file can be of varying size and can be taken with varying outage durations. Dumps can be triggered immediately or can be triggered by a variety of events including CPU utilization, Memory utilization, a Performance Counter, a Hung Window&nbsp;and/or&nbsp;Native/Managed exceptions.</p><p><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump">Part 1</a> (this week) covers what the tool captures and the outage durations that can be expected.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-10-ProcDump-Triggers">Part 2</a> goes through the&nbsp;wide variety of triggering options; in particular 1st and 2nd chance exceptions.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-11-ProcDump-Windows-8--Process-Monitor">Part 3</a> goes through Windows 8 Modern Application support and Process Monitor logging support.</p><p><strong>Resources:<br></strong><a href="http://technet.microsoft.com/en-us/sysinternals/dd996900.aspx">Sysinternals ProcDump</a><br><a href="http://technet.microsoft.com/en-us/sysinternals/dd535533.aspx">Sysinternals VMMap</a></p><p><span><span><strong>Timeline:</strong> <br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=01m15s">[01:15]</a> - Download latest version - <a href="http://www.sysinternals.com">www.sysinternals.com</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=02m23s">[02:23]</a> - ProcDump v5 features<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=03m52s">[03:52]</a> - Task Manager, Process Explorer vs.&nbsp;ProcDump<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=05m32s">[05:32]</a> - Dump architecture (x86 vs. x64) needs to match the target<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=08m02s">[08:02]</a> - Mini, Full (-ma), MiniPlus (-mp) and Custom (-d)&nbsp;dumps<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=13m45s">[13:45]</a> - WinDbg - rely on Mapped Memory Image File<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=16m54s">[16:54]</a> - ProcDump Custom Dump Support (-d &lt;dll&gt;) - [<a href="http://msdn.microsoft.com/en-us/magazine/28014460-afba-4167-aaa8-ba7960a6a902">MSDN Magazine</a>]<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=18m34s">[18:34]</a> - Detach at Shutdown, Logoff, Console Close, Ctrl-C, Ctrl-Break<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=19m15s">[19:15]</a> - Process Reflection (-r)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=21m44s">[21:44]</a> - Episode review and required permissions<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump#time=23m03s">[23:03]</a> - Next episode, triggering...</span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:ee164cb9f6104a229782a0d201415d7b">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump</comments>
      <itunes:summary>In this 3 part episode of Defrag Tools, Andrew Richards and Larry Larsen walk you through Sysinternals ProcDump. ProcDump allows you to capture the memory of a process running on the computer. The dump file can be of varying size and can be taken with varying outage durations. Dumps can be triggered immediately or can be triggered by a variety of events including CPU utilization, Memory utilization, a Performance Counter, a Hung Window&amp;nbsp;and/or&amp;nbsp;Native/Managed exceptions. Part 1 (this week) covers what the tool captures and the outage durations that can be expected.Part 2 goes through the&amp;nbsp;wide variety of triggering options; in particular 1st and 2nd chance exceptions.Part 3 goes through Windows 8 Modern Application support and Process Monitor logging support. Resources:Sysinternals ProcDumpSysinternals VMMap Timeline: [01:15] - Download latest version - www.sysinternals.com[02:23] - ProcDump v5 features[03:52] - Task Manager, Process Explorer vs.&amp;nbsp;ProcDump[05:32] - Dump architecture (x86 vs. x64) needs to match the target[08:02] - Mini, Full (-ma), MiniPlus (-mp) and Custom (-d)&amp;nbsp;dumps[13:45] - WinDbg - rely on Mapped Memory Image File[16:54] - ProcDump Custom Dump Support (-d &amp;lt;dll&amp;gt;) - [MSDN Magazine][18:34] - Detach at Shutdown, Logoff, Console Close, Ctrl-C, Ctrl-Break[19:15] - Process Reflection (-r)[21:44] - Episode review and required permissions[23:03] - Next episode, triggering... </itunes:summary>
      <itunes:duration>1442</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump</link>
      <pubDate>Mon, 24 Sep 2012 18:09:39 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.mp3" expression="full" duration="1442" fileSize="23081380" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.mp4" expression="full" duration="1442" fileSize="146437489" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.webm" expression="full" duration="1442" fileSize="52108927" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.wma" expression="full" duration="1442" fileSize="11669563" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.wmv" expression="full" duration="1442" fileSize="91393073" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9_high.mp4" expression="full" duration="1442" fileSize="310561111" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9_mid.mp4" expression="full" duration="1442" fileSize="218075980" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9_Source.wmv" expression="full" duration="1442" fileSize="324897900" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.ism/manifest" expression="full" duration="1442" fileSize="6036" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/defd/e87b8ed8-64a3-4042-9adc-6dbb9745defd/DefragTools9.wmv" length="91393073" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>3</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-9-ProcDump/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #8 - Mark Russinovich</title>
      <description><![CDATA[<p><strong>Mark Russinovich</strong> joins Andrew Richards and Larry&nbsp;Larsen on&nbsp;this episode of <strong>Defrag Tools</strong> to talk about the history of <strong>Sysinternals</strong>, his involvement with the <strong>Windows Internals</strong> book series and&nbsp;advice on <strong>Cybersecurity. </strong>Learn about new tools, retired tools and tools that never got completed.&nbsp; Get advice on troubleshooting.&nbsp;Get advice on how to survive a cyber attack. And much much more...</p><p><em>Write a comment before 24th Sept. for a chance to win a signed copy of <a href="http://www.russinovich.com/books/trojan-horse/">Trojan Horse</a>!</em></p><p><strong>Blog:</strong><br>Mark's Blog&nbsp;(TechNet) - <a href="http://blogs.technet.com/b/markrussinovich/">http://blogs.technet.com/b/markrussinovich/</a><br>Mark's Web Site - <a href="http://www.russinovich.com/">http://www.russinovich.com/</a><br>Sysinternals&nbsp;Web Site - <a href="http://www.sysinternals.com/">http://www.sysinternals.com</a></p><p><strong>Videos:</strong><br>All of Mark's <a href="http://channel9.msdn.com/Tags/mark&#43;russinovich">videos</a> on Channel 9 and <a href="http://channel9.msdn.com/Events/Speakers/Mark-Russinovich">talks</a>&nbsp;at conferences. Of note:<br>* <a href="http://channel9.msdn.com/search?term=Case&#43;of&#43;the&#43;Unexplained">Case of the Unexplained...</a><br>* Mysteries of Memory Management Revealed&nbsp;- <a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WCL405">Part 1</a>, <a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WCL406">Part 2</a><br>* <a href="http://channel9.msdn.com/search?term=Malware&#43;Hunting&#43;with&#43;the&#43;Sysinternals&#43;Tools">Malware Hunting with the Sysinternals Tools</a><br>* <a href="http://365.rsaconference.com/community/archive/usa/blog/2012/03/15/video-rsac-us-2012-rsa-conference-2012--zero-day-a-non-fiction-view--mark-russinovich">RSA Conference 2012&nbsp;-- Zero Day: A Non-Fiction View</a><br>* <a href="http://channel9.msdn.com/shows/Going&#43;Deep/Mark-Russinovich-Inside-Windows-7/">Inside Windows 7</a><br>* <a href="http://channel9.msdn.com/Shows/Going&#43;Deep/Mark-Russinovich-Inside-Windows-7-Redux">Inside Windows 7&nbsp;Redux</a><br>* <a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2010/WCL404">Windows 7 and Windows Server 2008 R2 Kernel Changes</a><br>* <a href="http://channel9.msdn.com/Shows/Going&#43;Deep/Mark-Russinovich-On-Working-at-Microsoft-Windows-Server-2008-Kernel-MinWin-vs-ServerCore-HyperV">Windows Vista and Windows Server 2008 Kernel Changes</a></p><p><strong>Books:</strong><br><a href="http://www.russinovich.com/books/windows-sysinternals-administrators-reference/">Sysinternals Administrator's Reference</a> - [<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]<br><a href="http://technet.microsoft.com/en-us/sysinternals/bb963901.aspx">Windows Internals</a>&nbsp;books:<br>* <a href="http://www.russinovich.com/books/windows-internals-4/">4th Edition</a> - Windows XP and Windows Server 2003 - [<a href="http://www.amazon.com/Microsoft-Windows-Internals-4th-Edition/dp/B002DMJTXM">Amazon</a>]<br>* <a href="http://www.russinovich.com/books/windows-internals-5/">5th Edition</a> - Windows Vista and Windows Server 2008 - [<a href="http://www.amazon.com/Windows%C2%AE-Internals-Including-Windows-Developer/dp/0735625301">Amazon</a>]<br>* <a href="http://www.russinovich.com/books/windows-internals-6/">6th Edition</a> - Windows 7 and Windows Server 2008 R2 - [Amazon:&nbsp;<a href="http://www.amazon.com/Windows-Internals-Part-Covering-Server/dp/0735648735">Part 1</a>,&nbsp;<a href="http://www.amazon.com/Windows-Internals-Part-Covering-Server/dp/0735648735">Part 2</a>]<br>Cybersecurity novels:<br>* <a href="http://www.russinovich.com/books/zero-day/">Zero Day</a> - A Novel - [<a href="http://www.amazon.com/Zero-Day-Novel-Mark-Russinovich/dp/1250007305">Amazon</a>]<br>* <a href="http://www.russinovich.com/books/trojan-horse/">Trojan Horse</a> - A Novel - [<a href="http://www.amazon.com/Zero-Day-Novel-Mark-Russinovich/dp/1250007305">Amazon</a>]<br>* <a href="http://www.russinovich.com/books/operation-desolation/">Operation Desolation</a> - A Short Story - [<a href="http://www.amazon.com/Operation-Desolation-Case-Defacement-ebook/dp/B0080K37P2">Amazon</a>]</p><p><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=00m00s">[00:00]</a> - How did Sysinternals start?<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=02m20s">[02:20]</a> - Tools that never got released and tool retirement<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=03m55s">[03:55]</a> - The most complex tool - <a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx">Process Explorer</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=04m51s">[04:51]</a> - Favorite tool - <a href="http://technet.microsoft.com/en-us/sysinternals/bb897434.aspx">ZoomIt</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=07m01s">[07:01]</a> - Windows Internals books<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=10m54s">[10:54]</a> - What's the best way to learn how to troubleshoot?<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=12m47s">[12:47]</a> - Do traditional techniques work when analyzing viruses?<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=13m49s">[13:49]</a> - Cybersecurity awareness<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=14m40s">[14:40]</a> - Cybersecurity novels<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=16m28s">[16:28]</a> - Cybersecurity advice for corporations and individuals<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=20m25s">[20:25]</a> - White Listing<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=22m53s">[22:53]</a> - User Account Control (UAC)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=29m55s">[29:55]</a> - Winternals vs Sysinternals vs Windows Internals<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=31m08s">[31:08]</a> - New&nbsp;Windows 8 <a href="http://blogs.technet.com/b/sysinternals/rss.aspx">features/support</a> in the Sysinternals tools:<br>*&nbsp;<a href="http://technet.microsoft.com/en-us/sysinternals/bb896653">Process Explorer v15.1</a><br>*&nbsp;<a href="http://technet.microsoft.com/en-us/sysinternals/bb896645">Process Monitor v3.0</a><br>* <a href="http://technet.microsoft.com/en-us/sysinternals/dd996900.aspx">ProcDump v5.0</a><br>* <a href="http://technet.microsoft.com/en-us/sysinternals/ff700229">RAMMap v1.2</a><br>*&nbsp;<a href="http://technet.microsoft.com/en-us/sysinternals/bb896647">DebugView&nbsp;v4.78</a><br>* <a href="http://technet.microsoft.com/en-us/sysinternals/bb664922">AccessChk v5.1</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=33m57s">[33:57]</a> - Windows Internals 7th edition (for Windows 8)? Windows Azure Internals?<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=36m47s">[36:47]</a> -&nbsp;New tools - PsPing, <a href="http://technet.microsoft.com/en-us/sysinternals/ff700229">RAMMap</a>, <a href="http://technet.microsoft.com/en-us/sysinternals/dd535533">VMMap</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich#time=40m33s">[40:33]</a> - Win a signed copy of <a href="http://www.russinovich.com/books/trojan-horse/">Trojan Horse</a>!</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:e5e8d6c186954e59a99ca0cc013ad6c7">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich</comments>
      <itunes:summary>Mark Russinovich joins Andrew Richards and Larry&amp;nbsp;Larsen on&amp;nbsp;this episode of Defrag Tools to talk about the history of Sysinternals, his involvement with the Windows Internals book series and&amp;nbsp;advice on Cybersecurity. Learn about new tools, retired tools and tools that never got completed.&amp;nbsp; Get advice on troubleshooting.&amp;nbsp;Get advice on how to survive a cyber attack. And much much more... Write a comment before 24th Sept. for a chance to win a signed copy of Trojan Horse! Blog:Mark&#39;s Blog&amp;nbsp;(TechNet) - http://blogs.technet.com/b/markrussinovich/Mark&#39;s Web Site - http://www.russinovich.com/Sysinternals&amp;nbsp;Web Site - http://www.sysinternals.com Videos:All of Mark&#39;s videos on Channel 9 and talks&amp;nbsp;at conferences. Of note:* Case of the Unexplained...* Mysteries of Memory Management Revealed&amp;nbsp;- Part 1, Part 2* Malware Hunting with the Sysinternals Tools* RSA Conference 2012&amp;nbsp;-- Zero Day: A Non-Fiction View* Inside Windows 7* Inside Windows 7&amp;nbsp;Redux* Windows 7 and Windows Server 2008 R2 Kernel Changes* Windows Vista and Windows Server 2008 Kernel Changes Books:Sysinternals Administrator&#39;s Reference - [Amazon]Windows Internals&amp;nbsp;books:* 4th Edition - Windows XP and Windows Server 2003 - [Amazon]* 5th Edition - Windows Vista and Windows Server 2008 - [Amazon]* 6th Edition - Windows 7 and Windows Server 2008 R2 - [Amazon:&amp;nbsp;Part 1,&amp;nbsp;Part 2]Cybersecurity novels:* Zero Day - A Novel - [Amazon]* Trojan Horse - A Novel - [Amazon]* Operation Desolation - A Short Story - [Amazon] Timeline:[00:00] - How did Sysinternals start?[02:20] - Tools that never got released and tool retirement[03:55] - The most complex tool - Process Explorer[04:51] - Favorite tool - ZoomIt[07:01] - Windows Internals books[10:54] - What&#39;s the best way to learn how to troubleshoot?[12:47] - Do traditional techniques work when analyzing viruses?[13:49] - Cybersecurity awareness[14:40] - Cybersecurity novels[16:28] - Cybersecurity advice for corporations and in</itunes:summary>
      <itunes:duration>2466</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich</link>
      <pubDate>Fri, 21 Sep 2012 21:35:54 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.mp3" expression="full" duration="2466" fileSize="39460769" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.mp4" expression="full" duration="2466" fileSize="235863051" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.webm" expression="full" duration="2466" fileSize="102253849" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.wma" expression="full" duration="2466" fileSize="19948587" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.wmv" expression="full" duration="2466" fileSize="160081385" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_high.mp4" expression="full" duration="2466" fileSize="513535915" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_mid.mp4" expression="full" duration="2466" fileSize="358965621" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8_Source.wmv" expression="full" duration="2466" fileSize="1015783530" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.ism/manifest" expression="full" duration="2466" fileSize="8430" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/6bdf/6c136fcb-501d-4295-a156-f7ea2dca6bdf/DefragTools8.wmv" length="160081385" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Mark Russinovich, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Mark Russinovich, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>54</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-8-Mark-Russinovich/RSS</wfw:commentRss>
      <category>Mark Russinovich</category>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #7 - VMMap</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew and I walk you through <strong>Sysinternals VMMap</strong>. VMMap allows you to see how the Virtual Memory of a process is being used. You can see how much is used, for what purpose it is being used, and if there has been any memory leaks. Like last week with <a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap">RAMMap</a>, we cover some Memory Management theory to understand the data in VMMap.</p><p><strong>Resources:</strong><br><a href="http://technet.microsoft.com/en-us/sysinternals/dd535533.aspx">Sysinternals VMMap</a><br>'Mysteries of Memory Management Revealed' talk [<a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WCL405">Part 1</a>, <a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WCL406">Part 2</a>]<br>Sysinternals Administrator's Reference - [<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]</p><p><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=01m32s">[01:32]</a> - Bar Graphs<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=02m58s">[02:58]</a> - Committed, Reserved or Free<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=03m35s">[03:35]</a> - Shared Memory and&nbsp;Copy on Write<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=05m35s">[05:35]</a> - Memory Types<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=09m06s">[09:06]</a> - CPU Addressing Limit (~44bits)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=10m17s">[10:17]</a> - Manual Refresh (F5) and Difference (Ctrl-D)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=11m49s">[11:49]</a> - 'Image' entries<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=14m55s">[14:55]</a> - Menus<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=17m33s">[17:33]</a> - Timeline... First look<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=18m30s">[18:30]</a> - Symbols<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=19m30s">[19:30]</a> - Tracing an application from launch<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=21m19s">[21:19]</a> - Timeline... Second look<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=22m58s">[22:58]</a> - Tracing an application from launch (2nd attempt)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=24m15s">[24:15]</a> - Application Symbol and Source Paths<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=25m50s">[25:50]</a> - Source&nbsp;code from a Stack<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap#time=27m07s">[27:07]</a> - Summary</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:58c2f454ff2e473eb7cca0be0148170f">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew and I walk you through Sysinternals VMMap. VMMap allows you to see how the Virtual Memory of a process is being used. You can see how much is used, for what purpose it is being used, and if there has been any memory leaks. Like last week with RAMMap, we cover some Memory Management theory to understand the data in VMMap. Resources:Sysinternals VMMap&#39;Mysteries of Memory Management Revealed&#39; talk [Part 1, Part 2]Sysinternals Administrator&#39;s Reference - [Amazon] Timeline:[01:32] - Bar Graphs[02:58] - Committed, Reserved or Free[03:35] - Shared Memory and&amp;nbsp;Copy on Write[05:35] - Memory Types[09:06] - CPU Addressing Limit (~44bits)[10:17] - Manual Refresh (F5) and Difference (Ctrl-D)[11:49] - &#39;Image&#39; entries[14:55] - Menus[17:33] - Timeline... First look[18:30] - Symbols[19:30] - Tracing an application from launch[21:19] - Timeline... Second look[22:58] - Tracing an application from launch (2nd attempt)[24:15] - Application Symbol and Source Paths[25:50] - Source&amp;nbsp;code from a Stack[27:07] - Summary </itunes:summary>
      <itunes:duration>1667</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap</link>
      <pubDate>Mon, 10 Sep 2012 18:05:20 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.mp3" expression="full" duration="1667" fileSize="26682085" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.mp4" expression="full" duration="1667" fileSize="161952846" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.webm" expression="full" duration="1667" fileSize="55279061" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.wma" expression="full" duration="1667" fileSize="13489987" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.wmv" expression="full" duration="1667" fileSize="81432431" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7_high.mp4" expression="full" duration="1667" fileSize="354703833" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7_mid.mp4" expression="full" duration="1667" fileSize="248699428" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7_Source.wmv" expression="full" duration="1667" fileSize="224581384" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.ism/manifest" expression="full" duration="1667" fileSize="6036" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/cf4d/a0d902cf-5b63-42a5-9063-61498e64cf4d/DefragTools7.wmv" length="81432431" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>3</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-7-VMMap/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #6 - RAMMap</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Andrew and I walk you through <strong>Sysinternals RAMMap</strong>. RAMMap allows you to see how the Physical Memory (RAM) on the computer is being used. You can see how much RAM there is, for what purpose it is being used, and if there has been any memory pressure (not enough memory). We also cover a lot of Memory Management theory to understand the data in RAMMap.</p><p><strong>Resources:<br><a href="http://technet.microsoft.com/en-us/sysinternals/ff700229.aspx">Sysinternals RAMMap</a></strong></p><p><strong>Timeline: </strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=01m00s">[01:00]</a> - 'Mysteries of Memory Management Revealed' talk [<a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WCL405">Part 1</a>, <a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2011/WCL406">Part 2</a>]<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=01m40s">[01:40]</a> - The brick wall analogy<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=05m35s">[05:35]</a> - Page Faults<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=06m32s">[06:32]</a> - 'Use Counts' tab<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=07m40s">[07:40]</a> - Memory Lists - state transition explanation<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=13m37s">[13:37]</a> - 'Use Counts' tab... continued<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=16m33s">[16:33]</a> - Paged and Nonpaged Pool<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=19m00s">[19:00]</a> - Driver Locked<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=21m40s">[21:40]</a> - 'Processes' tab... inc. Zombie Processes<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=24m00s">[24:00]</a> - 'Priority Summary' tab... inc. Memory Pressure<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=26m56s">[26:56]</a> - 'Physical Pages' tab<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=28m00s">[28:00]</a> - 'Physical Ranges' tab<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=28m38s">[28:38]</a> - 'File Summary' tab<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=29m36s">[29:36]</a> - 'File Details' tab<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=30m20s">[30:20]</a> - 'Empty' menu... inc. Performance Analysis<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=31m33s">[31:33]</a> - Sysinternals Administrator's Reference&nbsp;[<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap#time=32m05s">[32:05]</a> - Next time...VMMap</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:31b6c0c6362d467ab8d6a0b601696753">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew and I walk you through Sysinternals RAMMap. RAMMap allows you to see how the Physical Memory (RAM) on the computer is being used. You can see how much RAM there is, for what purpose it is being used, and if there has been any memory pressure (not enough memory). We also cover a lot of Memory Management theory to understand the data in RAMMap. Resources:Sysinternals RAMMap Timeline: [01:00] - &#39;Mysteries of Memory Management Revealed&#39; talk [Part 1, Part 2][01:40] - The brick wall analogy[05:35] - Page Faults[06:32] - &#39;Use Counts&#39; tab[07:40] - Memory Lists - state transition explanation[13:37] - &#39;Use Counts&#39; tab... continued[16:33] - Paged and Nonpaged Pool[19:00] - Driver Locked[21:40] - &#39;Processes&#39; tab... inc. Zombie Processes[24:00] - &#39;Priority Summary&#39; tab... inc. Memory Pressure[26:56] - &#39;Physical Pages&#39; tab[28:00] - &#39;Physical Ranges&#39; tab[28:38] - &#39;File Summary&#39; tab[29:36] - &#39;File Details&#39; tab[30:20] - &#39;Empty&#39; menu... inc. Performance Analysis[31:33] - Sysinternals Administrator&#39;s Reference&amp;nbsp;[Amazon][32:05] - Next time...VMMap </itunes:summary>
      <itunes:duration>1978</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap</link>
      <pubDate>Tue, 04 Sep 2012 17:12:18 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.mp3" expression="full" duration="1978" fileSize="31660397" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.mp4" expression="full" duration="1978" fileSize="192785188" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.webm" expression="full" duration="1978" fileSize="69800732" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.wma" expression="full" duration="1978" fileSize="16007339" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.wmv" expression="full" duration="1978" fileSize="92842481" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6_high.mp4" expression="full" duration="1978" fileSize="422809290" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6_mid.mp4" expression="full" duration="1978" fileSize="295244833" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6_Source.wmv" expression="full" duration="1978" fileSize="514169914" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.ism/manifest" expression="full" duration="1978" fileSize="7632" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/b643/6f12484d-1371-4d59-a817-7ef420d2b643/DefragTools6.wmv" length="92842481" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>10</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-6-RAMMap/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #5 - Autoruns and MSConfig</title>
      <description><![CDATA[<p>In this episode of <strong>Defrag Tools</strong>, Chad and I walk you through <strong>Sysinternals Autoruns</strong>. We also look at its predecessors: <strong>MSConfig</strong> and <strong>SysEdit</strong>. AutoRuns and MSConfig allow you to view and disable autostart entries on the computer. The autostart entries are locations in the registry and file system that can cause applications and&nbsp;DLLs to be automatically run at startup, login, application launch, and at many more registration points in Windows.</p><p><strong>Resources:<br><a href="http://technet.microsoft.com/en-us/sysinternals/bb963902.aspx">Sysinternals Autoruns</a></strong></p><p><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=01m05s">[01:05]</a> - A look back in time...<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=03m20s">[03:20]</a> - SysEdit on Windows 95<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=04m32s">[04:32]</a> - Bar Napkin (Janet Harris)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=06m19s">[06:19]</a> - MSConfig on Windows 98<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=07m25s">[07:25]</a> - MSConfig on Windows 7<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=13m03s">[13:03]</a> - Sysinternals Autoruns<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns#time=33m19s">[33:19]</a> - Reboot required</p><p><strong>Raymond Chen's Blog:<br></strong><strong><a href="http://blogs.msdn.com/b/oldnewthing/">The Old New Thing</a></strong></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:2486a95de45845ad896aa0af011cee0d">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns</comments>
      <itunes:summary>In this episode of Defrag Tools, Chad and I walk you through Sysinternals Autoruns. We also look at its predecessors: MSConfig and SysEdit. AutoRuns and MSConfig allow you to view and disable autostart entries on the computer. The autostart entries are locations in the registry and file system that can cause applications and&amp;nbsp;DLLs to be automatically run at startup, login, application launch, and at many more registration points in Windows. Resources:Sysinternals Autoruns Timeline:[01:05] - A look back in time...[03:20] - SysEdit on Windows 95[04:32] - Bar Napkin (Janet Harris)[06:19] - MSConfig on Windows 98[07:25] - MSConfig on Windows 7[13:03] - Sysinternals Autoruns[33:19] - Reboot required Raymond Chen&#39;s Blog:The Old New Thing </itunes:summary>
      <itunes:duration>2039</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns</link>
      <pubDate>Mon, 27 Aug 2012 17:18:32 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.mp3" expression="full" duration="2039" fileSize="32634643" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.mp4" expression="full" duration="2039" fileSize="197459283" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.webm" expression="full" duration="2039" fileSize="66864113" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.wma" expression="full" duration="2039" fileSize="16496991" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.wmv" expression="full" duration="2039" fileSize="93308975" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5_high.mp4" expression="full" duration="2039" fileSize="433110082" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5_mid.mp4" expression="full" duration="2039" fileSize="302108787" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5_Source.wmv" expression="full" duration="2039" fileSize="304705269" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.ism/manifest" expression="full" duration="2039" fileSize="6036" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/68c6/750e11f3-3c7f-46fa-bda5-bc4a78b068c6/DefragTools5.wmv" length="93308975" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards, Chad Beeder</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards, Chad Beeder</itunes:author>
      <slash:comments>11</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-5-Autoruns/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #4 - Process Monitor - Examples</title>
      <description><![CDATA[<p>In this 2 part episode of <strong>Defrag Tools</strong>, Andrew and I walk you through <strong>Sysinternals Process Monitor</strong>. Process Monitor allows you to view the File, Registy, Network, Process and Profiling details of the processes running on the computer. The logging allows you to go from a holistic view all the way down to the function in the stack that initiated an event. Process Monitor can be used to troubleshoot nearly all types of issues. As coined by <a href="http://www.solsem.com/">David Solomon</a> - &quot;When in doubt, run Process Monitor&quot;.</p><p><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor">Part 1</a> (last week) covers the tool itself.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor">Part 2</a> (this week) goes though a wide variety of examples showing how different techniques are required for different investigations.</p><p><strong>Resources:<br><a href="http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx">Sysinternals Process Monitor</a></strong></p><p><strong>Timeline: </strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=00m00s">[00:00]</a> - Last week...<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=01m08s">[01:08]</a> - Finding the Registry keys of the Explorer 'Folder Options' dialog<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=08m30s">[08:30]</a> - Using Summary reports to see the current filter's resource usage<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=15m09s">[15:09]</a> - Capturing a ProcMon log of system boot<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=19m25s">[19:25]</a> - Analyzing the boot log<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=27m32s">[27:32]</a> - The Startup/Shutdown chapter of the <a href="http://technet.microsoft.com/en-us/sysinternals/bb963901.aspx">Windows Internals</a> book [<a href="http://www.amazon.com/Microsoft-Windows-Internals-4th-Edition/dp/B002DMJTXM">4th edition</a>, <a href="http://www.amazon.com/Windows%C2%AE-Internals-Including-Windows-Developer/dp/0735625301">5th edition</a>,&nbsp;<a href="http://www.amazon.com/Windows-Internals-Part-Covering-Server/dp/0735648735">6th edition Part 2</a>]. Note, it's&nbsp;Chapter 13, not Chapter 4, as mentioned on the show. Chapter 13 is in Part 2 of the 6th edition.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor#time=28m17s">[28:17]</a> - Next time...Autoruns</p><p><strong>More Examples:</strong><br><a href="http://channel9.msdn.com/search?term=Case&#43;of&#43;the&#43;Unexplained">Case of the Unexplained...</a> by <a href="http://blogs.technet.com/b/markrussinovich/">Mark Russinovich</a><br><a href="http://channel9.msdn.com/search?term=sysinternals&#43;gems">Sysinternals Gems</a> by <a href="http://blogs.msdn.com/b/aaron_margosis/">Aaron Margosis</a></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:b218d31043c34138b5e4a0ae0017705d">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor</comments>
      <itunes:summary>In this 2 part episode of Defrag Tools, Andrew and I walk you through Sysinternals Process Monitor. Process Monitor allows you to view the File, Registy, Network, Process and Profiling details of the processes running on the computer. The logging allows you to go from a holistic view all the way down to the function in the stack that initiated an event. Process Monitor can be used to troubleshoot nearly all types of issues. As coined by David Solomon - &amp;quot;When in doubt, run Process Monitor&amp;quot;. Part 1 (last week) covers the tool itself.Part 2 (this week) goes though a wide variety of examples showing how different techniques are required for different investigations. Resources:Sysinternals Process Monitor Timeline: [00:00] - Last week...[01:08] - Finding the Registry keys of the Explorer &#39;Folder Options&#39; dialog[08:30] - Using Summary reports to see the current filter&#39;s resource usage[15:09] - Capturing a ProcMon log of system boot[19:25] - Analyzing the boot log[27:32] - The Startup/Shutdown chapter of the Windows Internals book [4th edition, 5th edition,&amp;nbsp;6th edition Part 2]. Note, it&#39;s&amp;nbsp;Chapter 13, not Chapter 4, as mentioned on the show. Chapter 13 is in Part 2 of the 6th edition.[28:17] - Next time...Autoruns More Examples:Case of the Unexplained... by Mark RussinovichSysinternals Gems by Aaron Margosis </itunes:summary>
      <itunes:duration>1753</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor</link>
      <pubDate>Mon, 20 Aug 2012 19:42:30 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.mp3" expression="full" duration="1753" fileSize="28052976" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.mp4" expression="full" duration="1753" fileSize="169033899" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.webm" expression="full" duration="1753" fileSize="66311660" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.wma" expression="full" duration="1753" fileSize="14183911" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.wmv" expression="full" duration="1753" fileSize="87749579" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4_high.mp4" expression="full" duration="1753" fileSize="368329732" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4_mid.mp4" expression="full" duration="1753" fileSize="257733347" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4_Source.wmv" expression="full" duration="1753" fileSize="298325558" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.ism/manifest" expression="full" duration="1753" fileSize="6036" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/a373/7afb3f09-a6a6-4a92-b89e-7969ec07a373/DefragTools4.wmv" length="87749579" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards</itunes:author>
      <slash:comments>8</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #3 - Process Monitor</title>
      <description><![CDATA[<p>In this 2 part episode of <strong>Defrag Tools</strong>, Andrew and I walk you through&nbsp;<strong>Sysinternals Process Monitor</strong>. Process Monitor&nbsp;allows you to view the File, Registy, Network, Process and Profiling details of the processes running on the computer. The logging allows you to go from a holistic view all the way down to the function in the stack that initiated an event. Process Monitor can be used to troubleshoot nearly all types of issues. As coined by <a href="http://www.solsem.com/">David Solomon</a> - &quot;When in doubt, run Process Monitor&quot;.</p><p><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor">Part 1</a> (this week) covers the tool itself.<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-4-Process-Monitor">Part 2</a> (next week) goes though a wide variety of examples showing how different techniques are required for different investigations.</p><p><strong>Resources:</strong><br><strong><a href="http://technet.microsoft.com/en-us/sysinternals/bb896645.aspx">Sysinternals Process Monitor</a></strong></p><p><span><span><strong>Timeline:</strong><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=01m03s">[01:03]</a> - Episode Overview<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=01m55s">[01:55]</a> - <a href="http://www.sysinternals.com">www.sysinternals.com</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=03m30s">[03:30]</a> - Launching &amp; EULA<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=04m00s">[04:00]</a> - Events traced<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=06m28s">[06:28]</a> - Sysinternals Administrator's Reference - [<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=07m00s">[07:00]</a> - File&nbsp;Menu - Open, Save,&nbsp;Backing Files/Pagefile,&nbsp;Capture Events and Configuration<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=10m34s">[10:34]</a> - Edit Menu - Copy, Find, Highlight, Bookmarks, Auto Scroll and Clear Display<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=14m52s">[14:52]</a> - Events Menu - Jump To, Search Online,&nbsp;(Quick) Filtering, Filemon/Regmon heritage, Highlight &amp;Filter dialogs<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=22m48s">[22:48]</a> - Filter Menu - </span></span><span><span>Advanced Output, Load/Save/Organize Filters, Drop Filtered Events<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=25m02s">[25:02]</a> - Tools Menu - Next episode...<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=25m28s">[25:28]</a> - Options Menu - Symbols,&nbsp;History Depth,&nbsp;Profiling and Network Addresses<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=28m47s">[28:47]</a> - Command Line - Refer to the book, help file and the dialog<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=29m08s">[29:08]</a> - Columns - in particular, the Relative Time and Duration columns<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor#time=31m48s">[31:48]</a> - Next episode, examples...</span></span></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:5d394cbfc3fa4b18a816a0a701303836">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor</comments>
      <itunes:summary>In this 2 part episode of Defrag Tools, Andrew and I walk you through&amp;nbsp;Sysinternals Process Monitor. Process Monitor&amp;nbsp;allows you to view the File, Registy, Network, Process and Profiling details of the processes running on the computer. The logging allows you to go from a holistic view all the way down to the function in the stack that initiated an event. Process Monitor can be used to troubleshoot nearly all types of issues. As coined by David Solomon - &amp;quot;When in doubt, run Process Monitor&amp;quot;. Part 1 (this week) covers the tool itself.Part 2 (next week) goes though a wide variety of examples showing how different techniques are required for different investigations. Resources:Sysinternals Process Monitor Timeline:[01:03] - Episode Overview[01:55] - www.sysinternals.com[03:30] - Launching &amp;amp; EULA[04:00] - Events traced[06:28] - Sysinternals Administrator&#39;s Reference - [Amazon][07:00] - File&amp;nbsp;Menu - Open, Save,&amp;nbsp;Backing Files/Pagefile,&amp;nbsp;Capture Events and Configuration[10:34] - Edit Menu - Copy, Find, Highlight, Bookmarks, Auto Scroll and Clear Display[14:52] - Events Menu - Jump To, Search Online,&amp;nbsp;(Quick) Filtering, Filemon/Regmon heritage, Highlight &amp;amp;Filter dialogs[22:48] - Filter Menu - Advanced Output, Load/Save/Organize Filters, Drop Filtered Events[25:02] - Tools Menu - Next episode...[25:28] - Options Menu - Symbols,&amp;nbsp;History Depth,&amp;nbsp;Profiling and Network Addresses[28:47] - Command Line - Refer to the book, help file and the dialog[29:08] - Columns - in particular, the Relative Time and Duration columns[31:48] - Next episode, examples... </itunes:summary>
      <itunes:duration>1919</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor</link>
      <pubDate>Mon, 13 Aug 2012 16:31:39 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.mp3" expression="full" duration="1919" fileSize="30708689" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.mp4" expression="full" duration="1919" fileSize="183569306" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.webm" expression="full" duration="1919" fileSize="76398050" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.wma" expression="full" duration="1919" fileSize="15523695" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.wmv" expression="full" duration="1919" fileSize="93523385" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3_high.mp4" expression="full" duration="1919" fileSize="398968015" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3_mid.mp4" expression="full" duration="1919" fileSize="279927523" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3_Source.wmv" expression="full" duration="1919" fileSize="307297910" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.ism/manifest" expression="full" duration="1919" fileSize="6036" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/5678/438d3438-d90c-4309-90b3-a5ffbbe35678/DefragTools3.wmv" length="93523385" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards</itunes:author>
      <slash:comments>6</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-3-Process-Monitor/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #2 - Process Explorer</title>
      <description><![CDATA[<p>In this episode of Defrag Tools, Andrew and I walk you through <strong>Sysinternals Process Explorer</strong>. Process Explorer is a comprehensive replacement for Task Manager.&nbsp;It allows you to view the details of the processes running on the computer, both at a point in time and historically. The performance graphs allow you to view the CPU, I/O, Memory and GPU usage. Process Explorer can be used to find file locks, loaded DLLs, autostart locations, and many more things.</p><p><strong>Resources:<br></strong><a href="http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx"><strong>Sysinternals Process Explorer</strong></a></p><p><strong>Timeline:<br></strong><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=00m15s">[00:15]</a> - <a href="http://www.sysinternals.com">www.sysinternals.com</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=01m18s">[01:18]</a> - Launching &amp; EULA<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=02m45s">[02:45]</a> - Task Manager vs. Process Explorer<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=03m30s">[03:30]</a> - CPU Usage<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=05m00s">[05:00]</a> - OS Support - Windows XP/2003 SP3 and above -&nbsp;x86, x64&nbsp;and IA64<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=05m25s">[05:25]</a> - Multiple Architecture binary - procexp.exe (32bit) creates procexp64.exe (64bit) on x64 system<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=06m53s">[06:53]</a> - &quot;Show Details for all users&quot; to access all processes<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=07m24s">[07:24]</a> - Interrupts not shown in Task Manager (it's in Idle)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=07m56s">[07:56]</a> - Performance Graphs - Menu, Tray and System Information<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=09m00s">[09:00]</a> - System Commit (Limit) - Physical Memory &#43; Pagefile<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=10m22s">[10:22]</a> - Historical data via tooltips on graphs<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=11m24s">[11:24]</a> - Always run Process Explorer - <em>&quot;procexp.exe /t /e&quot;</em>&nbsp;with run&nbsp;it elevated and will immediately minimize it to&nbsp;the notification tray (note, these switches are order sensitive)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=13m12s">[13:12]</a> - Data obtained via the Process Explorer device driver<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=14m20s">[14:20]</a> - Process Tree<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=16m06s">[16:06]</a> - Autostart Location and the Explore button (Jump to)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=17m30s">[17:30]</a> - Find Window target tool<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=18m07s">[18:07]</a> - Security - Integrity Levels (and UAC Virtualization), ASLR and Verified Signer<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=21m50s">[21:50]</a> - Columns - Process, I/O, GPU, Handle (View), DLL (View) and .NET<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=26m18s">[26:18]</a> - Sysinternals Administrator's Reference - [<a href="http://www.amazon.com/Windows-Sysinternals-Administrators-Reference-Russinovich/dp/073565672X">Amazon</a>]<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=26m42s">[26:42]</a> - File Menu<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=26m55s">[26:55]</a> - Options Menu - in particular: Replace Task Manager, Minimize to Tray and Configure Symbols<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=36m40s">[36:40]</a> - View Menu - in particular: Lower Pane, DLL View and Handle View (includes Find)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=39m12s">[39:12]</a> - Process Menu<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=39m43s">[39:43]</a> - Find, Users and Help Menus<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=40m00s">[40:00]</a> - Properties dialog<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer#time=41m05s">[41:05]</a> - Tooltip of service processes</p><p><strong>Examples:</strong><br><a href="http://channel9.msdn.com/search?term=Case&#43;of&#43;the&#43;Unexplained">Case of the Unexplained...</a>&nbsp;by <a href="http://blogs.technet.com/b/markrussinovich/">Mark Russinovich</a><br><a href="http://channel9.msdn.com/search?term=sysinternals&#43;gems">Sysinternals Gems</a> by <a href="http://blogs.msdn.com/b/aaron_margosis/">Aaron Margosis</a></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:c08382f3eb7644bd8178a0a50112970c">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer</comments>
      <itunes:summary>In this episode of Defrag Tools, Andrew and I walk you through Sysinternals Process Explorer. Process Explorer is a comprehensive replacement for Task Manager.&amp;nbsp;It allows you to view the details of the processes running on the computer, both at a point in time and historically. The performance graphs allow you to view the CPU, I/O, Memory and GPU usage. Process Explorer can be used to find file locks, loaded DLLs, autostart locations, and many more things. Resources:Sysinternals Process Explorer Timeline:[00:15] - www.sysinternals.com[01:18] - Launching &amp;amp; EULA[02:45] - Task Manager vs. Process Explorer[03:30] - CPU Usage[05:00] - OS Support - Windows XP/2003 SP3 and above -&amp;nbsp;x86, x64&amp;nbsp;and IA64[05:25] - Multiple Architecture binary - procexp.exe (32bit) creates procexp64.exe (64bit) on x64 system[06:53] - &amp;quot;Show Details for all users&amp;quot; to access all processes[07:24] - Interrupts not shown in Task Manager (it&#39;s in Idle)[07:56] - Performance Graphs - Menu, Tray and System Information[09:00] - System Commit (Limit) - Physical Memory &amp;#43; Pagefile[10:22] - Historical data via tooltips on graphs[11:24] - Always run Process Explorer - &amp;quot;procexp.exe /t /e&amp;quot;&amp;nbsp;with run&amp;nbsp;it elevated and will immediately minimize it to&amp;nbsp;the notification tray (note, these switches are order sensitive)[13:12] - Data obtained via the Process Explorer device driver[14:20] - Process Tree[16:06] - Autostart Location and the Explore button (Jump to)[17:30] - Find Window target tool[18:07] - Security - Integrity Levels (and UAC Virtualization), ASLR and Verified Signer[21:50] - Columns - Process, I/O, GPU, Handle (View), DLL (View) and .NET[26:18] - Sysinternals Administrator&#39;s Reference - [Amazon][26:42] - File Menu[26:55] - Options Menu - in particular: Replace Task Manager, Minimize to Tray and Configure Symbols[36:40] - View Menu - in particular: Lower Pane, DLL View and Handle View (includes Find)[39:12] - Process Menu[39:43] - Find, Users and Help Menu</itunes:summary>
      <itunes:duration>2521</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer</link>
      <pubDate>Mon, 06 Aug 2012 23:28:14 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.mp3" expression="full" duration="2521" fileSize="40351972" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.mp4" expression="full" duration="2521" fileSize="240244359" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.webm" expression="full" duration="2521" fileSize="92943192" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.wma" expression="full" duration="2521" fileSize="20399187" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.wmv" expression="full" duration="2521" fileSize="126353171" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2_high.mp4" expression="full" duration="2521" fileSize="525381795" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2_mid.mp4" expression="full" duration="2521" fileSize="367177220" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2_Source.wmv" expression="full" duration="2521" fileSize="427963271" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.ism/manifest" expression="full" duration="2521" fileSize="6036" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/2cea/40ede43a-4e85-43f0-82a3-af9d16d62cea/DefragTools2.wmv" length="126353171" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards</itunes:author>
      <slash:comments>12</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-2-Process-Explorer/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Defrag Tools: #1 - Building your USB thumbdrive</title>
      <description><![CDATA[<p>Welcome to the first episode of Defrag Tools where Andrew Richards and I will be walking you through the tools we use when troubleshooting Windows PC's. Each week we'll dive into the tools from SysInternals, showing you how to use them along with our best tips and tricks.</p><p>In this episode we'll be showing you how to get started by creating a thumb drive that you can use to fix PC's and troubleshoot problems.</p><p><strong>Resources: </strong><br><a href="http://www.microsoft.com/en-us/download/details.aspx?id=8279">Microsoft Windows SDK for Windows 7 and .NET Framework 4</a><br><a href="http://www.sysinternals.com">www.sysinternals.com</a></p><p><strong>Timeline:<br></strong><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=00m00s">[00:00]</a> - What is Defrag Tools?<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=02m50s">[02:50]</a> - The USB Stick light saber<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=03m59s">[03:59]</a> - Download, unblock and extract the <a href="http://technet.microsoft.com/en-us/sysinternals/bb842062.aspx">Sysinternals Suite</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=08m07s">[08:07]</a> - Add c:\my\sysinternals to the PATH<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=09m23s">[09:23]</a> - Download and install the <a href="http://www.microsoft.com/en-us/download/details.aspx?id=8279">Microsoft Windows SDK for Windows 7 and .NET Framework 4</a><br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=13m30s">[13:30]</a> - What is a Symbol?<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=15m10s">[15:10]</a> - Symbols script for environment variables<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=18m57s">[18:57]</a> - Symbol Logging (DbgHelp)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=20m45s">[20:45]</a> - Gather the 'Redist' MSI files of <strong>Application Verifier</strong>, <strong>Debugging Tools for Windows</strong>, and <strong>Windows Performance Toolkit</strong> from the SDK<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=22m29s">[22:29]</a> - <strong>Debugging Tool for Windows<br>- </strong>Install both the x64 <span>and</span> x86 versions of the <strong>Debugging Tool for Windows</strong> (to <em>&quot;c:\debuggers&quot;</em> and <em>&quot;c:\debuggers_x86&quot;</em>&nbsp;respectively)<br>- Copy the <em>&quot;c:\debuggers&quot;</em> and <em>&quot;c:\debuggers_x86&quot;</em> folders in to the <em>&quot;C:\My\Debugging Tool for Windows&quot;</em>&nbsp;folder for 'xcopy' use on any computer (no installation necessary)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=25m09s">[25:09]</a> - <strong>Windows Performance Toolkit</strong><br>-&nbsp;Install the x64 <span>or</span> x86 version of the <strong>Windows Performance Toolkit</strong> using the default options<br>- Copy <em>&quot;C:\Program Files\Microsoft Windows Performance Toolkit&quot;</em> to <em>&quot;C:\My\Windows Performance Toolkit&quot;&nbsp;</em>folder for 'xcopy' use on any computer (no installation necessary)<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=25m43s">[25:43]</a> - DbgHelp.dll v6.12<br><a href="http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive#time=26m55s">[26:55]</a>&nbsp;- Next episode... Process Explorer</p><p><strong>Scripts:<br></strong><em>Symbols.cmd</em></p><p><pre class="brush: text">
md c:\My
md c:\My\Src
md c:\My\Sym
md c:\My\SymCache
setx /M _NT_SOURCE_PATH SRV*C:\My\Src
setx /M _NT_SYMBOL_PATH SRV*C:\My\Sym*http://msdl.microsoft.com/download/symbols
setx /M _NT_SYMCACHE_PATH C:\My\SymCache
</pre></p><p><em>DbgHelp_Logging.cmd</em></p><p><pre class="brush: text">
rem msdn.microsoft.com/en-us/library/windows/desktop/ms680687.aspx
md c:\My
md c:\My\DbgHelp
setx DBGHELP_DBGOUT 1 
setx DBGHELP_LOG C:\My\DbgHelp\DbgHelpLog.txt
</pre></p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:19c51067e7f74d1b9755a09e014ae084">]]></description>
      <comments>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive</comments>
      <itunes:summary>Welcome to the first episode of Defrag Tools where Andrew Richards and I will be walking you through the tools we use when troubleshooting Windows PC&#39;s. Each week we&#39;ll dive into the tools from SysInternals, showing you how to use them along with our best tips and tricks. In this episode we&#39;ll be showing you how to get started by creating a thumb drive that you can use to fix PC&#39;s and troubleshoot problems. Resources: Microsoft Windows SDK for Windows 7 and .NET Framework 4www.sysinternals.com Timeline:[00:00] - What is Defrag Tools?[02:50] - The USB Stick light saber[03:59] - Download, unblock and extract the Sysinternals Suite[08:07] - Add c:\my\sysinternals to the PATH[09:23] - Download and install the Microsoft Windows SDK for Windows 7 and .NET Framework 4[13:30] - What is a Symbol?[15:10] - Symbols script for environment variables[18:57] - Symbol Logging (DbgHelp)[20:45] - Gather the &#39;Redist&#39; MSI files of Application Verifier, Debugging Tools for Windows, and Windows Performance Toolkit from the SDK[22:29] - Debugging Tool for Windows- Install both the x64 and x86 versions of the Debugging Tool for Windows (to &amp;quot;c:\debuggers&amp;quot; and &amp;quot;c:\debuggers_x86&amp;quot;&amp;nbsp;respectively)- Copy the &amp;quot;c:\debuggers&amp;quot; and &amp;quot;c:\debuggers_x86&amp;quot; folders in to the &amp;quot;C:\My\Debugging Tool for Windows&amp;quot;&amp;nbsp;folder for &#39;xcopy&#39; use on any computer (no installation necessary)[25:09] - Windows Performance Toolkit-&amp;nbsp;Install the x64 or x86 version of the Windows Performance Toolkit using the default options- Copy &amp;quot;C:\Program Files\Microsoft Windows Performance Toolkit&amp;quot; to &amp;quot;C:\My\Windows Performance Toolkit&amp;quot;&amp;nbsp;folder for &#39;xcopy&#39; use on any computer (no installation necessary)[25:43] - DbgHelp.dll v6.12[26:55]&amp;nbsp;- Next episode... Process Explorer Scripts:Symbols.cmd 
md c:\My
md c:\My\Src
md c:\My\Sym
md c:\My\SymCache
setx /M _NT_SOURCE_PATH SRV*C:\My\Src
setx /M _NT_SYMBOL_PATH SRV*C:\My\Sym*http://msdl.microsoft.com/d</itunes:summary>
      <itunes:duration>1640</itunes:duration>
      <link>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive</link>
      <pubDate>Tue, 31 Jul 2012 16:01:29 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.mp3" expression="full" duration="1640" fileSize="26256388" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.mp4" expression="full" duration="1640" fileSize="157311597" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.webm" expression="full" duration="1640" fileSize="56498881" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.wma" expression="full" duration="1640" fileSize="13276703" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.wmv" expression="full" duration="1640" fileSize="87007877" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01_high.mp4" expression="full" duration="1640" fileSize="346619857" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01_mid.mp4" expression="full" duration="1640" fileSize="241802818" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01_Source.wmv" expression="full" duration="1640" fileSize="345335613" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.ism/manifest" expression="full" duration="1640" fileSize="5996" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/c706/099655b9-4ff6-4220-aaeb-d7c84f12c706/Defrag01.wmv" length="87007877" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Larry Larsen, Andrew Richards</dc:creator>
      <itunes:author>Larry Larsen, Andrew Richards</itunes:author>
      <slash:comments>16</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/Defrag-Tools/Defrag-Tools-Building-your-USB-thumbdrive/RSS</wfw:commentRss>
      <category>sysinternals</category>
      <category>Tech Support</category>
    </item>
  <item>
      <title>Mark Russinovich: On Windows Azure IaaS, Sysinternals, Trojan Horse, Cybersecurity</title>
      <description><![CDATA[<p>Microsoft Technical Fellow <a href="http://blogs.technet.com/b/markrussinovich/" target="_blank"><strong>Mark Russinovich</strong></a> joins us for an impromptu conversation about what he's been up to lately. Topics include the newly added Windows Azure&nbsp;Infrastructure as a Service (IaaS) support&nbsp;(as part of the <a href="http://msdn.microsoft.com/en-us/library/windowsazure/dd163896" target="_blank"><strong>Windows Azure June 2012&nbsp;Release</strong></a>), virtual machines, software security, <a href="http://technet.microsoft.com/en-us/sysinternals/bb545021" target="_blank"><strong>Sysinternals</strong> </a>and Mark's soon-to-be released sequel to <a href="http://www.amazon.com/Zero-Day-A-Novel-ebook/dp/B00457X7XQ" target="_blank"><strong>Zero Day</strong></a>, <a href="http://blogs.technet.com/b/markrussinovich/archive/2012/05/08/3496339.aspx" target="_blank"><strong>Trojan Horse</strong></a>. Oh yeah, and then there's <a href="http://www.amazon.com/Windows-Internals-Part-Covering-Server/dp/0735648735" target="_blank"><strong>Windows Internals 6</strong>, part 1</a>. Mark's been busy...</p><p>Make sure to watch <a href="http://channel9.msdn.com/Events/TechEd/NorthAmerica/2012/AZR209" target="_blank"><strong>Mark's TechEd 2012 North America Windows Azure session </strong></a>to get much more thorough treatment of the new (and future) Windows Azure features/services Mark mentioned in this conversation.</p><p><br>Tune in. Enjoy.</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:bb4e2bc0ef7849228cb8a0690004d6ec">]]></description>
      <comments>http://channel9.msdn.com/posts/Mark-Russinovich-On-Windows-Azure-IaaS-Sysinternals-Cybersecurity-Trojan-Horse</comments>
      <itunes:summary>Microsoft Technical Fellow Mark Russinovich joins us for an impromptu conversation about what he&#39;s been up to lately. Topics include the newly added Windows Azure&amp;nbsp;Infrastructure as a Service (IaaS) support&amp;nbsp;(as part of the Windows Azure June 2012&amp;nbsp;Release), virtual machines, software security, Sysinternals and Mark&#39;s soon-to-be released sequel to Zero Day, Trojan Horse. Oh yeah, and then there&#39;s Windows Internals 6, part 1. Mark&#39;s been busy... Make sure to watch Mark&#39;s TechEd 2012 North America Windows Azure session to get much more thorough treatment of the new (and future) Windows Azure features/services Mark mentioned in this conversation. Tune in. Enjoy. </itunes:summary>
      <itunes:duration>1987</itunes:duration>
      <link>http://channel9.msdn.com/posts/Mark-Russinovich-On-Windows-Azure-IaaS-Sysinternals-Cybersecurity-Trojan-Horse</link>
      <pubDate>Tue, 12 Jun 2012 20:06:18 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/posts/Mark-Russinovich-On-Windows-Azure-IaaS-Sysinternals-Cybersecurity-Trojan-Horse</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse.mp3" expression="full" duration="1987" fileSize="31804633" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse.mp4" expression="full" duration="1987" fileSize="188684059" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse.webm" expression="full" duration="1987" fileSize="73505330" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse.wma" expression="full" duration="1987" fileSize="16079435" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse.wmv" expression="full" duration="1987" fileSize="393681407" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse_high.mp4" expression="full" duration="1987" fileSize="413650492" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse_mid.mp4" expression="full" duration="1987" fileSize="288963137" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse_Source.wmv" expression="full" duration="1987" fileSize="715127150" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/e0f4/548cb240-23ad-4a97-825e-4092b924e0f4/RussinovichAzureIaaSSysInternalsTrojanHorse.wmv" length="393681407" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Charles</dc:creator>
      <itunes:author>Charles</itunes:author>
      <slash:comments>12</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/posts/Mark-Russinovich-On-Windows-Azure-IaaS-Sysinternals-Cybersecurity-Trojan-Horse/rss</wfw:commentRss>
      <category>Infrastructure</category>
      <category>Mark Russinovich</category>
      <category>sysinternals</category>
      <category>Tech Ed</category>
      <category>Virtual Machines</category>
      <category>Windows Azure</category>
    </item>
  <item>
      <title>TechEd Quick Shot - Mark Russinovich</title>
      <description><![CDATA[<p>TechEd attendees (in both North America and Europe) are in for a treat. Mark Russinovich is a rock star when it comes to digging into the internal workings of the system. His talks are always well attended, and rich with deep technical information. At TechEd this year&nbsp;he will be doing several great sessions that will focus on Windows Azure, Security, and Windows Internals.</p><ul><li><a href="http://northamerica.msteched.com/speaker/details/9656fc58-7dfe-df11-82f7-001ec953730b" target="_blank">Mark's TechEd North America Sessions</a> </li><li><a href="http://europe.msteched.com/Sessions/Speaker/Mark-Russinovich" target="_blank">Mark's TechEd Europe Sessions</a> </li></ul><p>&nbsp;</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:a31fc1aa700747468fe1a06900014255">]]></description>
      <comments>http://channel9.msdn.com/posts/TechEd-Quick-Shot-Mark-Russinovich</comments>
      <itunes:summary>TechEd attendees (in both North America and Europe) are in for a treat. Mark Russinovich is a rock star when it comes to digging into the internal workings of the system. His talks are always well attended, and rich with deep technical information. At TechEd this year&amp;nbsp;he will be doing several great sessions that will focus on Windows Azure, Security, and Windows Internals. Mark&#39;s TechEd North America Sessions Mark&#39;s TechEd Europe Sessions &amp;nbsp; </itunes:summary>
      <itunes:duration>47</itunes:duration>
      <link>http://channel9.msdn.com/posts/TechEd-Quick-Shot-Mark-Russinovich</link>
      <pubDate>Thu, 07 Jun 2012 15:15:48 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/posts/TechEd-Quick-Shot-Mark-Russinovich</guid>
      <media:thumbnail url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics_100.jpg" height="56" width="100"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics_220.jpg" height="123" width="220"></media:thumbnail>
      <media:thumbnail url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics_512.jpg" height="288" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.mp3" expression="full" duration="47" fileSize="765680" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.mp4" expression="full" duration="47" fileSize="4585015" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.webm" expression="full" duration="47" fileSize="1833069" type="video/webm" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.wma" expression="full" duration="47" fileSize="395551" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.wmv" expression="full" duration="47" fileSize="8613767" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics_high.mp4" expression="full" duration="47" fileSize="10153215" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics_mid.mp4" expression="full" duration="47" fileSize="7099738" type="video/mp4" medium="video"></media:content>
        <media:content url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics_Source.wmv" expression="full" duration="47" fileSize="16918783" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.ism/manifest" expression="full" duration="47" fileSize="7842" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://media.ch9.ms/ch9/e5fa/2dd3ea91-cf12-4ea5-962c-ac81bed1e5fa/MarkRussinovichTechEdTopics.wmv" length="8613767" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Charles, Robert Hess</dc:creator>
      <itunes:author>Charles, Robert Hess</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/posts/TechEd-Quick-Shot-Mark-Russinovich/rss</wfw:commentRss>
      <category>Mark Russinovich</category>
      <category>Security</category>
      <category>sysinternals</category>
      <category>Windows Azure</category>
    </item>
  <item>
      <title>Mark Russinovich and Aaron Margosis: Introducing Windows Sysinternals Administrator&#39;s Reference</title>
      <description><![CDATA[ <p>Many of you use <strong><a href="http://technet.microsoft.com/en-us/sysinternals" target="_blank">Sysinternals tools</a></strong>&nbsp;to help you manage computing responsibilities ranging from monitoring/understanding&nbsp;process activity&nbsp;with Process Explorer to debugging Win32 code with DebugView. With over 70 utilities to choose from, Sysinternals tools cover a wide swath of computing, from the lowest levels to the highest.</p><p>For the first time, we now have a definitive guide to all of these tools: <strong><a href="http://technet.microsoft.com/en-us/sysinternals/hh290819" target="_blank">Windows Sysinternals Administrator's Reference</a></strong>.</p><p>Mark Russinovich, Technical Fellow working on the managed cloud OS&nbsp;kernel—you know this as the Windows Azure Fabric Controller—is the primary author of these powerful tools - all written in C and C&#43;&#43; (so, Mark's an expert&nbsp;native <em>and</em> managed dev).&nbsp;Aaron Margosis, meanwhile, is a Microsoft Consultant and Sysinternals user with expert-level knowledge and experience using Sysinternals tools. They are an important part of his job. Aaron yearned for a book that encapsulates detailed information about all of the Sysinternals tools. Mark agreed and asked Aaron to coauthor it with him—be careful what you ask for!&nbsp; <br><br>Here, we talk about the book, Mark demos a really cool new Sysinternals tool for GPU analysis that's not in the book, Charles randomizes the conversation, and we head all over the place (taking advantage of having Mark's undivided attention!) and even geek out a little on security. If you use Sysinternals tools, then this conversation is for you! Truly incredible work. It's hard to believe that for Mark this stuff is just a hobby.<br><br>Tune in.</p><p>&nbsp;</p><p>&nbsp;</p> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:206ecbf482b8488eabfa9f2c01399d4a">]]></description>
      <comments>http://channel9.msdn.com/posts/Mark-Russinovich-and-Aaron-Margosis-Introducing-Windows-Sysinternals-Administrators-Reference</comments>
      <itunes:summary> Many of you use Sysinternals tools&amp;nbsp;to help you manage computing responsibilities ranging from monitoring/understanding&amp;nbsp;process activity&amp;nbsp;with Process Explorer to debugging Win32 code with DebugView. With over 70 utilities to choose from, Sysinternals tools cover a wide swath of computing, from the lowest levels to the highest. For the first time, we now have a definitive guide to all of these tools: Windows Sysinternals Administrator&#39;s Reference. Mark Russinovich, Technical Fellow working on the managed cloud OS&amp;nbsp;kernel—you know this as the Windows Azure Fabric Controller—is the primary author of these powerful tools - all written in C and C&amp;#43;&amp;#43; (so, Mark&#39;s an expert&amp;nbsp;native and managed dev).&amp;nbsp;Aaron Margosis, meanwhile, is a Microsoft Consultant and Sysinternals user with expert-level knowledge and experience using Sysinternals tools. They are an important part of his job. Aaron yearned for a book that encapsulates detailed information about all of the Sysinternals tools. Mark agreed and asked Aaron to coauthor it with him—be careful what you ask for!&amp;nbsp; Here, we talk about the book, Mark demos a really cool new Sysinternals tool for GPU analysis that&#39;s not in the book, Charles randomizes the conversation, and we head all over the place (taking advantage of having Mark&#39;s undivided attention!) and even geek out a little on security. If you use Sysinternals tools, then this conversation is for you! Truly incredible work. It&#39;s hard to believe that for Mark this stuff is just a hobby.Tune in. &amp;nbsp; &amp;nbsp; </itunes:summary>
      <itunes:duration>1666</itunes:duration>
      <link>http://channel9.msdn.com/posts/Mark-Russinovich-and-Aaron-Margosis-Introducing-Windows-Sysinternals-Administrators-Reference</link>
      <pubDate>Thu, 28 Jul 2011 15:32:19 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/posts/Mark-Russinovich-and-Aaron-Margosis-Introducing-Windows-Sysinternals-Administrators-Reference</guid>
      <media:thumbnail url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternals_100_ch9.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternals_220_ch9.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternals_512_ch9.jpg" height="384" width="512"></media:thumbnail>
      <media:group>
        <media:content url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_2MB_ch9.wmv" expression="full" duration="1666" fileSize="212231493" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_ch9.mp3" expression="full" duration="1666" fileSize="13330832" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_ch9.wma" expression="full" duration="1666" fileSize="13480921" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_ch9.wmv" expression="full" duration="1666" fileSize="322239427" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_high_ch9.mp4" expression="full" duration="1666" fileSize="646920209" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_low_ch9.mp4" expression="full" duration="1666" fileSize="125459751" type="video/mp4" medium="video"></media:content>
        <media:content url="http://smooth.ch9.ms/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook.ism/manifest" expression="full" duration="1666" fileSize="6266" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ak.channel9.msdn.com/ch9/9d4a/206ecbf4-82b8-488e-abfa-9f2c01399d4a/RussinovichMargosisSysinternalsBook_ch9.wmv" length="322239427" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Charles</dc:creator>
      <itunes:author>Charles</itunes:author>
      <slash:comments>9</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/posts/Mark-Russinovich-and-Aaron-Margosis-Introducing-Windows-Sysinternals-Administrators-Reference/rss</wfw:commentRss>
      <category>C#</category>
      <category>C++</category>
      <category>IT Pro</category>
      <category>Mark Russinovich</category>
      <category>programming tools</category>
      <category>Security</category>
      <category>sysinternals</category>
      <category>Windows Azure</category>
      <category>IT professionals</category>
    </item>
  <item>
      <title>Ch9Live at Tech.Ed NA 2010 - Ask Mark Russinovich Anything... LIVE!</title>
      <description><![CDATA[Charles Torre sat down with Mark Russinovich at Tech.Ed North America 2010 to answer live questions from the Tweetosphere and studio audience.<br /><br /><span id="ctl00_MainPlaceHolder_Starter_BodyLabel"><em>Recorded live as part of Channel 9 Live at Tech.Ed North America 2010</em></span>
<br /> <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:e19b1238aeab4c248a1c9dea00a52bec">]]></description>
      <comments>http://channel9.msdn.com/Blogs/NicFill/Ch9Live-at-TechEd-NA-2010-Ask-Mark-Russinovich-Anything-LIVE</comments>
      <itunes:summary>Charles Torre sat down with Mark Russinovich at Tech.Ed North America 2010 to answer live questions from the Tweetosphere and studio audience.Recorded live as part of Channel 9 Live at Tech.Ed North America 2010
</itunes:summary>
      <itunes:duration>1715</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/NicFill/Ch9Live-at-TechEd-NA-2010-Ask-Mark-Russinovich-Anything-LIVE</link>
      <pubDate>Thu, 08 Jul 2010 20:11:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/NicFill/Ch9Live-at-TechEd-NA-2010-Ask-Mark-Russinovich-Anything-LIVE</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/556253_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/556253_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_320_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_512_ch9.png" height="384" width="512"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_85_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_2MB_ch9.wmv" expression="full" duration="1715" fileSize="411090809" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_ch9.mp3" expression="full" duration="1715" fileSize="13723891" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_ch9.mp4" expression="full" duration="1715" fileSize="202609383" type="video/mp4" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_ch9.wma" expression="full" duration="1715" fileSize="13877449" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_ch9.wmv" expression="full" duration="1715" fileSize="291133543" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_Zune_ch9.wmv" expression="full" duration="1715" fileSize="235181595" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://ecn.channel9.msdn.com/o9/ch9/3/5/2/6/5/5/Ch9LiveTechEdMarkRuss_ch9.wmv" length="291133543" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Nic Fillingham</dc:creator>
      <itunes:author>Nic Fillingham</itunes:author>
      <slash:comments>5</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/NicFill/Ch9Live-at-TechEd-NA-2010-Ask-Mark-Russinovich-Anything-LIVE/RSS</wfw:commentRss>
      <category>Ch9live</category>
      <category>Kernel</category>
      <category>Mark Russinovich</category>
      <category>sysinternals</category>
      <category>Windows 7</category>
      <category>Channel 9 Live</category>
    </item>
  <item>
      <title>Troubleshooting Windows SMB/SMB2 Issues</title>
      <description><![CDATA[Hongwei Sun, Escalation Engineer, presented a session covering&nbsp;<a shape="rect" href="http://www.microsoft.com/whdc/devtools/debugging/default.mspx" shape="rect">Debugging Tools for Windows</a> that can be used for troubleshooting Windows at the 2009 File
 Sharing <a shape="rect" href="http://msdn.microsoft.com/en-us/library/cc216517(PROT.10).aspx" shape="rect">
Windows Protocols</a> Plug-fest.&nbsp;&nbsp; Hongwei answered windows debugging questions as well.&nbsp;&nbsp; Examples of how to use Windbg&nbsp;Windows SMB issues were explained.&nbsp; &nbsp;Tracing calls with Windows ETW and IDNA tracing were demonstrated.&nbsp; Provided a demonstration of&nbsp;a few
 resource kit tools commonly used for Windows debugging as well as some sysinternals tools (process monitor &amp; filemon).&nbsp;
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:f47820863e8046cd91ad9deb00dbe67f">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Darryl/Troubleshooting-Windows-SMBSMB2-Issues</comments>
      <itunes:summary>Hongwei Sun, Escalation Engineer, presented a session covering&amp;nbsp;Debugging Tools for Windows that can be used for troubleshooting Windows at the 2009 File
 Sharing 
Windows Protocols Plug-fest.&amp;nbsp;&amp;nbsp; Hongwei answered windows debugging questions as well.&amp;nbsp;&amp;nbsp; Examples of how to use Windbg&amp;nbsp;Windows SMB issues were explained.&amp;nbsp; &amp;nbsp;Tracing calls with Windows ETW and IDNA tracing were demonstrated.&amp;nbsp; Provided a demonstration of&amp;nbsp;a few
 resource kit tools commonly used for Windows debugging as well as some sysinternals tools (process monitor &amp;amp; filemon).&amp;nbsp;
</itunes:summary>
      <itunes:duration>3810</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Darryl/Troubleshooting-Windows-SMBSMB2-Issues</link>
      <pubDate>Fri, 19 Jun 2009 01:50:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Darryl/Troubleshooting-Windows-SMBSMB2-Issues</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/473527_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/473527_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_2MB_ch9.wmv" expression="full" duration="3810" fileSize="261574709" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_ch9.mp3" expression="full" duration="3810" fileSize="30481907" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_ch9.mp4" expression="full" duration="3810" fileSize="129667705" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_ch9.wma" expression="full" duration="3810" fileSize="61635053" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_ch9.wmv" expression="full" duration="3810" fileSize="267292297" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_Zune_ch9.wmv" expression="full" duration="3810" fileSize="148188277" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_s_ch9.wmv" expression="full" duration="3810" fileSize="219" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/7/2/5/3/7/4/FSPF09TShootWindows_ch9.wmv" length="267292297" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Darryl Welch</dc:creator>
      <itunes:author>Darryl Welch</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Darryl/Troubleshooting-Windows-SMBSMB2-Issues/RSS</wfw:commentRss>
      <category>Debugging</category>
      <category>File Sharing Protocols Plugfest 2009</category>
      <category>Interoperability</category>
      <category>Open Protocols</category>
      <category>sysinternals</category>
      <category>utility</category>
      <category>Windows Protocols</category>
    </item>
  <item>
      <title>Tool Shed Tooltip #3: SysInternals from Episode 1</title>
      <description><![CDATA[Learn about this treasure chest of tools called SysInternals. This is a must for your developer toolbox!<br>
<br>
What is it?<br>
SysInternals utilities&nbsp; help you manage, troubleshoot and diagnose your Windows systems and applications<br>
<br>
Download Site: <a shape="rect" href="http://www.sysinternals.com/" shape="rect">http://www.sysinternals.com</a><br>
<br>
Example Problem(s) it solves: Problems associated with:<br>
File and Disk Utilities , Networking Utilities, Process Utilities, Security Utilities, System Information, and Miscellaneous Utilities<br>
<br>
This clip is Russ' Tool Shed Tooltip #3, the&nbsp;third of the clips from <a shape="rect" href="http://channel9.msdn.com/shows/toolshed/Show-Its-All-About-The-Tools--TV-Show-Episode-One" target="_blank" shape="rect">
Episode One </a>of the TV Show, Russ' Tool Shed presents... It's All About The Tools hosted by Russ Fustino and Co-Host Stan Schultes. Download code, ppt and demo script from
<a shape="rect" href="http://code.msdn.com/toolshed" shape="rect">http://code.msdn.com/toolshed</a> for all episodes. Also, use the links on
<a shape="rect" href="http://channel9.msdn.com/toolshed" shape="rect">http://channel9.msdn.com/toolshed</a> to download tools. Finally, check out some more great videos on the Developer Evangelist East site:
<a shape="rect" href="http://channel9.msdn.com/dpeeast" shape="rect">http://channel9.msdn.com/dpeeast</a>
<br>
<br>
<br>
<br>
<br>
 <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:eb1ffaef26594e7396ae9deb00db4741">]]></description>
      <comments>http://channel9.msdn.com/Shows/toolshed/Tool-Shed-Tooltip-3-SysInternals-from-Episode-1</comments>
      <itunes:summary>Learn about this treasure chest of tools called SysInternals. This is a must for your developer toolbox!

What is it?
SysInternals utilities&amp;nbsp; help you manage, troubleshoot and diagnose your Windows systems and applications

Download Site: http://www.sysinternals.com

Example Problem(s) it solves: Problems associated with:
File and Disk Utilities , Networking Utilities, Process Utilities, Security Utilities, System Information, and Miscellaneous Utilities

This clip is Russ&#39; Tool Shed Tooltip #3, the&amp;nbsp;third of the clips from 
Episode One of the TV Show, Russ&#39; Tool Shed presents... It&#39;s All About The Tools hosted by Russ Fustino and Co-Host Stan Schultes. Download code, ppt and demo script from
http://code.msdn.com/toolshed for all episodes. Also, use the links on
http://channel9.msdn.com/toolshed to download tools. Finally, check out some more great videos on the Developer Evangelist East site:
http://channel9.msdn.com/dpeeast





</itunes:summary>
      <itunes:duration>461</itunes:duration>
      <link>http://channel9.msdn.com/Shows/toolshed/Tool-Shed-Tooltip-3-SysInternals-from-Episode-1</link>
      <pubDate>Mon, 15 Jun 2009 04:58:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Shows/toolshed/Tool-Shed-Tooltip-3-SysInternals-from-Episode-1</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/473671_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/473671_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_ch9.mp3" expression="full" duration="461" fileSize="3694299" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_ch9.mp4" expression="full" duration="461" fileSize="26259537" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_ch9.wma" expression="full" duration="461" fileSize="7475937" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_ch9.wmv" expression="full" duration="461" fileSize="43464209" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_Zune_ch9.wmv" expression="full" duration="461" fileSize="29320189" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/3/1/6/5/7/4/ToolShedTooltip0003a_2MB_ch9.wmv" expression="full" duration="461" fileSize="32020425" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/1/7/6/3/7/4/ToolShedTooltip0003_ch9.wmv" length="43464209" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Russell Fustino</dc:creator>
      <itunes:author>Russell Fustino</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Shows/toolshed/Tool-Shed-Tooltip-3-SysInternals-from-Episode-1/RSS</wfw:commentRss>
      <category>florida</category>
      <category>sysinternals</category>
      <category>Tools</category>
      <category>Tool Shed</category>
    </item>
  <item>
      <title>Certificate Plugfest Troubleshooting Issues with Windows</title>
      <description><![CDATA[Richard Guthrie, Escalation Engineer, presented a session covering debugging tools that can be used for troubleshooting Windows at the 2009&nbsp;Certificate
<a shape="rect" href="http://msdn.microsoft.com/en-us/library/cc216517(PROT.10).aspx" shape="rect">
Windows Protocols</a> Plugfest.&nbsp;&nbsp; Richard answered windows debugging questions as well.&nbsp;&nbsp; Debugging with&nbsp;<a shape="rect" href="http://www.microsoft.com/whdc/DevTools/Debugging/default.mspx" shape="rect">Windbg</a> including assembly call stack analysis examples
 were provided.&nbsp; &nbsp;Tracing calls with Windows ETW and IDNA tracing were demonstrated.&nbsp; Provided a demonstration of a few&nbsp;resource kit tools commonly used for Windows debugging as well as some&nbsp;<a shape="rect" href="http://technet.microsoft.com/en-us/sysinternals/0e18b180-9b7a-4c49-8120-c47c5a693683.aspx" shape="rect">sysinternals</a>
 tools (process monitor &amp; filemon).  <img src="http://m.webtrends.com/dcs1wotjh10000w0irc493s0e_6x1g/njs.gif?dcssip=channel9.msdn.com&dcsuri=http://channel9.msdn.com/Tags/sysinternals/RSS&WT.dl=0&WT.entryid=Entry:RSSView:a33de58922b24109b5a39deb017663fa">]]></description>
      <comments>http://channel9.msdn.com/Blogs/Will+Gregg/Troubleshooting-Issues-with-Windows</comments>
      <itunes:summary>Richard Guthrie, Escalation Engineer, presented a session covering debugging tools that can be used for troubleshooting Windows at the 2009&amp;nbsp;Certificate

Windows Protocols Plugfest.&amp;nbsp;&amp;nbsp; Richard answered windows debugging questions as well.&amp;nbsp;&amp;nbsp; Debugging with&amp;nbsp;Windbg including assembly call stack analysis examples
 were provided.&amp;nbsp; &amp;nbsp;Tracing calls with Windows ETW and IDNA tracing were demonstrated.&amp;nbsp; Provided a demonstration of a few&amp;nbsp;resource kit tools commonly used for Windows debugging as well as some&amp;nbsp;sysinternals
 tools (process monitor &amp;amp; filemon). </itunes:summary>
      <itunes:duration>2188</itunes:duration>
      <link>http://channel9.msdn.com/Blogs/Will+Gregg/Troubleshooting-Issues-with-Windows</link>
      <pubDate>Sat, 02 May 2009 14:21:00 GMT</pubDate>
      <guid isPermaLink="false">http://channel9.msdn.com/Blogs/Will+Gregg/Troubleshooting-Issues-with-Windows</guid>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/100/467354_100x75.jpg" height="75" width="100"></media:thumbnail>
      <media:thumbnail url="http://ecn.channel9.msdn.com/o9/previewImages/220/467354_220x165.jpg" height="165" width="220"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_large_ch9.png" height="240" width="320"></media:thumbnail>
      <media:thumbnail url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_small_ch9.png" height="64" width="85"></media:thumbnail>
      <media:group>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_2MB_ch9.wmv" expression="full" duration="2188" fileSize="214714883" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_ch9.mp3" expression="full" duration="2188" fileSize="17505820" type="audio/mp3" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_ch9.mp4" expression="full" duration="2188" fileSize="93080963" type="video/mp4" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_ch9.wma" expression="full" duration="2188" fileSize="35404125" type="audio/x-ms-wma" medium="audio"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_ch9.wmv" expression="full" duration="2188" fileSize="58994565" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_Zune_ch9.wmv" expression="full" duration="2188" fileSize="84930545" type="video/x-ms-wmv" medium="video"></media:content>
        <media:content url="mms://mschnlnine.wmod.llnwd.net/a1809/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_s_ch9.wmv" expression="full" duration="2188" fileSize="244" type="video/x-ms-wmv" medium="video"></media:content>
      </media:group>      
      <enclosure url="http://mschnlnine.vo.llnwd.net/d1/ch9/4/5/3/7/6/4/TroubleshootingIssuesWithWindows_ch9.wmv" length="58994565" type="video/x-ms-wmv"></enclosure>
      <dc:creator>Will Gregg</dc:creator>
      <itunes:author>Will Gregg</itunes:author>
      <slash:comments>0</slash:comments>
      <wfw:commentRss>http://channel9.msdn.com/Blogs/Will+Gregg/Troubleshooting-Issues-with-Windows/RSS</wfw:commentRss>
      <category>Certificate Plugfest 2009</category>
      <category>Debugging</category>
      <category>Interoperability</category>
      <category>Open Protocols</category>
      <category>sysinternals</category>
      <category>utility</category>
      <category>Windows Protocols</category>
    </item>    
</channel>
</rss>