<?xml version="1.0" encoding="windows-1252"?>
<rss version="2.0"><channel><title>Sysinternals</title><description>Advanced Windows Tools, Source Code and Information</description><link>http://www.sysinternals.com</link><docs>http://blogs.law.harvard.edu/tech/rss</docs><lastBuildDate>Tue, 11 Jul 2006 19:41:21 -0500</lastBuildDate><pubDate>Tue, 11 Jul 2006 19:40:40 -0500</pubDate><generator>FeedForAll v1.0 (1.0.2.0)</generator><item><title>TechEd On-Demand Webcast: Windows Hang and Crash Dump Analysis </title><description>Watch the recording of Mark&apos;s top-rated TechEd session in this free webcast from Microsoft TechNet. Learn to analyze Microsoft Windows crash dumps, diagnose the cause, pinpoint a solution, and resolve the problem. Intended for system administrators, this webcast explains how system crashes occur and what happens when you reboot a crashed system. Mark leads you through the crash dump analysis process step by step, introducing the latest tools from Microsoft and handy tricks for isolating the cause of a crash. </description><link>http://www.microsoft.com/events/EventDetails.aspx?CMTYSvcSource=MSCOMMedia&amp;Params=~CMTYDataSvcParams^~arg+Name=&quot;ID&quot;+Value=&quot;1032298076&quot;/^~arg+Name=&quot;ProviderID&quot;+Value=&quot;A6B43178-497C-4225-BA42-DF595171F04C&quot;/^~arg+Name=&quot;lang&quot;+Value=&quot;en&quot;/^~arg+Name=&quot;cr&quot;+Value=&quot;US&quot;/^~sParams^~/sParams^~/CMTYDataSvcParams^</link><pubDate>Tue, 11 Jul 2006 19:40:40 -0500</pubDate></item><item><title>PsExec v1.72</title><description>You can launch windows on the Winlogon desktop with the new PsExec -x switch.</description><link>http://www.sysinternals.com/Utilities/PsExec.html</link><pubDate>Mon, 10 Jul 2006 14:51:26 -0500</pubDate></item><item><title>Process Explorer v10.2</title><description>This release targets Windows Vista with new integrity level and virtualized columns as well as a signed driver for 64-bit Vista for x64 processors.</description><link>http://www.sysinternals.com/Utilities/ProcessExplorer.html</link><pubDate>Mon, 10 Jul 2006 14:47:15 -0500</pubDate></item><item><title>ZoomIt v1.15</title><description>ZoomIt v1.15 fixes a multimonitor drawing bug.</description><link>http://www.sysinternals.com/Utilities/ZoomIt.html</link><pubDate>Mon, 10 Jul 2006 14:48:34 -0500</pubDate></item><item><title>Autoruns v8.53</title><description>This update fixes issues related to malformed Registry entries and listview drawing flicker during scans.</description><link>http://www.sysinternals.com/Utilities/Autoruns.html</link><pubDate>Mon, 10 Jul 2006 14:47:38 -0500</pubDate></item><item><title>Strings v2.3</title><description>A new option has Strings print the offsets within a file at which strings are located.</description><link>http://www.sysinternals.com/Utilities/Strings.html</link><pubDate>Mon, 10 Jul 2006 14:49:30 -0500</pubDate></item><item><title>ZoomIt v1.13</title><description>This update fixes a bug in 1.12 and adds a Draw item to the tray icon&apos;s context menu.</description><link>http://www.sysinternals.com/Utilities/ZoomIt.html</link><pubDate>Tue, 27 Jun 2006 01:36:11 -0500</pubDate></item><item><title>ZoomIt v1.12</title><description>This ZoomIt update now bounds the drawing cursor so that you can&apos;t lose track of it off the screen and includes new context menu entries and mouse behaviors so that its fully controllable with just a mouse.</description><link>http://www.sysinternals.com/Utilities/ZoomIt.html</link><pubDate>Fri, 23 Jun 2006 09:21:39 -0500</pubDate></item><item><title>Autoruns v8.52</title><description>Autoruns now includes an autostart location that&apos;s used by malware to hijack the desktop background.</description><link>http://www.sysinternals.com/Utilities/Autoruns.html</link><pubDate>Fri, 23 Jun 2006 09:21:20 -0500</pubDate></item><item><title>Apple Hi-Res Screen Dump</title><description>Mark&apos;s first magazine article, one he published in Compute! in 1985 that describes a program he wrote to dump Apple ][ hi-resolution screen contents to Epson printers, is now on line!</description><link>http://www.atarimagazines.com/compute/issue67/348_1_Apple_Hi-Res_Screen_Dump.php</link><pubDate>Fri, 23 Jun 2006 09:21:06 -0500</pubDate></item><item><title>The Sysinternals Video Library</title><description>We&apos;re pleased to announce The Sysinternals Video Library, a set of six DVDs that cover essential Windows troubleshooting topics. Each video is personally presented by Mark Russinovich and David Solomon. The complete set is available for pre-order at a discounted price and the first video, Tour of the Sysinternals Tools, is free for download.</description><link>http://www.sysinternals.com/videos.html</link><pubDate>Mon, 12 Jun 2006 05:19:49 -0500</pubDate></item><item><title>RootkitRevealer Top 100 Products of 2006</title><description>RootkitRevealer has earned a spot in PC World&apos;s top 100 products of the year (it might be #100, but its still in)! We&apos;re honored to be in the company of products like the Xbox 360 and the iPod. &lt;br&gt;</description><link>http://www.pcworld.com/reviews/article/0,aid,125706,pg,13,00.asp</link><pubDate>Mon, 12 Jun 2006 05:20:14 -0500</pubDate></item><item><title>London Seminar Registration Reopened!</title><description>We&apos;ve found a larger venue and so have reopened registration for our upcoming Windows Internals and Advanced Troubleshooting seminar in London June 26-30. Sign up now before we sell out again!</description><link>http://www.sysinternals.com/Troubleshooting.html</link><pubDate>Tue, 6 Jun 2006 17:17:39 -0500</pubDate></item><item><title>AccessChk v2.0</title><description>AccessChk now has an option to dump security descriptors and also has support for showing and filtering Vista object Integrity Levels</description><link>http://www.sysinternals.com/Utilities/AccessChk.html</link><pubDate>Tue, 6 Jun 2006 17:17:15 -0500</pubDate></item><item><title>Handle v3.2</title><description>This Handle update includes an option for not prompting on handle closes and also reports the sharing flags configured for open files.</description><link>http://www.sysinternals.com/utilities/handle.html</link><pubDate>Tue, 6 Jun 2006 17:16:57 -0500</pubDate></item><item><title>Windows Hang and Crash Dump Analysis Live Webcast</title><description>Sign up to see the free live Webcast of one of Mark&apos;s TechEd sessions, Friday, June 16 at 10:45 Eastern Time!</description><link>http://msevents.microsoft.com/CUI/WebCastEventDetails.aspx?EventID=1032298075&amp;EventCategory=4&amp;culture=en-US&amp;CountryCode=US</link><pubDate>Tue, 6 Jun 2006 17:16:26 -0500</pubDate></item><item><title>Process Explorer v10.11</title><description>Through support from HP, Process Explorer is now available on 64-bit Windows for Itanium-based systems to support increased market demand.  In addition, this release adds I/O counter columns and process statistics, system-wide and per-process I/O history graphs, memory and I/O minigraphs, service permissions editing, and support for Vista process cycle counters.</description><link>http://www.sysinternals.com/Utilities/processexplorer.html</link><pubDate>Thu, 11 May 2006 15:30:51 -0500</pubDate></item><item><title>AccessChk v1.0</title><description>This new security utility shows you what accesses that a user or group you specify has to files, Registry keys or Windows services.</description><link>http://www.sysinternals.com/Utilities/AccessChk.html</link><pubDate>Tue, 18 Apr 2006 12:38:59 -0500</pubDate></item><item><title>ZoomIt v1.1</title><description>As a result of more field testing ZoomIt now includes a break timer hotkey and tweaks to its drawing behavior.</description><link>http://www.sysinternals.com/Utilities/ZoomIt.html</link><pubDate>Tue, 18 Apr 2006 12:39:17 -0500</pubDate></item><item><title>PsService v2.2</title><description>PsService now includes an option to dump service security descriptors.</description><link>http://www.sysinternals.com/utilities/psservice.html</link><pubDate>Sun, 9 Apr 2006 08:00:00 -0500</pubDate></item><item><title>Autoruns v8.51</title><description>This Autoruns update fixes bugs related to malformed paths.</description><link>http://www.sysinternals.com/utilities/autoruns.html</link><pubDate>Sun, 9 Apr 2006 08:00:00 -0500</pubDate></item><item><title>DebugView v4.6</title><description>This DebugView release adds support for WIndows Vista and fixes a buffer overflow that could occur when the option to force carriage returns is off.</description><link>http://www.sysinternals.com/utilities/debugview.html</link><pubDate>Mon, 10 Apr 2006 08:00:00 -0500</pubDate></item><item><title>ZoomIt v1.0</title><description>ZoomIt is a presentation tool that let&apos;s you zoom the screen and move around, draw on a zoomed image, and display a fullscreen break countdown timer. Mark wrote it specifically for use during his presentations.</description><link>http://www.sysinternals.com/Utilities/zoomit.html</link><pubDate>Mon, 27 Mar 2006 09:09:24 -0500</pubDate></item><item><title>PsShutdown v2.51</title><description>This update fixes a bug that affected the use of the -v switch.</description><link>http://www.sysinternals.com/utilities/psshutdown.html</link><pubDate>Mon, 27 Mar 2006 09:09:46 -0500</pubDate></item><item><title>PsLoggedOn v1.22</title><description>A formatting bug caused by the -x switch is fixed in this release.</description><link>http://www.sysinternals.com/utilities/psloggedon.html</link><pubDate>Mon, 27 Mar 2006 09:10:25 -0500</pubDate></item><item><title>Contig v1.53</title><description>This version fixes filename wildcard parsing bugs.</description><link>http://www.sysinternals.com/utilities/contig.html</link><pubDate>Mon, 27 Mar 2006 09:11:59 -0500</pubDate></item><item><title>PsExec v1.71</title><description>This version fixed a bug that sometimes caused the PsExec client to hang after running multiple times in quick succession.</description><link>http://www.sysinternals.com/utilities/psexec.html</link><pubDate>Tue, 7 Mar 2006 15:47:13 -0500</pubDate></item><item><title>Autoruns v8.5</title><description>This new Autoruns release adds scanning of LSA security, notification, and authentication providers as well as Explorer protocol handlers and extensions.</description><link>http://www.sysinternals.com/Utilities/autoruns.html</link><pubDate>Tue, 7 Mar 2006 15:46:57 -0500</pubDate></item><item><title>Mark to Speak at Microsoft TechEd 2006</title><description>Mark is copresenting a preconference tutorial on advanced malware cleaning at TechEd US in Boston on June 11. In addition, he&apos;s delivering breakout sessions on topics including Vista kernel changes, troubleshooting with Filemon and Regmon, analyzing Windows crashes and hangs, Vista security changes, and advanced malware cleaning techniques.</description><link>http://www.sysinternals.com/Information/SpeakingSchedule.html</link><pubDate>Thu, 23 Feb 2006 05:59:53 -0500</pubDate></item><item><title>Process Explorer v10.06</title><description>This update includes a number of minor bug fixes (after the 10.0 release I quickly learned that people run Process Explorer with a vast array of diverse configurations).</description><link>http://www.sysinternals.com/Utilities/ProcessExplorer.html</link><pubDate>Thu, 23 Feb 2006 05:57:33 -0500</pubDate></item><item><title>Process Explorer v10.02</title><description>This major Process Explorer update has an extensive list of new features and enhancements aimed at usability and malware hunting. Just some of the examples include Runas and Run As Limited User commands, process restart, column sets, enhanced process tooltips for service-hosting and Rundll32 processes, working set breakdown columns, and DLL image verification and packed-image detection.</description><link>http://www.sysinternals.com/Utilities/ProcessExplorer.html</link><pubDate>Wed, 8 Feb 2006 15:00:47 -0500</pubDate></item><item><title>RootkitRevealer v1.7</title><description>This new RootkitRevealer release includes more sophisticated rootkit counter-measures, scanning of all Registry hives including user profiles, and numerous bug fixes.</description><link>http://www.sysinternals.com/Utilities/RootkitRevealer.html</link><pubDate>Thu, 2 Feb 2006 13:53:45 -0500</pubDate></item><item><title>Regdelnull v1.1</title><description>In response to the use of such keys by malware, RegDelNull can now unlock and delete keys that not only have embedded nulls, but that also have security permissions that make them otherwise inaccessible.</description><link>http://www.sysinternals.com/Utilities/RegDelNull.html</link><pubDate>Fri, 13 Jan 2006 17:42:25 -0500</pubDate></item><item><title>Sigcheck v1.3</title><description>Sigcheck, a powerful command-line file version information and signature verification tool, now includes a new flag that has it only show a file&apos;s version number.</description><link>http://www.sysinternals.com/Utilities/Sigcheck.html</link><pubDate>Fri, 13 Jan 2006 17:41:57 -0500</pubDate></item><item><title>PsExec v1.7</title><description>This PsExec update includes a new -l switch for use by administrative accounts to run processes with limited-user account privileges. Run a low-rights Internet Explorer before IE 7 comes out simply by creating a shortcut to launch it with the switch.</description><link>http://www.sysinternals.com/Utilities/PsExec.html</link><pubDate>Fri, 13 Jan 2006 17:41:34 -0500</pubDate></item><item><title>Autoruns v8.43</title><description>This update fixes several bugs and adds on-demand signature verification for individual items.</description><link>http://www.sysinternals.com/Utilities/autoruns.html</link><pubDate>Wed, 7 Dec 2005 15:40:11 -0500</pubDate></item><item><title>RootkitRevealer v1.6</title><description>This version runs from Windows XP remote desktop sessions, includes a number of bug fixes and reduces the number of false positive descrepancies.</description><link>http://www.sysinternals.com/Utilities/RootkitRevealer.html</link><pubDate>Wed, 7 Dec 2005 15:39:54 -0500</pubDate></item><item><title>PowerTools: PsLoglist</title><description>Check out the December issue of Windows IT Pro Magazine for Mark&apos;s column where he tells you how to get the most out of PsLoglist (subscription required).</description><link>http://www.windowsitpro.com/Windows/Article/ArticleID/48080/48080.html</link><pubDate>Wed, 7 Dec 2005 15:39:42 -0500</pubDate></item><item><title>Inside Sony&apos;s Rootkit</title><description>Mark dives into the technical details of Sony&apos;s rootkit implementation in the December issue of Virus Bulletin, the magazine for professional anti-malware researchers (subscription required).</description><link>http://www.virusbtn.com/virusbulletin/archive/2005/12/index</link><pubDate>Wed, 7 Dec 2005 15:39:05 -0500</pubDate></item><item><title>Four Sysinternals Tools Picked as Pricelessware 2006</title><description>Filemon, Regmon, Process Explorer and Autoruns have been picked as the &quot;best of the best&quot; by alt.comp.freeware newsgroup participants.</description><link>http://www.pricelesswarehome.org/2006/about2006PL.php</link><pubDate>Mon, 28 Nov 2005 17:24:51 -0500</pubDate></item><item><title>RegDelNull v1.0</title><description>Use this new applet to find and delete Registry keys that are &quot;undeleteable&quot; by standard Registry-editing utilities because they have embedded null characters in their names.</description><link>http://www.sysinternals.com/Utilities/RegDelNull.html</link><pubDate>Mon, 28 Nov 2005 17:24:31 -0500</pubDate></item></channel></rss>