Sign In
Mark's Blog
Mark Russinovich's technical blog covering topics such as Windows troubleshooting, technologies and security.
Translate This Page
Translate this page
Powered by
Microsoft® Translator
Options
About
Email Blog Author
RSS for posts
Atom
RSS for comments
OK
Search Blogs
Advanced search options...
Search In:
Everything
Blogs
Forums
People
Groups
Places
Pages
Date range:
All Time
Last Year
Last 6 Months
Last 3 Months
Last Month
Last Week
Last Two Days
Tags
No tags have been created or used yet.
Archive
Archives
May 2012
(1)
January 2012
(1)
November 2011
(2)
October 2011
(1)
August 2011
(1)
July 2011
(1)
May 2011
(2)
April 2011
(1)
March 2011
(4)
February 2011
(1)
January 2011
(3)
December 2010
(2)
October 2010
(1)
August 2010
(1)
June 2010
(1)
April 2010
(1)
March 2010
(1)
February 2010
(1)
January 2010
(1)
November 2009
(1)
October 2009
(2)
September 2009
(1)
August 2009
(1)
July 2009
(2)
May 2009
(1)
March 2009
(1)
February 2009
(1)
December 2008
(1)
November 2008
(1)
September 2008
(2)
July 2008
(1)
June 2008
(1)
May 2008
(1)
April 2008
(1)
February 2008
(1)
January 2008
(1)
October 2007
(2)
August 2007
(2)
July 2007
(1)
June 2007
(1)
May 2007
(2)
April 2007
(1)
February 2007
(1)
December 2006
(1)
November 2006
(1)
October 2006
(1)
August 2006
(2)
July 2006
(2)
May 2006
(1)
April 2006
(1)
March 2006
(2)
February 2006
(1)
January 2006
(3)
December 2005
(2)
November 2005
(6)
October 2005
(3)
September 2005
(1)
August 2005
(2)
July 2005
(2)
June 2005
(3)
May 2005
(2)
April 2005
(6)
March 2005
(8)
TechNet Blogs
>
Mark's Blog
Posts
Subscribe via RSS
Sort by:
Most Recent
|
Most Views
|
Most Comments
Excerpt View
|
Full Post View
Mark's Blog
Announcing Trojan Horse, the Novel!
Posted
13 days ago
by
Mark Russinovich
3
Comments
Many of you have read Zero Day , my first novel. It’s a cyberthriller that features Jeff Aiken and the beautiful Daryl Haugen, computer security experts that save the world from a devastating cyberattack. Its reviews and sales exceeded my expectations...
Mark's Blog
The Case of My Mom’s Broken Microsoft Security Essentials Installation
Posted
4 months ago
by
Mark Russinovich
22
Comments
As a reader of this blog I suspect that you, like me, are the IT support staff for your family and friends. And I bet many of you performed system maintenance duties when you visited your family and friends during the recent holidays. Every time I’m visiting...
Mark's Blog
The Case of the Installer Service Error
Posted
5 months ago
by
Mark Russinovich
4
Comments
This case unfolds with a network administrator charged with the rollout of the Microsoft Windows Intune client software on their network. Windows Intune is a cloud service that manages systems on a corporate network, keeping their software up to date...
Mark's Blog
Fixing Disk Signature Collisions
Posted
6 months ago
by
Mark Russinovich
0
Comments
Disk cloning has become common as IT professionals virtualize physical servers using tools like Sysinternals Disk2vhd and use a master virtual hard disk image as the base for copies created for virtual machine clones. In most cases, you can operate with...
Mark's Blog
The Case of the Mysterious Reboots
Posted
7 months ago
by
Mark Russinovich
6
Comments
This case opens when a Sysinternals power user, who also works as a system administrator at a large corporation, had a friend report that their laptop had become unusable. Whenever the friend connected it to a network, their laptop would reboot. The power...
Mark's Blog
The Case of the Hung Game Launcher
Posted
9 months ago
by
Mark Russinovich
8
Comments
I love the cases people send me where the Sysinternals tools have helped them successfully troubleshoot, but nothing is more satisfying than using them to solve my own cases. This case in particular was fun because, well, solving it helped me get back...
Mark's Blog
Troubleshooting with the New Sysinternals Administrator’s Reference
Posted
10 months ago
by
Mark Russinovich
5
Comments
Aaron Margosis and I are thrilled to announce that the long awaited, and some say long overdue, official guide to the Sysinternals tools is now available ! I’ve always had the idea of writing a book on the tools in the back of my mind, but it wasn’t until...
Mark's Blog
Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3
Posted
over 1 year ago
by
Mark Russinovich
6
Comments
In the first post of this series , I used Autoruns , Process Explorer and VMMap to statically analyze a Stuxnet infection on Windows XP. That phase of the investigation revealed that Stuxnet infected multiple processes, launched infected processes that...
Mark's Blog
The Zero Day Book Trailer
Posted
over 1 year ago
by
Mark Russinovich
5
Comments
I just got back the finished version of the video trailer for my new cyber thriller Zero Day , which I think came out awesome! It’s not hard to imagine what a Zero Day movie trailer would look like. Let me know what you think. Zero Day Book Trailer
Mark's Blog
Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 2
Posted
over 1 year ago
by
Mark Russinovich
22
Comments
In Part 1 I began my investigation of an example infection of the infamous Stuxnet worm with the Sysinternals tools. I used Process Explorer , Autoruns and VMMap for a post-infection survey of the system. Autoruns quickly revealed the heart of Stuxnet...
Mark's Blog
Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 1
Posted
over 1 year ago
by
Mark Russinovich
23
Comments
Though I didn’t realize what I was seeing, Stuxnet first came to my attention on July 5 last summer when I received an email from a programmer that included a driver file, Mrxnet.sys, that they had identified as a rootkit. A driver that implements rootkit...
Mark's Blog
Zero Day is Here!
Posted
over 1 year ago
by
Mark Russinovich
53
Comments
I’m excited to announce that my first novel, a cyber thriller entitled Zero Day , is now available at all major book retailers! Zero Day is a book in the style of Crichton and Clancy, weaving technical fact into the story. If you like the Sysinternals...
Mark's Blog
The Case of the Unusable System
Posted
over 1 year ago
by
Mark Russinovich
38
Comments
This post continues in the malware hunting theme of the last couple of posts as Zero Day availability draws near (it’s available tomorrow!). It began when a friend of mine at Microsoft told me that a neighbor of hers had a laptop that malware had rendered...
Mark's Blog
The Case of the Sysinternals-Blocking Malware
Posted
over 1 year ago
by
Mark Russinovich
27
Comments
Continuing the theme of focusing on malware-related cases (last week I posted The Case of the Malicious Autostart ) as a lead up to the publication on March 15 of my novel Zero Day , this post describes one submitted to me by a user that took a unique...
Mark's Blog
The Case of the Malicious Autostart
Posted
over 1 year ago
by
Mark Russinovich
43
Comments
Given that my novel, Zero Day , will be published in a few weeks and is based on malware’s use as a weapon by terrorists, I thought it appropriate to post a case that deals with malware cleanup with the Sysinternals tools. This one starts when Microsoft...
Mark's Blog
The Cases of the Blue Screens: Finding Clues in a Crash Dump and on the Web
Posted
over 1 year ago
by
Mark Russinovich
19
Comments
My last couple of posts have looked at the lighter side of blue screens by showing you how to customize their colors. Windows kernel mode code reliability has gotten better and better every release such that many never experience the infamous BSOD. But...
Mark's Blog
Announcing Zero Day, the Novel!
Posted
over 1 year ago
by
Mark Russinovich
23
Comments
You’ve seen the news if you’re my friend on Facebook , follow me on Twitter , or subscribe to the Sysinternals blog : I’m proud to announce that my first novel, a cyberthriller entitled Zero Day , is due to be published by St. Martin’s Press in mid-March...
Mark's Blog
“Blue Screens” in Designer Colors with One Click
Posted
over 1 year ago
by
Mark Russinovich
10
Comments
My last blog post described how to use local kernel debugging to change the colors of the Windows crash screen, also known as the “blue screen of death”. No doubt many of you thought that showing off a green screen of death or red screen of death to your...
Mark's Blog
A Bluescreen By Any Other Color
Posted
over 2 years ago
by
Mark Russinovich
20
Comments
Note: for an easier way to customize the blue screen’s colors, see my next blog post, “ Blue Screens in Designer Colors with One Click ”. Seeing a bluescreen that’s not blue is disconcerting, even for me, and based on the reaction of the TechEd audiences...
Mark's Blog
The Case of the Slow Project File Opens
Posted
over 2 years ago
by
Mark Russinovich
21
Comments
If you’ve seen one of my Case of the Unexplained presentations (like the one I delivered at TechEd Europe last month that’s posted for on-demand viewing ), you know that I emphasize how thread stacks are a powerful troubleshooting tool for diagnosing...
Mark's Blog
LiveKd for Virtual Machine Debugging
Posted
over 2 years ago
by
Mark Russinovich
11
Comments
When Dave Solomon and I were writing the 3 rd edition of the Windows Internals book series Inside Windows 2000 back in 1999, we pondered if there was a way to enable kernel debuggers like Windbg and Kd (part of the free Debugging Tools for Windows package...
Mark's Blog
The Compound Case of the Outlook Hangs
Posted
over 2 years ago
by
Mark Russinovich
39
Comments
This case was shared with me by a friend of mine, Andrew Richards, a Microsoft Exchange Server Escalation Engineer. It’s a really interesting case because it highlights the use of a Sysinternals tool I specifically wrote for use by Microsoft support...
Mark's Blog
The Case of the Random IE Crash
Posted
over 2 years ago
by
Mark Russinovich
62
Comments
While I long for the day when I no longer experience the effects of buggy software, there’s something rewarding about solving my own troubleshooting cases. In the process, I often come up with new techniques to add to my bag of tricks and to share...
Mark's Blog
The Case of the Printing Failure
Posted
over 2 years ago
by
Mark Russinovich
29
Comments
The most interesting cases I receive are those that demonstrate a unique troubleshooting technique or uncover an interesting root cause. I received this one recently that has both characteristics. The case opened when a systems administrator got a report...
Mark's Blog
Pushing the Limits of Windows: USER and GDI Objects – Part 2
Posted
over 2 years ago
by
Mark Russinovich
25
Comments
Last time , I covered the limits and how to measure usage of one of the two key window manager resources, USER objects. This time, I’m going to cover the other key resource, GDI objects. As always, I recommend you read the previous posts before this one...
Page 1 of 5 (107 items)
1
2
3
4
5