<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx</link><description>In the first post of this series , I used Autoruns , Process Explorer and VMMap to statically analyze a Stuxnet infection on Windows XP. That phase of the investigation revealed that Stuxnet infected multiple processes, launched infected processes that</description><dc:language>en-US</dc:language><generator>Telligent Evolution Platform Developer Build (Build: 5.6.50428.7875)</generator><item><title>re: Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx#3430690</link><pubDate>Fri, 20 May 2011 16:45:24 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3430690</guid><dc:creator>jader3rd</dc:creator><description>&lt;p&gt;So the ability to modify the task sechduling file. Do you think that that&amp;#39;s something someone at Microsoft intentionally enabled for some backwards compatability purposes? I can invision a bug where something with Task Scheulding was broken (or undesirably difficult) because of new admin security models, so someone intentionally shimmed the scenario, by passing the credentials. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3430690" width="1" height="1"&gt;</description></item><item><title>re: Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx#3429070</link><pubDate>Fri, 13 May 2011 16:06:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3429070</guid><dc:creator>Mark Russinovich</dc:creator><description>&lt;p&gt;@Feet Command: virtual&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3429070" width="1" height="1"&gt;</description></item><item><title>re: Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx#3429069</link><pubDate>Fri, 13 May 2011 16:05:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3429069</guid><dc:creator>Mark Russinovich</dc:creator><description>&lt;p&gt;@RichardVJ the seminar is being simulcast for web viewing. &lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3429069" width="1" height="1"&gt;</description></item><item><title>re: Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx#3429047</link><pubDate>Fri, 13 May 2011 15:09:53 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3429047</guid><dc:creator>Fleet Command</dc:creator><description>&lt;p&gt;Indeed, I agree, Mark. I understand that it should have been difficult preparing this blog post, in fact more difficult than just learning it for yourself. Thank you.&lt;/p&gt;
&lt;p&gt;By the way, Mark, did you use an actual computer or a virtual one?&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3429047" width="1" height="1"&gt;</description></item><item><title>re: Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx#3428987</link><pubDate>Fri, 13 May 2011 10:31:08 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3428987</guid><dc:creator>RichardVJ</dc:creator><description>&lt;p&gt;Good work Dr Mark :)&lt;/p&gt;
&lt;p&gt;Mark Please host a online session for the planned seminar, We are all interested in your Zero Day Malware Cleaning with the Sysinternals Tools seminar but really difficult to travel from EU to US for it.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3428987" width="1" height="1"&gt;</description></item><item><title>re: Analyzing a Stuxnet Infection with the Sysinternals Tools, Part 3</title><link>http://blogs.technet.com/b/markrussinovich/archive/2011/05/10/3422212.aspx#3427918</link><pubDate>Tue, 10 May 2011 19:18:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3427918</guid><dc:creator>TheJoshuaTSmith</dc:creator><description>&lt;p&gt;Mark, thank you SO much for sharing, as usual. This series on Stuxnet, in particular, was a most interesting read, and, as per your usual style, easy to assimilate and follow.&lt;/p&gt;
&lt;p&gt;Again, we very much appreciate the Sysinternals tools and your personal interactivity with the tech community.&lt;/p&gt;
&lt;div style="clear:both;"&gt;&lt;/div&gt;&lt;img src="http://blogs.technet.com/aggbug.aspx?PostID=3427918" width="1" height="1"&gt;</description></item></channel></rss>