Forum     

Go Back   Digit Technology Discussion Forum > News > Technology News
Register FAQ Calendar Mark Forums Read

Technology News News from the world of technology that our members stumble across. NOTE: Sources to be mentioned at the beginning of each post.


Closed Thread
 
LinkBack Thread Tools Display Modes
Old 09-11-2006, 11:12 PM   #1 (permalink)
Apprentice
 
Join Date: Aug 2005
Posts: 68
Default Microsoft Ships New Malware Hunting Utility


On the heels of its July 2006 acquisition of Mark Russinovich's Winternals Software, Microsoft has replaced the popular Regmon and Filemon utilities with a single tool offering advanced capabilities for real-time monitoring of registry and process thread activity.

The release of the new utility, called Process Monitor coincides with the relaunch of the Sysinternals portal as the Windows Sysinternals TechCenter on Microsoft TechNet.

Russinovich, a respected Windows kernel guru who joined the Redmond, Wash. vendor as a Technical Fellow in the Platforms and Services Division, describes Process Monitor as "a powerful new monitoring tool that is best described as Regmon and Filemon on steroids."

Regmon and Filemon are hugely popular among virus and spyware researchers who use the real-time file and registry monitoring tools to determine changes made to an infected operating system.

The new Process Monitor, which was rewritten from scratch, will also include a third utility called Process Explorer in a single interface.

According to Microsoft, the new utility features an extensive list of enhancements including rich and non-destructive filtering, comprehensive event properties such session IDs and user names, reliable process information, full thread stacks with integrated symbol support for each operation, and simultaneous logging to a file.



"[These] powerful features will make Process Monitor a core utility in your system troubleshooting and malware hunting toolkit," the company said.

Process Monitor, available as a free download, runs on Windows 2000 SP4 with Update Rollup 1, Windows XP SP2, Windows Server 2003, and Windows Vista as well as x64 versions of Windows XP, Windows Server 2003 and Windows Vista.

Process Monitor can be used to track process and thread startup and exit, including exit status codes; monitor image (DLL and kernel-mode device driver) loads. It also captures data for operation input and output parameters, as well as capture thread stacks for each operation to identify the root cause of an operation.

Microsoft also announced the release of Sysinternals Suite, a single download package that includes the entire set of SysInternals tools and utilities.



Since closing the Winternals Software acquisition, Microsoft has completed the migration of Sysinternals content and tools to its domains. Russinovich's blog, which was used to expose Sony BMG's use of a rootkit in its copy protection scheme, has been ported to Microsoft's TechNet site and the free utilities have been moved to Microsoft Download.

However, the source code for the tools will not be migrated. "The number of source code downloads didn't justify the migration, support and possible integration problems it might cause with other Windows components down the road," said Otto Helweg, program manager in Microsoft's Windows Server and Tools division.

http://www.eweek.com/article2/0,1895,2054266,00.asp
saipothuri is offline  
Advertisements. Register and be a member of the community to get rid of them.
Advertisement

Old 10-11-2006, 07:16 PM   #2 (permalink)
Distinguished Member
 
anandk's Avatar
 
Join Date: Mar 2005
Location: Pune
Posts: 3,783
Default Re: Microsoft Ships New Malware Hunting Utility

thanx 4 d info a good development too.
__________________
> www.TheWindowsClub.com <
= www.WinVistaClub.com =
Microsoft® MVP
anandk is offline  
Old 10-11-2006, 08:09 PM   #3 (permalink)
In The Zone
 
damnthenet's Avatar
 
Join Date: Apr 2005
Location: Chennai
Posts: 224
Default Re: Microsoft Ships New Malware Hunting Utility

Hope this sorts out a few prob's
__________________
Sony Xperia Neo V - Review and Discussion Thread:
http://www.thinkdigit.com/forum/mobi...ml#post1520514
damnthenet is offline  
Old 10-11-2006, 11:47 PM   #4 (permalink)
Coming back to life ..
 
it_waaznt_me's Avatar
 
Join Date: Nov 2003
Location: A bit closer to heaven
Posts: 1,997
Default Re: Microsoft Ships New Malware Hunting Utility

Acquiring Sysinternals was the best thing that MS did this year .. Me using Mark's tools for soooo long .. I hope the default Windows Task Manager is replaced by his Process Explorer ..
__________________
Sleight of hand and twist of fate...
On a bed of nails she makes me wait...
And I wait without you ...
With or without you ..
----
Batty = Too Busy Now !!!
it_waaznt_me is offline  
Old 11-11-2006, 12:02 AM   #5 (permalink)
Alpha Geek
 
sabret00the's Avatar
 
Join Date: Aug 2006
Location: Calcutta
Posts: 732
Default Re: Microsoft Ships New Malware Hunting Utility

__________________
C2D E6600,Asus P5N32 e SLI,1GB 667mhz,Samsung 940BW,Zeb 8600GT,Seagate 250GB sata II,16x Sony(OEM) dvd RW,Zeb Anitibiotic & Platinum 500W,Microsoft desktop pro 700,bluetooth,Logitech MX Revolution
sabret00the is offline  
Old 12-11-2006, 06:20 PM   #6 (permalink)
Apprentice
 
delivi's Avatar
 
Join Date: Jul 2006
Location: Tuticorin
Posts: 55
Default Re: Microsoft Ships New Malware Hunting Utility

wow microsoft is returining back to its normal form by giving us more surprises just like Google does
__________________
Born to live Online

http://www.delivi.info/
http://ms.delivi.info/
delivi is offline  
Closed Thread

Bookmarks

Thread Tools
Display Modes

Posting Rules
You may not post new threads
You may not post replies
You may not post attachments
You may not edit your posts

BB code is On
Smilies are On
[IMG] code is On
HTML code is Off
Trackbacks are On
Pingbacks are On
Refbacks are On


 
Latest Threads
- by Tenida
- by Charan
- by Niilesh

Advertisement




All times are GMT +5.5. The time now is 06:10 PM.


Powered by vBulletin® Version 3.8.7
Copyright ©2000 - 2012, vBulletin Solutions, Inc.

Search Engine Optimization by vBSEO 3.3.2