Malware Hunting with Mark Russinovich and the Sysinternals Tools

Поділитися
Вставка
  • Опубліковано 16 січ 2025

КОМЕНТАРІ • 49

  • @ebeaulieu813
    @ebeaulieu813 2 роки тому +8

    I've been using a Windows PC since windows 95. I have no desire to deal with the fails of windows from it's own software failures to viruses but unfortunately a necessity. This video is so over the top for me but informative. This guy is a SAVANT.

    • @cloakface-sv5sm
      @cloakface-sv5sm 9 місяців тому

      As one smart guy once said, computers don't fail from doing wrong what you ask them to do. They fail from doing what you ask too literally.

  • @user-pg9te8ug1j
    @user-pg9te8ug1j 3 роки тому +23

    To whom it may concern: this talk is from 2014.

  • @timlind3129
    @timlind3129 2 роки тому +5

    Amazing how powerful this tool is and the whole suite. Amazing also is that since the original winternals, it's freeware. Respect to the developers on this.

    • @Rdaj0491
      @Rdaj0491 10 місяців тому

      I was amazed at the amount of tools you get and the little space it takes up. Mind blown lol 😆

  • @QQ_Victory
    @QQ_Victory 2 роки тому +5

    Great talk! I am always learning new things about the Sysinternals tools with these videos. I wish there was an updated talk. Keep it up!

  • @cloakface-sv5sm
    @cloakface-sv5sm 9 місяців тому +2

    I started learning computer science since 9 years old. Now I'm 17 and I'm graduating from the school and going on to a system administrator education program. Mark Russinovich was inspiring me into that for the whole last year :)

    • @ME-ov7vp
      @ME-ov7vp 6 місяців тому +1

      "i started learning computer science since 2 years old", this part ,nobody cares.

    • @cloakface-sv5sm
      @cloakface-sv5sm 6 місяців тому

      @@ME-ov7vp looks like you started learning English yesterday

    • @domzzy6432
      @domzzy6432 4 місяці тому

      I started learning computer science when i was 9months old "who cares"

    • @cloakface-sv5sm
      @cloakface-sv5sm 4 місяці тому +1

      Answering to all these fools saying that nobody cares: I’ve got purpose in my life, my life makes sense, I’m on my way to new implementations in IT. And your life, gee’s, makes no sense, should you choose to listen to my words. I left my comment here as an appreciation and sign of respect to Mark Russinovich, not for you, birdies

    • @domzzy6432
      @domzzy6432 4 місяці тому

      @@cloakface-sv5sm Broskii i was just messing with you it wasn't that deep 😂😂

  • @nemo1877
    @nemo1877 3 роки тому +10

    This guy is a genius. I really don't know how to appreciate his work..

  • @sekousekou8838
    @sekousekou8838 2 роки тому

    his tools make you a windows internal guru in about 1h30 min. Thanks Mark!!!

  • @getoutmore
    @getoutmore 2 роки тому +2

    I loved this. Im motivated to get Into Malware hunting on Windows and this vid fired me up even more. I will Check your Channel and Hope Theres more Like this

  • @liamodonnell368
    @liamodonnell368 4 роки тому +11

    Good stuff mark, just add the year of the video to the title, I thought you'd actually done one for this year's ignite

  • @parthmaniar
    @parthmaniar 4 роки тому +4

    You inspire so many of us. :)

  • @RealShinpin
    @RealShinpin Рік тому +1

    great video, i just wish it weren't so blurry... Anyone have a fixed version? Maybe one that's been run through a Deblurring AI model?

  • @ColdFireInBox
    @ColdFireInBox 4 роки тому +5

    Thanks for sharing this video Mark. I am using your tools almost every day! They are amazing and Must

  • @tloy1966
    @tloy1966 2 роки тому +1

    Super, so many useful tools

  • @famspower
    @famspower 4 роки тому +3

    I have to thank you for this amazing tools. Our analyst life is much easier

  • @AustinHypes
    @AustinHypes 7 місяців тому

    great video

  • @hickenc2187
    @hickenc2187 4 роки тому

    끝 없는 개선 박수 짝짝짝 = I applaud the endless improvement

  • @samas69420
    @samas69420 Рік тому

    What's the buddy system?

  • @marlonbonilla919
    @marlonbonilla919 2 роки тому

    Magnific Work!

  • @simmonszhu
    @simmonszhu 4 роки тому +2

    The sigcheck doesn't seem to work for windows 10 after download.
    Any update?

    • @cts3029
      @cts3029 2 роки тому

      In the command line, you need to navigate to the directory where you saved sigcheck.

    • @QQ_Victory
      @QQ_Victory 2 роки тому +1

      @@cts3029 Correct or you can add it to the path variable so you can access it from anywhere.

  • @sirtimatbob
    @sirtimatbob 2 роки тому +3

    Are there any significant differences with malware now in 2022?
    Is the information in the presentation still entirely relevant?
    For cleaning the system, wouldn't it be better to fully wipe, format the drive, and reinstall Windows?

    • @tech29X
      @tech29X 2 роки тому +1

      If the software you are using have unpatched or zero day vulnerabilities, you will be stuck in an infinite loop; Fully wipe drive, Reinstall Windows, Reinstall Vulnerable software/process, Get hacked again, and goto 10 (repeat). Without understanding the root cause, reinstalling windows may achieve little to nothing. In a distant future if newer programming languages with stricter enforcement for code safety like Rust or GoLang replace older ones like C for writing operating systems and application software, maybe then we can see a significant reduction in malware. Until then, keep formatting and reinstalling is the only solution for common people. There are so called opensource software contributors who are actually government agents deliberately incorporating vulnerable code to be exploited later that makes the matter more complex. You can't secure a product if some of its components are deliberately designed to exploited by certain people later.

    • @tech29X
      @tech29X 2 роки тому

      Linux anyone? I'm sure people will bash me, touting how secure Linux is because it is open source, and there for it is safer or more secure... I can show my dog my secret diary, do you think my dog can make any sense of what's in it?

  • @Sensualfr0g
    @Sensualfr0g 11 місяців тому

    I think i have a wmi malware but its not showing up in autoruns pls halp!

    • @Sensualfr0g
      @Sensualfr0g 11 місяців тому

      there is a grayed out wmiprvse service in process explorer and it wont let me look at it there is no verification and i saw two fo the same file then one disappeared.

  • @b_tssl
    @b_tssl Рік тому

    💯💯

  • @PassionataDance
    @PassionataDance 3 роки тому +2

    I blame powershell.

  • @Jonas028
    @Jonas028 Рік тому

    18:00

  • @restoration2489
    @restoration2489 4 роки тому +1

    Is there a more succinct way of describing it? like my videos for example

  • @av733
    @av733 2 роки тому +1

    This is a nice presentation but the video quality sucks.

  • @johnyriver96
    @johnyriver96 Рік тому

    At 26:00, your malware is so bad it is detected just by looking similar to other malware even though you haven't even published it as you say. Also all the malware you examine are super obvious, you make absolutely no effort to analyze something that tries to evade detection. Also everything you say is completely useless if you don't already know beforehand the name of the malware that exists on your pc.

    • @puucca
      @puucca Рік тому +4

      The video has educational purposes dude, calm down.

  • @RakibHasan-hs1me
    @RakibHasan-hs1me Рік тому

    Yeah that is super annoying.

  • @The_Ghost_In_Heaven
    @The_Ghost_In_Heaven 3 роки тому +3

    AaaS LMAOO

  • @The_Penguin_City
    @The_Penguin_City 2 роки тому

    An intrussion mega virus like windose, searching for an intrusion virus.
    Hilarious.

  • @nin1ten1do
    @nin1ten1do 3 роки тому +4

    just use kaspersky and forget this flex..