explorer.exe is het dus niet.
Het is Deferred Procedure Calls die zoveel CPU vreet.
Hieronder de tekstfile van Process Explorer.
Process PID CPU Description Company Name
System Idle Process 0 66
Interrupts n/a Hardware Interrupts
----------------------------------------------------------------------------------------------------------
DPCs n/a 24 Deferred Procedure Calls
----------------------------------------------------------------------------------------------------------
System 4
smss.exe 300 Windows NT Session Manager Microsoft Corporation
csrss.exe 360 Client Server Runtime Process Microsoft Corporation
winlogon.exe 384 Toepassing Windows NT-aanmelding Microsoft Corporation
services.exe 428 1 Services en controllertoepassingen Microsoft Corporation
lsass.exe 440 LSA Shell (Export Version) Microsoft Corporation
ctfmon.exe 1684 CTF Loader Microsoft Corporation
explorer.exe 248 4 Windows Verkenner Microsoft Corporation
procexp.exe 780 4 Sysinternals Process Explorer Sysinternals
IEXPLORE.EXE 504 Internet Explorer Microsoft Corporation
Process: services.exe Pid: 428
Type Name
Desktop \Default
Directory \Windows
Directory \BaseNamedObjects
Directory \KnownDlls
Event \BaseNamedObjects\SC_AutoStartComplete
Event \BaseNamedObjects\SvcctrlStartEvent_A3752DX
Event \BaseNamedObjects\ScNetDrvMsg
Event \BaseNamedObjects\WBEM_ESS_OPEN_FOR_BUSINESS
Event \BaseNamedObjects\PnP_No_Pending_Install_Events
Event \BaseNamedObjects\userenv: User Profile setup event
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\scerpc
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\scerpc
File \Device\KsecDD
File \Device\NamedPipe\svcctl
File \Device\NamedPipe\net\NtControlPipe1
File \Device\NamedPipe\net\NtControlPipe1
File C:\WINDOWS\SYSTEM32\config\Antivirus.Evt
File C:\WINDOWS\SYSTEM32\config\AppEvent.Evt
File C:\WINDOWS\SYSTEM32\config\SecEvent.Evt
File C:\WINDOWS\SYSTEM32\config\SysEvent.Evt
File \Device\NamedPipe\net\NtControlPipe2
File \Device\NamedPipe\net\NtControlPipe0
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\PIPE_EVENTROOT\CIMV2SCM EVENT PROVIDER
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\net\NtControlPipe6
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\net\NtControlPipe15
File \Device\NamedPipe\net\NtControlPipe7
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\net\NtControlPipe8
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\net\NtControlPipe16
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File \Device\NamedPipe\ntsvcs
File C:\WINDOWS\SYSTEM32
Key HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\Order
Key HKLM\SYSTEM\ControlSet001\Control\ServiceGroupOrder
Key HKLM
Key HKLM\SYSTEM\ControlSet001\Control\ServiceCurrent
Key HKLM\SYSTEM\ControlSet001\Services\Eventlog
Key HKLM\SYSTEM\ControlSet001\Control\ComputerName\ActiveComputerName
Key HKU
Key HKU\S-1-5-19
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
Key HKLM\SYSTEM\ControlSet001\Enum
Key HKLM\SYSTEM\ControlSet001\Services
Key HKLM\SYSTEM\ControlSet001\Control\Class
Key HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\PerHwIdStorage
KeyedEvent \KernelObjects\CritSecOutOfMemoryEvent
Mutant \NlsCacheMutant
Mutant \BaseNamedObjects\ShimCacheMutex
Mutant \BaseNamedObjects\PnP_Init_Mutex
Port \RPC Control\ntsvcs
Port \ErrorLogPort
Process svchost.exe(620)
Process spoolsv.exe(792)
Process svchost.exe(1888)
Process nvsvc32.exe(1000)
Process svchost.exe(1040)
Process svchost.exe(348)
Section \BaseNamedObjects\ShimSharedMemory
Thread services.exe(428): 452
Thread services.exe(428): 456
Thread services.exe(428): 460
Thread services.exe(428): 700
Thread services.exe(428): 556
Thread services.exe(428): 560
Thread services.exe(428): 580
Thread services.exe(428): 1664
Thread services.exe(428): 596
Thread services.exe(428): 1600
Thread services.exe(428): 616
Thread services.exe(428): 1476
Thread services.exe(428): 1736
Thread services.exe(428): 572
Thread services.exe(428): 320
Thread services.exe(428): 1876
Thread services.exe(428): 696
Thread services.exe(428): 1856
Thread services.exe(428): 1868
Thread services.exe(428): 992
Token COMPUTER\Computer
Token NT AUTHORITY\Lokale service
WindowStation \Windows\WindowStations\Service-0x0-3e7$
WindowStation \Windows\WindowStations\Service-0x0-3e7$
[
Voor 97% gewijzigd door
Verwijderd op 19-11-2004 19:43
]