ProcessPIDCPUDescriptionCompany Name
System Idle Process079
Interruptsn/aHardware Interrupts
DPCsn/a3Deferred Procedure Calls
System44
smss.exe520Windows NT Session ManagerMicrosoft Corporation
csrss.exe600Client Server Runtime ProcessMicrosoft Corporation
winlogon.exe624Windows NT-AnmeldungMicrosoft Corporation
services.exe6681Anwendung für Dienste und ControllerMicrosoft Corporation
svchost.exe852Generic Host Process for Win32 ServicesMicrosoft Corporation
winamp.exe512WinampNullsoft
svchost.exe904Generic Host Process for Win32 ServicesMicrosoft Corporation
svchost.exe968Generic Host Process for Win32 ServicesMicrosoft Corporation
svchost.exe99613Generic Host Process for Win32 ServicesMicrosoft Corporation
spoolsv.exe1196Spooler SubSystem AppMicrosoft Corporation
nvsvc32.exe1356
svchost.exe1396Generic Host Process for Win32 ServicesMicrosoft Corporation
cpd.exe1680McAfee FirewallNetwork Associates, Inc.
cpd.exe1772McAfee FirewallNetwork Associates, Inc.
lsass.exe680LSA Shell (Export Version)Microsoft Corporation
explorer.exe1204Windows ExplorerMicrosoft Corporation
CMGrdian.exe1884McAfee Guardian AgentNetwork Associates, Inc.
SOUNDMAN.EXE1900Avance Sound ManagerAvance Logic, Inc.
MsgPlus.exe1924Messenger Plus!Patchou
realsched.exe1932RealNetworks SchedulerRealNetworks, Inc.
Client.exe1944
iexplore.exe1112Internet ExplorerMicrosoft Corporation
procexp.exe1288Sysinternals Process ExplorerSysinternals
EM_EXEC.EXE2020Logitech Events Handler ApplicationLogitech Inc.
Process: svchost.exe Pid: 996
TypeName
Desktop\Default
Directory\Windows
Directory\BaseNamedObjects
Directory\KnownDlls
Event\BaseNamedObjects\crypt32LogoffEvent
FileC:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Temporary Internet Files\Content.IE5\index.dat
FileC:\Dokumente und Einstellungen\LocalService\Cookies\index.dat
FileC:\Dokumente und Einstellungen\LocalService\Lokale Einstellungen\Verlauf\History.IE5\index.dat
File\Device\WebDavRedirector
File\Device\WebDavRedirector
File\Device\NamedPipe\DAV RPC SERVICE
File\Device\NamedPipe\DAV RPC SERVICE
File\Device\NamedPipe\DAV RPC SERVICE
File\Device\NamedPipe\svcctl
File\Device\Tcp
File\Device\KsecDD
File\Device\NamedPipe\net\NtControlPipe5
File\Device\NamedPipe\svcctl
File\Device\Tcp
File\Device\Ip
File\Device\Ip
FileC:\WINDOWS\system32
File\Device\Tcp
File\Device\NetBt_Wins_Export
File\Device\NetBt_Wins_Export
FileC:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805
File\Device\WebDavRedirector
File\Device\WebDavRedirector
FileC:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.10.0_x-ww_f7fb5805
KeyHKLM
KeyHKLM\SYSTEM\ControlSet001\Services\Tcpip\Linkage
KeyHKLM\SYSTEM\ControlSet001\Services\Tcpip\Parameters
KeyHKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters\Interfaces
KeyHKLM\SYSTEM\ControlSet001\Services\NetBT\Parameters
KeyHKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9
KeyHKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5
KeyHKU\S-1-5-19\Software\Microsoft\Windows\CurrentVersion\Internet Settings
KeyedEvent\KernelObjects\CritSecOutOfMemoryEvent
Mutant\BaseNamedObjects\_!MSFTHISTORY!_
Mutant\BaseNamedObjects\c:!dokumente und einstellungen!localservice!lokale einstellungen!temporary internet files!content.ie5!
Mutant\BaseNamedObjects\c:!dokumente und einstellungen!localservice!cookies!
Mutant\BaseNamedObjects\c:!dokumente und einstellungen!localservice!lokale einstellungen!verlauf!history.ie5!
Mutant\BaseNamedObjects\WininetStartupMutex
Mutant\BaseNamedObjects\WininetProxyRegistryMutex
Section\BaseNamedObjects\C:_Dokumente und Einstellungen_LocalService_Lokale Einstellungen_Temporary Internet Files_Content.IE5_index.dat_32768
Section\BaseNamedObjects\C:_Dokumente und Einstellungen_LocalService_Lokale Einstellungen_Verlauf_History.IE5_index.dat_16384
Section\BaseNamedObjects\C:_Dokumente und Einstellungen_LocalService_Cookies_index.dat_16384
Semaphore\BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
Threadsvchost.exe(996): 1328
Threadsvchost.exe(996): 1332
Threadsvchost.exe(996): 2032
Threadsvchost.exe(996): 2040
Threadsvchost.exe(996): 1000
Threadsvchost.exe(996): 1036
Threadsvchost.exe(996): 1036
Threadsvchost.exe(996): 1040
Threadsvchost.exe(996): 1324
Threadsvchost.exe(996): 980
TokenNT-AUTORITÄT\LOKALER DIENST
WindowStation\Windows\WindowStations\Service-0x0-3e5$
WindowStation\Windows\WindowStations\Service-0x0-3e5$