Автор: dfdvcvy
Дата сообщения: 17.05.2009 23:44
		[more] 
 Process    PID    CPU    Description    Company Name 
 ashDisp.exe    2444        avast! service GUI component    ALWIL Software 
 ashServ.exe    1980        avast! antivirus service    ALWIL Software 
 aswUpdSv.exe    1968        avast! Antivirus updating service    ALWIL Software 
 audiodg.exe    1452        Изоляция графиков аудиоустройств Windows     Microsoft Corporation 
 cfp.exe    2408             
 cmdagent.exe    2728             
 CNAB4RPK.EXE    1692        Canon Advanced Printing Technology RPC Server Process    CANON INC. 
 csrss.exe    768        Процесс исполнения клиент-сервер    Microsoft Corporation 
 csrss.exe    832    1.89    Процесс исполнения клиент-сервер    Microsoft Corporation 
 DPCs    n/a        Deferred Procedure Calls     
 dwm.exe    1380    2.65    Диспетчер рабочего стола    Microsoft Corporation 
 explorer.exe    3072        Проводник    Microsoft Corporation 
 explorer.exe    5452    42.35    Проводник    Microsoft Corporation 
 firefox.exe    4196    0.76    Firefox    Mozilla Corporation 
 FNPLicensingService.exe    3768        Activation Licensing Service    Acresso Software Inc. 
 foobar2000.exe    5264    0.76    foobar2000 Application     
 Illustrator.exe    3408    0.38    Adobe Illustrator CS4    Adobe Systems Inc. 
 infium.exe    5500    2.27    QIP Infium    QIP 
 InputPersonalization.exe    4416        Сервер персонализации ввода    Microsoft Corporation 
 Interrupts    n/a        Hardware Interrupts     
 lsass.exe    876        Процесс локального администратора безопасности    Microsoft Corporation 
 lsm.exe    884        Служба диспетчера локальных сеансов    Microsoft Corporation 
 MegaFon Internet.exe    4116    1.13         
 nvvsvc.exe    1132        NVIDIA Driver Helper Service, Version 182.50    NVIDIA Corporation 
 Pen_Tablet.exe    3164        Tablet Service for consumer driver    Wacom Technology, Corp. 
 Pen_Tablet.exe    3600        Tablet Service for consumer driver    Wacom Technology, Corp. 
 Pen_TabletUser.exe    3572        Tablet user module for consumer driver    Wacom Technology, Corp. 
 Photoshop.exe    2300    0.38    Adobe Photoshop CS4    Adobe Systems, Incorporated 
 procexp.exe    4424    22.69    Sysinternals Process Explorer    Sysinternals 
 PsiService_2.exe    2824        PsiService PsiService    Protexis Inc. 
 RtHDVCpl.exe    2368        HD Audio Control Panel    Realtek Semiconductor 
 rundll32.exe    1628        Хост-процесс Windows (Rundll32)    Microsoft Corporation 
 rundll32.exe    2532        Хост-процесс Windows (Rundll32)    Microsoft Corporation 
 SearchFilterHost.exe    2576        Microsoft Windows Search Filter Host    Microsoft Corporation 
 SearchIndexer.exe    3324        Microsoft Windows Search Indexer    Корпорация Майкрософт 
 SearchProtocolHost.exe    5000        Microsoft Windows Search Protocol Host    Microsoft Corporation 
 services.exe    864        Приложение служб и контроллеров    Microsoft Corporation 
 sidebar.exe    2344        Боковая панель Windows    Microsoft Corporation 
 sidebar.exe    6016    0.76    Боковая панель Windows    Microsoft Corporation 
 SLsvc.exe    1488        Служба лицензирования программного обеспечения Майкрософт    Microsoft Corporation 
 smss.exe    652        Windows Session Manager    Microsoft Corporation 
 spoolsv.exe    2240        Диспетчер очереди печати    Microsoft Corporation 
 svchost.exe    1080    3.02    Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1160        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1196        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1292        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1352    6.43    Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1368        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1532        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1780        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    2268        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    2804        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    3052        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    3300        Хост-процесс для служб Windows    Microsoft Corporation 
 System    4    3.02         
 System Idle Process    0    9.45         
 TabTip.exe    1772        Tablet PC Input Panel Accessory    Microsoft Corporation 
 TabTip.exe    776        Tablet PC Input Panel Accessory    Microsoft Corporation 
 taskeng.exe    2284        Обработчик планировщика заданий    Microsoft Corporation 
 taskeng.exe    3152        Обработчик планировщика заданий    Microsoft Corporation 
 TimeZero.exe    4180             
 UnlockerAssistant.exe    2388             
 unsecapp.exe    3140        Sink to receive asynchronous callbacks for WMI client application    Microsoft Corporation 
 wininit.exe    820        Автозагрузка приложений Windows    Microsoft Corporation 
 winlogon.exe    968        Программа входа в систему Windows    Microsoft Corporation 
 wisptis.exe    1764        Microsoft Tablet PC Input Component    Microsoft Corporation 
 wisptis.exe    748        Microsoft Tablet PC Input Component    Microsoft Corporation 
 WmiPrvSE.exe    2524        WMI Provider Host    Microsoft Corporation 
 dllhost.exe    3532    1.89    COM Surrogate    Microsoft Corporation 
  
 Process: explorer.exe Pid: 5452 
  
 Type    Name 
 Desktop    \Default 
 Directory    \KnownDlls 
 Directory    \Sessions\1\BaseNamedObjects 
 Event    \BaseNamedObjects\ShutdownMSIDLLv262144.393299536 
 Event    \BaseNamedObjects\RestartMSIDLLv262144.393299536 
 Event    \Sessions\1\BaseNamedObjects\ShellDesktopSwitchEvent 
 Event    \Sessions\1\BaseNamedObjects\DINPUTWINMM 
 Event    \Sessions\1\BaseNamedObjects\ShellReadyEvent 
 Event    \BaseNamedObjects\TermSrvReadyEvent 
 Event    \Sessions\1\BaseNamedObjects\HPlugEjectEvent 
 File    C:\Windows\System32 
 File    C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3 
 File    \FileSystem\Filters\FltMgrMsg 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\KsecDD 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    D:\ProcessExplorer 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\Burn 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\Burn 
 File    C:\Users\ma elle\Desktop 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\Desktop 
 File    C:\ProgramData\Microsoft\Windows\Start Menu 
 File    C:\ProgramData\Microsoft\Windows\Start Menu 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Start Menu 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Start Menu 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\System32\en-US\imageres.dll.mui 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\Public\Desktop 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\Public\Desktop 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Local\Temp\FXSAPIDebugLogFile.txt 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\GameExplorer 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\GameExplorer 
 File    \Device\KsecDD 
 File    \Device\Nsi 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\System32\ru-RU\FXSRESM.dll.mui 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    D:\ 
 File    C:\Users\ma elle\Links 
 File    C:\Windows\System32\catroot\{F750E6C3-38EE-11D1-85E5-00C04FC295EE}\Package_30_for_KB936330~31bf3856ad364e35~x86~~6.0.1.18000.cat 
 File    D:\ 
 File    C:\Users\ma elle\Links 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 
 File    C:\Windows\System32\ru-RU\wmpshell.dll.mui 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\Null 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Cookies\index.dat 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\WMIDataDevice 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Printer Shortcuts 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Printer Shortcuts 
 File    \Device\KsecDD 
 File    \Device\KsecDD 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Portable Devices 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\SystemCertificates\My 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012009051820090519\index.dat 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\System32\en-US\imageres.dll.mui 
 File    C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_ru-ru_bc080af385e4a760\comctl32.dll.mui 
 File    C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_ru-ru_bc080af385e4a760 
 File    D:\ProcessExplorer 
 File    D:\Учеба 
 File    D:\Учеба 
 File    D:\Учеба\лицо Вики.cdr 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    D:\Учеба\лицо Вики.cdr 
 Key    HKLM 
 Key    HKLM\SYSTEM\ControlSet001\Control\Session Manager 
 Key    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options 
 Key    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions 
 Key    HKCU 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer 
 Key    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer 
 Key    HKCU\Software\Classes 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache 
 Key    HKCU\Software\Microsoft\Windows\Shell 
 Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Locale 
 Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts 
 Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts 
 Key    HKCU\Software\Microsoft\Internet Explorer\TypedURLs 
 Key    HKU 
 Key    HKCU\Software\Policies 
 Key    HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop 
 Key    HKCU\Software\Policies\Microsoft\SystemCertificates 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\91\Shell 
 Key    HKLM\SYSTEM\ControlSet001\Services\crypt32 
 Key    HKCU\Software 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\RunMRU 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKLM\SOFTWARE 
 Key    HKCU\Software\Policies 
 Key    HKLM\SOFTWARE 
 Key    HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch 
 Key    HKCU\Software 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings 
 Key    HKLM\SYSTEM\ControlSet001\Control\NetworkProvider\HwOrder 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\91\Shell\{B3690E58-E961-423B-B687-386EBFD83239} 
 Key    HKCU\Software\Microsoft\SystemCertificates\CA 
 Key    HKLM\SOFTWARE\Policies\Microsoft\SystemCertificates 
 Key    HKCU 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\Disallowed 
 Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Trust 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\trust 
 Key    HKCU 
 Key    HKCU\Software\Microsoft\SystemCertificates\trust 
 Key    HKCU\Software\Microsoft\SystemCertificates\My 
 Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\TrustedPeople 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\TrustedPeople 
 Key    HKCU 
 Key    HKCU\Software\Microsoft\SystemCertificates\TrustedPeople 
 Key    HKCU 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\SmartCardRoot 
 Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Disallowed 
 Key    HKCU\Software\Microsoft\SystemCertificates\Disallowed 
 Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\CA 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\CA 
 Key    HKCU\Software\Microsoft\SystemCertificates\SmartCardRoot 
 Key    HKLM\SOFTWARE\Microsoft\EnterpriseCertificates\Root 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\AuthRoot 
 Key    HKCU\Software\Microsoft\SystemCertificates\Root 
 Key    HKLM\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CertDllCreateCertificateChainEngine\Config 
 Key    HKLM\SOFTWARE\Microsoft\SystemCertificates\ROOT 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\91\Shell\{B3690E58-E961-423B-B687-386EBFD83239} 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\Modules\CommonPlaces 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{B3690E58-E961-423B-B687-386EBFD83239} 
 Key    HKCR 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap 
 Key    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Drivers32 
 Key    HKLM\SOFTWARE 
 Key    HKCU\Software\Policies 
 Key    HKCU\Software 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\91\Shell 
 Key    HKCU\Software\Policies 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKCU\Software 
 Key    HKLM\SOFTWARE 
 Key    HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 
 Key    HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 
 Key    HKLM\SOFTWARE\Microsoft\Fax\Client\ServiceStartup 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKLM\SOFTWARE\Microsoft\Security Center 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones 
 Key    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\Inherit 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\78\Shell 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\78\Shell 
 Key    HKCU\Software\Classes 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\78\Shell\{7D49D726-3C21-4F05-99AA-FDC2C9474656} 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\Bags\14\Shell\{B3690E58-E961-423B-B687-386EBFD83239} 
 Mutant    \Sessions\1\BaseNamedObjects\ZonesCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefaultS-1-5-21-2904571734-1680507556-3174952670-1000 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!local!microsoft!windows!history!history.ie5!mshist012009051820090519! 
 Mutant    \Sessions\1\BaseNamedObjects\_!SHMSFTHISTORY!_ 
 Mutant    \Sessions\1\BaseNamedObjects\ZonesLockedCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ZonesCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\_!MSFTHISTORY!_ 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!local!microsoft!windows!temporary internet files!content.ie5! 
 Mutant    \Sessions\1\BaseNamedObjects\MidiMapper_modLongMessage_RefCnt 
 Mutant    \Sessions\1\BaseNamedObjects\_SHuassist.mtx 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!roaming!microsoft!windows!cookies! 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!local!microsoft!windows!history!history.ie5! 
 Mutant    \Sessions\1\BaseNamedObjects\WininetStartupMutex 
 Mutant    \Sessions\1\BaseNamedObjects\WininetConnectionMutex 
 Mutant    \Sessions\1\BaseNamedObjects\WininetProxyRegistryMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ALTTAB_RUNNING_MUTEX 
 Mutant    \Sessions\1\BaseNamedObjects\ZoneAttributeCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ZoneAttributeCacheCounterMutex 
 Section    \BaseNamedObjects\__ComCatalogCache__ 
 Section    \Sessions\1\BaseNamedObjects\windows_shell_global_counters 
 Section    \BaseNamedObjects\__ComCatalogCache__ 
 Section    \BaseNamedObjects\windows_shell_global_counters 
 Section    \Sessions\1\BaseNamedObjects\windows_shell_global_counters 
 Section    \Sessions\1\BaseNamedObjects\1TIPSharedMemory 
 Section    \Sessions\1\BaseNamedObjects\1TIPSharedMemory 
 Section    \Sessions\1\BaseNamedObjects\1TIPSharedMemory 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Local_Microsoft_Windows_History_History.IE5_MSHist012009051820090519_index.dat_32768 
 Section    \BaseNamedObjects\mmGlobalPnpInfo 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Roaming_Microsoft_Windows_Cookies_index.dat_32768 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Local_Microsoft_Windows_Temporary Internet Files_Content.IE5_index.dat_311296 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Local_Microsoft_Windows_History_History.IE5_index.dat_131072 
 Section    \Sessions\1\BaseNamedObjects\UrlZonesSM_ma elle 
 Thread    explorer.exe(5452): 5952 
 Thread    explorer.exe(5452): 1232 
 Thread    explorer.exe(5452): 2180 
 Thread    explorer.exe(5452): 4664 
 Thread    explorer.exe(5452): 2180 
 Thread    explorer.exe(5452): 3448 
 Thread    explorer.exe(5452): 3580 
 Thread    explorer.exe(5452): 5748 
 Thread    explorer.exe(5452): 5320 
 Thread    explorer.exe(5452): 5232 
 Thread    explorer.exe(5452): 5028 
 Thread    explorer.exe(5452): 4856 
 Thread    explorer.exe(5452): 3516 
 Thread    explorer.exe(5452): 436 
 Thread    explorer.exe(5452): 4856 
 Thread    explorer.exe(5452): 436 
 Thread    explorer.exe(5452): 4856 
 Thread    explorer.exe(5452): 3608 
 Thread    explorer.exe(5452): 6068 
 Thread    explorer.exe(5452): 4752 
 Thread    explorer.exe(5452): 1860 
 Thread    explorer.exe(5452): 4752 
 Thread    explorer.exe(5452): 216 
 Thread    explorer.exe(5452): 6068 
 Thread    explorer.exe(5452): 5736 
 Thread    explorer.exe(5452): 5492 
 Thread    explorer.exe(5452): 5748 
 Thread    explorer.exe(5452): 4128 
 Thread    explorer.exe(5452): 4128 
 Thread    explorer.exe(5452): 1800 
 Thread    explorer.exe(5452): 4952 
 Thread    explorer.exe(5452): 3448 
 Thread    explorer.exe(5452): 5520 
 Thread    explorer.exe(5452): 484 
 Thread    explorer.exe(5452): 5520 
 Thread    explorer.exe(5452): 5520 
 Thread    explorer.exe(5452): 5520 
 Thread    explorer.exe(5452): 5520 
 Thread    explorer.exe(5452): 3608 
 Thread    explorer.exe(5452): 216 
 WindowStation    \Sessions\1\Windows\WindowStations\WinSta0 
 WindowStation    \Sessions\1\Windows\WindowStations\WinSta0 
  
  
 Добавлено: 
 а это после рестарта процесса, (загрузка проца в норме) 
 Process    PID    CPU    Description    Company Name 
 ashDisp.exe    2444        avast! service GUI component    ALWIL Software 
 ashServ.exe    1980        avast! antivirus service    ALWIL Software 
 aswUpdSv.exe    1968        avast! Antivirus updating service    ALWIL Software 
 audiodg.exe    1452        Изоляция графиков аудиоустройств Windows     Microsoft Corporation 
 cfp.exe    2408             
 cmdagent.exe    2728             
 CNAB4RPK.EXE    1692        Canon Advanced Printing Technology RPC Server Process    CANON INC. 
 conime.exe    4628        Console IME    Microsoft Corporation 
 csrss.exe    768        Процесс исполнения клиент-сервер    Microsoft Corporation 
 csrss.exe    832    0.61    Процесс исполнения клиент-сервер    Microsoft Corporation 
 DPCs    n/a        Deferred Procedure Calls     
 dwm.exe    1380    1.21    Диспетчер рабочего стола    Microsoft Corporation 
 explorer.exe    5352    1.21    Проводник    Microsoft Corporation 
 firefox.exe    4196    7.88    Firefox    Mozilla Corporation 
 FNPLicensingService.exe    3768        Activation Licensing Service    Acresso Software Inc. 
 foobar2000.exe    5264        foobar2000 Application     
 Illustrator.exe    3408        Adobe Illustrator CS4    Adobe Systems Inc. 
 infium.exe    5500        QIP Infium    QIP 
 InputPersonalization.exe    4416        Сервер персонализации ввода    Microsoft Corporation 
 Interrupts    n/a        Hardware Interrupts     
 lsass.exe    876        Процесс локального администратора безопасности    Microsoft Corporation 
 lsm.exe    884        Служба диспетчера локальных сеансов    Microsoft Corporation 
 MegaFon Internet.exe    4116    1.82         
 notepad.exe    6028        Блокнот    Microsoft Corporation 
 nvvsvc.exe    1132        NVIDIA Driver Helper Service, Version 182.50    NVIDIA Corporation 
 Pen_Tablet.exe    3164        Tablet Service for consumer driver    Wacom Technology, Corp. 
 Pen_Tablet.exe    3600    0.61    Tablet Service for consumer driver    Wacom Technology, Corp. 
 Pen_TabletUser.exe    3572        Tablet user module for consumer driver    Wacom Technology, Corp. 
 Photoshop.exe    2300        Adobe Photoshop CS4    Adobe Systems, Incorporated 
 procexp.exe    4424    15.15    Sysinternals Process Explorer    Sysinternals 
 PsiService_2.exe    2824        PsiService PsiService    Protexis Inc. 
 RtHDVCpl.exe    2368        HD Audio Control Panel    Realtek Semiconductor 
 rundll32.exe    1628        Хост-процесс Windows (Rundll32)    Microsoft Corporation 
 rundll32.exe    2532        Хост-процесс Windows (Rundll32)    Microsoft Corporation 
 SearchFilterHost.exe    5036        Microsoft Windows Search Filter Host    Microsoft Corporation 
 SearchIndexer.exe    3324        Microsoft Windows Search Indexer    Корпорация Майкрософт 
 SearchProtocolHost.exe    2112        Microsoft Windows Search Protocol Host    Microsoft Corporation 
 services.exe    864        Приложение служб и контроллеров    Microsoft Corporation 
 sidebar.exe    2344        Боковая панель Windows    Microsoft Corporation 
 sidebar.exe    6016    0.61    Боковая панель Windows    Microsoft Corporation 
 SLsvc.exe    1488        Служба лицензирования программного обеспечения Майкрософт    Microsoft Corporation 
 smss.exe    652        Windows Session Manager    Microsoft Corporation 
 spoolsv.exe    2240        Диспетчер очереди печати    Microsoft Corporation 
 svchost.exe    1080    5.45    Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1160        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1196        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1292        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1352    0.61    Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1368        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1532        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    1780        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    2268        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    2804        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    3052        Хост-процесс для служб Windows    Microsoft Corporation 
 svchost.exe    3300        Хост-процесс для служб Windows    Microsoft Corporation 
 System    4             
 System Idle Process    0    65.46         
 TabTip.exe    1772        Tablet PC Input Panel Accessory    Microsoft Corporation 
 TabTip.exe    776        Tablet PC Input Panel Accessory    Microsoft Corporation 
 taskeng.exe    2284        Обработчик планировщика заданий    Microsoft Corporation 
 taskeng.exe    3152        Обработчик планировщика заданий    Microsoft Corporation 
 taskeng.exe    3612        Обработчик планировщика заданий    Microsoft Corporation 
 TimeZero.exe    4180             
 UnlockerAssistant.exe    2388             
 unsecapp.exe    3140        Sink to receive asynchronous callbacks for WMI client application    Microsoft Corporation 
 wininit.exe    820        Автозагрузка приложений Windows    Microsoft Corporation 
 winlogon.exe    968        Программа входа в систему Windows    Microsoft Corporation 
 wisptis.exe    1764        Microsoft Tablet PC Input Component    Microsoft Corporation 
 wisptis.exe    748        Microsoft Tablet PC Input Component    Microsoft Corporation 
 WmiPrvSE.exe    2524        WMI Provider Host    Microsoft Corporation 
  
 Process: explorer.exe Pid: 5352 
  
 Type    Name 
 Desktop    \Default 
 Directory    \KnownDlls 
 Directory    \Sessions\1\BaseNamedObjects 
 Event    \BaseNamedObjects\ShutdownMSIDLLv262144.393299536 
 Event    \Sessions\1\BaseNamedObjects\ShellDesktopSwitchEvent 
 Event    \Sessions\1\BaseNamedObjects\ShellReadyEvent 
 Event    \Sessions\1\BaseNamedObjects\HPlugEjectEvent 
 Event    \BaseNamedObjects\TermSrvReadyEvent 
 Event    \BaseNamedObjects\RestartMSIDLLv262144.393299536 
 File    C:\Windows\System32 
 File    C:\Windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.0.6001.18000_none_9e752e5ac9c619f3 
 File    \FileSystem\Filters\FltMgrMsg 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\KsecDD 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\NamedPipe\lsass 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\Burn 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\Burn 
 File    \Device\NamedPipe\lsass 
 File    C:\Users\ma elle\Links 
 File    C:\Users\ma elle\Links 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\Desktop 
 File    C:\Users\ma elle\Desktop 
 File    C:\ProgramData\Microsoft\Windows\Start Menu 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Network Shortcuts 
 File    C:\ProgramData\Microsoft\Windows\Start Menu 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Start Menu 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Start Menu 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\GameExplorer 
 File    C:\Users\Public\Desktop 
 File    C:\Users\Public\Desktop 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\GameExplorer 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_ru-ru_bc080af385e4a760 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\NamedPipe\wkssvc 
 File    \Device\NamedPipe\srvsvc 
 File    D:\ 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.c..-controls.resources_6595b64144ccf1df_6.0.6001.18000_ru-ru_bc080af385e4a760\comctl32.dll.mui 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Portable Devices 
 File    \Device\Nsi 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    \Device\KsecDD 
 File    \Device\KsecDD 
 File    \Device\KsecDD 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Printer Shortcuts 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Network Shortcuts 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Printer Shortcuts 
 File    \Device\WMIDataDevice 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    D:\ 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat 
 File    C:\Users\ma elle\AppData\Roaming\Microsoft\Windows\Cookies\index.dat 
 File    C:\Users\ma elle\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat 
 File    C:\Windows\System32\en-US\imageres.dll.mui 
 File    C:\Users\ma elle\AppData\Local\Temp\FXSAPIDebugLogFile.txt 
 File    C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc 
 File    C:\Windows\System32\ru-RU\FXSRESM.dll.mui 
 Key    HKLM 
 Key    HKLM\SYSTEM\ControlSet001\Control\Session Manager 
 Key    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options 
 Key    HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\DllNXOptions 
 Key    HKCU\Software\Classes 
 Key    HKCU 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer 
 Key    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\explorer 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer 
 Key    HKCU\Software\Classes 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell\MuiCache 
 Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Locale 
 Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alternate Sorts 
 Key    HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts 
 Key    HKU 
 Key    HKCU\Software\Policies 
 Key    HKCU\Software\Classes\Local Settings\Software\Microsoft\Windows\Shell 
 Key    HKLM\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\Zones 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones 
 Key    HKLM\SOFTWARE\Microsoft\Security Center 
 Key    HKCU\Software 
 Key    HKCU\Software\Microsoft\Windows\Shell 
 Key    HKLM\SYSTEM\ControlSet001\Services\SharedAccess\Epoch 
 Key    HKCU\Software\Policies 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\NameSpace_Catalog5 
 Key    HKCU\Software 
 Key    HKLM\SOFTWARE 
 Key    HKLM\SYSTEM\ControlSet001\Services\WinSock2\Parameters\Protocol_Catalog9 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{75048700-EF1F-11D0-9888-006097DEACF9}\Count 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{5E6AB780-7743-11CF-A12B-00AA004AE837}\Count 
 Key    HKCU\Software\Microsoft\Windows\Shell\Bags\1\Desktop 
 Key    HKLM\SOFTWARE 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings 
 Key    HKCU\Software\Policies 
 Key    HKLM\SOFTWARE\Policies 
 Key    HKCU\Software 
 Key    HKLM\SOFTWARE 
 Key    HKLM\SOFTWARE\Microsoft\Fax\Client\ServiceStartup 
 Mutant    \Sessions\1\BaseNamedObjects\MSCTF.Asm.MutexDefaultS-1-5-21-2904571734-1680507556-3174952670-1000 
 Mutant    \Sessions\1\BaseNamedObjects\ZoneAttributeCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ZoneAttributeCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ALTTAB_RUNNING_MUTEX 
 Mutant    \Sessions\1\BaseNamedObjects\WininetConnectionMutex 
 Mutant    \Sessions\1\BaseNamedObjects\WininetStartupMutex 
 Mutant    \Sessions\1\BaseNamedObjects\WininetProxyRegistryMutex 
 Mutant    \Sessions\1\BaseNamedObjects\_SHuassist.mtx 
 Mutant    \Sessions\1\BaseNamedObjects\ZonesCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ZonesLockedCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\ZonesCacheCounterMutex 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!local!microsoft!windows!temporary internet files!content.ie5! 
 Mutant    \Sessions\1\BaseNamedObjects\_!MSFTHISTORY!_ 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!roaming!microsoft!windows!cookies! 
 Mutant    \Sessions\1\BaseNamedObjects\c:!users!ma elle!appdata!local!microsoft!windows!history!history.ie5! 
 Section    \BaseNamedObjects\__ComCatalogCache__ 
 Section    \Sessions\1\BaseNamedObjects\windows_shell_global_counters 
 Section    \BaseNamedObjects\__ComCatalogCache__ 
 Section    \BaseNamedObjects\windows_shell_global_counters 
 Section    \Sessions\1\BaseNamedObjects\UrlZonesSM_ma elle 
 Section    \Sessions\1\BaseNamedObjects\1TIPSharedMemory 
 Section    \Sessions\1\BaseNamedObjects\1TIPSharedMemory 
 Section    \Sessions\1\BaseNamedObjects\windows_shell_global_counters 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Local_Microsoft_Windows_Temporary Internet Files_Content.IE5_index.dat_311296 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Roaming_Microsoft_Windows_Cookies_index.dat_32768 
 Section    \Sessions\1\BaseNamedObjects\C:_Users_ma elle_AppData_Local_Microsoft_Windows_History_History.IE5_index.dat_131072 
 Thread    explorer.exe(5352): 5064 
 Thread    explorer.exe(5352): 5472 
 Thread    explorer.exe(5352): 4672 
 Thread    explorer.exe(5352): 3344 
 Thread    explorer.exe(5352): 1184 
 Thread    explorer.exe(5352): 5540 
 Thread    explorer.exe(5352): 4804 
 Thread    explorer.exe(5352): 4804 
 Thread    explorer.exe(5352): 4804 
 Thread    explorer.exe(5352): 4804 
 Thread    explorer.exe(5352): 5784 
 Thread    explorer.exe(5352): 3892 
 Thread    explorer.exe(5352): 4312 
 Thread    explorer.exe(5352): 5672 
 Thread    explorer.exe(5352): 4804 
 Thread    explorer.exe(5352): 4060 
 Thread    explorer.exe(5352): 2316 
 Thread    explorer.exe(5352): 4312 
 Thread    explorer.exe(5352): 5724 
 Thread    explorer.exe(5352): 5328 
 Thread    explorer.exe(5352): 3228 
 Thread    explorer.exe(5352): 3228 
 Thread    explorer.exe(5352): 5004 
 Thread    explorer.exe(5352): 5544 
 Thread    explorer.exe(5352): 4832 
 Thread    explorer.exe(5352): 5800 
 Thread    explorer.exe(5352): 5004 
 Thread    explorer.exe(5352): 3892 
 Thread    explorer.exe(5352): 5488 
 Thread    explorer.exe(5352): 3892 
 Thread    explorer.exe(5352): 5488 
 Thread    explorer.exe(5352): 5204 
 Thread    explorer.exe(5352): 5944 
 Thread    explorer.exe(5352): 5204 
 WindowStation    \Sessions\1\Windows\WindowStations\WinSta0 
 WindowStation    \Sessions\1\Windows\WindowStations\WinSta0 
 [/more]