SampleTime	SessionID	ProcessID	Handle	ParentProcessID	Name	ExecutablePath	CommandLine	CreationDate	Priority	HandleCount	ThreadCount	KernelModeTime	UserModeTime	ReadOperationCount	ReadTransferCount	WriteOperationCount	WriteTransferCount	OtherOperationCount	OtherTransferCount	PageFaults	PageFileUsage	PeakPageFileUsage	WorkingSetSize	MaximumWorkingSetSize	MinimumWorkingSetSize	PeakWorkingSetSize	PrivatePageCount	QuotaNonPagedPoolUsage	QuotaPeakNonPagedPoolUsage	QuotaPagedPoolUsage	QuotaPeakPagedPoolUsage	VirtualSize	PeakVirtualSize
2009-12-16 13:04:09.154	0	0	0	0	System Idle Process				0	0	2	1339011718750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:04:09.154	0	4	4	0	System				8	870	71	5445937500	0	253	5980710	17627	97198208	37455	1808886	6358	44	44	258048	1380	0	4736	94208	1	1	6358	0	2490368	6025216
2009-12-16 13:04:09.154	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:04:09.154	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	697	15	10750625000	34843750	122522	8637481	0	0	87871	1285574	8876	1896	1940	3284992	1380	200	4416	1941504	13	13	8876	197	55595008	76775424
2009-12-16 13:04:09.154	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	692	19	20000000	11406250	488	130346	454	51657	7489	287420	9567	11072	11808	6733824	1380	200	16264	11337728	193	199	9567	176	84738048	107282432
2009-12-16 13:04:09.154	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	373	17	4239218750	1085468750	15407	2423058	20063	7835203	381017	3134418	5304	6552	10364	5357568	1380	200	8948	6709248	17	26	5304	87	318889984	361951232
2009-12-16 13:04:09.154	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	743	33	246406250	75468750	128005	10110316	120198	10002909	234376	3642747	7249	12144	12144	8269824	1380	200	13936	12435456	38	39	7249	115	76271616	76795904
2009-12-16 13:04:09.154	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	4843750	1562500	7354	397186	7354	59132	340	11417	1522	1552	1652	1667072	1380	200	4028	1589248	6	8	1522	54	30121984	31051776
2009-12-16 13:04:09.154	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	268	10	26250000	16093750	7353	323560	7353	58972	572	17432	2253	2176	2284	2330624	1380	200	5240	2228224	34	35	2253	67	33902592	35119104
2009-12-16 13:04:09.154	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	155	9	12500000	4218750	14705	677026	14703	117620	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:04:09.154	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	192	16	222968750	19687500	14810	713644	14810	119516	9130	164108	2869	2364	2440	1908736	1380	200	5732	2420736	10	13	2869	62	40763392	41287680
2009-12-16 13:04:09.154	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1335	60	527187500	613437500	184903	138993164	167438	11254523	49596	1094311	402522	27316	86868	24170496	1380	200	98276	27971584	97	138	402522	354	537006080	849031168
2009-12-16 13:04:09.154	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	126	13	16875000	5000000	7359	353504	7359	59668	392	4052	2551	5056	5300	1871872	1380	200	7424	5177344	10	12	2551	102	59080704	61669376
2009-12-16 13:04:09.154	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274218750	31250000	44797	1793470	44761	1412748	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:04:09.154	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7387	551340	7386	134608	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:04:09.154	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7354	426402	7353	58848	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:04:09.154	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218593750	11718750	37393	1868342	37392	1500832	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:04:09.154	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7355	353008	7354	59008	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:04:09.154	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7355	323696	7380	219872	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:04:09.154	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7353	323560	7353	58972	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:04:09.154	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7404	592067	7356	59408	398	5152	5613	49040	57320	3362816	1380	200	21560	50216960	10	12	5613	185	2822803456	2839580672
2009-12-16 13:04:09.154	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7352	455762	7352	58812	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:04:09.154	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7376	384964	7376	62392	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:04:09.154	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	152	16	6250000	1562500	7410	425932	7395	65205	856	69528	2064	2656	22592	2633728	1380	200	5692	2719744	10	12	2064	97	73478144	74534912
2009-12-16 13:04:09.154	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7357	471268	7363	59902	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:04:09.154	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7354	294272	7354	59132	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:04:09.154	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1403	18	1998281250	1726562500	74345	16447700	73712	6904949	159954	1829263	1291560	20988	28756	44965888	1380	200	52768	21491712	30	37	1291560	335	154775552	220725248
2009-12-16 13:04:09.154	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	426	10	124218750	38906250	1573	1958383	91	29019	46107	829374	32362	10812	11220	11710464	1380	200	18760	11071488	25	28	32362	252	123854848	141737984
2009-12-16 13:04:09.154	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	7968750	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:04:09.154	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	523	7	22031250	72187500	669	2767660	141	889167	9285	43076	34255	37080	47908	29126656	1380	200	39212	37969920	18	21	34255	364	605962240	626016256
2009-12-16 13:04:09.154	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:04:09.154	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	815	20	965468750	3462500000	10032	9401086	4616	3696858	31911	2649578	240578	191764	236504	136134656	1380	200	154524	196366336	52	59	240578	653	558247936	589316096
2009-12-16 13:04:09.154	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	766	71	1155937500	36638593750	74779	13264356275	47824	1320762284	44244	11625827	696736	1501916	1538612	1389572096	1380	200	1475220	1537961984	150	228	696736	389	5796806656	5816467456
2009-12-16 13:04:09.154	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5201	5024	5072	1089536	1380	200	5788	5144576	7	8	5201	65	40542208	41066496
2009-12-16 13:04:09.154	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73593750	32968750	7241	636864	7118	204799	14471	222750	12938	24220	24380	8142848	1380	200	22748	24801280	34	38	12938	179	531070976	533159936
2009-12-16 13:04:09.154	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4929	236748	4929	39884	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:04:09.154	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	273	6	68437500	27343750	1013	52673	9	1132	44204	930034	30551	7856	8320	17567744	1380	200	17416	8044544	13	17	30551	249	110153728	128147456
2009-12-16 13:04:09.154	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:04:09.154	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:04:09.154	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	269	4	16093750	4843750	66	2969722	763	444881	879	207872	192898	15820	15820	21327872	1380	200	20828	16199680	14	14	192898	123	93020160	93024256
2009-12-16 13:04:09.154	0	3952	3952	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /Cstart /B /WAIT MSInfo32.exe /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.217	8	109	2	937500	156250	1	92	1	116	511	9034	1607	3740	5036	5931008	1380	200	6200	3829760	5	6	1607	118	44957696	58687488
2009-12-16 13:04:09.154	0	4000	4000	3952	msinfo32.exe	C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe	"C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe"  /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.311	8	98	6	1093750	937500	2	232	2	320	183	2932	2107	4132	5364	8048640	1380	200	7860	4231168	8	8	2107	101	59789312	59789312
2009-12-16 13:04:09.154	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	137	5	1250000	1093750	69	208263	976	282058	371	3646	2932	4820	4828	10199040	1380	200	9960	4935680	11	14	2932	116	69165056	69165056
2009-12-16 13:04:09.154	0	3028	3028	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.576	8	136	5	781250	468750	83	255439	710	352843	371	3622	2711	4264	6320	9609216	1380	200	9388	4366336	11	13	2711	116	67067904	69173248
2009-12-16 13:04:09.154	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:04:09.154	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	211	8	1875000	7031250	144	650211	4	972	666	4872	11454	49212	50000	45424640	1380	200	44476	50393088	14	16	11454	245	555057152	556204032
2009-12-16 13:04:09.154	0	2032	2032	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-LogicalDiskProperties.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\'	2009-12-16 13:04:06.748	8	35	1	156250	0	0	0	0	0	70	616	554	1932	1932	2273280	1380	200	2220	1978368	3	3	554	42	17014784	17014784
2009-12-16 13:04:09.154	0	2248	2248	2032	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-LogicalDiskProperties.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\'	2009-12-16 13:04:06.764	8	210	8	1562500	7812500	143	647898	4	593	649	4872	11448	49216	50004	45424640	1380	200	44360	50397184	14	15	11448	245	555057152	555679744
2009-12-16 13:04:09.154	0	2552	2552	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-VolumeProperties.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' -IncludeFragmentationAnalysis	2009-12-16 13:04:06.889	8	35	1	156250	0	0	0	0	0	70	616	555	1932	1932	2277376	1380	200	2224	1978368	3	3	555	42	17014784	17014784
2009-12-16 13:04:09.154	0	2164	2164	2552	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-VolumeProperties.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' -IncludeFragmentationAnalysis	2009-12-16 13:04:06.920	8	243	8	2656250	6875000	144	651995	3	436	629	4872	11656	51284	52000	47063040	1380	200	45960	52514816	14	15	11656	245	555057152	555679744
2009-12-16 13:04:24.904	0	0	0	0	System Idle Process				0	0	2	1339150625000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:04:24.904	0	4	4	0	System				8	874	72	5450000000	0	254	6046246	17643	97634432	37479	1809124	6370	44	44	258048	1380	0	4736	94208	1	1	6370	0	2490368	6025216
2009-12-16 13:04:24.904	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:04:24.904	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	650	15	10750781250	35000000	122647	8660169	0	0	88231	1289670	8911	1896	1940	3223552	1380	200	4416	1941504	12	13	8911	197	55267328	76775424
2009-12-16 13:04:24.904	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	692	19	20000000	11406250	488	130346	454	51657	7495	287588	9567	11072	11808	6733824	1380	200	16264	11337728	193	199	9567	176	84738048	107282432
2009-12-16 13:04:24.904	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	373	18	4241250000	1086875000	15427	2436950	20165	7857727	381108	3134862	5309	6600	10364	5378048	1380	200	8948	6758400	17	26	5309	87	319414272	361951232
2009-12-16 13:04:24.904	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	733	33	255781250	77812500	135730	10786240	127428	10767340	251610	3783155	7254	12164	12164	8290304	1380	200	13936	12455936	38	39	7254	115	76271616	76795904
2009-12-16 13:04:24.904	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7355	397240	7355	59140	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:04:24.904	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	270	11	27187500	16406250	7354	323604	7354	58980	624	17432	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:04:24.904	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	153	9	12500000	4218750	14707	677118	14705	117636	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:04:24.904	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	192	16	223125000	19687500	14812	713740	14812	119532	9131	164136	2869	2364	2440	1908736	1380	200	5732	2420736	10	13	2869	62	40763392	41287680
2009-12-16 13:04:24.904	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1344	66	533593750	623593750	185475	141598730	167526	11620163	51538	1112227	416836	29704	86868	25989120	1380	200	98276	30416896	102	138	416836	354	580382720	849555456
2009-12-16 13:04:24.904	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5000000	7360	353552	7360	59676	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:04:24.904	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274375000	31250000	44806	1793818	44770	1413044	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:04:24.904	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7388	551404	7387	134616	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:04:24.904	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7355	426460	7354	58856	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:04:24.904	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218593750	11718750	37402	1868784	37401	1501224	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:04:24.904	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7356	353056	7355	59016	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:04:24.904	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7356	323740	7381	219880	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:04:24.904	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7354	323604	7354	58980	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:04:24.904	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7405	592129	7357	59416	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:04:24.904	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7353	455824	7353	58820	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:04:24.904	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7377	385016	7377	62400	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:04:24.904	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	152	16	6250000	1562500	7411	425988	7396	65213	856	69528	2064	2656	22592	2633728	1380	200	5692	2719744	10	12	2064	97	73478144	74534912
2009-12-16 13:04:24.904	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7358	471332	7364	59910	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:04:24.904	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7355	294312	7355	59140	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:04:24.904	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1692	19	2033125000	1776718750	81486	18609552	80775	7570875	172864	1958671	1388070	25468	30548	56573952	1380	200	59964	26079232	33	37	1388070	349	168407040	226025472
2009-12-16 13:04:24.904	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	426	10	124218750	38906250	1573	1958383	91	29019	46112	829476	32374	10812	11220	11710464	1380	200	18760	11071488	25	28	32374	252	123854848	141737984
2009-12-16 13:04:24.904	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	7968750	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:04:24.904	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:04:24.904	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:04:24.904	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	803	19	965468750	3463281250	10039	9402022	4623	3709684	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:04:24.904	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	646	48	1157187500	36655937500	74925	13268514363	47891	1322750466	44428	11642138	697298	1442884	1538612	1374720000	1380	200	1475220	1477513216	145	228	697298	389	5746880512	5816467456
2009-12-16 13:04:24.904	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5201	5024	5072	1089536	1380	200	5788	5144576	7	8	5201	65	40542208	41066496
2009-12-16 13:04:24.904	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73593750	32968750	7247	637223	7119	204807	14645	225482	12978	24100	24380	8118272	1380	200	22748	24678400	34	38	12978	179	531070976	533159936
2009-12-16 13:04:24.904	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4930	236796	4930	39892	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:04:24.904	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	273	6	68437500	27500000	1013	52673	9	1132	44305	939884	30554	7856	8320	17567744	1380	200	17416	8044544	13	17	30554	249	110153728	128147456
2009-12-16 13:04:24.904	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:04:24.904	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:04:24.904	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	16562500	5000000	71	2971002	856	546973	1134	267174	193925	16456	16628	22224896	1380	200	21876	16850944	14	17	193925	123	94060544	94130176
2009-12-16 13:04:24.904	0	3952	3952	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /Cstart /B /WAIT MSInfo32.exe /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.217	8	109	2	937500	156250	1	92	1	116	511	9034	1607	3740	5036	5931008	1380	200	6200	3829760	5	6	1607	118	44957696	58687488
2009-12-16 13:04:24.904	0	4000	4000	3952	msinfo32.exe	C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe	"C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe"  /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.311	8	100	6	3906250	2656250	2	232	2	320	183	2932	3244	6720	6720	10743808	1380	200	10492	6881280	8	8	3244	101	65032192	65032192
2009-12-16 13:04:24.904	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	137	5	1406250	1093750	71	209856	987	284501	371	3646	2935	4820	4828	10211328	1380	200	9972	4935680	11	14	2935	116	69165056	69165056
2009-12-16 13:04:24.904	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:04:24.904	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	222	8	2187500	10625000	144	650211	9	17531	691	4880	12052	50512	50580	47173632	1380	200	46176	51724288	14	16	12052	246	556105728	557252608
2009-12-16 13:04:41.092	0	0	0	0	System Idle Process				0	0	2	1339238593750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:04:41.092	0	4	4	0	System				8	874	72	5453125000	0	254	6046246	17653	97983616	37519	1809362	6370	44	44	258048	1380	0	4736	94208	1	1	6370	0	2490368	6025216
2009-12-16 13:04:41.092	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:04:41.092	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	651	15	10751406250	35156250	122730	8662713	0	0	88231	1289670	8911	1896	1940	3223552	1380	200	4416	1941504	12	13	8911	197	55267328	76775424
2009-12-16 13:04:41.092	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	692	19	20000000	11406250	488	130346	454	51657	7495	287588	9567	11072	11808	6733824	1380	200	16264	11337728	193	199	9567	176	84738048	107282432
2009-12-16 13:04:41.092	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	373	18	4243906250	1089218750	15431	2437150	20343	7893379	381215	3135706	5534	6604	10364	5447680	1380	200	8948	6762496	17	26	5534	87	319479808	361951232
2009-12-16 13:04:41.092	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	734	33	266250000	81093750	144749	11585564	135823	11660964	271703	3965455	7276	12184	12208	8310784	1380	200	13936	12476416	38	41	7276	115	76271616	76795904
2009-12-16 13:04:41.092	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7357	397348	7357	59156	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:04:41.092	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	270	11	27500000	16406250	7356	323692	7356	58996	631	18712	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:04:41.092	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14711	677302	14709	117668	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:04:41.092	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	16	223125000	19687500	14816	713932	14816	119564	9134	164164	2869	2364	2440	1908736	1380	200	5732	2420736	10	13	2869	62	40763392	41287680
2009-12-16 13:04:41.092	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1353	66	539687500	634375000	185558	141765710	167595	11670687	51552	1112501	432762	29024	86868	25321472	1380	200	98276	29720576	102	138	432762	354	580382720	849555456
2009-12-16 13:04:41.092	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5000000	7362	353648	7362	59692	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:04:41.092	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274531250	31250000	44816	1794226	44780	1413348	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:04:41.092	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7390	551532	7389	134632	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:04:41.092	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7357	426576	7356	58872	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:04:41.092	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218593750	11718750	37410	1869188	37409	1501528	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:04:41.092	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7358	353152	7357	59032	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:04:41.092	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7358	323828	7383	219896	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:04:41.092	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7356	323692	7356	58996	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:04:41.092	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7407	592253	7359	59432	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:04:41.092	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7355	455948	7355	58836	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:04:41.092	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7379	385120	7379	62416	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:04:41.092	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	154	17	6406250	1562500	7420	428151	7403	65958	860	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:04:41.092	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7360	471460	7366	59926	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:04:41.092	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7357	294392	7357	59156	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:04:41.092	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1693	19	2088906250	1795937500	89632	19604062	88920	8338547	183977	2098674	1399544	25576	30548	57860096	1380	200	59964	26189824	34	37	1399544	349	190033920	226025472
2009-12-16 13:04:41.092	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46116	829476	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:04:41.092	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	7968750	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:04:41.092	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:04:41.092	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:04:41.092	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	805	19	965625000	3464687500	10047	9402958	4631	3722604	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:04:41.092	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	646	48	1162187500	36733593750	75015	13268895244	49680	1350677040	45276	11719300	697387	1407500	1538612	1338540032	1380	200	1475220	1441280000	145	270	697387	389	5746880512	5816467456
2009-12-16 13:04:41.092	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5201	5024	5072	1089536	1380	200	5788	5144576	7	8	5201	65	40542208	41066496
2009-12-16 13:04:41.092	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73593750	32968750	7253	637855	7125	205728	14776	227578	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:04:41.092	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4932	236892	4932	39908	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:04:41.092	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	273	6	68593750	27500000	1013	52673	9	1132	44322	942798	30584	7856	8320	17580032	1380	200	17416	8044544	13	17	30584	249	110153728	128147456
2009-12-16 13:04:41.092	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:04:41.092	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:04:41.092	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	16562500	5156250	78	2972794	863	576877	1414	343110	194933	16456	16628	22228992	1380	200	21880	16850944	14	17	194933	123	94060544	94130176
2009-12-16 13:04:41.092	0	3952	3952	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /Cstart /B /WAIT MSInfo32.exe /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.217	8	109	2	937500	156250	1	92	1	116	511	9034	1607	3740	5036	5931008	1380	200	6200	3829760	5	6	1607	118	44957696	58687488
2009-12-16 13:04:41.092	0	4000	4000	3952	msinfo32.exe	C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe	"C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe"  /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.311	8	99	6	5000000	6875000	2	232	2	320	183	2932	4015	8416	8516	12500992	1380	200	12264	8617984	8	8	4015	101	66080768	66080768
2009-12-16 13:04:41.092	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	137	5	1406250	1093750	75	210746	995	284625	371	3646	2935	4820	4828	10211328	1380	200	9972	4935680	11	14	2935	116	69165056	69165056
2009-12-16 13:04:41.092	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:04:41.092	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	222	8	2656250	16718750	144	650211	13	32047	716	4888	12162	50656	50724	47460352	1380	200	46464	51871744	14	16	12162	246	556105728	557252608
2009-12-16 13:04:56.483	0	0	0	0	System Idle Process				0	0	2	1339319843750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:04:56.483	0	4	4	0	System				8	874	72	5453750000	0	254	6046246	17665	98279552	37551	1809600	6370	44	44	258048	1380	0	4736	94208	1	1	6370	0	2490368	6025216
2009-12-16 13:04:56.483	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:04:56.483	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	651	15	10751562500	35156250	122730	8662713	0	0	88231	1289670	8911	1896	1940	3223552	1380	200	4416	1941504	12	13	8911	197	55267328	76775424
2009-12-16 13:04:56.483	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	688	20	20000000	11406250	488	130346	454	51657	7497	287588	9571	11120	11808	6750208	1380	200	16264	11386880	193	199	9571	176	85262336	107282432
2009-12-16 13:04:56.483	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	372	18	4251093750	1092187500	15433	2437250	20489	7922735	381267	3136142	5634	6604	10364	5857280	1380	200	8948	6762496	17	26	5634	87	319479808	361951232
2009-12-16 13:04:56.483	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	731	33	267031250	82031250	145377	11654536	136375	11728723	273048	3991471	7292	12244	12244	8376320	1380	200	13936	12537856	38	41	7292	115	76271616	76795904
2009-12-16 13:04:56.483	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7358	397402	7358	59164	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:04:56.483	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	270	11	27500000	16406250	7357	323736	7357	59004	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:04:56.483	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14713	677394	14711	117684	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:04:56.483	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14818	714028	14818	119580	9135	164192	2869	2316	2440	1892352	1380	200	5732	2371584	10	13	2869	62	40239104	41287680
2009-12-16 13:04:56.483	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1368	66	540781250	637343750	185644	142187494	167640	11731159	51710	1117953	435770	29004	86868	25317376	1380	200	98276	29700096	102	138	435770	354	580382720	849555456
2009-12-16 13:04:56.483	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5000000	7363	353696	7363	59700	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:04:56.483	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274687500	31250000	44825	1794574	44789	1413644	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:04:56.483	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7391	551596	7390	134640	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:04:56.483	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7358	426634	7357	58880	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:04:56.483	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218593750	11718750	37417	1869534	37416	1501824	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:04:56.483	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7359	353200	7358	59040	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:04:56.483	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7359	323872	7384	219904	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:04:56.483	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7357	323736	7357	59004	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:04:56.483	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7408	592315	7360	59440	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:04:56.483	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7356	456010	7356	58844	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:04:56.483	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7380	385172	7380	62424	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:04:56.483	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	154	17	6406250	1562500	7421	428207	7404	65966	860	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:04:56.483	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7361	471524	7367	59934	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:04:56.483	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7358	294432	7358	59164	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:04:56.483	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1690	18	2183437500	1820937500	89960	19637030	89248	8369031	185281	2117710	1405406	25408	30548	58449920	1380	200	59964	26017792	36	38	1405406	349	195338240	226025472
2009-12-16 13:04:56.483	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46128	829604	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:04:56.483	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	7968750	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:04:56.483	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:04:56.483	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:04:56.483	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	802	19	965781250	3465156250	10051	9403439	4635	3729064	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:04:56.483	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	648	50	1163906250	36799062500	75072	13268981961	49785	1354160082	46043	11919521	697492	1408612	1538612	1335619584	1380	200	1475220	1442418688	145	270	697492	389	5751074816	5816467456
2009-12-16 13:04:56.483	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5201	5024	5072	1089536	1380	200	5788	5144576	7	8	5201	65	40542208	41066496
2009-12-16 13:04:56.483	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73593750	32968750	7258	638425	7130	206641	14891	229418	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:04:56.483	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4933	236940	4933	39916	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:04:56.483	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	273	6	68593750	27500000	1013	52673	9	1132	44322	942798	30584	7856	8320	17580032	1380	200	17416	8044544	13	17	30584	249	110153728	128147456
2009-12-16 13:04:56.483	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:04:56.483	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	242	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:04:56.483	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	16875000	5625000	83	2974074	868	598237	1615	397350	195679	16456	16628	22228992	1380	200	21880	16850944	14	17	195679	123	94060544	94130176
2009-12-16 13:04:56.483	0	3952	3952	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /Cstart /B /WAIT MSInfo32.exe /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.217	8	109	2	937500	156250	1	92	1	116	511	9034	1607	3740	5036	5931008	1380	200	6200	3829760	5	6	1607	118	44957696	58687488
2009-12-16 13:04:56.483	0	4000	4000	3952	msinfo32.exe	C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe	"C:\Program Files\Common Files\Microsoft Shared\MSInfo\MSInfo32.exe"  /computer DB04 /report "C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\DB04_MSINFO32.TXT" /categories +SystemSummary	2009-12-16 13:04:02.311	8	100	6	5000000	7031250	2	232	2	320	183	2932	4093	8640	8640	12746752	1380	200	12448	8847360	8	8	4093	101	66080768	66080768
2009-12-16 13:04:56.483	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1093750	77	211191	999	284687	371	3646	2937	4764	4828	10170368	1380	200	9980	4878336	10	14	2937	116	68116480	69165056
2009-12-16 13:04:56.483	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:04:56.483	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	222	8	2812500	20312500	144	650211	17	46563	741	4896	12252	50736	50800	47661056	1380	200	46656	51953664	14	16	12252	246	556105728	557252608
2009-12-16 13:05:12.936	0	0	0	0	System Idle Process				0	0	2	1339574375000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:05:12.936	0	4	4	0	System				8	872	72	5455781250	0	254	6046246	17681	98642560	37577	1809838	6370	44	44	258048	1380	0	4736	94208	1	1	6370	0	2490368	6025216
2009-12-16 13:05:12.936	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:05:12.936	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	639	15	10753281250	35156250	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:05:12.936	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	688	20	20000000	11406250	488	130346	454	51657	7497	287588	9571	11120	11808	6750208	1380	200	16264	11386880	193	199	9571	176	85262336	107282432
2009-12-16 13:05:12.936	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4257187500	1095156250	15437	2437450	20543	7932815	381371	3136994	5634	6604	10364	5857280	1380	200	8948	6762496	17	26	5634	87	319479808	361951232
2009-12-16 13:05:12.936	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	726	33	267968750	82500000	145966	11710412	136918	11788879	274335	4006671	7292	12244	12244	8376320	1380	200	13936	12537856	37	41	7292	115	76271616	76795904
2009-12-16 13:05:12.936	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7360	397510	7360	59180	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:05:12.936	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27656250	16562500	7359	323824	7359	59020	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:05:12.936	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14717	677578	14715	117716	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:05:12.936	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14822	714220	14822	119612	9136	164220	2869	2316	2440	1892352	1380	200	5732	2371584	10	13	2869	62	40239104	41287680
2009-12-16 13:05:12.936	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1362	65	542031250	639687500	185771	142699848	167723	11776075	51757	1118729	437661	29472	86868	25772032	1380	200	98276	30179328	102	138	437661	354	579858432	849555456
2009-12-16 13:05:12.936	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7365	353792	7365	59716	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:05:12.936	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274687500	31250000	44835	1794982	44799	1413948	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:05:12.936	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7393	551724	7392	134656	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:05:12.936	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7360	426750	7359	58896	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:05:12.936	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37425	1869938	37424	1502128	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:05:12.936	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7361	353296	7360	59056	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:05:12.936	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7361	323960	7386	219920	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:05:12.936	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7359	323824	7359	59020	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:05:12.936	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7410	592439	7362	59456	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:05:12.936	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7358	456134	7358	58860	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:05:12.936	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7382	385276	7382	62440	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:05:12.936	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	154	17	6406250	1562500	7423	428319	7406	65982	860	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:05:12.936	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7363	471652	7369	59950	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:05:12.936	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7360	294512	7360	59180	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:05:12.936	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1709	20	2189843750	1822500000	90440	19686158	89714	8412127	191577	2190282	1409327	23588	30548	56705024	1380	200	59964	24154112	36	38	1409327	349	196575232	226025472
2009-12-16 13:05:12.936	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46128	829604	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:05:12.936	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	7968750	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:05:12.936	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:05:12.936	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:05:12.936	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	965781250	3466718750	10059	9404375	4643	3741984	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:05:12.936	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	644	50	1165781250	36810937500	75107	13269292666	49916	1359642115	46603	13222087	697539	1408012	1538612	1335029760	1380	200	1475220	1441804288	144	270	697539	389	5751074816	5816467456
2009-12-16 13:05:12.936	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5205	5024	5072	1089536	1380	200	5788	5144576	7	8	5205	65	40542208	41066496
2009-12-16 13:05:12.936	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73593750	32968750	7264	639057	7136	207562	15052	231994	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:05:12.936	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4935	237036	4935	39932	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:05:12.936	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:05:12.936	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:05:12.936	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	242	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:05:12.936	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	17187500	5781250	89	2975610	874	623869	1856	462750	196191	16460	16628	22233088	1380	200	21880	16855040	14	17	196191	123	94060544	94130176
2009-12-16 13:05:12.936	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1406250	119	293748	1664	427299	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:05:12.936	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:05:12.936	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	3593750	23437500	144	650211	21	61080	766	4904	12342	50828	50896	47861760	1380	200	46856	52047872	14	16	12342	246	556105728	557252608
2009-12-16 13:05:28.218	0	0	0	0	System Idle Process				0	0	2	1339846562500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:05:28.218	0	4	4	0	System				8	868	72	5456093750	0	254	6046246	17685	98904704	37601	1810076	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:05:28.218	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:05:28.218	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	638	15	10756093750	35156250	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:05:28.218	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	688	20	20000000	11406250	488	130346	454	51657	7497	287588	9571	11120	11808	6750208	1380	200	16264	11386880	193	199	9571	176	85262336	107282432
2009-12-16 13:05:28.218	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4257500000	1095468750	15439	2437550	20545	7932831	381423	3137430	5634	6556	10364	5840896	1380	200	8948	6713344	17	26	5634	87	318955520	361951232
2009-12-16 13:05:28.218	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	716	33	268125000	82500000	145976	11711040	136927	11789163	274353	4006743	7292	12244	12244	8376320	1380	200	13936	12537856	36	41	7292	115	76271616	76795904
2009-12-16 13:05:28.218	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7361	397564	7361	59188	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:05:28.218	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27656250	16562500	7360	323868	7360	59028	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:05:28.218	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14719	677670	14717	117732	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:05:28.218	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14824	714316	14824	119628	9137	164248	2869	2316	2440	1892352	1380	200	5732	2371584	10	13	2869	62	40239104	41287680
2009-12-16 13:05:28.218	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1366	65	542187500	640000000	185812	142743728	167765	11819091	51771	1118969	437714	29472	86868	25772032	1380	200	98276	30179328	102	138	437714	354	579858432	849555456
2009-12-16 13:05:28.218	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7366	353840	7366	59724	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:05:28.218	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274843750	31406250	44843	1795294	44807	1414208	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:05:28.218	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7394	551788	7393	134664	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:05:28.218	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7361	426808	7360	58904	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:05:28.218	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37432	1870284	37431	1502424	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:05:28.218	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7362	353344	7361	59064	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:05:28.218	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7362	324004	7387	219928	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:05:28.218	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7360	323868	7360	59028	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:05:28.218	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7411	592501	7363	59464	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:05:28.218	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7359	456196	7359	58868	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:05:28.218	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7383	385328	7383	62448	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:05:28.218	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	154	17	6406250	1562500	7424	428375	7407	65990	860	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:05:28.218	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7364	471716	7370	59958	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:05:28.218	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7361	294552	7361	59188	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:05:28.218	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1709	20	2190000000	1822656250	90444	19686382	89718	8412503	191581	2190282	1409451	23528	30548	56643584	1380	200	59964	24092672	36	38	1409451	349	196575232	226025472
2009-12-16 13:05:28.218	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46128	829604	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:05:28.218	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:05:28.218	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:05:28.218	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:05:28.218	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	965937500	3468906250	10063	9404843	4647	3748444	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:05:28.218	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	644	50	1165781250	36811718750	75116	13269300087	49940	1360650260	46603	13222087	697556	1408012	1538612	1335029760	1380	200	1475220	1441804288	144	270	697556	389	5751074816	5816467456
2009-12-16 13:05:28.218	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5205	5024	5072	1089536	1380	200	5788	5144576	7	8	5205	65	40542208	41066496
2009-12-16 13:05:28.218	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73906250	32968750	7269	639627	7141	208475	15202	234394	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:05:28.218	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4936	237084	4936	39940	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:05:28.218	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:05:28.218	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:05:28.218	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:05:28.218	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	17187500	6406250	95	2977146	880	649501	2095	527838	196566	16460	16628	22233088	1380	200	21880	16855040	14	17	196566	123	94060544	94130176
2009-12-16 13:05:28.218	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1406250	121	295341	1675	429742	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:05:28.218	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:05:28.218	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	3750000	25781250	144	650211	25	74743	791	4912	12424	50916	50980	48033792	1380	200	47020	52137984	14	16	12424	246	556105728	557252608
2009-12-16 13:05:43.500	0	0	0	0	System Idle Process				0	0	2	1340117031250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:05:43.500	0	4	4	0	System				8	868	72	5456718750	0	254	6046246	17689	99166848	37621	1810410	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:05:43.500	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:05:43.500	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	637	15	10757812500	35156250	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:05:43.500	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	688	20	20000000	11406250	488	130346	454	51657	7497	287588	9571	11120	11808	6750208	1380	200	16264	11386880	193	199	9571	176	85262336	107282432
2009-12-16 13:05:43.500	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4258750000	1095468750	15443	2437750	20549	7932863	381529	3138274	5634	6556	10364	5840896	1380	200	8948	6713344	17	26	5634	87	318955520	361951232
2009-12-16 13:05:43.500	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	710	32	268125000	82500000	145990	11711884	136940	11789479	274371	4006815	7292	12180	12244	8359936	1380	200	13936	12472320	35	41	7292	115	75747328	76795904
2009-12-16 13:05:43.500	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7363	397672	7363	59204	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:05:43.500	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27656250	16562500	7362	323956	7362	59044	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:05:43.500	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14723	677854	14721	117764	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:05:43.500	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14828	714508	14828	119660	9140	164276	2869	2316	2440	1892352	1380	200	5732	2371584	10	13	2869	62	40239104	41287680
2009-12-16 13:05:43.500	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1365	64	542500000	640312500	185875	142788728	167829	11862283	51777	1119033	437834	29424	86868	25743360	1380	200	98276	30130176	101	138	437834	354	579334144	849555456
2009-12-16 13:05:43.500	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7368	353936	7368	59740	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:05:43.500	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274843750	31406250	44853	1795702	44817	1414512	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:05:43.500	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7396	551916	7395	134680	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:05:43.500	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7363	426924	7362	58920	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:05:43.500	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37440	1870688	37439	1502728	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:05:43.500	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7364	353440	7363	59080	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:05:43.500	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7364	324092	7389	219944	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:05:43.500	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7362	323956	7362	59044	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:05:43.500	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7413	592625	7365	59480	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:05:43.500	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7361	456320	7361	58884	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:05:43.500	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7385	385432	7385	62464	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:05:43.500	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7426	428487	7409	66006	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:05:43.500	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7366	471844	7372	59974	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:05:43.500	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7363	294632	7363	59204	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:05:43.500	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1709	20	2190468750	1822812500	90448	19686606	89722	8412879	191585	2190282	1409605	23592	30548	56713216	1380	200	59964	24158208	36	38	1409605	349	196575232	226025472
2009-12-16 13:05:43.500	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46128	829604	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:05:43.500	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:05:43.500	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:05:43.500	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:05:43.500	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966093750	3470937500	10071	9405779	4655	3761364	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:05:43.500	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	645	51	1166093750	36813593750	75126	13269313119	49976	1362405190	46605	13222087	697578	1410068	1538612	1335042048	1380	200	1475220	1443909632	145	270	697578	389	5753171968	5816467456
2009-12-16 13:05:43.500	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5205	5024	5072	1089536	1380	200	5788	5144576	7	8	5205	65	40542208	41066496
2009-12-16 13:05:43.500	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73906250	33125000	7271	639751	7143	208491	15353	236810	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:05:43.500	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4938	237180	4938	39956	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:05:43.500	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:05:43.500	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:05:43.500	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11943	51660	51660	47390720	1380	200	46280	52899840	13	15	11943	245	554987520	555610112
2009-12-16 13:05:43.500	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	17343750	6718750	101	2978682	886	675133	2333	592926	196941	16460	16628	22233088	1380	200	21880	16855040	14	17	196941	123	94060544	94130176
2009-12-16 13:05:43.500	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1406250	125	296231	1683	429866	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:05:43.500	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:05:43.500	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	3750000	28593750	144	650211	29	88406	816	4920	12506	51004	51064	48209920	1380	200	47188	52228096	14	16	12506	246	556105728	557252608
2009-12-16 13:05:58.813	0	0	0	0	System Idle Process				0	0	2	1340385468750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:05:58.813	0	4	4	0	System				8	872	72	5457968750	0	254	6046246	17701	99462784	37639	1810648	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:05:58.813	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:05:58.813	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	639	15	10760781250	35156250	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:05:58.813	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	688	20	20000000	11406250	488	130346	454	51657	7497	287588	9571	11120	11808	6750208	1380	200	16264	11386880	193	199	9571	176	85262336	107282432
2009-12-16 13:05:58.813	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4259843750	1095468750	15445	2437850	20611	7945135	381581	3138710	5634	6556	10364	5840896	1380	200	8948	6713344	17	26	5634	87	318955520	361951232
2009-12-16 13:05:58.813	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	716	33	268593750	82968750	146104	11727684	137037	11803821	274619	4014491	7324	12280	12280	8413184	1380	200	13936	12574720	36	41	7324	115	76271616	76795904
2009-12-16 13:05:58.813	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7364	397726	7364	59212	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:05:58.813	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27656250	16562500	7363	324000	7363	59052	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:05:58.813	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14725	677946	14723	117780	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:05:58.813	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14830	714604	14830	119676	9141	164304	2869	2316	2440	1892352	1380	200	5732	2371584	10	13	2869	62	40239104	41287680
2009-12-16 13:05:58.813	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1365	64	542500000	640468750	185916	142832608	167871	11905299	51785	1119097	437883	29424	86868	25743360	1380	200	98276	30130176	101	138	437883	354	579334144	849555456
2009-12-16 13:05:58.813	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7369	353984	7369	59748	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:05:58.813	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274843750	31406250	44862	1796050	44826	1414808	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:05:58.813	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7397	551980	7396	134688	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:05:58.813	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7364	426982	7363	58928	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:05:58.813	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37447	1871034	37446	1503024	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:05:58.813	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7365	353488	7364	59088	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:05:58.813	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7365	324136	7390	219952	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:05:58.813	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7363	324000	7363	59052	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:05:58.813	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7414	592687	7366	59488	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:05:58.813	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7362	456382	7362	58892	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:05:58.813	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7386	385484	7386	62472	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:05:58.813	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7427	428543	7410	66014	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:05:58.813	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7367	471908	7373	59982	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:05:58.813	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7364	294672	7364	59212	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:05:58.813	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1709	20	2190937500	1823125000	90452	19686830	89726	8413255	191589	2190282	1409708	23592	30548	56713216	1380	200	59964	24158208	36	38	1409708	349	196575232	226025472
2009-12-16 13:05:58.813	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46140	829732	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:05:58.813	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:05:58.813	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:05:58.813	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:05:58.813	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966093750	3472343750	10075	9406247	4659	3767824	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:05:58.813	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	656	52	1166562500	36815625000	75151	13269322324	50022	1363840020	46889	13238196	697650	1412124	1538612	1335181312	1380	200	1475220	1446014976	145	270	697650	389	5755269120	5816467456
2009-12-16 13:05:58.813	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5205	5024	5072	1089536	1380	200	5788	5144576	7	8	5205	65	40542208	41066496
2009-12-16 13:05:58.813	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73906250	33281250	7276	640321	7148	209404	15503	239210	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:05:58.813	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4939	237228	4939	39964	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:05:58.813	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:05:58.813	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:05:58.813	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11944	51660	51660	47394816	1380	200	46284	52899840	13	15	11944	245	554987520	555610112
2009-12-16 13:05:58.813	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	17500000	6875000	107	2980218	892	700765	2572	658014	197316	16460	16628	22233088	1380	200	21880	16855040	14	17	197316	123	94060544	94130176
2009-12-16 13:05:58.813	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1406250	129	297121	1690	429987	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:05:58.813	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:05:58.813	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	3906250	30781250	144	650211	33	102070	841	4928	12602	51100	51168	48435200	1380	200	47420	52326400	14	16	12602	246	556171264	557318144
2009-12-16 13:06:14.172	0	0	0	0	System Idle Process				0	0	2	1340655156250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:06:14.172	0	4	4	0	System				8	868	72	5458750000	0	254	6046246	17705	99724928	37643	1810886	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:06:14.172	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:06:14.172	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	639	15	10763125000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:06:14.172	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	688	20	20000000	11406250	488	130346	454	51657	7497	287588	9571	11120	11808	6750208	1380	200	16264	11386880	193	199	9571	176	85262336	107282432
2009-12-16 13:06:14.172	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4260625000	1096093750	15449	2438050	20615	7945167	381684	3139554	5634	6556	10364	5840896	1380	200	8948	6713344	17	26	5634	87	318955520	361951232
2009-12-16 13:06:14.172	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	708	33	268593750	82968750	146118	11728528	137050	11804137	274633	4014563	7324	12280	12280	8413184	1380	200	13936	12574720	35	41	7324	115	76271616	76795904
2009-12-16 13:06:14.172	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7366	397834	7366	59228	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:06:14.172	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27812500	16562500	7365	324088	7365	59068	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:06:14.172	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14729	678130	14727	117812	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:06:14.172	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14834	714796	14834	119708	9142	164332	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:06:14.172	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1369	64	542656250	640468750	185979	142877608	167935	11948491	51791	1119161	438000	29424	86868	25743360	1380	200	98276	30130176	101	138	438000	354	579334144	849555456
2009-12-16 13:06:14.172	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7371	354080	7371	59764	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:06:14.172	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274843750	31406250	44871	1796422	44835	1415076	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:06:14.172	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7399	552108	7398	134704	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:06:14.172	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7366	427098	7365	58944	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:06:14.172	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37455	1871438	37454	1503328	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:06:14.172	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7367	353584	7366	59104	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:06:14.172	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7367	324224	7392	219968	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:06:14.172	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7365	324088	7365	59068	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:06:14.172	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7416	592811	7368	59504	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:06:14.172	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7364	456506	7364	58908	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:06:14.172	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7388	385588	7388	62488	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:06:14.172	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7429	428655	7412	66030	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:06:14.172	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7369	472036	7375	59998	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:06:14.172	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7366	294752	7366	59228	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:06:14.172	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1709	20	2191718750	1823281250	90456	19687054	89730	8413631	191593	2190282	1409859	23500	30548	56614912	1380	200	59964	24064000	36	38	1409859	349	196575232	226025472
2009-12-16 13:06:14.172	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46140	829732	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:06:14.172	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:06:14.172	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:06:14.172	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:06:14.172	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966406250	3474375000	10083	9407183	4667	3780744	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:06:14.172	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	656	52	1166562500	36819062500	75165	13269336261	50099	1366217467	46889	13238196	697670	1412124	1538612	1335181312	1380	200	1475220	1446014976	145	270	697670	389	5755269120	5816467456
2009-12-16 13:06:14.172	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5205	5024	5072	1089536	1380	200	5788	5144576	7	8	5205	65	40542208	41066496
2009-12-16 13:06:14.172	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73906250	33281250	7282	640953	7154	210325	15655	241642	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:06:14.172	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4941	237324	4941	39980	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:06:14.172	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:06:14.172	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:06:14.172	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	240	8	1250000	9062500	144	648587	3	436	663	4976	11944	51660	51660	47394816	1380	200	46284	52899840	13	15	11944	245	554987520	555610112
2009-12-16 13:06:14.172	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	17500000	6875000	113	2981754	898	726397	2813	723414	197691	16460	16628	22233088	1380	200	21880	16855040	14	17	197691	123	94060544	94130176
2009-12-16 13:06:14.172	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	164	374740	2338	566661	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:06:14.172	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:06:14.172	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	3906250	33593750	144	650211	37	115735	866	4936	12687	51188	51256	48611328	1380	200	47588	52416512	14	16	12687	246	556171264	557318144
2009-12-16 13:06:29.485	0	0	0	0	System Idle Process				0	0	2	1340925781250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:06:29.485	0	4	4	0	System				8	868	72	5458906250	0	254	6046246	17709	99987072	37643	1811124	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:06:29.485	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:06:29.485	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	636	15	10766406250	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:06:29.485	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	686	19	20000000	11406250	488	130346	454	51657	7500	287588	9579	11072	11808	6733824	1380	200	16264	11337728	193	199	9579	176	84738048	107282432
2009-12-16 13:06:29.485	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4261718750	1096250000	15451	2438150	20617	7945183	381736	3139990	5634	6556	10364	5840896	1380	200	8948	6713344	17	26	5634	87	318955520	361951232
2009-12-16 13:06:29.485	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	708	33	268593750	82968750	146128	11729156	137059	11804421	274645	4014635	7324	12280	12280	8413184	1380	200	13936	12574720	35	41	7324	115	76271616	76795904
2009-12-16 13:06:29.485	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7367	397888	7367	59236	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:06:29.485	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27812500	16562500	7366	324132	7366	59076	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:06:29.485	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14731	678222	14729	117828	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:06:29.485	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14836	714892	14836	119724	9143	164360	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:06:29.485	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1373	64	542812500	640625000	186020	142921488	167977	11991507	51797	1119225	438052	29424	86868	25743360	1380	200	98276	30130176	101	138	438052	354	579334144	849555456
2009-12-16 13:06:29.485	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7372	354128	7372	59772	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:06:29.485	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	274843750	31406250	44880	1796770	44844	1415372	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:06:29.485	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7400	552172	7399	134712	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:06:29.485	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7367	427156	7366	58952	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:06:29.485	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37462	1871784	37461	1503624	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:06:29.485	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7368	353632	7367	59112	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:06:29.485	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7368	324268	7393	219976	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:06:29.485	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7366	324132	7366	59076	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:06:29.485	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7417	592873	7369	59512	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:06:29.485	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1718750	7365	456568	7365	58916	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:06:29.485	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7389	385640	7389	62496	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:06:29.485	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7430	428711	7413	66038	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:06:29.485	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7370	472100	7376	60006	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:06:29.485	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7367	294792	7367	59236	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:06:29.485	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1703	19	2191875000	1823437500	90460	19687278	89734	8414007	191597	2190282	1409988	23620	30548	56733696	1380	200	59964	24186880	36	38	1409988	349	196022272	226025472
2009-12-16 13:06:29.485	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46140	829732	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:06:29.485	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:06:29.485	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:06:29.485	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:06:29.485	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966406250	3475468750	10091	9408119	4675	3793664	31914	2649578	240638	191912	236504	136318976	1380	200	154524	196517888	52	59	240638	653	556937216	589316096
2009-12-16 13:06:29.485	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	656	52	1166875000	36821093750	75178	13269350142	50142	1368037533	46889	13238196	697708	1412124	1538612	1335263232	1380	200	1475220	1446014976	145	270	697708	389	5755269120	5816467456
2009-12-16 13:06:29.485	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5209	5024	5072	1089536	1380	200	5788	5144576	7	8	5209	65	40542208	41066496
2009-12-16 13:06:29.485	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73906250	33281250	7287	641523	7159	211238	15806	244058	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:06:29.485	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4942	237372	4942	39988	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:06:29.485	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:06:29.485	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:06:29.485	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	237	7	1250000	9062500	144	648587	3	436	663	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:06:29.485	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	17968750	7031250	119	2983290	904	752029	3052	788502	198066	16460	16628	22233088	1380	200	21880	16855040	14	17	198066	123	94060544	94130176
2009-12-16 13:06:29.485	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	168	376778	2352	569163	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:06:29.485	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:06:29.485	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	4218750	36250000	144	650211	41	129400	891	4944	12774	51136	51260	48705536	1380	200	47676	52363264	14	16	12774	246	556171264	557318144
2009-12-16 13:06:44.767	0	0	0	0	System Idle Process				0	0	2	1341133437500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:06:44.767	0	4	4	0	System				8	882	72	5460156250	0	254	6046246	17713	100249216	37645	1811362	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:06:44.767	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:06:44.767	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	651	15	10768281250	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:06:44.767	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	686	19	20000000	11406250	488	130346	454	51657	7500	287588	9579	11072	11808	6733824	1380	200	16264	11337728	193	199	9579	176	84738048	107282432
2009-12-16 13:06:44.767	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	367	16	4262812500	1097031250	15455	2438350	20661	7954855	381843	3140834	5695	6508	10364	5148672	1380	200	8948	6664192	17	26	5695	87	318496768	361951232
2009-12-16 13:06:44.767	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	727	33	269062500	82968750	146248	11745244	137161	11818863	274899	4024803	7357	12296	12320	8417280	1380	200	13936	12591104	36	41	7357	115	76271616	76795904
2009-12-16 13:06:44.767	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7369	397996	7369	59252	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:06:44.767	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27812500	16562500	7368	324220	7368	59092	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:06:44.767	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14735	678406	14733	117860	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:06:44.767	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14840	715084	14840	119756	9146	164388	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:06:44.767	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1365	62	542968750	640937500	186083	142966488	168041	12034699	51803	1119289	438184	29328	86868	25694208	1380	200	98276	30031872	101	138	438184	354	578285568	849555456
2009-12-16 13:06:44.767	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7374	354224	7374	59788	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:06:44.767	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275000000	31406250	44889	1797142	44853	1415640	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:06:44.767	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7402	552300	7401	134728	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:06:44.767	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7369	427272	7368	58968	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:06:44.767	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218750000	11718750	37470	1872188	37469	1503928	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:06:44.767	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7370	353728	7369	59128	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:06:44.767	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7370	324356	7395	219992	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:06:44.767	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7368	324220	7368	59092	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:06:44.767	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7419	592997	7371	59528	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:06:44.767	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7367	456692	7367	58932	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:06:44.767	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7391	385744	7391	62512	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:06:44.767	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7432	428823	7415	66054	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:06:44.767	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7372	472228	7378	60022	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:06:44.767	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7369	294872	7369	59252	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:06:44.767	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1703	19	2192187500	1824062500	90464	19687502	89738	8414383	191601	2190282	1410139	23524	30548	56639488	1380	200	59964	24088576	36	38	1410139	349	196022272	226025472
2009-12-16 13:06:44.767	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46140	829732	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:06:44.767	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:06:44.767	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:06:44.767	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:06:44.767	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966562500	3476406250	10095	9408587	4679	3800124	31914	2649578	240656	191976	236504	136392704	1380	200	154524	196583424	52	59	240656	653	556937216	589316096
2009-12-16 13:06:44.767	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	739	70	1167968750	36884687500	75201	13269358566	50219	1370590722	47218	13311601	698635	1449492	1538612	1337032704	1380	200	1475220	1484279808	154	270	698635	389	5793411072	5816467456
2009-12-16 13:06:44.767	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5209	5024	5072	1089536	1380	200	5788	5144576	7	8	5209	65	40542208	41066496
2009-12-16 13:06:44.767	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	73906250	33281250	7289	641647	7161	211254	15955	246442	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:06:44.767	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4944	237468	4944	40004	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:06:44.767	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:06:44.767	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:06:44.767	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	237	7	1250000	9062500	144	648587	3	436	663	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:06:44.767	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	18750000	7343750	125	2984826	910	777661	3290	853590	198441	16460	16628	22233088	1380	200	21880	16855040	14	17	198441	123	94060544	94130176
2009-12-16 13:06:44.767	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	170	377223	2357	569228	371	3646	2944	4792	4828	10199040	1380	200	9980	4907008	10	14	2944	116	68116480	69165056
2009-12-16 13:06:44.767	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:06:44.767	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	4375000	39062500	144	650211	45	143065	916	4952	12861	51244	51312	48898048	1380	200	47868	52473856	14	16	12861	246	556171264	557318144
2009-12-16 13:07:00.283	0	0	0	0	System Idle Process				0	0	2	1341134687500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:07:00.283	0	4	4	0	System				8	880	72	5460468750	0	254	6046246	17725	100545152	37655	1811600	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:07:00.283	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:07:00.283	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	655	15	10768750000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:07:00.283	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	686	19	20000000	11406250	488	130346	454	51657	7500	287588	9579	11072	11808	6733824	1380	200	16264	11337728	193	199	9579	176	84738048	107282432
2009-12-16 13:07:00.283	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4263593750	1097500000	15457	2438450	20663	7954871	381895	3141270	5699	6556	10364	5165056	1380	200	8948	6713344	17	26	5699	87	319021056	361951232
2009-12-16 13:07:00.283	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	721	33	269062500	82968750	146258	11745872	137170	11819147	274915	4024875	7357	12296	12320	8417280	1380	200	13936	12591104	35	41	7357	115	76271616	76795904
2009-12-16 13:07:00.283	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7370	398050	7370	59260	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:07:00.283	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	266	11	27812500	16562500	7369	324264	7369	59100	636	19480	2285	2224	2284	2355200	1380	200	5240	2277376	34	35	2285	67	34426880	35119104
2009-12-16 13:07:00.283	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14737	678498	14735	117876	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:07:00.283	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14842	715180	14842	119772	9147	164416	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:07:00.283	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1361	62	542968750	641250000	186124	143010368	168083	12077715	51809	1119353	438232	29328	86868	25694208	1380	200	98276	30031872	101	138	438232	354	578285568	849555456
2009-12-16 13:07:00.283	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7375	354272	7375	59796	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:07:00.283	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275000000	31406250	44898	1797490	44862	1415936	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:07:00.283	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7403	552364	7402	134736	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:07:00.283	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7370	427330	7369	58976	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:07:00.283	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218906250	11718750	37479	1872630	37478	1504320	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:07:00.283	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7371	353776	7370	59136	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:07:00.283	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7371	324400	7396	220000	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:07:00.283	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7369	324264	7369	59100	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:07:00.283	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7420	593059	7372	59536	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:07:00.283	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7368	456754	7368	58940	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:07:00.283	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7392	385796	7392	62520	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:07:00.283	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7433	428879	7416	66062	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:07:00.283	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7373	472292	7379	60030	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:07:00.283	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7370	294912	7370	59260	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:07:00.283	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1698	18	2192500000	1824218750	90468	19687726	89742	8414759	191605	2190282	1410253	23452	30548	56627200	1380	200	59964	24014848	36	38	1410253	349	195497984	226025472
2009-12-16 13:07:00.283	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46152	829860	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:07:00.283	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:07:00.283	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:07:00.283	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:07:00.283	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966718750	3477187500	10103	9409523	4687	3813044	31914	2649578	240656	191976	236504	136392704	1380	200	154524	196583424	52	59	240656	653	556937216	589316096
2009-12-16 13:07:00.283	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	767	74	1171718750	37155781250	75312	13310537247	50382	1377932201	47321	13429761	701198	1457936	1538612	1338470400	1380	200	1475220	1492926464	155	270	701198	389	5802061824	5816467456
2009-12-16 13:07:00.283	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5209	5024	5072	1089536	1380	200	5788	5144576	7	8	5209	65	40542208	41066496
2009-12-16 13:07:00.283	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74218750	33281250	7294	642217	7166	212167	16106	248858	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:07:00.283	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4945	237516	4945	40012	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:07:00.283	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:07:00.283	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:07:00.283	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:07:00.283	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	18750000	7500000	131	2986362	916	803293	3529	918678	198816	16460	16628	22233088	1380	200	21880	16855040	14	17	198816	123	94060544	94130176
2009-12-16 13:07:00.283	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	181	399234	2404	609245	371	3646	2951	4808	4828	10227712	1380	200	9988	4923392	10	14	2951	116	68116480	69165056
2009-12-16 13:07:00.283	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:07:00.283	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	4843750	42656250	144	650211	49	156731	941	4960	12944	51324	51392	49074176	1380	200	48032	52555776	14	16	12944	246	556171264	557318144
2009-12-16 13:07:15.738	0	0	0	0	System Idle Process				0	0	2	1341136562500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:07:15.738	0	4	4	0	System				8	880	72	5460468750	0	254	6046246	17730	100872832	37655	1811838	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:07:15.738	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:07:15.738	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	654	15	10768750000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:07:15.738	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	686	19	20000000	11406250	488	130346	454	51657	7500	287588	9579	11072	11808	6733824	1380	200	16264	11337728	193	199	9579	176	84738048	107282432
2009-12-16 13:07:15.738	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4265156250	1097812500	15461	2438650	20667	7954903	381998	3142114	5699	6556	10364	5165056	1380	200	8948	6713344	17	26	5699	87	319021056	361951232
2009-12-16 13:07:15.738	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	721	33	269062500	82968750	146272	11746716	137183	11819463	274927	4024947	7357	12296	12320	8417280	1380	200	13936	12591104	35	41	7357	115	76271616	76795904
2009-12-16 13:07:15.738	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7372	398158	7372	59276	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:07:15.738	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	256	10	27812500	16562500	7371	324352	7371	59116	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:07:15.738	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14741	678682	14739	117908	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:07:15.738	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14846	715372	14846	119804	9148	164444	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:07:15.738	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1362	62	543281250	641406250	186187	143055368	168147	12120907	51815	1119417	438349	29328	86868	25694208	1380	200	98276	30031872	101	138	438349	354	578285568	849555456
2009-12-16 13:07:15.738	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7377	354368	7377	59812	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:07:15.738	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275000000	31406250	44908	1797898	44872	1416240	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:07:15.738	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7405	552492	7404	134752	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:07:15.738	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7372	427446	7371	58992	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:07:15.738	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218906250	11718750	37487	1873034	37486	1504624	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:07:15.738	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7373	353872	7372	59152	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:07:15.738	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7373	324488	7398	220016	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:07:15.738	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7371	324352	7371	59116	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:07:15.738	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7422	593183	7374	59552	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:07:15.738	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7370	456878	7370	58956	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:07:15.738	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7394	385900	7394	62536	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:07:15.738	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7435	428991	7418	66078	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:07:15.738	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7375	472420	7381	60046	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:07:15.738	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7372	294992	7372	59276	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:07:15.738	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1698	18	2192656250	1824687500	90472	19687950	89746	8415135	191609	2190282	1410399	23452	30548	56627200	1380	200	59964	24014848	36	38	1410399	349	195497984	226025472
2009-12-16 13:07:15.738	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46152	829860	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:07:15.738	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:07:15.738	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:07:15.738	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:07:15.738	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	966718750	3477968750	10107	9410004	4691	3819504	31914	2649578	240656	191976	236504	136392704	1380	200	154524	196583424	52	59	240656	653	556937216	589316096
2009-12-16 13:07:15.738	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	769	74	1176093750	37426406250	75369	13331000148	50512	1383729904	47401	13511929	705661	1468824	1538612	1349734400	1380	200	1475220	1504075776	155	270	705661	389	5802520576	5816467456
2009-12-16 13:07:15.738	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5209	5024	5072	1089536	1380	200	5788	5144576	7	8	5209	65	40542208	41066496
2009-12-16 13:07:15.738	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74375000	33281250	7300	642849	7172	213088	16256	251258	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:07:15.738	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4947	237612	4947	40028	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:07:15.738	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:07:15.738	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:07:15.738	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:07:15.738	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	19375000	7500000	137	2987898	922	828925	3770	984078	199191	16460	16628	22233088	1380	200	21880	16855040	14	17	199191	123	94060544	94130176
2009-12-16 13:07:15.738	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	192	422620	2452	649351	371	3646	2951	4808	4828	10227712	1380	200	9988	4923392	10	14	2951	116	68116480	69165056
2009-12-16 13:07:15.738	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:07:15.738	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5156250	45781250	144	650211	53	170397	966	4968	13033	50908	51392	48754688	1380	200	48032	52129792	14	16	13033	246	558268416	559415296
2009-12-16 13:07:31.038	0	0	0	0	System Idle Process				0	0	2	1341137031250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:07:31.038	0	4	4	0	System				8	876	72	5460625000	0	254	6046246	17734	101134976	37659	1812076	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:07:31.038	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:07:31.038	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	656	15	10768906250	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:07:31.038	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	686	19	20000000	11406250	488	130346	454	51657	7500	287588	9579	11072	11808	6733824	1380	200	16264	11337728	193	199	9579	176	84738048	107282432
2009-12-16 13:07:31.038	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4265468750	1097812500	15464	2438800	20670	7954927	382074	3142742	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:07:31.038	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	711	32	269062500	82968750	146283	11747394	137193	11819755	274983	4027683	7357	12232	12320	8400896	1380	200	13936	12525568	34	41	7357	115	75747328	76795904
2009-12-16 13:07:31.038	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7374	398266	7374	59292	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:07:31.038	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	256	10	27812500	16718750	7372	324396	7372	59124	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:07:31.038	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14745	678866	14743	117940	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:07:31.038	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14849	715516	14849	119828	9149	164472	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:07:31.038	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1371	62	543281250	641406250	186240	143099866	168201	12164019	51821	1119481	438413	29328	86868	25694208	1380	200	98276	30031872	101	138	438413	354	578285568	849555456
2009-12-16 13:07:31.038	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7378	354416	7378	59820	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:07:31.038	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275000000	31406250	44916	1798210	44880	1416500	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:07:31.038	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7406	552556	7405	134760	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:07:31.038	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7373	427504	7372	59000	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:07:31.038	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	218906250	11718750	37494	1873380	37493	1504920	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:07:31.038	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7374	353920	7373	59160	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:07:31.038	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7375	324576	7400	220032	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:07:31.038	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7373	324440	7373	59132	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:07:31.038	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7424	593307	7376	59568	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:07:31.038	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7371	456940	7371	58964	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:07:31.038	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7395	385952	7395	62544	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:07:31.038	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7436	429047	7419	66086	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:07:31.038	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7377	472548	7383	60062	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:07:31.038	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7374	295072	7374	59292	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:07:31.038	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1698	18	2193437500	1824843750	90476	19688174	89750	8415511	191613	2190282	1410526	23372	30548	56549376	1380	200	59964	23932928	36	38	1410526	349	195497984	226025472
2009-12-16 13:07:31.038	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46152	829860	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:07:31.038	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:07:31.038	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:07:31.038	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:07:31.038	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	804	19	967343750	3478593750	10115	9410953	4699	3832424	31914	2649578	240656	191976	236504	136392704	1380	200	154524	196583424	52	59	240656	653	556937216	589316096
2009-12-16 13:07:31.038	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	773	76	1179218750	37700000000	75427	13351387589	50686	1390708415	47476	13606265	707434	1473108	1538612	1350062080	1380	200	1475220	1508462592	158	270	707434	389	5806452736	5816467456
2009-12-16 13:07:31.038	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5209	5024	5072	1089536	1380	200	5788	5144576	7	8	5209	65	40542208	41066496
2009-12-16 13:07:31.038	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74687500	33281250	7305	643419	7177	214001	16405	253642	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:07:31.038	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4948	237660	4948	40036	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:07:31.038	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:07:31.038	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:07:31.038	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:07:31.038	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	19687500	7500000	143	2989434	928	854557	4009	1049166	199566	16460	16628	22233088	1380	200	21880	16855040	14	17	199566	123	94060544	94130176
2009-12-16 13:07:31.038	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	238	532714	3163	843640	371	3646	2951	4808	4828	10227712	1380	200	9988	4923392	10	14	2951	116	68116480	69165056
2009-12-16 13:07:31.038	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:07:31.038	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5156250	48437500	144	650211	57	184063	991	4976	13116	51048	51392	48934912	1380	200	48032	52273152	14	16	13116	246	558268416	559415296
2009-12-16 13:07:46.386	0	0	0	0	System Idle Process				0	0	2	1341138437500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:07:46.386	0	4	4	0	System				8	876	72	5460781250	0	254	6046246	17746	101430912	37667	1812314	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:07:46.386	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:07:46.386	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	660	15	10769062500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:07:46.386	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	686	19	20000000	11406250	488	130346	454	51657	7500	287588	9579	11072	11808	6733824	1380	200	16264	11337728	193	199	9579	176	84738048	107282432
2009-12-16 13:07:46.386	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4265937500	1097968750	15467	2438950	20673	7954951	382156	3143394	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:07:46.386	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	711	32	269062500	82968750	146296	11748188	137205	11820063	274995	4027755	7357	12232	12320	8400896	1380	200	13936	12525568	34	41	7357	115	75747328	76795904
2009-12-16 13:07:46.386	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7375	398320	7375	59300	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:07:46.386	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	256	10	27812500	16875000	7374	324484	7374	59140	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:07:46.386	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14747	678958	14745	117956	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:07:46.386	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14852	715660	14852	119852	9152	164500	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:07:46.386	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1362	62	543281250	641562500	186291	143144248	168253	12207115	51827	1119545	438533	28972	86868	25378816	1380	200	98276	29667328	101	138	438533	354	578285568	849555456
2009-12-16 13:07:46.386	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7380	354512	7380	59836	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:07:46.386	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44926	1798618	44890	1416804	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:07:46.386	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7408	552684	7407	134776	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:07:46.386	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7375	427620	7374	59016	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:07:46.386	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219062500	11718750	37502	1873784	37501	1505224	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:07:46.386	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7376	354016	7375	59176	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:07:46.386	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7376	324620	7401	220040	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:07:46.386	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7374	324484	7374	59140	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:07:46.386	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7425	593369	7377	59576	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:07:46.386	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7373	457064	7373	58980	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:07:46.386	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7397	386056	7397	62560	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:07:46.386	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7438	429159	7421	66102	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:07:46.386	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7378	472612	7384	60070	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:07:46.386	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7375	295112	7375	59300	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:07:46.386	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1701	19	2193437500	1825781250	90480	19688398	89754	8415887	191617	2190282	1410653	23532	30548	56643584	1380	200	59964	24096768	36	38	1410653	349	196022272	226025472
2009-12-16 13:07:46.386	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46152	829860	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:07:46.386	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:07:46.386	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:07:46.386	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:07:46.386	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	19	967343750	3478906250	10119	9411421	4703	3838884	31914	2649578	240656	191976	236504	136392704	1380	200	154524	196583424	52	59	240656	653	556937216	589316096
2009-12-16 13:07:46.386	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1182968750	37971875000	75513	13387070265	50811	1396406350	47556	13707268	709089	1479040	1538612	1349939200	1380	200	1475220	1514536960	156	270	709089	389	5812416512	5816467456
2009-12-16 13:07:46.386	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5213	5024	5072	1089536	1380	200	5788	5144576	7	8	5213	65	40542208	41066496
2009-12-16 13:07:46.386	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74843750	33437500	7307	643543	7179	214017	16554	256026	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:07:46.386	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4950	237756	4950	40052	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:07:46.386	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:07:46.386	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:07:46.386	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:07:46.386	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	19687500	7968750	149	2990970	934	880189	4247	1114254	199941	16460	16628	22233088	1380	200	21880	16855040	14	17	199941	123	94060544	94130176
2009-12-16 13:07:46.386	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	252	562845	3229	896317	371	3646	2953	4816	4828	10235904	1380	200	9996	4931584	10	14	2953	116	68116480	69165056
2009-12-16 13:07:46.386	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:07:46.386	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5468750	50937500	144	650211	61	197730	1016	4984	13198	51212	51392	49111040	1380	200	48076	52441088	14	16	13198	246	559316992	560463872
2009-12-16 13:08:01.689	0	0	0	0	System Idle Process				0	0	2	1341139218750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:08:01.689	0	4	4	0	System				8	876	72	5460781250	0	254	6046246	17750	101693056	37667	1812552	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:08:01.689	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:08:01.689	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	660	15	10769218750	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:08:01.689	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:08:01.689	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4266406250	1098437500	15471	2439150	20677	7954983	382259	3144238	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:08:01.689	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	711	32	269062500	82968750	146310	11749032	137218	11820379	275007	4027827	7357	12232	12320	8400896	1380	200	13936	12525568	34	41	7357	115	75747328	76795904
2009-12-16 13:08:01.689	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7377	398428	7377	59316	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:08:01.689	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	259	10	27812500	16875000	7376	324572	7376	59156	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:08:01.689	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	151	9	12500000	4218750	14751	679142	14749	117988	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:08:01.689	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14856	715852	14856	119884	9153	164528	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:08:01.689	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1367	62	543593750	641718750	186354	143189248	168317	12250307	51833	1119609	438664	29032	86868	25440256	1380	200	98276	29728768	101	138	438664	354	578285568	849555456
2009-12-16 13:08:01.689	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7382	354608	7382	59852	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:08:01.689	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44936	1799026	44900	1417108	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:08:01.689	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7410	552812	7409	134792	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:08:01.689	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7377	427736	7376	59032	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:08:01.689	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219062500	11718750	37510	1874188	37509	1505528	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:08:01.689	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7378	354112	7377	59192	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:08:01.689	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7378	324708	7403	220056	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:08:01.689	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7376	324572	7376	59156	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:08:01.689	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7427	593493	7379	59592	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:08:01.689	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7375	457188	7375	58996	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:08:01.689	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7399	386160	7399	62576	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:08:01.689	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7440	429271	7423	66118	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:08:01.689	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7380	472740	7386	60086	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:08:01.689	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7377	295192	7377	59316	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:08:01.689	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1702	19	2193593750	1826093750	90484	19688622	89758	8416263	191621	2190282	1410777	23528	30548	56647680	1380	200	59964	24092672	36	38	1410777	349	196022272	226025472
2009-12-16 13:08:01.689	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46164	829988	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:08:01.689	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:08:01.689	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:08:01.689	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:08:01.689	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	813	20	967343750	3479062500	10127	9412383	4711	3851804	31914	2649578	240663	192020	236504	136421376	1380	200	154524	196628480	52	59	240663	653	558247936	589316096
2009-12-16 13:08:01.689	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1185312500	38262187500	75699	13463499178	50924	1402076111	47558	13709526	709232	1478832	1538612	1349914624	1380	200	1475220	1514323968	156	270	709232	389	5812154368	5816467456
2009-12-16 13:08:01.689	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5213	5024	5072	1089536	1380	200	5788	5144576	7	8	5213	65	40542208	41066496
2009-12-16 13:08:01.689	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74843750	33437500	7313	644175	7185	214938	16702	258394	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:08:01.689	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4952	237852	4952	40068	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:08:01.689	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:08:01.689	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:08:01.689	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:08:01.689	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	19843750	8125000	155	2992506	940	905821	4486	1179342	200316	16460	16628	22233088	1380	200	21880	16855040	14	17	200316	123	94060544	94130176
2009-12-16 13:08:01.689	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	278	612432	3328	977160	371	3646	2953	4816	4828	10235904	1380	200	9996	4931584	10	14	2953	116	68116480	69165056
2009-12-16 13:08:01.689	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:08:01.689	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5625000	53437500	144	650211	65	211398	1041	4992	13294	51440	51504	49344512	1380	200	48300	52674560	14	16	13294	246	559316992	560463872
2009-12-16 13:08:16.993	0	0	0	0	System Idle Process				0	0	2	1341140156250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:08:16.993	0	4	4	0	System				8	876	72	5460937500	0	254	6046246	17754	101955200	37667	1812790	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:08:16.993	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:08:16.993	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	659	15	10769218750	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:08:16.993	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:08:16.993	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4266406250	1098593750	15473	2439250	20679	7954999	382311	3144674	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:08:16.993	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146330	11750564	137235	11821671	275041	4028043	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:08:16.993	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7378	398482	7378	59324	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:08:16.993	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	259	10	27812500	16875000	7377	324616	7377	59164	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:08:16.993	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14753	679234	14751	118004	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:08:16.993	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14858	715948	14858	119900	9154	164556	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:08:16.993	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1367	62	543750000	641875000	186401	143282280	168359	12293323	51839	1119721	438751	29032	86868	25440256	1380	200	98276	29728768	101	138	438751	354	578285568	849555456
2009-12-16 13:08:16.993	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7383	354656	7383	59860	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:08:16.993	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44944	1799338	44908	1417368	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:08:16.993	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7411	552876	7410	134800	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:08:16.993	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7378	427794	7377	59040	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:08:16.993	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219062500	11718750	37517	1874534	37516	1505824	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:08:16.993	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7379	354160	7378	59200	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:08:16.993	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7379	324752	7404	220064	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:08:16.993	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7377	324616	7377	59164	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:08:16.993	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7428	593555	7380	59600	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:08:16.993	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7376	457250	7376	59004	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:08:16.993	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7400	386212	7400	62584	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:08:16.993	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7441	429327	7424	66126	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:08:16.993	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7381	472804	7387	60094	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:08:16.993	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7378	295232	7378	59324	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:08:16.993	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1702	19	2194062500	1826093750	90488	19688846	89762	8416639	191625	2190282	1410870	23528	30548	56643584	1380	200	59964	24092672	36	38	1410870	349	196022272	226025472
2009-12-16 13:08:16.993	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46164	829988	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:08:16.993	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:08:16.993	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:08:16.993	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:08:16.993	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	967343750	3479218750	10135	9413663	4720	3858880	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:08:16.993	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1186875000	38552500000	75887	13539922423	50995	1405133119	47579	13710334	709323	1478832	1538612	1350090752	1380	200	1475220	1514323968	156	270	709323	389	5812154368	5816467456
2009-12-16 13:08:16.993	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5213	5024	5072	1089536	1380	200	5788	5144576	7	8	5213	65	40542208	41066496
2009-12-16 13:08:16.993	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74843750	33437500	7318	644745	7190	215851	16851	260778	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:08:16.993	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4953	237900	4953	40076	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:08:16.993	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:08:16.993	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:08:16.993	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:08:16.993	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	20312500	8281250	161	2994042	946	931453	4727	1244742	200691	16460	16628	22233088	1380	200	21880	16855040	14	17	200691	123	94060544	94130176
2009-12-16 13:08:16.993	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	292	636284	3376	1014663	371	3646	2953	4816	4828	10235904	1380	200	9996	4931584	10	14	2953	116	68116480	69165056
2009-12-16 13:08:16.993	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:08:16.993	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5625000	56093750	144	650211	69	225066	1066	5000	13378	51604	51672	49528832	1380	200	48484	52842496	14	16	13378	246	559316992	560463872
2009-12-16 13:08:32.298	0	0	0	0	System Idle Process				0	0	2	1341140781250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:08:32.298	0	4	4	0	System				8	876	72	5460937500	0	254	6046246	17758	102217344	37667	1813028	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:08:32.298	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:08:32.298	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	658	15	10769218750	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:08:32.298	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:08:32.298	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4266718750	1099218750	15477	2439450	20683	7955031	382414	3145518	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:08:32.298	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146344	11751408	137248	11821987	275053	4028115	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:08:32.298	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7380	398590	7380	59340	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:08:32.298	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	259	10	27812500	16875000	7379	324704	7379	59180	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:08:32.298	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14757	679418	14755	118036	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:08:32.298	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14862	716140	14862	119932	9155	164584	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:08:32.298	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1365	61	543750000	642187500	186464	143327280	168423	12336515	51845	1119785	438835	28984	86868	25407488	1380	200	98276	29679616	101	138	438835	354	577761280	849555456
2009-12-16 13:08:32.298	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7385	354752	7385	59876	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:08:32.298	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44954	1799746	44918	1417672	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:08:32.298	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7413	553004	7412	134816	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:08:32.298	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7380	427910	7379	59056	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:08:32.298	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219062500	11718750	37525	1874938	37524	1506128	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:08:32.298	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7381	354256	7380	59216	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:08:32.298	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7381	324840	7406	220080	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:08:32.298	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7379	324704	7379	59180	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:08:32.298	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7430	593679	7382	59616	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:08:32.298	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7378	457374	7378	59020	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:08:32.298	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7402	386316	7402	62600	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:08:32.298	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7443	429439	7426	66142	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:08:32.298	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7383	472932	7389	60110	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:08:32.298	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7380	295312	7380	59340	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:08:32.298	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1702	19	2194843750	1826406250	90492	19689070	89766	8417015	191629	2190282	1411147	23512	30548	56561664	1380	200	59964	24076288	36	38	1411147	349	195854336	226025472
2009-12-16 13:08:32.298	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46164	829988	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:08:32.298	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:08:32.298	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:08:32.298	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:08:32.298	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	967500000	3479687500	10143	9414625	4728	3871800	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:08:32.298	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1189062500	38841562500	76071	13616359528	51089	1408901012	47579	13710334	714114	1497760	1538612	1369513984	1380	200	1475220	1533706240	156	270	714114	389	5812154368	5816467456
2009-12-16 13:08:32.298	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5213	5024	5072	1089536	1380	200	5788	5144576	7	8	5213	65	40542208	41066496
2009-12-16 13:08:32.298	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	74843750	33437500	7324	645377	7196	216772	16999	263146	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:08:32.298	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4955	237996	4955	40092	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:08:32.298	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:08:32.298	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:08:32.298	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	7	1250000	9062500	144	648587	3	436	664	4976	11944	51636	51660	47378432	1380	200	46284	52875264	13	15	11944	245	554463232	555610112
2009-12-16 13:08:32.298	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	20468750	8750000	167	2995578	952	957085	4966	1309830	201066	16460	16628	22233088	1380	200	21880	16855040	14	17	201066	123	94060544	94130176
2009-12-16 13:08:32.298	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1406250	1562500	306	659971	3423	1052109	371	3646	2953	4816	4828	10235904	1380	200	9996	4931584	10	14	2953	116	68116480	69165056
2009-12-16 13:08:32.298	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:08:32.298	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5781250	58437500	144	650211	73	238735	1091	5008	13457	51760	51828	49692672	1380	200	48644	53002240	14	16	13457	246	559316992	560463872
2009-12-16 13:08:47.620	0	0	0	0	System Idle Process				0	0	2	1341141250000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:08:47.620	0	4	4	0	System				8	877	72	5461093750	0	254	6046246	17772	102644352	37675	1813266	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:08:47.620	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:08:47.620	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	656	15	10769531250	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:08:47.620	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:08:47.620	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4267500000	1099375000	15479	2439550	20685	7955047	382469	3145954	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:08:47.620	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146354	11752036	137257	11822271	275065	4028187	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:08:47.620	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7381	398644	7381	59348	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:08:47.620	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	259	10	27812500	16875000	7380	324748	7380	59188	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:08:47.620	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14759	679510	14757	118052	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:08:47.620	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14864	716236	14864	119948	9158	164612	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:08:47.620	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1369	61	543750000	642187500	186511	143385400	168471	12393771	51851	1119849	438874	28984	86868	25407488	1380	200	98276	29679616	101	138	438874	354	577761280	849555456
2009-12-16 13:08:47.620	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7386	354800	7386	59884	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:08:47.620	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44963	1800094	44927	1417968	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:08:47.620	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7414	553068	7413	134824	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:08:47.620	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7381	427968	7380	59064	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:08:47.620	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37532	1875284	37531	1506424	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:08:47.620	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7382	354304	7381	59224	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:08:47.620	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7382	324884	7407	220088	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:08:47.620	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7380	324748	7380	59188	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:08:47.620	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7431	593741	7383	59624	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:08:47.620	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7379	457436	7379	59028	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:08:47.620	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7403	386368	7403	62608	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:08:47.620	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7444	429495	7427	66150	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:08:47.620	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7384	472996	7390	60118	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:08:47.620	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7381	295352	7381	59348	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:08:47.620	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1698	18	2195000000	1826718750	90496	19689294	89770	8417391	191633	2190282	1411297	23432	30548	56545280	1380	200	59964	23994368	35	38	1411297	349	195330048	226025472
2009-12-16 13:08:47.620	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46176	830116	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:08:47.620	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:08:47.620	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:08:47.620	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:08:47.620	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	810	20	967656250	3480312500	10147	9415106	4732	3878260	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:08:47.620	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1191093750	39130156250	76235	13687701980	51228	1414810944	47581	13710334	715407	1502568	1538612	1374482432	1380	200	1475220	1538629632	156	270	715407	389	5812154368	5816467456
2009-12-16 13:08:47.620	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5213	5024	5072	1089536	1380	200	5788	5144576	7	8	5213	65	40542208	41066496
2009-12-16 13:08:47.620	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75000000	33593750	7325	645439	7197	216780	17148	265530	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:08:47.620	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4956	238044	4956	40100	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:08:47.620	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:08:47.620	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:08:47.620	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11945	51612	51660	47366144	1380	200	46284	52850688	13	15	11945	245	553938944	555610112
2009-12-16 13:08:47.620	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	20625000	9218750	175	2997626	960	991261	5284	1396614	201566	16460	16628	22233088	1380	200	21880	16855040	14	17	201566	123	94060544	94130176
2009-12-16 13:08:47.620	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	4	1718750	1718750	367	786886	4173	1267791	371	3646	2953	4816	4828	10235904	1380	200	9996	4931584	10	14	2953	116	68116480	69165056
2009-12-16 13:08:47.620	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:08:47.620	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	5937500	60781250	144	650211	77	252404	1116	5016	13538	51928	51992	49864704	1380	200	48808	53174272	14	16	13538	246	559316992	560463872
2009-12-16 13:09:03.054	0	0	0	0	System Idle Process				0	0	2	1341141562500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:09:03.054	0	4	4	0	System				8	878	72	5461093750	0	254	6046246	17776	102906496	37675	1813504	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:09:03.054	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:09:03.054	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	656	15	10769531250	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:09:03.054	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:09:03.054	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4267968750	1099687500	15483	2439750	20689	7955079	382572	3146798	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:09:03.054	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146368	11752880	137270	11822587	275077	4028259	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:09:03.054	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7383	398752	7383	59364	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:09:03.054	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	259	10	27812500	16875000	7382	324836	7382	59204	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:09:03.054	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14763	679694	14761	118084	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:09:03.054	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14868	716428	14868	119980	9159	164640	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:09:03.054	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1369	61	543906250	642500000	186571	143423280	168532	12429843	51857	1119913	438958	28992	86868	25411584	1380	200	98276	29687808	101	138	438958	354	577761280	849555456
2009-12-16 13:09:03.054	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7388	354896	7388	59900	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:09:03.054	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44972	1800466	44936	1418236	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:09:03.054	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7416	553196	7415	134840	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:09:03.054	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7383	428084	7382	59080	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:09:03.054	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37540	1875688	37539	1506728	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:09:03.054	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7384	354400	7383	59240	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:09:03.054	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7384	324972	7409	220104	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:09:03.054	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7382	324836	7382	59204	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:09:03.054	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7433	593865	7385	59640	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:09:03.054	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7381	457560	7381	59044	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:09:03.054	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7405	386472	7405	62624	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:09:03.054	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7446	429607	7429	66166	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:09:03.054	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7386	473124	7392	60134	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:09:03.054	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7383	295432	7383	59364	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:09:03.054	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1701	19	2195781250	1826718750	90500	19689518	89774	8417767	191637	2190282	1411458	23520	30548	56569856	1380	200	59964	24084480	36	38	1411458	349	195854336	226025472
2009-12-16 13:09:03.054	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46176	830116	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:09:03.054	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:09:03.054	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:09:03.054	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:09:03.054	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	811	20	967656250	3480781250	10155	9416068	4740	3891180	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:09:03.054	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1193437500	39420468750	76428	13764221005	51307	1418488378	47581	13710334	715465	1502568	1538612	1374527488	1380	200	1475220	1538629632	156	270	715465	389	5812154368	5816467456
2009-12-16 13:09:03.054	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5217	5024	5072	1089536	1380	200	5788	5144576	7	8	5217	65	40542208	41066496
2009-12-16 13:09:03.054	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75000000	33593750	7331	646071	7203	217701	17298	267930	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:09:03.054	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4958	238140	4958	40116	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:09:03.054	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:09:03.054	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:09:03.054	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11945	51612	51660	47366144	1380	200	46284	52850688	13	15	11945	245	553938944	555610112
2009-12-16 13:09:03.054	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	5	20781250	9218750	180	2998906	965	1012621	5484	1450854	201904	16460	16628	22233088	1380	200	21880	16855040	14	17	201904	123	94060544	94130176
2009-12-16 13:09:03.054	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	1718750	381	810738	4222	1305297	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:09:03.054	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:09:03.054	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	8	6093750	64531250	144	650211	81	266073	1141	5024	13625	52116	52184	50061312	1380	200	49004	53366784	14	16	13625	246	559316992	560463872
2009-12-16 13:09:18.395	0	0	0	0	System Idle Process				0	0	2	1341142031250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:09:18.395	0	4	4	0	System				8	880	72	5461093750	0	254	6046246	17780	103168640	37675	1813504	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:09:18.395	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:09:18.395	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	650	15	10769687500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:09:18.395	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:09:18.395	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4268750000	1100156250	15485	2439850	20691	7955095	382623	3147206	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:09:18.395	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146377	11753472	137278	11822843	275087	4028331	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:09:18.395	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7384	398806	7384	59372	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:09:18.395	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	259	10	27812500	16875000	7383	324880	7383	59212	636	19480	2285	2176	2284	2330624	1380	200	5240	2228224	34	35	2285	67	33902592	35119104
2009-12-16 13:09:18.395	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14765	679786	14763	118100	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:09:18.395	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14870	716524	14870	119996	9159	164640	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:09:18.395	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1345	57	543906250	642500000	186611	143467120	168587	12501503	52092	1121849	439108	27120	86868	24129536	1380	200	98276	27770880	96	138	439108	354	535433216	849555456
2009-12-16 13:09:18.395	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7389	354944	7389	59908	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:09:18.395	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275156250	31406250	44981	1800814	44945	1418532	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:09:18.395	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7417	553260	7416	134848	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:09:18.395	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7384	428142	7383	59088	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:09:18.395	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37547	1876034	37546	1507024	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:09:18.395	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7385	354448	7384	59248	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:09:18.395	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7385	325016	7410	220112	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:09:18.395	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7383	324880	7383	59212	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:09:18.395	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7434	593927	7386	59648	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:09:18.395	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7382	457622	7382	59052	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:09:18.395	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7406	386524	7406	62632	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:09:18.395	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7447	429663	7430	66174	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:09:18.395	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7387	473188	7393	60142	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:09:18.395	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7384	295472	7384	59372	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:09:18.395	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1695	19	2196093750	1826875000	90504	19689742	89778	8418143	191642	2190282	1411574	23452	30548	56233984	1380	200	59964	24014848	35	38	1411574	349	195026944	226025472
2009-12-16 13:09:18.395	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46176	830116	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:09:18.395	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:09:18.395	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:09:18.395	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:09:18.395	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	811	20	967656250	3481250000	10159	9416549	4744	3897640	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:09:18.395	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1194843750	39712187500	76622	13840725322	51384	1421709863	47581	13710334	715553	1502568	1538612	1374568448	1380	200	1475220	1538629632	156	270	715553	389	5812154368	5816467456
2009-12-16 13:09:18.395	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66250000	10000000	5	580	0	0	155	2760	5217	5024	5072	1089536	1380	200	5788	5144576	7	8	5217	65	40542208	41066496
2009-12-16 13:09:18.395	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75156250	33593750	7336	646641	7208	218614	17446	270298	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:09:18.395	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4959	238188	4959	40124	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:09:18.395	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:09:18.395	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:09:18.395	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11945	51612	51660	47366144	1380	200	46284	52850688	13	15	11945	245	553938944	555610112
2009-12-16 13:09:18.395	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	21093750	9375000	186	3000442	971	1038253	5739	1516350	202277	16424	16628	22212608	1380	200	21880	16818176	14	17	202277	123	93011968	94130176
2009-12-16 13:09:18.395	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	1718750	395	834810	4270	1342794	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:09:18.395	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:09:18.395	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	7	6250000	67031250	144	650211	85	279744	1167	5032	13699	52248	52316	50221056	1380	200	49160	53501952	14	16	13699	246	558792704	560463872
2009-12-16 13:09:33.705	0	0	0	0	System Idle Process				0	0	2	1341143281250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:09:33.705	0	4	4	0	System				8	880	72	5461562500	0	254	6046246	17784	103430784	37675	1813742	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:09:33.705	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:09:33.705	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	651	15	10769843750	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:09:33.705	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:09:33.705	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4269375000	1100156250	15489	2440050	20695	7955127	382726	3148050	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:09:33.705	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146391	11754316	137291	11823159	275099	4028403	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:09:33.705	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7386	398914	7386	59388	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:09:33.705	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	261	11	27812500	16875000	7385	324968	7385	59228	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:09:33.705	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14769	679970	14767	118132	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:09:33.705	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223125000	19687500	14874	716716	14874	120028	9162	164668	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:09:33.705	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1349	57	544218750	642500000	186674	143512120	168651	12544695	52098	1121913	439189	27120	86868	24129536	1380	200	98276	27770880	96	138	439189	354	535433216	849555456
2009-12-16 13:09:33.705	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7391	355040	7391	59924	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:09:33.705	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275312500	31406250	44990	1801186	44954	1418800	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:09:33.705	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7419	553388	7418	134864	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:09:33.705	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7386	428258	7385	59104	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:09:33.705	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37555	1876438	37554	1507328	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:09:33.705	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7387	354544	7386	59264	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:09:33.705	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7387	325104	7412	220128	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:09:33.705	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7385	324968	7385	59228	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:09:33.705	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7436	594051	7388	59664	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:09:33.705	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7384	457746	7384	59068	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:09:33.705	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7408	386628	7408	62648	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:09:33.705	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7449	429775	7432	66190	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:09:33.705	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7389	473316	7395	60158	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:09:33.705	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7386	295552	7386	59388	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:09:33.705	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1695	19	2196406250	1827343750	90508	19689966	89782	8418519	191646	2190282	1411739	23456	30548	56238080	1380	200	59964	24018944	35	38	1411739	349	195026944	226025472
2009-12-16 13:09:33.705	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	430	10	124218750	38906250	1573	1958383	91	29019	46176	830116	32379	10812	11220	11710464	1380	200	18760	11071488	25	28	32379	252	123854848	141737984
2009-12-16 13:09:33.705	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:09:33.705	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:09:33.705	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:09:33.705	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	812	20	967812500	3481718750	10167	9417511	4752	3910560	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:09:33.705	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1196562500	40000000000	76814	13917187003	51539	1428117404	47581	13710334	715644	1502568	1538612	1374613504	1380	200	1475220	1538629632	156	270	715644	389	5812154368	5816467456
2009-12-16 13:09:33.705	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5217	5024	5072	1089536	1380	200	5788	5144576	7	8	5217	65	40542208	41066496
2009-12-16 13:09:33.705	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75312500	33593750	7342	647273	7214	219535	17595	272682	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:09:33.705	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4961	238284	4961	40140	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:09:33.705	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	272	5	68593750	27812500	1013	52673	9	1132	44325	942798	30585	7784	8320	17547264	1380	200	17416	7970816	13	17	30585	249	109629440	128147456
2009-12-16 13:09:33.705	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:09:33.705	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11945	51612	51660	47366144	1380	200	46284	52850688	13	15	11945	245	553938944	555610112
2009-12-16 13:09:33.705	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	21406250	9687500	192	3001978	977	1063885	5977	1581438	202629	16548	16628	22339584	1380	200	21880	16945152	14	17	202629	123	93016064	94130176
2009-12-16 13:09:33.705	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	1718750	423	882337	4363	1417683	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:09:33.705	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:09:33.705	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	7	6406250	69375000	144	650211	89	293414	1192	5040	13778	52404	52468	50384896	1380	200	49316	53661696	14	16	13778	246	558792704	560463872
2009-12-16 13:09:48.999	0	0	0	0	System Idle Process				0	0	2	1341144218750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:09:48.999	0	4	4	0	System				8	880	72	5461718750	0	254	6046246	17796	103726720	37683	1813980	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:09:48.999	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:09:48.999	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	649	15	10770000000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:09:48.999	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:09:48.999	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4270000000	1100312500	15491	2440150	20697	7955143	382781	3148486	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:09:48.999	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146401	11754944	137300	11823443	275111	4028475	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:09:48.999	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7387	398968	7387	59396	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:09:48.999	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	264	11	27812500	16875000	7386	325012	7386	59236	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:09:48.999	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14771	680062	14769	118148	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:09:48.999	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223281250	19687500	14876	716812	14876	120044	9163	164696	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:09:48.999	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1353	57	544687500	642500000	186715	143556000	168693	12587711	52104	1121977	439224	27120	86868	24129536	1380	200	98276	27770880	96	138	439224	354	535433216	849555456
2009-12-16 13:09:48.999	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7392	355088	7392	59932	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:09:48.999	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275312500	31406250	44999	1801534	44963	1419096	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:09:48.999	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7420	553452	7419	134872	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:09:48.999	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7387	428316	7386	59112	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:09:48.999	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37562	1876784	37561	1507624	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:09:48.999	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7388	354592	7387	59272	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:09:48.999	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7388	325148	7413	220136	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:09:48.999	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7386	325012	7386	59236	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:09:48.999	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7437	594113	7389	59672	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:09:48.999	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7385	457808	7385	59076	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:09:48.999	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7409	386680	7409	62656	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:09:48.999	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7450	429831	7433	66198	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:09:48.999	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7390	473380	7396	60166	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:09:48.999	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7387	295592	7387	59396	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:09:48.999	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1694	19	2196406250	1828281250	90512	19690190	89786	8418895	191650	2190282	1411855	23452	30548	56225792	1380	200	59964	24014848	35	38	1411855	349	195026944	226025472
2009-12-16 13:09:48.999	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46191	830244	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:09:48.999	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:09:48.999	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:09:48.999	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:09:48.999	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	810	20	967968750	3482031250	10172	9417992	4757	3917114	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:09:48.999	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1198906250	40288437500	76983	13988514070	51655	1432258065	47583	13710334	715710	1502568	1538612	1374654464	1380	200	1475220	1538629632	156	270	715710	389	5812154368	5816467456
2009-12-16 13:09:48.999	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5217	5024	5072	1089536	1380	200	5788	5144576	7	8	5217	65	40542208	41066496
2009-12-16 13:09:48.999	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7347	647843	7219	220448	17743	275050	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:09:48.999	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4962	238332	4962	40148	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:09:48.999	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:09:48.999	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:09:48.999	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:09:48.999	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	21562500	9843750	198	3003514	983	1089517	6216	1646526	202938	16548	16704	22339584	1380	200	21964	16945152	14	17	202938	123	93016064	94130176
2009-12-16 13:09:48.999	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	1718750	470	983857	5058	1593417	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:09:48.999	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:09:48.999	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	7	6406250	72031250	144	650211	93	307084	1217	5048	13859	52572	52640	50556928	1380	200	49488	53833728	14	16	13859	246	558792704	560463872
2009-12-16 13:10:04.310	0	0	0	0	System Idle Process				0	0	2	1341144843750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:10:04.310	0	4	4	0	System				8	881	72	5462031250	0	254	6046246	17800	103988864	37683	1814218	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:10:04.310	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:10:04.310	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	648	15	10770312500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:10:04.310	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:10:04.310	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4270937500	1100312500	15495	2440350	20701	7955175	382884	3149330	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:10:04.310	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146415	11755788	137313	11823759	275123	4028547	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:10:04.310	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7389	399076	7389	59412	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:10:04.310	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27812500	16875000	7388	325100	7388	59252	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:10:04.310	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14775	680246	14773	118180	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:10:04.310	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223281250	19687500	14880	717004	14880	120076	9164	164724	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:10:04.310	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1353	57	544843750	642656250	186778	143601000	168757	12630903	52110	1122041	439305	27120	86868	24129536	1380	200	98276	27770880	96	138	439305	354	535433216	849555456
2009-12-16 13:10:04.310	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7394	355184	7394	59948	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:10:04.310	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275312500	31406250	45009	1801942	44973	1419400	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:10:04.310	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7422	553580	7421	134888	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:10:04.310	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7389	428432	7388	59128	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:10:04.310	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37570	1877188	37569	1507928	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:10:04.310	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7390	354688	7389	59288	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:10:04.310	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7390	325236	7415	220152	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:10:04.310	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7388	325100	7388	59252	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:10:04.310	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7439	594237	7391	59688	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:10:04.310	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7387	457932	7387	59092	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:10:04.310	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7411	386784	7411	62672	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:10:04.310	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7452	429943	7435	66214	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:10:04.310	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7392	473508	7398	60182	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:10:04.310	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7389	295672	7389	59412	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:10:04.310	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1697	18	2197031250	1828750000	90516	19690414	89790	8419271	191655	2190282	1412009	23348	30548	56168448	1380	200	59964	23908352	35	38	1412009	349	194445312	226025472
2009-12-16 13:10:04.310	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46191	830244	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:10:04.310	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:10:04.310	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:10:04.310	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:10:04.310	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	813	20	967968750	3482500000	10179	9418954	4764	3929940	31917	2649578	240665	192020	236504	136421376	1380	200	154524	196628480	52	59	240665	653	558247936	589316096
2009-12-16 13:10:04.310	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1201718750	40576875000	77174	14065040288	51718	1435522520	47583	13710334	715769	1502568	1538612	1374695424	1380	200	1475220	1538629632	156	270	715769	389	5812154368	5816467456
2009-12-16 13:10:04.310	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5217	5024	5072	1089536	1380	200	5788	5144576	7	8	5217	65	40542208	41066496
2009-12-16 13:10:04.310	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7349	647967	7221	220464	17892	277434	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:10:04.310	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4964	238428	4964	40164	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:10:04.310	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:10:04.310	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:10:04.310	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:10:04.310	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	21718750	9843750	204	3005050	989	1115149	6454	1711614	203247	16548	16704	22339584	1380	200	21964	16945152	14	17	203247	123	93016064	94130176
2009-12-16 13:10:04.310	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	1718750	484	1008934	5114	1633314	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:10:04.310	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:10:04.310	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	7	6562500	74375000	144	650211	97	320753	1242	5056	13941	52748	52804	50733056	1380	200	49652	54013952	14	16	13941	246	558792704	560463872
2009-12-16 13:10:19.605	0	0	0	0	System Idle Process				0	0	2	1341145781250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:10:19.605	0	4	4	0	System				8	881	72	5462031250	0	254	6046246	17804	104251008	37683	1814456	6372	44	44	258048	1380	0	4736	94208	1	1	6372	0	2490368	6025216
2009-12-16 13:10:19.605	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:10:19.605	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	648	15	10770312500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:10:19.605	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:10:19.605	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4271718750	1100468750	15497	2440450	20703	7955191	382936	3149766	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:10:19.605	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	31	269218750	82968750	146425	11756416	137322	11824043	275135	4028619	7357	12160	12320	8372224	1380	200	13936	12451840	34	41	7357	115	75223040	76795904
2009-12-16 13:10:19.605	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7390	399130	7390	59420	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:10:19.605	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	270	11	27968750	16875000	7389	325144	7389	59260	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:10:19.605	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	150	9	12500000	4218750	14777	680338	14775	118196	4256	261584	3084	5896	6276	2138112	1380	200	7584	6037504	12	18	3084	119	69795840	71368704
2009-12-16 13:10:19.605	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223437500	19687500	14882	717100	14882	120092	9165	164752	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:10:19.605	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1358	57	545000000	642812500	186819	143644880	168799	12673919	52116	1122105	439340	27108	86868	24117248	1380	200	98276	27758592	96	138	439340	354	535433216	849555456
2009-12-16 13:10:19.605	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7395	355232	7395	59956	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:10:19.605	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275312500	31406250	45017	1802254	44981	1419660	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:10:19.605	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7423	553644	7422	134896	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:10:19.605	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7390	428490	7389	59136	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:10:19.605	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37577	1877534	37576	1508224	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:10:19.605	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7391	354736	7390	59296	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:10:19.605	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7391	325280	7416	220160	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:10:19.605	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7389	325144	7389	59260	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:10:19.605	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7440	594299	7392	59696	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:10:19.605	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7388	457994	7388	59100	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:10:19.605	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7412	386836	7412	62680	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:10:19.605	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7453	429999	7436	66222	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:10:19.605	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7393	473572	7399	60190	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:10:19.605	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7390	295712	7390	59420	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:10:19.605	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1697	18	2197343750	1828906250	90520	19690638	89794	8419647	191659	2190282	1412112	23348	30548	56168448	1380	200	59964	23908352	35	38	1412112	349	194445312	226025472
2009-12-16 13:10:19.605	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46191	830244	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:10:19.605	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:10:19.605	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:10:19.605	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:10:19.605	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	813	20	967968750	3482968750	10187	9419916	4772	3942860	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:10:19.605	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1204687500	40865000000	77360	14136488409	52251	1445021987	47583	13710334	715866	1502568	1538612	1374740480	1380	200	1475220	1538629632	156	270	715866	389	5812154368	5816467456
2009-12-16 13:10:19.605	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5221	5024	5072	1089536	1380	200	5788	5144576	7	8	5221	65	40542208	41066496
2009-12-16 13:10:19.605	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7354	648537	7226	221377	18040	279802	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:10:19.605	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4965	238476	4965	40172	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:10:19.605	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:10:19.605	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:10:19.605	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:10:19.605	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	21875000	9843750	210	3006586	995	1140781	6696	1777014	203556	16548	16704	22339584	1380	200	21964	16945152	14	17	203556	123	93016064	94130176
2009-12-16 13:10:19.605	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	1875000	501	1033387	5165	1670854	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:10:19.605	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:10:19.605	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	6562500	77031250	144	650211	101	334423	1267	5064	14020	52900	52968	50896896	1380	200	49820	54169600	14	16	14020	246	558792704	560463872
2009-12-16 13:10:34.917	0	0	0	0	System Idle Process				0	0	2	1341146562500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:10:34.917	0	4	4	0	System				8	884	72	5462343750	0	254	6046246	17809	104578688	37710	1815044	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:10:34.917	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:10:34.917	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	649	15	10770468750	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:10:34.917	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:10:34.917	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	371	18	4272500000	1100937500	15501	2440650	20707	7955223	383039	3150610	5704	6604	10364	5185536	1380	200	8948	6762496	17	26	5704	87	319545344	361951232
2009-12-16 13:10:34.917	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	710	32	269218750	83281250	146458	11758590	137352	11826635	275225	4031611	7363	12224	12320	8396800	1380	200	13936	12517376	34	41	7363	115	75747328	76795904
2009-12-16 13:10:34.917	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7392	399238	7392	59436	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:10:34.917	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	270	11	27968750	16875000	7391	325232	7391	59276	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:10:34.917	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14781	680522	14779	118228	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:10:34.917	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223593750	19687500	14886	717292	14886	120124	9182	164924	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:10:34.917	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1366	57	545156250	642968750	186899	143692156	168880	12718441	52140	1122195	439424	27120	86868	24129536	1380	200	98276	27770880	96	138	439424	354	535433216	849555456
2009-12-16 13:10:34.917	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7397	355328	7397	59972	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:10:34.917	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275312500	31406250	45027	1802662	44991	1419964	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:10:34.917	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7425	553772	7424	134912	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:10:34.917	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7392	428606	7391	59152	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:10:34.917	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219218750	11718750	37585	1877938	37584	1508528	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:10:34.917	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7393	354832	7392	59312	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:10:34.917	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7393	325368	7418	220176	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:10:34.917	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7391	325232	7391	59276	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:10:34.917	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7442	594423	7394	59712	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:10:34.917	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7390	458118	7390	59116	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:10:34.917	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7414	386940	7414	62696	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:10:34.917	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7455	430111	7438	66238	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:10:34.917	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7395	473700	7401	60206	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:10:34.917	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7392	295792	7392	59436	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:10:34.917	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1696	18	2197812500	1829531250	90524	19690862	89798	8420023	191663	2190282	1412285	23348	30548	56164352	1380	200	59964	23908352	35	38	1412285	349	194445312	226025472
2009-12-16 13:10:34.917	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46191	830244	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:10:34.917	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:10:34.917	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:10:34.917	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:10:34.917	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	813	20	968125000	3483437500	10191	9420397	4776	3949320	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:10:34.917	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1206562500	41152031250	77553	14213041934	53096	1457306000	47583	13710334	715928	1502632	1538612	1374810112	1380	200	1475220	1538695168	156	270	715928	389	5812219904	5816467456
2009-12-16 13:10:34.917	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5221	5024	5072	1089536	1380	200	5788	5144576	7	8	5221	65	40542208	41066496
2009-12-16 13:10:34.917	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7360	649169	7232	222298	18189	282186	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:10:34.917	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4967	238572	4967	40188	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:10:34.917	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:10:34.917	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:10:34.917	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:10:34.917	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	22343750	9843750	216	3008122	1001	1166413	6934	1842102	203865	16548	16704	22339584	1380	200	21964	16945152	14	17	203865	123	93016064	94130176
2009-12-16 13:10:34.917	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	2031250	526	1080619	5259	1745862	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:10:34.917	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:10:34.917	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	6875000	79375000	144	650211	105	348094	1292	5072	14101	53064	53124	51068928	1380	200	49980	54337536	14	16	14101	246	558792704	560463872
2009-12-16 13:10:50.260	0	0	0	0	System Idle Process				0	0	2	1341147031250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:10:50.260	0	4	4	0	System				8	881	72	5462343750	0	254	6046246	17821	104874624	37741	1815378	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:10:50.260	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:10:50.260	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	648	15	10770625000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:10:50.260	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:10:50.260	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	370	17	4272812500	1100937500	15503	2440750	20709	7955239	383094	3151046	5704	6556	10364	5169152	1380	200	8948	6713344	17	26	5704	87	319021056	361951232
2009-12-16 13:10:50.260	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	710	32	269218750	83281250	146468	11759218	137361	11826919	275237	4031683	7363	12224	12320	8396800	1380	200	13936	12517376	34	41	7363	115	75747328	76795904
2009-12-16 13:10:50.260	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7393	399292	7393	59444	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:10:50.260	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	270	11	27968750	16875000	7392	325276	7392	59284	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:10:50.260	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14783	680614	14781	118244	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:10:50.260	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223593750	19687500	14888	717388	14888	120140	9183	164952	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:10:50.260	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1366	57	545156250	643125000	186940	143736036	168922	12761457	52146	1122259	439459	27120	86868	24129536	1380	200	98276	27770880	96	138	439459	354	535433216	849555456
2009-12-16 13:10:50.260	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7398	355376	7398	59980	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:10:50.260	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275468750	31406250	45036	1803010	45000	1420260	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:10:50.260	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7426	553836	7425	134920	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:10:50.260	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7393	428664	7392	59160	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:10:50.260	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37594	1878380	37593	1508920	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:10:50.260	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7394	354880	7393	59320	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:10:50.260	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7394	325412	7419	220184	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:10:50.260	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7392	325276	7392	59284	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:10:50.260	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7443	594485	7395	59720	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:10:50.260	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7391	458180	7391	59124	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:10:50.260	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7415	386992	7415	62704	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:10:50.260	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7456	430167	7439	66246	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:10:50.260	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7396	473764	7402	60214	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:10:50.260	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7393	295832	7393	59444	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:10:50.260	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1697	18	2197968750	1829531250	90528	19691086	89802	8420399	191667	2190282	1412389	23176	30548	55996416	1380	200	59964	23732224	35	38	1412389	349	194445312	226025472
2009-12-16 13:10:50.260	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46203	830372	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:10:50.260	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:10:50.260	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:10:50.260	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:10:50.260	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	813	20	968437500	3483906250	10199	9421359	4784	3962240	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:10:50.260	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1209062500	41442500000	77745	14289610055	53174	1460826589	47585	13710334	716000	1502632	1538612	1374912512	1380	200	1475220	1538695168	156	270	716000	389	5812219904	5816467456
2009-12-16 13:10:50.260	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5221	5024	5072	1089536	1380	200	5788	5144576	7	8	5221	65	40542208	41066496
2009-12-16 13:10:50.260	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7365	649739	7237	223211	18337	284554	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:10:50.260	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4968	238620	4968	40196	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:10:50.260	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:10:50.260	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:10:50.260	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:10:50.260	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	22500000	9843750	222	3009658	1007	1192045	7173	1907190	204174	16548	16704	22339584	1380	200	21964	16945152	14	17	204174	123	93016064	94130176
2009-12-16 13:10:50.260	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1718750	2031250	540	1104306	5306	1783308	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:10:50.260	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:10:50.260	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	7343750	81718750	144	650211	109	361766	1317	5080	14184	53240	53308	51249152	1380	200	50164	54517760	14	16	14184	246	558792704	560463872
2009-12-16 13:11:05.588	0	0	0	0	System Idle Process				0	0	2	1341147500000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:11:05.588	0	4	4	0	System				8	881	72	5462656250	0	254	6046246	17825	105136768	37741	1815616	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:11:05.588	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:11:05.588	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	647	15	10771250000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:11:05.588	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:11:05.588	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	370	17	4273437500	1101406250	15507	2440950	20713	7955271	383197	3151890	5704	6556	10364	5169152	1380	200	8948	6713344	17	26	5704	87	319021056	361951232
2009-12-16 13:11:05.588	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	710	32	269218750	83281250	146482	11760062	137374	11827235	275249	4031755	7363	12224	12320	8396800	1380	200	13936	12517376	34	41	7363	115	75747328	76795904
2009-12-16 13:11:05.588	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7395	399400	7395	59460	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:11:05.588	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27968750	16875000	7394	325364	7394	59300	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:11:05.588	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14787	680798	14785	118276	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:11:05.588	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223593750	19687500	14892	717580	14892	120172	9184	164980	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:11:05.588	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1364	58	545156250	643437500	187003	143781036	168986	12804649	52152	1122323	439594	27152	86868	24129536	1380	200	98276	27803648	96	138	439594	354	535957504	849555456
2009-12-16 13:11:05.588	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7400	355472	7400	59996	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:11:05.588	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275625000	31406250	45045	1803382	45009	1420528	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:11:05.588	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7428	553964	7427	134936	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:11:05.588	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7395	428780	7394	59176	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:11:05.588	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37602	1878784	37601	1509224	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:11:05.588	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7396	354976	7395	59336	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:11:05.588	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7396	325500	7421	220200	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:11:05.588	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7394	325364	7394	59300	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:11:05.588	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7445	594609	7397	59736	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:11:05.588	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7393	458304	7393	59140	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:11:05.588	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7417	387096	7417	62720	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:11:05.588	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7458	430279	7441	66262	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:11:05.588	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7398	473892	7404	60230	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:11:05.588	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7395	295912	7395	59460	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:11:05.588	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1678	16	2198281250	1830000000	90532	19691310	89806	8420775	191671	2190282	1412583	22808	30548	53460992	1380	200	59964	23355392	31	38	1412583	349	164851712	226025472
2009-12-16 13:11:05.588	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46203	830372	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:11:05.588	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:11:05.588	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:11:05.588	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:11:05.588	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	968437500	3484218750	10203	9421840	4788	3968700	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:11:05.588	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1210937500	41729687500	77923	14361050867	53272	1464665500	47585	13710334	716061	1502632	1538612	1374957568	1380	200	1475220	1538695168	156	270	716061	389	5812219904	5816467456
2009-12-16 13:11:05.588	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5221	5024	5072	1089536	1380	200	5788	5144576	7	8	5221	65	40542208	41066496
2009-12-16 13:11:05.588	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7367	649863	7239	223227	18485	286922	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:11:05.588	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4970	238716	4970	40212	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:11:05.588	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:11:05.588	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:11:05.588	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:11:05.588	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	22656250	10000000	228	3011194	1013	1217677	7411	1972278	204483	16548	16704	22339584	1380	200	21964	16945152	14	17	204483	123	93016064	94130176
2009-12-16 13:11:05.588	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2031250	587	1206144	6001	1959096	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:11:05.588	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:11:05.588	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	7343750	83906250	144	650211	113	375438	1342	5088	14266	53396	53460	51425280	1380	200	50332	54677504	14	16	14266	246	558792704	560463872
2009-12-16 13:11:20.900	0	0	0	0	System Idle Process				0	0	2	1341148125000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:11:20.900	0	4	4	0	System				8	881	72	5462656250	0	254	6046246	17829	105398912	37741	1815854	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:11:20.900	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:11:20.900	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	646	15	10771250000	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:11:20.900	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:11:20.900	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4274062500	1101562500	15509	2441050	20715	7955287	383249	3152326	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:11:20.900	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	32	269218750	83281250	146492	11760690	137383	11827519	275261	4031827	7367	12220	12320	8392704	1380	200	13936	12513280	34	41	7367	115	75747328	76795904
2009-12-16 13:11:20.900	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7396	399454	7396	59468	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:11:20.900	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27968750	16875000	7395	325408	7395	59308	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:11:20.900	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14789	680890	14787	118292	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:11:20.900	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223750000	19687500	14894	717676	14894	120188	9185	165008	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:11:20.900	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1364	58	545468750	643593750	187044	143824916	169028	12847665	52158	1122387	439631	27164	86868	24137728	1380	200	98276	27815936	96	138	439631	354	535957504	849555456
2009-12-16 13:11:20.900	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7401	355520	7401	60004	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:11:20.900	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	275781250	31406250	45054	1803730	45018	1420824	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:11:20.900	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7429	554028	7428	134944	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:11:20.900	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7396	428838	7395	59184	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:11:20.900	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37609	1879130	37608	1509520	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:11:20.900	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7397	355024	7396	59344	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:11:20.900	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7397	325544	7422	220208	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:11:20.900	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7395	325408	7395	59308	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:11:20.900	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7446	594671	7398	59744	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:11:20.900	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7394	458366	7394	59148	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:11:20.900	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7418	387148	7418	62728	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:11:20.900	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7459	430335	7442	66270	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:11:20.900	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7399	473956	7405	60238	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:11:20.900	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7396	295952	7396	59468	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:11:20.900	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1679	16	2198281250	1830156250	90536	19691534	89810	8421151	191675	2190282	1412744	22688	30548	53338112	1380	200	59964	23232512	31	38	1412744	349	164851712	226025472
2009-12-16 13:11:20.900	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46203	830372	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:11:20.900	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:11:20.900	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:11:20.900	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:11:20.900	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	968750000	3485312500	10211	9422802	4796	3981620	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:11:20.900	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1212343750	42019843750	78119	14437553452	53394	1470588973	47585	13710334	716149	1502632	1538612	1374998528	1380	200	1475220	1538695168	156	270	716149	389	5812219904	5816467456
2009-12-16 13:11:20.900	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5221	5024	5072	1089536	1380	200	5788	5144576	7	8	5221	65	40542208	41066496
2009-12-16 13:11:20.900	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7372	650433	7244	224140	18633	289290	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:11:20.900	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4971	238764	4971	40220	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:11:20.900	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:11:20.900	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:11:20.900	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:11:20.900	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	22812500	10000000	234	3012730	1019	1243309	7653	2037678	204792	16548	16704	22339584	1380	200	21964	16945152	14	17	204792	123	93016064	94130176
2009-12-16 13:11:20.900	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2031250	615	1254987	6103	2036388	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:11:20.900	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:11:20.900	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	7500000	86406250	144	650211	117	389111	1367	5096	14348	53572	53640	51601408	1380	200	50508	54857728	14	16	14348	246	560889856	562036736
2009-12-16 13:11:36.198	0	0	0	0	System Idle Process				0	0	2	1341148281250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:11:36.198	0	4	4	0	System				8	881	72	5462656250	0	254	6046246	17833	105661056	37741	1816092	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:11:36.198	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:11:36.198	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	646	15	10771562500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:11:36.198	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:11:36.198	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4274687500	1102187500	15513	2441250	20719	7955319	383352	3153170	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:11:36.198	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	32	269218750	83281250	146506	11761534	137396	11827835	275273	4031899	7367	12220	12320	8392704	1380	200	13936	12513280	34	41	7367	115	75747328	76795904
2009-12-16 13:11:36.198	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7398	399562	7398	59484	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:11:36.198	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27968750	16875000	7397	325496	7397	59324	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:11:36.198	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14793	681074	14791	118324	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:11:36.198	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223750000	19687500	14898	717868	14898	120220	9188	165036	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:11:36.198	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1368	58	545468750	643593750	187107	143869916	169092	12890857	52164	1122451	439712	27164	86868	24137728	1380	200	98276	27815936	96	138	439712	354	535957504	849555456
2009-12-16 13:11:36.198	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7403	355616	7403	60020	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:11:36.198	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276093750	31406250	45063	1804102	45027	1421092	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:11:36.198	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7431	554156	7430	134960	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:11:36.198	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7398	428954	7397	59200	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:11:36.198	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37617	1879534	37616	1509824	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:11:36.198	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7399	355120	7398	59360	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:11:36.198	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7399	325632	7424	220224	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:11:36.198	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7397	325496	7397	59324	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:11:36.198	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7448	594795	7400	59760	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:11:36.198	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7396	458490	7396	59164	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:11:36.198	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7420	387252	7420	62744	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:11:36.198	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7461	430447	7444	66286	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:11:36.198	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7401	474084	7407	60254	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:11:36.198	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7398	296032	7398	59484	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:11:36.198	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1679	16	2198437500	1830468750	90540	19691758	89814	8421527	191679	2190282	1412928	22796	30548	53444608	1380	200	59964	23343104	31	38	1412928	349	164851712	226025472
2009-12-16 13:11:36.198	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46203	830372	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:11:36.198	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:11:36.198	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:11:36.198	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:11:36.198	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	968750000	3485937500	10215	9423283	4800	3988080	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:11:36.198	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1213906250	42307500000	78300	14508995169	53478	1473926970	47585	13710334	716229	1502632	1538612	1375043584	1380	200	1475220	1538695168	156	270	716229	389	5812219904	5816467456
2009-12-16 13:11:36.198	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5225	5024	5072	1089536	1380	200	5788	5144576	7	8	5225	65	40542208	41066496
2009-12-16 13:11:36.198	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75468750	33593750	7378	651065	7250	225061	18782	291674	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:11:36.198	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4973	238860	4973	40236	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:11:36.198	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:11:36.198	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:11:36.198	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:11:36.198	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	23125000	10312500	240	3014266	1025	1268941	7891	2102766	205101	16548	16704	22339584	1380	200	21964	16945152	14	17	205101	123	93016064	94130176
2009-12-16 13:11:36.198	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2187500	629	1278827	6151	2073885	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:11:36.198	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:11:36.198	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	7500000	89218750	144	650211	121	402784	1392	5104	14426	53724	53788	51761152	1380	200	50660	55013376	14	16	14426	246	560889856	562036736
2009-12-16 13:11:51.528	0	0	0	0	System Idle Process				0	0	2	1341158750000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:11:51.528	0	4	4	0	System				8	881	72	5462656250	0	254	6046246	17845	105956992	37749	1816330	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:11:51.528	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:11:51.528	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	646	15	10771562500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:11:51.528	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:11:51.528	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4275156250	1102187500	15515	2441350	20721	7955335	383407	3153606	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:11:51.528	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	706	32	269218750	83281250	146516	11762162	137405	11828119	275285	4031971	7367	12220	12320	8392704	1380	200	13936	12513280	34	41	7367	115	75747328	76795904
2009-12-16 13:11:51.528	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7399	399616	7399	59492	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:11:51.528	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27968750	16875000	7398	325540	7398	59332	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:11:51.528	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14795	681166	14793	118340	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:11:51.528	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223750000	19687500	14900	717964	14900	120236	9189	165064	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:11:51.528	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1368	58	545468750	643750000	187148	143913796	169134	12933873	52170	1122515	439747	27164	86868	24137728	1380	200	98276	27815936	96	138	439747	354	535957504	849555456
2009-12-16 13:11:51.528	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7404	355664	7404	60028	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:11:51.528	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276093750	31406250	45072	1804450	45036	1421388	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:11:51.528	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7432	554220	7431	134968	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:11:51.528	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7399	429012	7398	59208	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:11:51.528	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37624	1879880	37623	1510120	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:11:51.528	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7400	355168	7399	59368	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:11:51.528	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7400	325676	7425	220232	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:11:51.528	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7398	325540	7398	59332	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:11:51.528	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7449	594857	7401	59768	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:11:51.528	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	4843750	1875000	7397	458552	7397	59172	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:11:51.528	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7421	387304	7421	62752	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:11:51.528	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7462	430503	7445	66294	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:11:51.528	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7402	474148	7408	60262	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:11:51.528	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7399	296072	7399	59492	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:11:51.528	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1679	16	2198593750	1830625000	90544	19691982	89818	8421903	191683	2190282	1413046	22800	30548	53448704	1380	200	59964	23347200	31	38	1413046	349	164851712	226025472
2009-12-16 13:11:51.528	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46215	830500	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:11:51.528	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:11:51.528	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:11:51.528	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:11:51.528	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	808	20	969062500	3486875000	10223	9424245	4808	4001000	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:11:51.528	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1215781250	42583750000	78492	14582130842	53550	1477371744	47587	13710334	716286	1502632	1538612	1375084544	1380	200	1475220	1538695168	161	270	716286	389	5812219904	5816467456
2009-12-16 13:11:51.528	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5225	5024	5072	1089536	1380	200	5788	5144576	7	8	5225	65	40542208	41066496
2009-12-16 13:11:51.528	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75625000	33593750	7383	651635	7255	225974	18930	294042	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:11:51.528	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4974	238908	4974	40244	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:11:51.528	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:11:51.528	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:11:51.528	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:11:51.528	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	23593750	10312500	246	3015802	1031	1294573	8130	2167854	205410	16548	16704	22339584	1380	200	21964	16945152	14	17	205410	123	93016064	94130176
2009-12-16 13:11:51.528	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2343750	643	1302987	6201	2111491	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:11:51.528	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:11:51.528	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	7500000	91718750	144	650211	125	416457	1417	5112	14508	53892	53960	51937280	1380	200	50836	55185408	14	16	14508	246	560889856	562036736
2009-12-16 13:12:06.827	0	0	0	0	System Idle Process				0	0	2	1341159843750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:12:06.827	0	4	4	0	System				8	881	72	5462812500	0	254	6046246	17849	106219136	37749	1816568	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:12:06.827	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:12:06.827	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	646	15	10771562500	35312500	122740	8667695	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:12:06.827	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:12:06.827	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4275781250	1102500000	15519	2441550	20725	7955367	383510	3154450	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:12:06.827	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	707	32	269375000	83281250	146530	11763006	137418	11828435	275295	4032043	7371	12220	12320	8392704	1380	200	13936	12513280	34	41	7371	115	75747328	76795904
2009-12-16 13:12:06.827	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	91	6	5000000	1562500	7401	399724	7401	59508	380	12157	1529	1552	1652	1675264	1380	200	4028	1589248	6	8	1529	54	30121984	31051776
2009-12-16 13:12:06.827	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27968750	16875000	7400	325628	7400	59348	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:12:06.827	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	154	9	12500000	4218750	14799	681350	14797	118372	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:12:06.827	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	190	15	223750000	19687500	14904	718156	14904	120268	9190	165092	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:12:06.827	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1374	58	545625000	644218750	187211	143958796	169198	12977065	52176	1122579	439846	27176	86868	24150016	1380	200	98276	27828224	96	138	439846	354	535957504	849555456
2009-12-16 13:12:06.827	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	127	13	16875000	5156250	7406	355760	7406	60044	392	4052	2553	5056	5300	1880064	1380	200	7424	5177344	10	12	2553	102	59080704	61669376
2009-12-16 13:12:06.827	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276093750	31406250	45082	1804858	45046	1421692	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:12:06.827	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7434	554348	7433	134984	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:12:06.827	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7401	429128	7400	59224	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:12:06.827	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37632	1880284	37631	1510424	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:12:06.827	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7402	355264	7401	59384	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:12:06.827	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7402	325764	7427	220248	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:12:06.827	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7400	325628	7400	59348	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:12:06.827	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7451	594981	7403	59784	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:12:06.827	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7399	458676	7399	59188	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:12:06.827	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7423	387408	7423	62768	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:12:06.827	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	149	17	6406250	1562500	7464	430615	7447	66310	862	69544	2069	2704	22592	2650112	1380	200	5692	2768896	10	12	2069	97	74002432	74534912
2009-12-16 13:12:06.827	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7404	474276	7410	60278	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:12:06.827	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7401	296152	7401	59508	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:12:06.827	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1679	16	2198906250	1831406250	90548	19692206	89822	8422279	191687	2190282	1413233	22800	30548	53448704	1380	200	59964	23347200	31	38	1413233	349	164851712	226025472
2009-12-16 13:12:06.827	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46215	830500	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:12:06.827	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:12:06.827	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:12:06.827	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:12:06.827	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	969375000	3487031250	10227	9424726	4812	4007460	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:12:06.827	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1217031250	42870156250	78670	14656971334	53680	1482965386	47587	13710334	716378	1502632	1538612	1375129600	1380	200	1475220	1538695168	156	270	716378	389	5812219904	5816467456
2009-12-16 13:12:06.827	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5225	5024	5072	1089536	1380	200	5788	5144576	7	8	5225	65	40542208	41066496
2009-12-16 13:12:06.827	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75625000	33593750	7385	651759	7257	225990	19079	296426	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:12:06.827	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4976	239004	4976	40260	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:12:06.827	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:12:06.827	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:12:06.827	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:12:06.827	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	23750000	10781250	252	3017338	1037	1320205	8368	2232942	205719	16548	16704	22339584	1380	200	21964	16945152	14	17	205719	123	93016064	94130176
2009-12-16 13:12:06.827	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2500000	694	1419780	6883	2311832	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:12:06.827	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:12:06.827	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	7656250	94218750	144	650211	129	430130	1442	5120	14592	54076	54144	52121600	1380	200	51012	55373824	14	16	14592	246	560889856	562036736
2009-12-16 13:12:22.142	0	0	0	0	System Idle Process				0	0	2	1341160156250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:12:22.142	0	4	4	0	System				8	881	72	5463281250	0	254	6046246	17853	106481280	37749	1816806	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:12:22.142	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:12:22.142	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	641	15	10771875000	35312500	122799	8669327	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:12:22.142	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:12:22.142	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4276250000	1102656250	15521	2441650	20727	7955383	383562	3154886	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:12:22.142	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	703	32	269375000	83281250	146540	11763634	137427	11828719	275314	4032115	7371	12220	12320	8392704	1380	200	13936	12513280	34	41	7371	115	75747328	76795904
2009-12-16 13:12:22.142	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7402	399778	7402	59516	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:12:22.142	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	267	11	27968750	16875000	7401	325672	7401	59356	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:12:22.142	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	153	9	12500000	4218750	14801	681442	14799	118388	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:12:22.142	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223750000	19687500	14906	718252	14906	120284	9191	165120	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:12:22.142	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1375	58	545625000	644531250	187252	144002676	169240	13020081	52184	1122643	439900	27176	86868	24150016	1380	200	98276	27828224	96	138	439900	354	535957504	849555456
2009-12-16 13:12:22.142	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7407	355808	7407	60052	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:12:22.142	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276250000	31406250	45090	1805170	45054	1421952	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:12:22.142	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7435	554412	7434	134992	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:12:22.142	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7402	429186	7401	59232	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:12:22.142	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37639	1880630	37638	1510720	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:12:22.142	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7403	355312	7402	59392	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:12:22.142	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7403	325808	7428	220256	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:12:22.142	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7401	325672	7401	59356	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:12:22.142	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7452	595043	7404	59792	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:12:22.142	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7400	458738	7400	59196	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:12:22.142	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7424	387460	7424	62776	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:12:22.142	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7465	430671	7448	66318	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:12:22.142	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7405	474340	7411	60286	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:12:22.142	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7402	296192	7402	59516	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:12:22.142	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1679	16	2199062500	1832187500	90552	19692430	89826	8422655	191691	2190282	1413380	22644	30548	53293056	1380	200	59964	23187456	31	38	1413380	349	164851712	226025472
2009-12-16 13:12:22.142	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46215	830500	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:12:22.142	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:12:22.142	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:12:22.142	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:12:22.142	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	969375000	3487656250	10235	9425688	4820	4020380	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:12:22.142	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1218125000	43159375000	78853	14728435839	53775	1487200341	47587	13710334	716436	1502632	1538612	1375174656	1380	200	1475220	1538695168	156	270	716436	389	5812219904	5816467456
2009-12-16 13:12:22.142	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5225	5024	5072	1089536	1380	200	5788	5144576	7	8	5225	65	40542208	41066496
2009-12-16 13:12:22.142	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75625000	33593750	7390	652329	7262	226903	19227	298794	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:12:22.142	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4977	239052	4977	40268	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:12:22.142	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:12:22.142	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:12:22.142	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	239	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:12:22.142	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	23750000	10937500	258	3018874	1043	1345837	8610	2298342	206028	16548	16704	22339584	1380	200	21964	16945152	14	17	206028	123	93016064	94130176
2009-12-16 13:12:22.142	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2500000	718	1453833	6999	2364628	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:12:22.142	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:12:22.142	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	228	7	8125000	96406250	144	650211	133	443803	1467	5128	14666	54212	54276	52269056	1380	200	51156	55513088	14	16	14666	246	560889856	562036736
2009-12-16 13:12:37.442	0	0	0	0	System Idle Process				0	0	2	1341160312500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:12:37.442	0	4	4	0	System				8	881	72	5463593750	0	254	6046246	17858	106808960	37749	1817044	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:12:37.442	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:12:37.442	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	641	15	10772031250	35312500	122802	8669375	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:12:37.442	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:12:37.442	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4277031250	1103125000	15525	2441850	20731	7955415	383665	3155730	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:12:37.442	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	703	32	269531250	83281250	146554	11764478	137440	11829035	275326	4032187	7375	12220	12320	8392704	1380	200	13936	12513280	34	41	7375	115	75747328	76795904
2009-12-16 13:12:37.442	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7404	399886	7404	59532	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:12:37.442	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	27968750	16875000	7403	325760	7403	59372	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:12:37.442	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	153	9	12500000	4218750	14805	681626	14803	118420	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:12:37.442	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223906250	19687500	14910	718444	14910	120316	9194	165148	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:12:37.442	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1375	58	545937500	644687500	187315	144047676	169304	13063273	52190	1122707	440017	27172	86868	24150016	1380	200	98276	27824128	96	138	440017	354	535957504	849555456
2009-12-16 13:12:37.442	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7409	355904	7409	60068	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:12:37.442	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276250000	31406250	45100	1805578	45064	1422256	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:12:37.442	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7437	554540	7436	135008	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:12:37.442	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7404	429302	7403	59248	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:12:37.442	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37647	1881034	37646	1511024	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:12:37.442	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7405	355408	7404	59408	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:12:37.442	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7405	325896	7430	220272	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:12:37.442	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7403	325760	7403	59372	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:12:37.442	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7454	595167	7406	59808	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:12:37.442	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7402	458862	7402	59212	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:12:37.442	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7426	387564	7426	62792	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:12:37.442	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7467	430783	7450	66334	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:12:37.442	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7407	474468	7413	60302	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:12:37.442	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7404	296272	7404	59532	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:12:37.442	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1675	16	2199218750	1832500000	90556	19692654	89830	8423031	191695	2190282	1413622	22608	30548	53260288	1380	200	59964	23150592	31	38	1413622	349	164851712	226025472
2009-12-16 13:12:37.442	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46215	830500	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:12:37.442	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:12:37.442	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:12:37.442	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:12:37.442	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	970000000	3487968750	10239	9426169	4824	4026840	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:12:37.442	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1221250000	43446406250	79094	14804391348	53843	1490256817	47587	13710334	716549	1502632	1538612	1375215616	1380	200	1475220	1538695168	156	270	716549	389	5812219904	5816467456
2009-12-16 13:12:37.442	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5225	5024	5072	1089536	1380	200	5788	5144576	7	8	5225	65	40542208	41066496
2009-12-16 13:12:37.442	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75625000	33593750	7396	652961	7268	227824	19376	301178	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:12:37.442	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4979	239148	4979	40284	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:12:37.442	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:12:37.442	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:12:37.442	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:12:37.442	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	23906250	11093750	264	3020410	1049	1371469	8848	2363430	206337	16548	16704	22339584	1380	200	21964	16945152	14	17	206337	123	93016064	94130176
2009-12-16 13:12:37.442	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	1875000	2500000	732	1477752	7046	2402074	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:12:37.442	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:12:37.442	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	7	8437500	98750000	144	650211	137	457475	1492	5136	14747	54380	54448	52441088	1380	200	51328	55685120	14	16	14747	246	560889856	562036736
2009-12-16 13:12:52.758	0	0	0	0	System Idle Process				0	0	2	1341161718750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:12:52.758	0	4	4	0	System				8	881	72	5464218750	0	254	6046246	17870	107104896	37757	1817282	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:12:52.758	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:12:52.758	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	641	15	10772343750	35312500	122802	8669375	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:12:52.758	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:12:52.758	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4277500000	1103125000	15527	2441950	20733	7955431	383720	3156166	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:12:52.758	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	704	32	269531250	83281250	146569	11765558	137453	11829823	275347	4032331	7375	12220	12320	8392704	1380	200	13936	12513280	34	41	7375	115	75747328	76795904
2009-12-16 13:12:52.758	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7405	399940	7405	59540	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:12:52.758	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	27968750	16875000	7404	325804	7404	59380	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:12:52.758	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	153	9	12500000	4218750	14807	681718	14805	118436	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:12:52.758	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223906250	19687500	14912	718540	14912	120332	9195	165176	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:12:52.758	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1382	58	545937500	645156250	187360	144092060	169350	13106741	52199	1122771	440127	27116	86868	24092672	1380	200	98276	27766784	96	138	440127	354	535957504	849555456
2009-12-16 13:12:52.758	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7410	355952	7410	60076	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:12:52.758	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276406250	31406250	45108	1805890	45072	1422516	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:12:52.758	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7438	554604	7437	135016	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:12:52.758	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7405	429360	7404	59256	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:12:52.758	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37654	1881380	37653	1511320	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:12:52.758	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7406	355456	7405	59416	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:12:52.758	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7406	325940	7431	220280	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:12:52.758	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7404	325804	7404	59380	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:12:52.758	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7455	595229	7407	59816	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:12:52.758	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7403	458924	7403	59220	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:12:52.758	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7427	387616	7427	62800	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:12:52.758	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7468	430839	7451	66342	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:12:52.758	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7408	474532	7414	60310	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:12:52.758	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7405	296312	7405	59540	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:12:52.758	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1674	16	2199687500	1832500000	90560	19692878	89834	8423407	191699	2190282	1413780	22804	30548	53452800	1380	200	59964	23351296	31	38	1413780	349	164851712	226025472
2009-12-16 13:12:52.758	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46227	830628	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:12:52.758	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:12:52.758	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:12:52.758	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:12:52.758	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	970312500	3488281250	10247	9427131	4832	4039760	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:12:52.758	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1222968750	43732187500	79280	14875847661	53939	1495025069	47589	13710334	716635	1502632	1538612	1375260672	1380	200	1475220	1538695168	156	270	716635	389	5812219904	5816467456
2009-12-16 13:12:52.758	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5229	5024	5072	1089536	1380	200	5788	5144576	7	8	5229	65	40542208	41066496
2009-12-16 13:12:52.758	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75781250	33593750	7401	653531	7273	228737	19524	303546	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:12:52.758	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4980	239196	4980	40292	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:12:52.758	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:12:52.758	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:12:52.758	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:12:52.758	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	23906250	11093750	270	3021946	1055	1397101	9087	2428518	206646	16548	16704	22339584	1380	200	21964	16945152	14	17	206646	123	93016064	94130176
2009-12-16 13:12:52.758	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2031250	2656250	749	1502382	7099	2439728	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:12:52.758	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:12:52.758	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	224	7	8437500	101406250	144	650211	141	471147	1517	5144	14829	54556	54620	52617216	1380	200	51496	55865344	14	16	14829	246	565084160	566231040
2009-12-16 13:13:08.121	0	0	0	0	System Idle Process				0	0	2	1341162187500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:13:08.121	0	4	4	0	System				8	881	72	5464218750	0	254	6046246	17874	107367040	37757	1817520	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:13:08.121	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:13:08.121	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	641	15	10772343750	35312500	122802	8669375	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:13:08.121	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:13:08.121	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4278437500	1103281250	15531	2442150	20737	7955463	383823	3157010	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:13:08.121	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	704	32	269531250	83281250	146583	11766402	137466	11830139	275359	4032403	7375	12220	12320	8392704	1380	200	13936	12513280	34	41	7375	115	75747328	76795904
2009-12-16 13:13:08.121	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7407	400048	7407	59556	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:13:08.121	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	27968750	17031250	7406	325892	7406	59396	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:13:08.121	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	153	9	12500000	4218750	14811	681902	14809	118468	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:13:08.121	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223906250	19687500	14916	718732	14916	120364	9196	165204	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:13:08.121	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1292	58	545937500	645312500	187423	144137060	169414	13149933	52205	1122835	440193	27000	86868	23986176	1380	200	98276	27648000	96	138	440193	354	535957504	849555456
2009-12-16 13:13:08.121	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7412	356048	7412	60092	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:13:08.121	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276406250	31406250	45118	1806298	45082	1422820	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:13:08.121	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7440	554732	7439	135032	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:13:08.121	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7407	429476	7406	59272	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:13:08.121	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37662	1881784	37661	1511624	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:13:08.121	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7408	355552	7407	59432	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:13:08.121	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7408	326028	7433	220296	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:13:08.121	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7406	325892	7406	59396	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:13:08.121	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7457	595353	7409	59832	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:13:08.121	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7405	459048	7405	59236	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:13:08.121	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7429	387720	7429	62816	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:13:08.121	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7470	430951	7453	66358	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:13:08.121	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7410	474660	7416	60326	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:13:08.121	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7407	296392	7407	59556	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:13:08.121	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1675	16	2200000000	1832500000	90564	19693102	89838	8423783	191703	2190282	1413998	22336	30548	51576832	1380	200	59964	22872064	30	38	1413998	349	157618176	226025472
2009-12-16 13:13:08.121	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46227	830628	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:13:08.121	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:13:08.121	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:13:08.121	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:13:08.121	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	970468750	3488750000	10251	9427612	4836	4046220	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:13:08.121	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1225468750	44020312500	79457	14947296665	54022	1499114014	47589	13710334	716695	1502632	1538612	1375301632	1380	200	1475220	1538695168	156	270	716695	389	5812219904	5816467456
2009-12-16 13:13:08.121	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5229	5024	5072	1089536	1380	200	5788	5144576	7	8	5229	65	40542208	41066496
2009-12-16 13:13:08.121	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75937500	33593750	7403	653655	7275	228753	19673	305930	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:13:08.121	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4982	239292	4982	40308	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:13:08.121	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:13:08.121	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:13:08.121	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:13:08.121	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	24218750	11406250	276	3023482	1061	1422733	9325	2493606	206955	16548	16704	22339584	1380	200	21964	16945152	14	17	206955	123	93016064	94130176
2009-12-16 13:13:08.121	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2187500	2656250	774	1549614	7192	2514685	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:13:08.121	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:13:08.121	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	225	7	8593750	104218750	144	650211	145	484820	1542	5152	14910	52632	54708	50720768	1380	200	51536	53895168	14	16	14910	246	564826112	566231040
2009-12-16 13:13:23.438	0	0	0	0	System Idle Process				0	0	2	1341162500000	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:13:23.438	0	4	4	0	System				8	881	72	5464531250	0	254	6046246	17878	107629184	37757	1817758	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:13:23.438	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:13:23.438	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	641	15	10772500000	35312500	122802	8669375	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:13:23.438	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:13:23.438	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4278593750	1103906250	15533	2442250	20739	7955479	383875	3157446	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:13:23.438	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	704	32	269531250	83281250	146593	11767030	137475	11830423	275371	4032475	7379	12220	12320	8392704	1380	200	13936	12513280	34	41	7379	115	75747328	76795904
2009-12-16 13:13:23.438	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7408	400102	7408	59564	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:13:23.438	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	27968750	17031250	7407	325936	7407	59404	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:13:23.438	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	153	9	12500000	4218750	14813	681994	14811	118484	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:13:23.438	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	223906250	19687500	14918	718828	14918	120380	9197	165232	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:13:23.438	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1296	58	545937500	645468750	187464	144180940	169456	13192949	52211	1122899	440252	26812	86868	23797760	1380	200	98276	27455488	96	138	440252	354	535957504	849555456
2009-12-16 13:13:23.438	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7413	356096	7413	60100	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:13:23.438	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276406250	31406250	45127	1806646	45091	1423116	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:13:23.438	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7441	554796	7440	135040	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:13:23.438	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7408	429534	7407	59280	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:13:23.438	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37669	1882130	37668	1511920	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:13:23.438	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7409	355600	7408	59440	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:13:23.438	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7409	326072	7434	220304	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:13:23.438	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7407	325936	7407	59404	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:13:23.438	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7458	595415	7410	59840	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:13:23.438	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7406	459110	7406	59244	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:13:23.438	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7430	387772	7430	62824	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:13:23.438	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7471	431007	7454	66366	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:13:23.438	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7411	474724	7417	60334	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:13:23.438	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7408	296432	7408	59564	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:13:23.438	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1675	16	2200156250	1832500000	90568	19693326	89842	8424159	191707	2190282	1414127	22328	30548	51572736	1380	200	59964	22863872	30	38	1414127	349	157618176	226025472
2009-12-16 13:13:23.438	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46227	830628	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:13:23.438	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:13:23.438	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:13:23.438	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:13:23.438	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	970468750	3488906250	10259	9428574	4844	4059140	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:13:23.438	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	781	79	1227187500	44308750000	79633	15013338066	54136	1503560626	47589	13710334	716758	1502632	1538612	1375346688	1380	200	1475220	1538695168	156	270	716758	389	5812219904	5816467456
2009-12-16 13:13:23.438	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5229	5024	5072	1089536	1380	200	5788	5144576	7	8	5229	65	40542208	41066496
2009-12-16 13:13:23.438	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75937500	33750000	7408	654225	7280	229666	19821	308298	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:13:23.438	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4983	239340	4983	40316	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:13:23.438	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:13:23.438	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:13:23.438	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:13:23.438	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	24375000	11562500	282	3025018	1067	1448365	9567	2559006	207264	16548	16704	22339584	1380	200	21964	16945152	14	17	207264	123	93016064	94130176
2009-12-16 13:13:23.438	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2500000	2812500	821	1651452	7887	2690473	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:13:23.438	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:13:23.438	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	225	7	8593750	107031250	144	650211	149	498493	1567	5160	14956	52636	54708	50728960	1380	200	51536	53899264	14	16	14956	246	564826112	566231040
2009-12-16 13:13:38.754	0	0	0	0	System Idle Process				0	0	2	1341222656250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:13:38.754	0	4	4	0	System				8	881	72	5464843750	0	254	6046246	17882	107891328	37757	1817996	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:13:38.754	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:13:38.754	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	640	15	10772500000	35312500	122802	8669375	0	0	88337	1290694	8915	1896	1940	3198976	1380	200	4416	1941504	12	13	8915	197	55136256	76775424
2009-12-16 13:13:38.754	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:13:38.754	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	368	16	4280000000	1104218750	15537	2442450	20743	7955511	383978	3158290	5704	6508	10364	5152768	1380	200	8948	6664192	17	26	5704	87	318496768	361951232
2009-12-16 13:13:38.754	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	702	32	269531250	83281250	146608	11768010	137489	11830799	275428	4035211	7379	12220	12320	8392704	1380	200	13936	12513280	34	41	7379	115	75747328	76795904
2009-12-16 13:13:38.754	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7410	400210	7410	59580	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:13:38.754	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	27968750	17031250	7409	326024	7409	59420	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:13:38.754	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14817	682178	14815	118516	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:13:38.754	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	224062500	19687500	14922	719020	14922	120412	9201	165320	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:13:38.754	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1297	57	546093750	645625000	187527	144225940	169520	13236141	52217	1122963	440359	26944	86868	23965696	1380	200	98276	27590656	96	138	440359	354	535433216	849555456
2009-12-16 13:13:38.754	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7415	356192	7415	60116	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:13:38.754	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276406250	31406250	45136	1807018	45100	1423384	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:13:38.754	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7443	554924	7442	135056	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:13:38.754	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7410	429650	7409	59296	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:13:38.754	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37677	1882534	37676	1512224	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:13:38.754	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7411	355696	7410	59456	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:13:38.754	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7411	326160	7436	220320	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:13:38.754	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7409	326024	7409	59420	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:13:38.754	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7460	595539	7412	59856	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:13:38.754	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7408	459234	7408	59260	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:13:38.754	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7432	387876	7432	62840	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:13:38.754	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7473	431119	7456	66382	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:13:38.754	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7413	474852	7419	60350	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:13:38.754	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7410	296512	7410	59580	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:13:38.754	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1675	16	2200468750	1832812500	90572	19693550	89846	8424535	191711	2190282	1414316	22252	30548	51490816	1380	200	59964	22786048	30	38	1414316	349	157618176	226025472
2009-12-16 13:13:38.754	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46227	830628	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:13:38.754	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:13:38.754	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:13:38.754	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:13:38.754	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	970468750	3488906250	10263	9429042	4848	4065600	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:13:38.754	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	783	79	1229218750	44543906250	80255	15314303239	54251	1508340635	47623	13748226	718014	1484728	1538612	1357000704	1380	200	1475220	1520361472	158	270	718014	389	5813661696	5816467456
2009-12-16 13:13:38.754	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5229	5024	5072	1089536	1380	200	5788	5144576	7	8	5229	65	40542208	41066496
2009-12-16 13:13:38.754	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75937500	33750000	7414	654857	7286	230587	19963	310570	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:13:38.754	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4985	239436	4985	40332	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:13:38.754	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:13:38.754	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:13:38.754	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:13:38.754	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	278	4	24531250	11718750	288	3026554	1073	1473997	9805	2624094	207573	16548	16704	22339584	1380	200	21964	16945152	14	17	207573	123	93016064	94130176
2009-12-16 13:13:38.754	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2500000	2812500	834	1675013	7940	2727403	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:13:38.754	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:13:38.754	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	225	7	8750000	109531250	144	650211	153	512166	1592	5168	15016	52716	54708	50814976	1380	200	51536	53981184	14	16	15016	246	564826112	566231040
2009-12-16 13:13:54.086	0	0	0	0	System Idle Process				0	0	2	1341235468750	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:13:54.086	0	4	4	0	System				8	881	72	5465000000	0	254	6046246	17893	108121728	37765	1818234	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:13:54.086	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:13:54.086	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	648	15	10772968750	35625000	122842	8688854	0	0	88628	1295202	8929	1896	1940	3211264	1380	200	4416	1941504	12	13	8929	197	55201792	76775424
2009-12-16 13:13:54.086	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:13:54.086	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4280312500	1104531250	15539	2442550	20751	7956355	384033	3158726	5708	6556	10364	5169152	1380	200	8948	6713344	17	26	5708	87	319021056	361951232
2009-12-16 13:13:54.086	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	708	32	269531250	83437500	146628	11769542	137506	11832091	275463	4036115	7383	12220	12320	8392704	1380	200	13936	12513280	34	41	7383	115	75747328	76795904
2009-12-16 13:13:54.086	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7411	400264	7411	59588	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:13:54.086	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	28125000	17031250	7410	326068	7410	59428	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:13:54.086	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14819	682270	14817	118532	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:13:54.086	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	224218750	19843750	14924	719116	14924	120428	9202	165348	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:13:54.086	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1295	56	546093750	645781250	187562	144255580	169556	13264917	52223	1123027	440419	26896	86868	23937024	1380	200	98276	27541504	96	138	440419	354	534908928	849555456
2009-12-16 13:13:54.086	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7416	356240	7416	60124	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:13:54.086	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276406250	31406250	45145	1807366	45109	1423680	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:13:54.086	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7444	554988	7443	135064	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:13:54.086	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7411	429708	7410	59304	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:13:54.086	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37684	1882880	37683	1512520	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:13:54.086	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7412	355744	7411	59464	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:13:54.086	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7412	326204	7437	220328	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:13:54.086	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7410	326068	7410	59428	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:13:54.086	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7461	595601	7413	59864	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:13:54.086	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7409	459296	7409	59268	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:13:54.086	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7433	387928	7433	62848	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:13:54.086	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7474	431175	7457	66390	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:13:54.086	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7414	474916	7420	60358	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:13:54.086	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7411	296552	7411	59588	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:13:54.086	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1670	15	2200468750	1833125000	90576	19693774	89850	8424911	191715	2190282	1414448	22248	30548	51544064	1380	200	59964	22781952	30	38	1414448	349	157093888	226025472
2009-12-16 13:13:54.086	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46239	830756	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:13:54.086	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:13:54.086	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:13:54.086	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:13:54.086	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	809	20	970468750	3489375000	10271	9429991	4856	4078520	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:13:54.086	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	797	81	1233437500	44802187500	80333	15332250475	54472	1518437575	47759	13871251	720310	1488240	1538612	1356771328	1380	200	1475220	1523957760	157	270	720310	389	5817135104	5818183680
2009-12-16 13:13:54.086	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5229	5024	5072	1089536	1380	200	5788	5144576	7	8	5229	65	40542208	41066496
2009-12-16 13:13:54.086	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75937500	33750000	7422	655643	7291	231500	20115	313002	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:13:54.086	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4986	239484	4986	40340	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:13:54.086	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:13:54.086	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:13:54.086	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:13:54.086	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	282	4	25000000	11718750	292	3027578	1086	1491931	9973	2667654	214731	16568	16704	22360064	1380	200	21964	16965632	14	17	214731	123	93016064	94130176
2009-12-16 13:13:54.086	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2500000	2812500	856	1728497	8030	2820627	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:13:54.086	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:13:54.086	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	225	7	8750000	112500000	144	650211	157	525839	1617	5176	15080	52816	54708	50917376	1380	200	51536	54083584	14	16	15080	246	564826112	566231040
2009-12-16 13:13:54.086	0	2804	2804	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:13:49.533	8	136	5	1093750	468750	22	44316	238	45258	372	3606	2577	3896	3940	9138176	1380	200	8924	3989504	11	12	2577	116	67067904	67067904
2009-12-16 13:14:09.513	0	0	0	0	System Idle Process				0	0	2	1341236562500	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:14:09.513	0	4	4	0	System				8	881	72	5465625000	0	254	6046246	17898	108143232	37774	1818234	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:14:09.513	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:14:09.513	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	649	15	10773437500	35625000	122842	8688854	0	0	88628	1295202	8929	1896	1940	3211264	1380	200	4416	1941504	12	13	8929	197	55201792	76775424
2009-12-16 13:14:09.513	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:14:09.513	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4282656250	1104843750	15543	2442750	20755	7956387	384135	3159542	5708	6556	10364	5169152	1380	200	8948	6713344	17	26	5708	87	319021056	361951232
2009-12-16 13:14:09.513	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	708	32	269531250	83437500	146641	11770350	137518	11832379	275473	4036187	7383	12220	12320	8392704	1380	200	13936	12513280	34	41	7383	115	75747328	76795904
2009-12-16 13:14:09.513	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7413	400372	7413	59604	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:14:09.513	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	28281250	17031250	7412	326156	7412	59444	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:14:09.513	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14823	682454	14821	118564	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:14:09.513	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	224375000	19843750	14928	719308	14928	120460	9202	165348	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:14:09.513	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1299	56	546250000	646250000	187618	144286300	169613	13293841	52225	1123035	440482	26896	86868	23941120	1380	200	98276	27541504	96	138	440482	354	534908928	849555456
2009-12-16 13:14:09.513	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7418	356336	7418	60140	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:14:09.513	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276406250	31406250	45155	1807774	45119	1423984	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:14:09.513	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7446	555116	7445	135080	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:14:09.513	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7413	429824	7412	59320	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:14:09.513	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37692	1883284	37691	1512824	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:14:09.513	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7414	355840	7413	59480	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:14:09.513	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7414	326292	7439	220344	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:14:09.513	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7412	326156	7412	59444	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:14:09.513	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7463	595725	7415	59880	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:14:09.513	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7411	459420	7411	59284	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:14:09.513	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7435	388032	7435	62864	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:14:09.513	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7476	431287	7459	66406	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:14:09.513	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7416	475044	7422	60374	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:14:09.513	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7413	296632	7413	59604	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:14:09.513	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1670	15	2201093750	1833906250	90580	19693998	89854	8425287	191719	2190424	1414691	22148	30548	51445760	1380	200	59964	22679552	30	38	1414691	349	157093888	226025472
2009-12-16 13:14:09.513	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46239	830756	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:14:09.513	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:14:09.513	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:14:09.513	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:14:09.513	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	806	20	970625000	3489843750	10277	9430498	4862	4085326	31917	2649578	240671	192084	236504	136445952	1380	200	154524	196694016	52	59	240671	653	558247936	589316096
2009-12-16 13:14:09.513	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	809	82	1239687500	45072500000	80520	15364261564	54748	1526920911	48277	13989737	733021	1501472	1538612	1370062848	1380	200	1475220	1537507328	159	270	733021	389	5821784064	5829451776
2009-12-16 13:14:09.513	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5233	5024	5072	1089536	1380	200	5788	5144576	7	8	5233	65	40542208	41066496
2009-12-16 13:14:09.513	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75937500	33750000	7424	655767	7293	231516	20264	315386	13010	24236	24380	8249344	1380	200	22748	24817664	34	38	13010	179	531070976	533159936
2009-12-16 13:14:09.513	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4988	239580	4988	40356	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:14:09.513	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:14:09.513	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:14:09.513	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:14:09.513	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	282	4	25312500	11718750	296	3028602	1090	1509019	10127	2711046	214859	16568	16704	22360064	1380	200	21964	16965632	14	17	214859	123	93016064	94130176
2009-12-16 13:14:09.513	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2500000	2968750	870	1757678	8097	2872095	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:14:09.513	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:14:09.513	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	225	7	8906250	115468750	144	650211	161	539783	1642	5184	15139	52896	54708	50999296	1380	200	51536	54165504	14	16	15139	246	564826112	566231040
2009-12-16 13:14:09.513	0	2804	2804	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:13:49.533	8	136	5	1093750	1562500	129	482588	2386	1136347	372	3606	2803	4624	6624	10039296	1380	200	9804	4734976	11	12	2803	116	67067904	69185536
2009-12-16 13:14:24.893	0	0	0	0	System Idle Process				0	0	2	1341238281250	0	0	0	0	0	0	0	0	0	0	24576			0	0	0	0	0	0	0	0
2009-12-16 13:14:24.893	0	4	4	0	System				8	881	72	5465937500	0	254	6046246	17898	108143232	37774	1818472	6373	44	44	258048	1380	0	4736	94208	1	1	6373	0	2490368	6025216
2009-12-16 13:14:24.893	0	332	332	4	smss.exe		\SystemRoot\System32\smss.exe	2009-12-15 14:10:17.500	11	19	3	937500	0	8	26	4	4	179	56026	331	248	2468	204800	1380	200	700	253952	2	3	331	31	5218304	17682432
2009-12-16 13:14:24.893	0	388	388	332	csrss.exe	C:\WINDOWS\system32\csrss.exe	C:\WINDOWS\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,20480,768 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16	2009-12-15 14:10:24.171	13	649	15	10773750000	35781250	122842	8688854	0	0	88628	1295202	8929	1896	1940	3211264	1380	200	4416	1941504	12	13	8929	197	55201792	76775424
2009-12-16 13:14:24.893	0	412	412	332	winlogon.exe	C:\WINDOWS\system32\winlogon.exe	winlogon.exe	2009-12-15 14:10:24.390	13	685	18	20000000	11406250	488	130346	454	51657	7503	287588	9587	11024	11808	6717440	1380	200	16264	11288576	193	199	9587	176	84213760	107282432
2009-12-16 13:14:24.893	0	460	460	412	services.exe	C:\WINDOWS\system32\services.exe	C:\WINDOWS\system32\services.exe	2009-12-15 14:10:24.578	9	369	17	4283281250	1105000000	15545	2442850	20759	7956687	384187	3159978	5708	6556	10364	5169152	1380	200	8948	6713344	17	26	5708	87	319021056	361951232
2009-12-16 13:14:24.893	0	472	472	412	lsass.exe	C:\WINDOWS\system32\lsass.exe	C:\WINDOWS\system32\lsass.exe	2009-12-15 14:10:24.609	9	708	32	269531250	83593750	146661	11771882	137535	11833671	275507	4036403	7383	12220	12320	8392704	1380	200	13936	12513280	34	41	7383	115	75747328	76795904
2009-12-16 13:14:24.893	0	668	668	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k DcomLaunch	2009-12-15 14:10:24.968	8	89	5	5000000	1562500	7414	400426	7414	59612	380	12157	1529	1504	1652	1650688	1380	200	4028	1540096	6	8	1529	54	29597696	31051776
2009-12-16 13:14:24.893	0	728	728	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k rpcss	2009-12-15 14:10:25.125	8	258	11	28281250	17031250	7413	326200	7413	59452	636	19480	2289	2224	2284	2347008	1380	200	5240	2277376	34	35	2289	67	34426880	35119104
2009-12-16 13:14:24.893	0	792	792	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k NetworkService	2009-12-15 14:10:25.203	8	152	9	12500000	4218750	14825	682546	14823	118580	4306	264770	3103	5896	6276	2146304	1380	200	7584	6037504	12	18	3103	119	69795840	71368704
2009-12-16 13:14:24.893	0	828	828	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k LocalService	2009-12-15 14:10:25.234	8	188	15	224375000	20000000	14930	719404	14930	120476	9203	165376	2873	2316	2440	1892352	1380	200	5732	2371584	10	13	2873	62	40239104	41287680
2009-12-16 13:14:24.893	0	848	848	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k netsvcs	2009-12-15 14:10:25.265	8	1299	56	546562500	646406250	187650	144308820	169646	13315497	52231	1123099	440540	26896	86868	23941120	1380	200	98276	27541504	96	138	440540	354	534908928	849555456
2009-12-16 13:14:24.893	0	996	996	460	spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	C:\WINDOWS\system32\spoolsv.exe	2009-12-15 14:10:25.484	8	123	11	16875000	5156250	7419	356384	7419	60148	392	4052	2553	4928	5300	1839104	1380	200	7424	5046272	9	12	2553	102	58556416	61669376
2009-12-16 13:14:24.893	0	1020	1020	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Heartbeat	2009-12-15 14:10:25.515	8	102	3	276562500	31406250	45163	1808086	45127	1424244	467	11636	2145	3948	4232	872448	1380	200	7580	4042752	9	13	2145	91	52248576	55349248
2009-12-16 13:14:24.893	0	1056	1056	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature KvpExchange	2009-12-15 14:10:25.578	8	154	5	5156250	2187500	7447	555180	7446	135088	1023	658590	4767	8524	9472	716800	1380	200	9168	8728576	11	14	4767	122	77250560	78823424
2009-12-16 13:14:24.893	0	1080	1080	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature Shutdown	2009-12-15 14:10:25.640	8	78	3	4062500	625000	7414	429882	7413	59328	132	2476	1139	3048	3072	495616	1380	200	4480	3121152	6	8	1139	89	42704896	45694976
2009-12-16 13:14:24.893	0	1096	1096	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature TimeSync	2009-12-15 14:10:25.703	8	87	3	219531250	11718750	37699	1883630	37698	1513120	134	3020	1203	3064	3088	733184	1380	200	4720	3137536	6	8	1203	89	42557440	45694976
2009-12-16 13:14:24.893	0	1140	1140	460	vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe	C:\WINDOWS\system32\vmicsvc.exe -feature VSS	2009-12-15 14:10:25.796	8	88	3	3125000	1875000	7415	355888	7414	59488	138	2824	1234	3132	3156	577536	1380	200	4852	3207168	6	8	1234	89	45465600	45989888
2009-12-16 13:14:24.893	0	1176	1176	460	msdtc.exe	C:\WINDOWS\system32\msdtc.exe	C:\WINDOWS\system32\msdtc.exe	2009-12-15 16:10:26.365	8	153	13	6406250	2187500	7415	326336	7440	220352	217	3388	1913	2632	2696	577536	1380	200	6688	2695168	11	14	1913	63	38940672	40005632
2009-12-16 13:14:24.893	0	1284	1284	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k WinErr	2009-12-15 16:10:26.600	8	69	2	2656250	1093750	7413	326200	7413	59452	84	2428	816	1108	1156	307200	1380	200	3244	1134592	5	7	816	49	25645056	26169344
2009-12-16 13:14:24.893	0	1336	1336	460	MsDtsSrvr.exe	C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe	"C:\Program Files\Microsoft SQL Server\100\DTS\Binn\MsDtsSrvr.exe"	2009-12-15 16:10:26.678	8	163	6	5468750	8281250	7464	595787	7416	59888	398	5152	5635	49040	57320	3452928	1380	200	21560	50216960	10	12	5635	185	2822803456	2839580672
2009-12-16 13:14:24.893	0	1456	1456	460	svchost.exe	C:\WINDOWS\system32\svchost.exe	C:\WINDOWS\system32\svchost.exe -k regsvc	2009-12-15 16:10:33.037	8	42	2	5000000	1875000	7412	459482	7412	59292	82	256	781	896	1232	380928	1380	200	2736	917504	4	4	781	41	16613376	20742144
2009-12-16 13:14:24.893	0	1492	1492	460	sqlwriter.exe	C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe	"C:\Program Files\Microsoft SQL Server\90\Shared\sqlwriter.exe"	2009-12-15 16:10:33.100	8	83	3	3437500	2187500	7436	388084	7436	62872	257	9614	1436	1904	2276	569344	1380	200	5688	1949696	6	8	1436	61	37679104	43970560
2009-12-16 13:14:24.893	0	1808	1808	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k termsvcs	2009-12-15 16:10:40.178	8	145	15	6406250	1562500	7477	431343	7460	66414	862	69544	2069	2608	22592	2613248	1380	200	5692	2670592	10	12	2069	97	72953856	74534912
2009-12-16 13:14:24.893	0	1840	1840	460	fdlauncher.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdlauncher.exe" -s MSSQL10.MSSQLSERVER	2009-12-15 16:10:40.287	8	37	1	5468750	1718750	7417	475108	7423	60382	134	1498	827	1164	1216	397312	1380	200	3240	1191936	4	4	827	38	20078592	22175744
2009-12-16 13:14:24.893	0	1932	1932	460	alg.exe	C:\WINDOWS\System32\alg.exe	C:\WINDOWS\System32\alg.exe	2009-12-15 16:10:40.412	8	88	5	4531250	1250000	7414	296672	7414	59612	106	3196	1098	1392	1464	466944	1380	200	4344	1425408	8	11	1098	55	30244864	31817728
2009-12-16 13:14:24.893	0	2080	2080	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:11:18.991	8	1670	15	2201093750	1834062500	90584	19694222	89858	8425663	191723	2190424	1414862	22152	30548	51445760	1380	200	59964	22683648	30	38	1414862	349	157093888	226025472
2009-12-16 13:14:24.893	0	2316	2316	2288	explorer.exe	C:\WINDOWS\Explorer.EXE	C:\WINDOWS\Explorer.EXE	2009-12-15 16:11:40.226	8	427	9	124218750	38906250	1573	1958383	91	29019	46239	830756	32387	10740	11220	11694080	1380	200	18760	10997760	25	28	32387	252	123330560	141737984
2009-12-16 13:14:24.893	0	2532	2532	668	wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	C:\WINDOWS\system32\wbem\wmiprvse.exe	2009-12-15 16:12:02.508	8	159	4	8125000	6562500	383	44404	390	35890	565	17822	6830	2868	3504	806912	1380	200	8092	2936832	7	10	6830	71	40382464	43053056
2009-12-16 13:14:24.893	0	2676	2676	2316	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe	"C:\WINDOWS\system32\WindowsPowerShell\v1.0\PowerShell.exe" 	2009-12-15 16:12:14.461	8	421	7	22187500	72500000	669	2767660	141	889167	9285	43076	34255	33852	47908	25821184	1380	200	39212	34664448	18	21	34255	364	605962240	626016256
2009-12-16 13:14:24.893	0	2756	2756	412	wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	C:\WINDOWS\system32\wpabaln.exe	2009-12-15 16:13:40.184	8	41	1	2031250	781250	0	0	0	0	68	2104	873	1228	1264	413696	1380	200	3412	1257472	4	7	873	124	55492608	64917504
2009-12-16 13:14:24.893	0	2904	2904	2316	Ssms.exe	C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe	"C:\Program Files (x86)\Microsoft SQL Server\100\Tools\Binn\VSShell\Common7\IDE\SSMS.exe" 	2009-12-15 16:20:50.393	8	805	20	970625000	3491093750	10287	9432207	4873	4098516	31920	2649578	240673	192084	236504	136445952	1380	200	154524	196694016	52	59	240673	653	558247936	589316096
2009-12-16 13:14:24.893	0	1796	1796	460	sqlservr.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\sqlservr.exe" -sMSSQLSERVER	2009-12-15 19:14:29.231	8	812	82	1243750000	45345000000	80608	15384846059	55124	1535354874	48423	14118450	739257	1502188	1538612	1370943488	1380	200	1475220	1538240512	159	270	739257	389	5822427136	5832794112
2009-12-16 13:14:24.893	0	504	504	1840	fdhost.exe	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\fdhost.exe" "MSSQL10.MSSQLSERVERC7e4d333bf6485f4a8efb561fdfb7949476981388mc" "MSSQL10.MSSQLSERVER" "MSSQL10.MSSQLSERVER" "4" "" "4096" "M" "0" "" "" "" 	2009-12-15 19:14:30.200	8	136	6	66406250	10000000	5	580	0	0	155	2760	5233	5024	5072	1089536	1380	200	5788	5144576	7	8	5233	65	40542208	41066496
2009-12-16 13:14:24.893	0	868	868	460	SQLAGENT.EXE	C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE	"C:\Program Files\Microsoft SQL Server\MSSQL10.MSSQLSERVER\MSSQL\Binn\SQLAGENT.EXE" -i MSSQLSERVER	2009-12-15 19:14:30.559	8	370	14	75937500	33750000	7429	656337	7298	232429	20421	317872	13023	24236	24380	8249344	1380	200	22748	24817664	34	38	13023	179	531070976	533159936
2009-12-16 13:14:24.893	0	1652	1652	460	svchost.exe	C:\WINDOWS\System32\svchost.exe	C:\WINDOWS\System32\svchost.exe -k tapisrv	2009-12-15 23:12:50.954	8	227	16	2343750	2500000	4989	239628	4989	40364	268	11040	1714	3868	3964	1703936	1380	200	5592	3960832	13	15	1714	87	51781632	52830208
2009-12-16 13:14:24.893	0	2468	2468	2676	explorer.exe	C:\WINDOWS\explorer.exe	"C:\WINDOWS\explorer.exe" C:\Temp\SQLDiagSupportDirectory\	2009-12-16 10:39:10.903	13	270	4	68593750	27812500	1013	52673	9	1132	44328	942798	30593	7712	8320	17530880	1380	200	17416	7897088	13	17	30593	249	109105152	128147456
2009-12-16 13:14:24.893	0	1052	1052	868	cmd.exe	C:\WINDOWS\system32\cmd.exe	cmd /c C:\Temp\PASS\LaunchSQLDiag.cmd	2009-12-16 13:03:45.139	8	30	1	156250	0	1	99	5	122	168	1496	602	1928	1928	2478080	1380	200	2420	1974272	3	4	602	42	17018880	17018880
2009-12-16 13:14:24.893	0	3768	3768	1052	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\Invoke-SQLDiag.ps1';"	2009-12-16 13:03:45.155	8	235	6	1250000	9062500	144	648587	3	436	665	4976	11946	51612	51660	47370240	1380	200	46284	52850688	13	15	11946	245	553938944	555610112
2009-12-16 13:14:24.893	0	3512	3512	3768	SQLdiag.exe	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe	"C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLDiag.exe" /I C:\Temp\PASS\SupportDirectory\SQLDiag_TNB_Detailed_2008.xml /O C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347 /P C:\Temp\PASS\SupportDirectory /E +00:10:00	2009-12-16 13:03:47.983	8	282	4	25625000	11875000	299	3029370	1093	1521835	10257	2743998	214955	16568	16704	22360064	1380	200	21964	16965632	14	17	214955	123	93016064	94130176
2009-12-16 13:14:24.893	0	3864	3864	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:04:02.451	8	133	3	2500000	2968750	880	1777260	8140	2904221	372	3646	2954	4784	4828	10223616	1380	200	10000	4898816	10	14	2954	116	67067904	69165056
2009-12-16 13:14:24.893	0	2384	2384	3512	cmd.exe	C:\WINDOWS\system32\cmd.exe	"C:\WINDOWS\system32\cmd.exe"  /CPowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.467	8	35	1	156250	0	0	0	0	0	70	616	556	1932	1932	2281472	1380	200	2228	1978368	3	3	556	42	17014784	17014784
2009-12-16 13:14:24.893	0	1656	1656	2384	powershell.exe	C:\WINDOWS\system32\WindowsPowerShell\v1.0\powershell.exe	PowerShell.exe -NoLogo -NoProfile -NonInteractive -Command "& 'C:\Temp\PASS\SupportDirectory\Get-ProcessList.ps1' 'C:\Temp\PASS\DB04,SQLDiagOutput,20091216T130347\' 15000 240	2009-12-16 13:04:06.483	8	225	7	8906250	118750000	144	650211	165	553735	1667	5192	15202	52992	54708	51097600	1380	200	51536	54263808	14	16	15202	246	564826112	566231040
2009-12-16 13:14:24.893	0	2804	2804	3512	SQLCMD.EXE	C:\Program Files\Microsoft SQL Server\100\Tools\Binn\SQLCMD.EXE		2009-12-16 13:13:49.533	8	136	5	1250000	1718750	329	1301788	3841	4787925	372	3606	2824	4656	6624	10067968	1380	200	9872	4767744	11	12	2824	116	67067904	69185536
