High CPU usage by WMIPRVSE.EXE

  • Thread starter Thread starter Steve S
  • Start date Start date
S

Steve S

I'm running XP Pro w/sp2 My computer will lock up/ run real slow. it
will take over 2 hours to shut down after I request a restart ( has taken
over 1o hurs some times). it will run ok from 15 minutes to 3 hours then will
lock up again. Looking at the task manager the program wmiprvse.exe is
using about 100% of the cpu when the system locks up. i have applied the
hotfix to fix the memory leak problem, still have the real slow problem. Is
there a way to find out which program is running in wmiprvse that is causing
the system to run slow? or a way to remove WMI from my computer?


Steve
 
Steve said:
I'm running XP Pro w/sp2 My computer will lock up/ run real slow. it
will take over 2 hours to shut down after I request a restart ( has taken
over 1o hurs some times). it will run ok from 15 minutes to 3 hours then will
lock up again. Looking at the task manager the program wmiprvse.exe is
using about 100% of the cpu when the system locks up. i have applied the
hotfix to fix the memory leak problem, still have the real slow problem. Is
there a way to find out which program is running in wmiprvse that is causing
the system to run slow? or a way to remove WMI from my computer?


Steve

The following link, the first hit under Google, shows that you might
have malware running under that name:
http://www.neuber.com/taskmanager/process/wmiprvse.exe.html
 
Caution: There is a legitimate Microsoft process by that name !

I had a simialr problem at work. The IT folks applied some patch from
Microsoft, and that fixed everything.

A Goggle search turned a fix to a similar problem on server 2003.
Unfortunately, I do not know if this works on XP Pro.:

http://www.microsoft.com/downloads/...19-109B-41C6-851D-0BE19D29172E&displaylang=en

Until they applied the patch, the bes tthat I could do was to drop the
afinity and the priority of that process. (Affinity refers to number of
CPUs; I have two at work, and restricted the process to only one.)

I found that a program called "process explorer" is more effective in
controlling these sort of things that task manager. Process explorer is
free from Microsoft at:
http://technet.microsoft.com/en-us/sysinternals/bb896653.aspx
 
Steve

Download and install the User Profile Hive Cleanup Service
Download details: User Profile Hive Cleanup Service
http://snipurl.com/5b61

UPHClean v1.5e readme.txt
http://snipurl.com/ko8m

Please post copies of all Error and Warning Reports appearing in
the System and Application logs in Event Viewer for the last boot. No
Information Reports or Duplicates please. Indicate which also appear in
a previous boot.

You can access Event Viewer by selecting Start, Control Panel,
Administrative Tools, and Event Viewer. When researching the meaning
of the error, information regarding Event ID, Source and Description
are important.

HOW TO: View and Manage Event Logs in Event Viewer in Windows XP
http://support.microsoft.com/kb/308427/en-us

A tip for posting copies of Error Reports! Run Event Viewer and double
click on the error you want to copy. In the window, which appears is a
button resembling two pages. Click the button and close Event
Viewer.Now start your message (email) and do a paste into the body of
the message. Make sure this is the first paste after exiting from
Event Viewer.

--



Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~



--



Hope this helps.

Gerry
~~~~
FCA
Stourport, England
Enquire, plan and execute
~~~~~~~~~~~~~~~~~~~
 
Steve S said:
I'm running XP Pro w/sp2 My computer will lock up/ run real slow. it
will take over 2 hours to shut down after I request a restart ( has taken
over 1o hurs some times). it will run ok from 15 minutes to 3 hours then will
lock up again. Looking at the task manager the program wmiprvse.exe is
using about 100% of the cpu when the system locks up. i have applied the
hotfix to fix the memory leak problem, still have the real slow problem. Is
there a way to find out which program is running in wmiprvse that is causing
the system to run slow? or a way to remove WMI from my computer?


Steve

This can be a memory leak or a printer problem. Did you install any
hardware/software recently?.

Go through these cleaning steps:
1... Click start >> Control Panel >> Double Click Network and Internet
Connections >> Double click Internet Options, on the IE Properties window
you will see these Options:
General | Security | Privacy | Content | Connections | Programs
| Advanced .

Click on General Tab (1st Tab on the left) and you will see a Button called
[ Clear History ..] click on it to clear your History caches, then click on
[Delete Files..] to delete Internet Files created over the time, click on [
Delete Cookies...] to delete your cookies left by visiting websites.

= Then try to Disable the Add-Ons on your Browser somehow installed on your
browser, On how to disable the Add-ons follow this:
Click on Programs Tab and then click the Manage Add-Ons Button there Disable
the None/Not Verified Plug-ins/Add-ons ( you need to Renable them one-by-one
later and see which is the culprit .
How to manage Add-Ons:
http://support.microsoft.com/kb/883256

Scan for malware from here:
http://onecare.live.com/site/en-gb/default.htm?s_cid=sah
http://onecare.live.com/standard/en-gb/default.htm

Scan for viruses with an up2date Anti-virus software (full scan).

the legit files for WMi located here:
C:\WINDOWS\system32\wbem\wmiprvse.exe

There a backup copy here
C:\WINDOWS\system32\dllcache
or here:
C:\WINDOWS\ServicePackFiles\i386

The Wmiprvse.exe process may experience a memory leak when WMI services and
RPC services are extensively used in Windows XP with Service Pack 2
http://support.microsoft.com/kb/925623


WMI search:
http://www.microsoft.com/communitie...&pt=&catlist=&dglist=&ptlist=&exp=&sloc=en-us
MS:: <Quote>
Stopping and Starting the WMI Service

If you are experiencing problems with the WMI service you might need to
manually stop and restart the service. Before doing so you should enable
WMI’s verbose logging option. This provides additional information in the WMI
error logs that might be useful in diagnosing the problem. To enable verbose
logging using the WMI control, do the following:
1.Open the Computer Management MMC snap-in and expand Services and
Applications.
2.Right-click WMI Control and click Properties.
3.In the WMI Control Properties dialog box, on the Logging tab, select
Verbose (includes extra information for Microsoft troubleshooting) and then
click OK.
Alternatively, you can modify the following registry values:
•Set HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\Logging to 2.
•Set HKEY_LOCAL_MACHINE\Software\Microsoft\WBEM\CIMOM\Logging File Max Size
to 4000000.
After enabling verbose logging try stopping the WMI service by typing the
following
Open a run command prompt:
net stop winmgmt

If the net stop command fails you can force the service to stop by typing
this:
winmgmt /kill

Important. If you are running Windows XP or Windows Server 2003 the WMI
service runs inside a process named Svchost; this process contains other
services as well as WMI. Because of that, you should not try to stop
Svchost;
if you succeed, you’ll stop all the other services running in that process
as
well. Instead, use net stop winmgmt or winmgmt /kill in order to stop just
the WMI service.

You can then restart the service by typing the following command:
net start winmgmt

If the service does not restart try rebooting the computer to see if that
corrects the problem.
If it does not, then continue reading.
MS:: </Quote>

"WMI Diagnosis Utility"
http://www.microsoft.com/technet/scriptcenter/topics/help/wmidiag.mspx

Systems that have changed the default Access Control List permissions on the
%windir%\registration directory may experience various problems after you
install the Microsoft Security Bulletin MS05-051 for COM+ and MS DTC
http://support.microsoft.com/kb/909444
Also you can download the DiagWMI from here and some good solutions on the
page:
http://windowsxp.mvps.org/repairwmi.htm.

= Open a run command and try to re-register these DLLs:
regsvr32 hnetcfg.dll
regsvr32 netcfgx.dll
regsvr32 netman.dll
regsvr32 atl.dll
regsvr32 netshell.dll
Also try repair the WMI as descriped here:
http://groups.google.com/group/microsoft.public.win32.programmer.wmi/msg/1da6ab3690bc75a0
What Firewall/Anti-Virus you have running on your machine?.
HTH.
Let us know.
nass
 
Back
Top