<?xml version="1.0" encoding="UTF-8" ?>
<?xml-stylesheet type="text/xsl" href="http://blogs.technet.com/utility/FeedStylesheets/rss.xsl" media="screen"?><rss version="2.0" xmlns:dc="http://purl.org/dc/elements/1.1/" xmlns:slash="http://purl.org/rss/1.0/modules/slash/" xmlns:wfw="http://wellformedweb.org/CommentAPI/"><channel><title>The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx</link><description>I’ve been extremely busy here at Microsoft and so haven’t had time to blog until now, but plan on getting back to posting regularly. Before I start with a look at a technical problem I ran into recently, I’m pleased to report that the Sysinternals integration</description><dc:language>en-US</dc:language><generator>CommunityServer 2.1 SP1 (Build: 61025.2)</generator><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453102</link><pubDate>Thu, 31 Aug 2006 20:06:43 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453102</guid><dc:creator>Tabernil</dc:creator><description>As usually great comments, but something's missing, don't know what :(</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453118</link><pubDate>Thu, 31 Aug 2006 21:11:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453118</guid><dc:creator>kizzer</dc:creator><description>Every time I've had these kind of delays, I just shut off Defender and they go away. &amp;nbsp;Not quite as scientific, but there you go!</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453134</link><pubDate>Thu, 31 Aug 2006 22:07:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453134</guid><dc:creator>George Devore</dc:creator><description>&lt;br&gt;Although I understood about 1% of that, it's&lt;br&gt;good to have you back!!! Microsoft has a 'new&lt;br&gt;foundation' with you two guys there!!!&lt;br&gt;&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453135</link><pubDate>Thu, 31 Aug 2006 22:08:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453135</guid><dc:creator>SSL</dc:creator><description>OT but, the links to https images on this blog sucks, Opera and Firefox doesnt have the certificate</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453137</link><pubDate>Thu, 31 Aug 2006 22:17:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453137</guid><dc:creator>rich</dc:creator><description>When I encounter any strange problems like this, before doing any investigation, I do the following:&lt;br&gt;&lt;br&gt;1) Remove any products from Symantec&lt;br&gt;2) Remove any anti virus or anti spyware products&lt;br&gt;3) Remove anything from Novell&lt;br&gt;&lt;br&gt;I find I rarely get to step 3!</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453139</link><pubDate>Thu, 31 Aug 2006 22:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453139</guid><dc:creator>stefan</dc:creator><description>nice article to read :)</description></item><item><title>nice</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453144</link><pubDate>Thu, 31 Aug 2006 23:03:10 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453144</guid><dc:creator>Raphael</dc:creator><description>Another nice detective story. &lt;br&gt;Thanks Mark.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453154</link><pubDate>Thu, 31 Aug 2006 23:45:58 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453154</guid><dc:creator>Marvin</dc:creator><description>Great article.&lt;br&gt;A small comment on the blog itself though.&lt;br&gt;Why are all the images .aspx pages (rather than .gif, .jpg etc.)? It prevents my RSS/Atom -&amp;gt; Outlook converter from getting them ;-(&lt;br&gt;</description></item><item><title>' + title + ' - ' + basename(imgurl) + '(' + w + 'x' + h +')</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453157</link><pubDate>Fri, 01 Sep 2006 00:03:07 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453157</guid><dc:creator>' + title + ' - ' + basename(imgurl) + '(' + w + 'x' + h +')</dc:creator><description>PingBack from &lt;A href="http://someguywitha.com/2006/08/31/resistance-is-futile/"&gt;http://someguywitha.com/2006/08/31/resistance-is-futile/&lt;/A&gt;&lt;A href="http://someguywitha.com/2006/09/01/resistance-is-futile/" target=_new rel=nofollow&gt;&lt;/A&gt;</description></item><item><title>The -kernelbreaking- work of a staggering genius&amp;#8230; &amp;laquo; Sharp Reflections</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453162</link><pubDate>Fri, 01 Sep 2006 00:19:34 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453162</guid><dc:creator>The -kernelbreaking- work of a staggering genius… « Sharp Reflections</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://sharpreflections.wordpress.com/2006/08/31/the-kernelbreaking-work-of-a-staggering-genius/"&gt;http://sharpreflections.wordpress.com/2006/08/31/the-kernelbreaking-work-of-a-staggering-genius/&lt;/a&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453170</link><pubDate>Fri, 01 Sep 2006 00:43:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453170</guid><dc:creator>UL-Tomten</dc:creator><description>What's that cmd.exe font?</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453192</link><pubDate>Fri, 01 Sep 2006 02:03:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453192</guid><dc:creator>Aaron</dc:creator><description>Mark, I am frequently humbled by your blog posts. &amp;nbsp;I'm fairly good with Windows and I have a basic idea of what makes it work. &amp;nbsp;However, my knowledge doesn't even compare to yours. &amp;nbsp;Keep up the good work. &amp;nbsp;MS is lucky to have you...whatever they are paying you, it isnt enough!&lt;br&gt;&lt;br&gt;~Aaron~</description></item><item><title>Mark Russinovich's Blog and Tools go to Technet site</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453194</link><pubDate>Fri, 01 Sep 2006 03:35:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453194</guid><dc:creator>External News</dc:creator><description>Mark's Blog: I’ve been extremely busy here at Microsoft and so haven’t had time to blog until now, but</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453205</link><pubDate>Fri, 01 Sep 2006 05:02:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453205</guid><dc:creator>Mike</dc:creator><description>More great Windows sleuthing, Mark.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453271</link><pubDate>Fri, 01 Sep 2006 05:38:44 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453271</guid><dc:creator>D.</dc:creator><description>I am not worthy!</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453316</link><pubDate>Fri, 01 Sep 2006 10:24:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453316</guid><dc:creator>Roger Persson</dc:creator><description>Interesting research Mark! I've always suspected that Windows Defender does a whole lot of extra procedure calls, but I have more problems with our CM software, that does similar actions.&lt;br&gt;&lt;br&gt;I think this was one of the most technical blogs I've read so far - and by far the most easy to follow...so keep up the good work.&lt;br&gt;&lt;br&gt;Will follow this blog with interest from here on!</description></item><item><title>The Case of the Annoying Popups on Mark's New Blog</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453324</link><pubDate>Fri, 01 Sep 2006 11:10:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453324</guid><dc:creator>Patrick Ogenstad</dc:creator><description>Thanks for the great post! It got me to do a bit of investigative work on my own. I've seen this on a few of other blogs on Technet too.&lt;br&gt;&lt;br&gt;The first think I see when I view this page (from Firefox) is popup with the title &amp;quot;Website Certified by an Unknown Authority&amp;quot;. Why would it involve SSL was my first thought, it turns out that all the pictures in the post are linked by https instead of http.&lt;br&gt;&lt;br&gt;So how come these images are protected by ssl. I have two theories.&lt;br&gt;&lt;br&gt;a) It's so people who are using Internet Explorer and are viewing the site &lt;a rel="nofollow" target="_new" href="https://blogs.technet.com/markrussinovich/"&gt;https://blogs.technet.com/markrussinovich/&lt;/a&gt; isn't bothered by the message &amp;quot;The page contains both secure and nonsecure items, do you want to display the nonsecure items?&amp;quot;&lt;br&gt;&lt;br&gt;b) Mark was logged in to his blog authoring software through ssl and just copied the link to the image which in that state was an ssl link.&lt;br&gt;&lt;br&gt;I'm favoring theory b, I don't think that many people are viewing the site through ssl.&lt;br&gt;&lt;br&gt;But the mystery itself, why do I get this popup? The certificate for blogs.technet.com chains to a Root CA called &amp;quot;GTE CyberTrust Global Root&amp;quot;.&lt;br&gt;&lt;br&gt;I open up the certificates in Firefox and it does indeed have a trusted root certificate for GTE CyberTrust Global Root. Strange indeed, so the chaining process is failing for some reason. The AIA information seems to be in order too.&lt;br&gt;&lt;br&gt;Before I fire up Wireshark to see what's happening I do a quick google search, and sure enough Larry beat me to it (&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/larryosterman/archive/2004/06/04/148612.aspx"&gt;http://blogs.msdn.com/larryosterman/archive/2004/06/04/148612.aspx&lt;/a&gt;) over two years ago. It turns out that Firefox doesn't follow the OID 1.3.6.1.5.5.7.48.2 when doing certificate chaining. &lt;br&gt;&lt;br&gt;At the end of Larry's post he said &amp;quot;Now all someone has to do is to file bugs against Mozilla and OpenSSL to get them to fix their certificate validation logic&amp;quot; I guess nobody did, or they ignored it.&lt;br&gt;&lt;br&gt;But I'm hoping Mark can verify if theory a or b was the correct one.&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453328</link><pubDate>Fri, 01 Sep 2006 11:38:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453328</guid><dc:creator>Drew</dc:creator><description>For looking up error codes, have you checked out DavidChr's err.exe? It's available on the intranet on that one server that I won't name publicly that has all the tools. It's also available on the internet downloadable from Microsoft, albeit probably in a slightly older version than the one posted internally. I use it about as frequently as I use SysInternals tools. That's *often*. My only gripe is that it doesn't include CLR exception codes yet.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453359</link><pubDate>Fri, 01 Sep 2006 12:09:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453359</guid><dc:creator>Joker</dc:creator><description>I thought, they would be using Linux there at Microsoft ;-) So they use Windows themselves...&lt;br&gt;&lt;br&gt;SCNR&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453387</link><pubDate>Fri, 01 Sep 2006 13:41:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453387</guid><dc:creator>Sean</dc:creator><description>Good point, well made, Jack!!!&lt;br&gt;&lt;br&gt;The RMC delays on my PC are at best, annoying.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453435</link><pubDate>Fri, 01 Sep 2006 15:26:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453435</guid><dc:creator>Liviu</dc:creator><description>But why does the hook need to pass the SID anyway?</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453447</link><pubDate>Fri, 01 Sep 2006 16:48:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453447</guid><dc:creator>Nikhil</dc:creator><description>Kudos, Mark with you to track down issues like this maybe Microsoft product quality can only go up :)&lt;br&gt;As far as the case of the certificate popup appearing in Firefox goes I saw Patricks comment and followed his trail to Larry's blog entry (&lt;a rel="nofollow" target="_new" href="http://blogs.msdn.com/larryosterman/archive/2004/06/04/148612.aspx"&gt;http://blogs.msdn.com/larryosterman/archive/2004/06/04/148612.aspx&lt;/a&gt;). I went through the comments there and sure enough a bug was indeed filed in Bugzilla (&lt;a rel="nofollow" target="_new" href="https://bugzilla.mozilla.org/show_bug.cgi?id=245609"&gt;https://bugzilla.mozilla.org/show_bug.cgi?id=245609&lt;/a&gt;). However, it seems there is some question regarding the RFC involved (&lt;a rel="nofollow" target="_new" href="http://www.ietf.org/rfc/rfc2459.txt"&gt;http://www.ietf.org/rfc/rfc2459.txt&lt;/a&gt;) and its validity. &lt;br&gt;</description></item><item><title>NetrLogonGetTrustRid and RPC</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453454</link><pubDate>Fri, 01 Sep 2006 17:29:35 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453454</guid><dc:creator>Marc Sherman</dc:creator><description>Mark, so NetrLogonGetTrustRid on the client side (PE in this case) performs RPC to a function of the *same* name in LSASS.exe? If so, is this just a convention used by NETLOGON when doing RPC? Or is this how RPC works in general? (eg. client side stub RPC's to real function of the same name on server side).&lt;br&gt;&lt;br&gt;thanks,&lt;br&gt;Marc</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453457</link><pubDate>Fri, 01 Sep 2006 18:04:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453457</guid><dc:creator>Justin</dc:creator><description>Great work, any opinion on this bug as it pertains to the state of windows in general? What I mean is how do you feel about all this code injection surface area that you guys expose in autoruns?&lt;br&gt;&lt;br&gt;It has been bugging me more and more how windows has so many places code can be placed to startup with the system which seems to have led to the spyware epidemic and now the anti-spyware causing thier own problems.&lt;br&gt;&lt;br&gt;My point is it seems the solutions are poor bandaids (good autruns fighting bad autoruns causing more running process and recource usage over all), when this stuff should be baked into the design so that 1. There is a consistent well known place for any startup code to be placed (perhaps services and startup folder only). 2. If a program trys to install anything there the user is warned explicity. 3. If the user wants to remove the startup they only need look in 2 places(1 would be ideal) and simply disable or delete startup they don't like.&lt;br&gt;&lt;br&gt;Now that definetly only helps part of the mainy issues involved in spyware, but its sorta like buffer overuns, autorunners are probably 90% of the problem, and windows defender is like trying to use some C library or code analyzer counter overruns when you should be making a new platform (.net) that inherintly doesnt have those issues.&lt;br&gt;&lt;br&gt;Would nice to hear your perspective, as autoruns really brings it home when looking at all the obsucre places startup code can be placed and you guys made it.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453459</link><pubDate>Fri, 01 Sep 2006 18:07:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453459</guid><dc:creator>Tom</dc:creator><description>Does anyone else think it's absolutely *insane* that launching Notepad should be this complex? Granted, when you pick it apart there may be a seemingly sane reason for each step, but when you step back and look at the big picture, the bottom line is that you can't simply launch Notepad without domains, RPCs and SIDs getting involved! It amazes me that by the time all this irrelevant overhead has taken place the system even remembers to actually launch Notepad at all. &lt;br&gt;&lt;br&gt;This is a perfect example of Microsoft's tendency to hypercomplexify everything it creates, and one of the reasons I can't stand them or their products. Unfortunately, I fear this is what will happen to the beautifully straightforward and simply functional Sysinternals tools.&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453466</link><pubDate>Fri, 01 Sep 2006 18:29:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453466</guid><dc:creator>Ed</dc:creator><description>Why has the old blog vanished? At least move the posts here...</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453473</link><pubDate>Fri, 01 Sep 2006 19:21:06 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453473</guid><dc:creator>Maurice</dc:creator><description>Excellent article, truly informative. &amp;nbsp;Thanks for the great tools and information. &amp;nbsp;Your knowledge has helped on countless occasions.</description></item><item><title>Mark Russinovich is Blogging on TechNet</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453487</link><pubDate>Fri, 01 Sep 2006 20:27:18 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453487</guid><dc:creator>David Ziembicki on Infrastructure Architecture</dc:creator><description>Mark now has a blog at &lt;a rel="nofollow" target="_new" href="http://blogs.technet.com/markrussinovich/&amp;amp;amp;nbsp;and"&gt;http://blogs.technet.com/markrussinovich/&amp;amp;amp;nbsp;and&lt;/a&gt; starts out with a typically...</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453515</link><pubDate>Fri, 01 Sep 2006 22:37:32 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453515</guid><dc:creator>C0D3R</dc:creator><description>It can be a help to get notified when you are logged on with cached credentials. It's a reminder that something is different about this session when problems present with consistency, but intermittently.&lt;br&gt;&lt;br&gt;HKLM\...\Winlogon&lt;br&gt;&amp;quot;ReportControllerMissing&amp;quot;=dword:00000001&lt;br&gt;&lt;br&gt;HKCU\...\Winlogon&lt;br&gt;&amp;quot;ReportDC&amp;quot;=dword:00000001&lt;br&gt;&lt;br&gt;See&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://support.microsoft.com/kb/242536/"&gt;http://support.microsoft.com/kb/242536/&lt;/a&gt;&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453517</link><pubDate>Fri, 01 Sep 2006 22:50:03 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453517</guid><dc:creator>Jon Wold</dc:creator><description>Mark said: &amp;nbsp;&amp;quot;The initial stack trace only went up as far as the NegotiateTransferSyntax frame, but there were obviously other frames that the symbol engine couldn’t determine. The stack display went further when I had hit the breakpoint I set in OpenLpcPort&amp;quot;&lt;br&gt;&lt;br&gt;On my windbg when the stack frames are all there for the walking (ie, nobody used EBP for their own scratchpad reg) then whacking the windbg stack backtrace More button will walk further w/o having to unwind the nested calls first. &amp;nbsp;Of course this was 64-bit Windows with which I'm far less familiar (what is that, rbp for amd64 / em64t ? or something completely unintelligible for Itanium ...).</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453527</link><pubDate>Fri, 01 Sep 2006 23:35:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453527</guid><dc:creator>Brian Murphy-Booth</dc:creator><description>Just wanted add -&lt;br&gt;&lt;br&gt;The only reason you didn't see MpShHook.dll on the first callstack (before the breakpoint is set) is because WinDBG only shows the first 20 &amp;quot;frames&amp;quot; by default. If you click the &amp;quot;more&amp;quot; button shown in the upper right of your screen shot you'll see more frames and would see the MpShHook. Breakpoints and registers sounds like more fun though! :-P&lt;br&gt;&lt;br&gt;Power to the debugger!!</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453545</link><pubDate>Sat, 02 Sep 2006 01:04:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453545</guid><dc:creator>markrussinovich</dc:creator><description>Ah, thanks. I never realized that was what the &amp;quot;more&amp;quot; button was for. I haven't done much debugging where the stack was more than 20 frames deep or I needed to look up a stack that far.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453549</link><pubDate>Sat, 02 Sep 2006 01:22:11 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453549</guid><dc:creator>Sebastian</dc:creator><description>I had the same delay problems, but i don't have the windows defender installed. I removed the domain integration and everything runs fine now.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453661</link><pubDate>Sat, 02 Sep 2006 18:37:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453661</guid><dc:creator>Adam Leinss</dc:creator><description>Good article, but I'm afraid that domain issues when the laptop is not connected are far too common with Windows. &amp;nbsp;We have a few sales guys that come in the office complaining about slow login times. &amp;nbsp;And indeed, login times can take 2 to 3 minutes when not on the domain. &amp;nbsp;Tried many suggestions on the Internet, but I just ended up having them hibernate the laptop to get around the slow login time.&lt;br&gt;&lt;br&gt;I can even get it to the point where all the event logs are clean and pristine and the login time is still really long. &amp;nbsp;Mind you this only happens on a handful of laptops, not all of them.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453670</link><pubDate>Sat, 02 Sep 2006 19:50:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453670</guid><dc:creator>Claus Valca</dc:creator><description>Mark,&lt;br&gt;&lt;br&gt;I love your articles! I'm learning so much! It's nice to see you posting again.&lt;br&gt;&lt;br&gt;I ran into a similar issue with XP Home locking up on my Dad's pc as soon as he hit his desktop.&lt;br&gt;&lt;br&gt;Using lessons (and your tools) I tracked the issue down to the wuauclt.exe process overloading his CPU.&lt;br&gt;&lt;br&gt;I've got the troubleshooting experience blogged over at &amp;lt;a href=&amp;quot;&lt;a rel="nofollow" target="_new" href="http://grandstreamdreams.blogspot.com/2006/09/thawing-xp-system.html&amp;quot;&amp;gt;Thawing"&gt;http://grandstreamdreams.blogspot.com/2006/09/thawing-xp-system.html&amp;quot;&amp;gt;Thawing&lt;/a&gt; an XP System&amp;lt;/a&amp;gt;&lt;br&gt;&lt;br&gt;Any chance you could take a look into this issue down the road? Or maybe you've run into it already. &amp;nbsp;I'm not on the elite level of process thread breakdown like you!&lt;br&gt;&lt;br&gt;Cheers!&lt;br&gt;--Claus</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453693</link><pubDate>Sun, 03 Sep 2006 02:04:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453693</guid><dc:creator>David Richter</dc:creator><description>I have learned from your web site zalot. A process context switch involves extracting that address requested from the Kernel Environment protection block and dumping it into the cr3 register of the cpu. The 1024 system file directories that form the mazin system file director has to page from the physcial and the linear. Address space laid out and a thread created. Hoevever, with explorer, the extra attention from the cpu, and subsytem environment only slow that loader that has read the Ds:DX header file so the app, or whater the process ( and relational dll) must have the DLL export the functions that the executable imported. Because of OLE 2, macro and stdin recordings, further user input may divert kernel code. Perhaps the symbolic files that represent the process for pdb info could load into the WinDbg. Changes in functionlity may also involve those cpu instensive sniffers, newtork traversal tools. Or it had an updated hotfix and the function signature differs and therefore does not respond to the API calling it. The, perhaps USER API calls the User32.dll, but is rerouted and packaged as an LPC and routed to the csrss.exe for processing ( before the overhead issue).</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453724</link><pubDate>Sun, 03 Sep 2006 08:07:02 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453724</guid><dc:creator>Jeff Gerard</dc:creator><description>I too have noticed this issue when not connected to the domain. &amp;nbsp;I am not using Defender here either and this is on XP Pro 32-bit.&lt;br&gt;&lt;br&gt;I have never actually tried to pinpoint the problem because there are just too many things running related to A/V, VPN, etc, but as a general rule, at least in my situation, a reboot and login with cached credentials typically fixes it up for me.&lt;br&gt;&lt;br&gt;This seems to happen more often when I'm logged into the domain at work, then hibernate, then power on and connect to my home network (from hibernate state).&lt;br&gt;&lt;br&gt;Nice article though..easy to follow and understand. &amp;nbsp;I firmly believe Microsoft will only benefit by having your skills supporting them behind the scenes.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453760</link><pubDate>Sun, 03 Sep 2006 12:56:13 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453760</guid><dc:creator>Gopi K</dc:creator><description>Nice article... but the problem is far to common. I don't think there is currently a reliable way to determine DC connectivity for netlogon (or any of the components involved) to behave any differently. &lt;br&gt;&lt;br&gt;I hope there is a non-intrusive fix to this. thoughts?</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453829</link><pubDate>Sun, 03 Sep 2006 21:40:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453829</guid><dc:creator>g-n-d.net</dc:creator><description>Thank you Mark for this article, and any other you share with us too. Regards from Poland.&lt;br&gt;&lt;br&gt;g-n-d.net</description></item><item><title>stuart @ amanzi  &amp;raquo; Blog Archive   &amp;raquo; Some new feeds for FeedDemon</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#453942</link><pubDate>Mon, 04 Sep 2006 12:23:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:453942</guid><dc:creator>stuart @ amanzi  » Blog Archive   » Some new feeds for FeedDemon</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://stuart.amanzi.co.nz/2006/09/04/some-new-feeds-for-feeddemon/"&gt;http://stuart.amanzi.co.nz/2006/09/04/some-new-feeds-for-feeddemon/&lt;/a&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#454057</link><pubDate>Mon, 04 Sep 2006 22:29:00 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454057</guid><dc:creator>nobody</dc:creator><description>Why does Windows Defender hook into ShellExecute to monitor starting processes, rather than CreateProcess?</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#454258</link><pubDate>Wed, 06 Sep 2006 01:30:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454258</guid><dc:creator>ddod</dc:creator><description>Intersting, your RSS link worked fine in Outlook 2007, that is until you moved your blog to Microsft servers. &amp;nbsp;When I try to add your new RSS feed outlook complains that it is invalid.&lt;br&gt;&lt;br&gt;Otherwise, as always you insights are useful and instructive.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#454439</link><pubDate>Wed, 06 Sep 2006 23:30:57 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454439</guid><dc:creator>mpd</dc:creator><description>@ nobody&lt;br&gt;&lt;br&gt;&amp;quot;Why does Windows Defender hook into ShellExecute to monitor starting processes, rather than CreateProcess?&amp;quot;&lt;br&gt;&lt;br&gt;My guess is because ShellExecute opens files whether they're executables, documents, or folders. &amp;nbsp;Defender sees more by hooking ShellExecute than CreateProcess.</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#454496</link><pubDate>Thu, 07 Sep 2006 02:41:20 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:454496</guid><dc:creator>Matt</dc:creator><description>I have seen this same process start delay on the Tablet PC edition of windows. &amp;nbsp;killing windows defender resolves the performance problem for me. &amp;nbsp;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#455214</link><pubDate>Mon, 11 Sep 2006 01:27:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455214</guid><dc:creator>umm</dc:creator><description>i see the same thing on my laptop too&lt;br&gt;XP PRo 32, NOD32 and SpySweeper loaded.&lt;br&gt;&lt;br&gt;when not on the DOMAIN, i need to delete any unconnected resources too.&lt;br&gt;I use batch files for that</description></item><item><title>RSS?</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#455383</link><pubDate>Mon, 11 Sep 2006 18:40:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455383</guid><dc:creator>John</dc:creator><description>Anyone got any idea why the RSS for this page isn't recognised by Bloglines. I can't get it to subscribe to this blog.&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#455681</link><pubDate>Tue, 12 Sep 2006 21:48:26 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455681</guid><dc:creator>Dalton Williams</dc:creator><description>Great post!!! &amp;nbsp;The CEO of my company has called me at least once a week for his slow start up for two years! &amp;nbsp;He does not run Defender though.&lt;br&gt;&lt;br&gt;Any chances of you running with this further and finding other causes in XP? &amp;nbsp;&lt;br&gt;&lt;br&gt;What about a patch to fix theis at some point?&lt;br&gt;&lt;br&gt;Thanks,&lt;br&gt;Dalton Williams&lt;br&gt;EVP &amp;amp; CIO WestStar Bank</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#455685</link><pubDate>Tue, 12 Sep 2006 22:15:23 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:455685</guid><dc:creator>Zach</dc:creator><description>Just thought it was puzzeling that Micrsoft would let you join your personal laptop to their internal network, or maybe they don't know. Nice post! &amp;nbsp;I think I'll be reading your BLOG more often.&lt;br&gt;&lt;br&gt;Take care,&lt;br&gt;Zach</description></item><item><title>Soci blog  &amp;raquo; Blog Archive   &amp;raquo; Szeretn??k ??n ??gy debugolni, mint ez a Russinovich gyerek</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#456997</link><pubDate>Sun, 17 Sep 2006 14:25:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:456997</guid><dc:creator>Soci blog  » Blog Archive   » Szeretn??k ??n ??gy debugolni, mint ez a Russinovich gyerek</dc:creator><description>PingBack from &lt;a rel="nofollow" target="_new" href="http://soci.hu/blog/index.php/2006/09/17/szeretnek-en-igy-debugolni-mint-ez-a-russinovich-gyerek/"&gt;http://soci.hu/blog/index.php/2006/09/17/szeretnek-en-igy-debugolni-mint-ez-a-russinovich-gyerek/&lt;/a&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457128</link><pubDate>Mon, 18 Sep 2006 03:27:30 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457128</guid><dc:creator>Vipzen</dc:creator><description>another great post Mark!&lt;br&gt;hugs from Brazil</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457159</link><pubDate>Mon, 18 Sep 2006 09:41:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457159</guid><dc:creator>Muad_Dib</dc:creator><description>Great job, but :&lt;br&gt;- I use XP Pro 32 bits&lt;br&gt;- I'm not connected to any domain (standalone laptop)&lt;br&gt;- I don't use Defender&lt;br&gt;and I frequently experience such long and boring delays when I start processes.&lt;br&gt;&lt;br&gt;So, where is the problem ?&lt;br&gt;</description></item><item><title>a new challenge for Mark</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457243</link><pubDate>Mon, 18 Sep 2006 17:36:01 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457243</guid><dc:creator>Ilia Barski</dc:creator><description>There is a very interesting task that only Mark could implement: to undercover a delays nature by Windows booting. I am afraid it would need a new early activating tool to bring a light splash on the boot scene</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457499</link><pubDate>Tue, 19 Sep 2006 16:33:15 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457499</guid><dc:creator>slemaire</dc:creator><description>The problem exists since a very long time, prior Windows Defender. I experienced it with Win NT 4 and Cygwin utilities few years ago. Some programs were performing pointless inits, which were causing long delay when disconnected from the domain.&lt;br&gt;&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457684</link><pubDate>Wed, 20 Sep 2006 11:31:47 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457684</guid><dc:creator>Alexander Suhovey</dc:creator><description>Hmm, I wonder if everyone is comfortable with Mark revealing internal MS's domain SID...</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457732</link><pubDate>Wed, 20 Sep 2006 13:08:36 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457732</guid><dc:creator>Alexander Suhovey</dc:creator><description>Drew, are you referring to Microsoft Exchange Server Error Code Look-up?&lt;br&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/downloads/details.aspx?familyid=be596899-7bb8-4208-b7fc-09e02a13696c&amp;amp;displaylang=en"&gt;http://www.microsoft.com/downloads/details.aspx?familyid=be596899-7bb8-4208-b7fc-09e02a13696c&amp;amp;displaylang=en&lt;/a&gt;&lt;br&gt;&lt;br&gt;If yes, it's v06.05.7226 (5/24/2004) so it's probably an old version. Could you by chance ask somebody to update this download with latest version?&lt;br&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#457951</link><pubDate>Thu, 21 Sep 2006 15:22:46 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:457951</guid><dc:creator>Berry</dc:creator><description>I usually DON'T JOIN any CORPORATE Domain.&lt;br&gt;I'll just login only to change password...&lt;br&gt;&lt;br&gt;And everything runs fine</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#458016</link><pubDate>Thu, 21 Sep 2006 22:40:29 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:458016</guid><dc:creator>JoNathon</dc:creator><description>The workaround I have our laptop users use is, do not plug in your laptop / turn on wireless, until you see the login screen when not at work (connected to the domain).</description></item><item><title>Ещё об оптимизации приложений</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#459593</link><pubDate>Thu, 28 Sep 2006 13:28:52 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:459593</guid><dc:creator>Проверенный чёрт</dc:creator><description>Я тут ранее упоминал про идентификацию проблем и оптимизацию загрузки Word'а &lt;a rel="nofollow" target="_new" href="http://ivbeg.livejournal.com/30511.html"&gt;http://ivbeg.livejournal.com/30511.html&lt;/a&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#470888</link><pubDate>Tue, 17 Oct 2006 13:01:37 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:470888</guid><dc:creator>ASB</dc:creator><description>&lt;p&gt;Good work, Mark, and great explanation.&lt;/p&gt;
&lt;p&gt;This accounts for one of the issues I have had recently. &amp;nbsp; However, as quite a few folks have noted here, there are issues that occur in 32-bit XP and 2003, (more so in XP), without the use of Defender, regardless of domain connectivity/status.&lt;/p&gt;
&lt;p&gt;Looks like I'm going to have to do the work and uncover them, because they are annoying...&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#487922</link><pubDate>Tue, 31 Oct 2006 01:33:45 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:487922</guid><dc:creator>goz</dc:creator><description>&lt;p&gt;we need and appreciate people like you&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#516687</link><pubDate>Wed, 15 Nov 2006 06:21:39 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:516687</guid><dc:creator>Anonyass</dc:creator><description>&lt;p&gt;It's no wonder we've got more cycles then ever before and we're still waiting for our computers. Blooooaaaaat. What ever happened to K.I.S.S.? Don't forget this all started to run a text editor! Geewiz.&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#517898</link><pubDate>Thu, 16 Nov 2006 17:56:55 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:517898</guid><dc:creator>Kevin Wright</dc:creator><description>&lt;p&gt;I have a Thinkpad laptop with Windows 2000. &amp;nbsp;When I am connected to my employer's network, then standby and go home, when I start working again I notice a long (30-60 second) delay for applications to start.&lt;/p&gt;
&lt;p&gt;Recently I discovered that if I unmap all network drives when I am at home, then my applications start almost immediately.&lt;/p&gt;
&lt;p&gt;Not sure if this is related to your problem.&lt;/p&gt;</description></item><item><title>Entelliblog  &amp;raquo; Blog Archive   &amp;raquo; General Microsoft and MCS. SharePoint and MOSS 2007.</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#520026</link><pubDate>Sat, 18 Nov 2006 05:29:21 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:520026</guid><dc:creator>Entelliblog  » Blog Archive   » General Microsoft and MCS. SharePoint and MOSS 2007.</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.entelliblog.com/?p=4966"&gt;http://www.entelliblog.com/?p=4966&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>The Case of the Delayed Windows Vista File Open Dialogs</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#532480</link><pubDate>Mon, 27 Nov 2006 20:38:54 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:532480</guid><dc:creator>Mark's Blog</dc:creator><description>&lt;p&gt;I was in Barcelona a couple of weeks ago speaking at Microsoft’s TechEd/ITForum conference, where I delivered&lt;/p&gt;
</description></item><item><title>Entelliblog  &amp;raquo; Blog Archive   &amp;raquo; Terminal Addict</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#563597</link><pubDate>Wed, 20 Dec 2006 10:17:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:563597</guid><dc:creator>Entelliblog  » Blog Archive   » Terminal Addict</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.entelliblog.com/?p=7268"&gt;http://www.entelliblog.com/?p=7268&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>Windows Vista打开对话框延时问题的排错实例</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#603678</link><pubDate>Sun, 21 Jan 2007 08:41:38 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:603678</guid><dc:creator>盆盆的博客</dc:creator><description>&lt;p&gt;原文 作者 Mark Russinovich 翻译 作者 盆盆 [ITECN站长] ITECN博客 &lt;a rel="nofollow" target="_new" href="http://blogs.itecn.net/blogs/"&gt;http://blogs.itecn.net/blogs/&lt;/a&gt; 盆盆 导读 本文由 Mark Russinovich&lt;/p&gt;
</description></item><item><title>Entelliblog  &amp;raquo; Blog Archive   &amp;raquo; Christoph R  egg</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#635549</link><pubDate>Sun, 11 Feb 2007 03:06:17 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:635549</guid><dc:creator>Entelliblog  » Blog Archive   » Christoph R  egg</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.entelliblog.com/?p=10537"&gt;http://www.entelliblog.com/?p=10537&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#642838</link><pubDate>Wed, 14 Feb 2007 21:50:41 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:642838</guid><dc:creator>Rob Shearman</dc:creator><description>&lt;p&gt;FYI, the reason this only affects Windows 2003 and not Windows XP is to do with the RPC_SECURITY_QOS_V3 structure introduced with Windows 2003 that adds a Sid field: &lt;a rel="nofollow" target="_new" href="http://msdn2.microsoft.com/en-us/library/aa378649.aspx"&gt;http://msdn2.microsoft.com/en-us/library/aa378649.aspx&lt;/a&gt;&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#643628</link><pubDate>Thu, 15 Feb 2007 11:34:48 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:643628</guid><dc:creator>S</dc:creator><description>&lt;p&gt;If you fancy doing some more digging, I find that whenever compiling with Visual Studio 2003 it causes windows in other unrelated apps to just lock up - e.g. Outlook, Explorer, IE won't repaint properly and appear to be hung. Sometimes, briefly, Explorer windows get the Visual Studio title. Deeply odd! The CPU isn't maxed out by any means. Is there some sort of 'global UI mutex' that MS products use in some way that Visual Studio used badly?&lt;/p&gt;</description></item><item><title>Entelliblog  &amp;raquo; Blog Archive   &amp;raquo; Thousands of free tutorials, articles, source code, components</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#672450</link><pubDate>Sun, 04 Mar 2007 03:52:49 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:672450</guid><dc:creator>Entelliblog  » Blog Archive   » Thousands of free tutorials, articles, source code, components</dc:creator><description>&lt;p&gt;PingBack from &lt;a rel="nofollow" target="_new" href="http://www.entelliblog.com/?p=11992"&gt;http://www.entelliblog.com/?p=11992&lt;/a&gt;&lt;/p&gt;
</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#719142</link><pubDate>Sat, 31 Mar 2007 07:11:33 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:719142</guid><dc:creator>Spencer Ferguson</dc:creator><description>&lt;p&gt;Way to go, Mark! &amp;nbsp;This was a great read.&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#816589</link><pubDate>Tue, 24 Apr 2007 22:41:51 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:816589</guid><dc:creator>Funbit</dc:creator><description>&lt;p&gt;Thanks for the great article! Too bad they appear very rarely though..&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#972274</link><pubDate>Wed, 16 May 2007 00:21:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:972274</guid><dc:creator>Phil Norris</dc:creator><description>&lt;p&gt;It's extremely interesting, educational &amp;amp; impressive for me (without programming background) to read how Mark gets to the bottom of the inner workings and shortcomings of Windows. I think Mark explains some complex points very effectively (even I understand a lot of it). A beginners guide to the basics, if there are any basics!, of the Windows kernel would be great from Marks perspective.&lt;/p&gt;
&lt;p&gt; I hope working at Microsoft won't stop Mark from discussing the bugs in these OS's to the general public. Great articles, very dedicated. &lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#1586487</link><pubDate>Mon, 23 Jul 2007 12:43:16 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:1586487</guid><dc:creator>JM_White</dc:creator><description>&lt;p&gt;Broken Link for autorun&lt;/p&gt;
&lt;p&gt;Link in blog aritcle:&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.sysinternals.com/utilities/autoruns.html"&gt;http://www.sysinternals.com/utilities/autoruns.html&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;Correct Link for autorun utility (as of 7.23.2007):&lt;/p&gt;
&lt;p&gt;&lt;a rel="nofollow" target="_new" href="http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/Autoruns.mspx"&gt;http://www.microsoft.com/technet/sysinternals/ProcessesAndThreads/Autoruns.mspx&lt;/a&gt;&lt;/p&gt;
&lt;p&gt;btw Thanks for all the Great SysInternals Utilities - I have Process Explorer set to startup all the time. I just wish there was a GUI shell that provide a mouse drive way to run all the PsTools cmd line utilities. Piping to text files all the time is a bit tedious.. &lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#3066861</link><pubDate>Fri, 06 Jun 2008 11:11:12 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3066861</guid><dc:creator>French reader</dc:creator><description>&lt;p&gt;Hi Mark!&lt;/p&gt;
&lt;p&gt;I tried to reproduce your debugging steps on my own laptop, but I stumbled on a problem early on.&lt;/p&gt;
&lt;p&gt;You said that you started by attaching Windbg to PROCESS EXPLORER and then you launched Notepad with PROCESS EXPLORER's Run dialog. &lt;/p&gt;
&lt;p&gt;If I attach Windbg to PROCESS EXPLORER, the PE window is frozen and I have no access to its file/run dialog.&lt;/p&gt;
&lt;p&gt;On the other hand if I attach Windbg to WINDOWS EXPLORER, PE window is not frozen and I can open notepad from its file/run dialog.&lt;/p&gt;
&lt;p&gt;Also the PID number (3460) which appears in you first Windbg's Calls window picture makes me think that Windbg was attached to WINDOWS EXPLORER rather than to PROCESS EXPLORER.&lt;/p&gt;
&lt;p&gt;Could you please confirm which process Windbg was attached to in your first debugging step?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;</description></item><item><title>re: The Case of the Process Startup Delays</title><link>http://blogs.technet.com/markrussinovich/archive/2006/08/31/453100.aspx#3158225</link><pubDate>Sun, 23 Nov 2008 16:07:50 GMT</pubDate><guid isPermaLink="false">d5e57398-b9ef-4490-9955-07cbb4e4a80d:3158225</guid><dc:creator>Harish</dc:creator><description>&lt;p&gt;Hi,&lt;/p&gt;
&lt;p&gt;I faced the same delays in Windows XP. It takes 5-6 seconds to open any app from run dialog.&lt;/p&gt;
&lt;p&gt;Does this explanation fits there too?&lt;/p&gt;
&lt;p&gt;Thanks&lt;/p&gt;</description></item></channel></rss>