Process PID CPU Description Company Name
System Idle Process 0 99.22
Interrupts n/a Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4
smss.exe 160 Windows NT Oturum Yöneticisi Microsoft Corporation
csrss.exe 208 0.78 Client Server Runtime Process Microsoft Corporation
winlogon.exe 232 Windows NT Oturum Açma Uygulaması Microsoft Corporation
services.exe 276 Hizmetler ve Denetleyici uygulaması Microsoft Corporation
svchost.exe 420 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 496 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 564 Generic Host Process for Win32 Services Microsoft Corporation
lsass.exe 288 LSA Shell (Export Version) Microsoft Corporation
explorer.exe 784 Windows Gezgini Microsoft Corporation
WINWORD.EXE 956 Microsoft Word Microsoft Corporation
procexp.exe 1084 Sysinternals Process Explorer Sysinternals
Process: WINWORD.EXE Pid: 956
Type Name
Desktop \Default
Directory \Windows
Directory \BaseNamedObjects
Directory \KnownDlls
Event \BaseNamedObjects\PrimaryWord10Mutex
File C:\WINDOWS\WinSxS\x86_Microsoft.Windows.Common-Controls_6595b64144ccf1df_6.0.2600.2982_x-ww_ac3f9c03
File C:\Documents and Settings\Administrator\Belgelerim
File \Device\KsecDD
Key HKCU\Software\Microsoft\Office\10.0\Common\UserInf o
Key HKCU\Software\Microsoft\Office\10.0\Common
Key HKCU\Software\Classes
Key HKCU\Software\Microsoft\Office\10.0\Word\Options
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKCR
Key HKU
Key HKCR
Key HKCU\Software\Classes
Key HKCU\Software\Microsoft\Office\10.0\Word
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKU
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKCR\CLSID
Key HKCR
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKU
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKLM\SOFTWARE\Microsoft\COM3
Key HKCR\CLSID
Key HKCU\Software\Classes
Key HKCU\Software\Classes
Key HKCR\TypeLib\{2DF8D04C-5BFA-101B-BDE5-00AA0044DE52}\2.2\0\win32
Key HKLM\SYSTEM\Setup
Key HKCU\Software\Classes
Key HKLM\SOFTWARE\Clients\Mail
Key HKLM
Key HKCU\Software\Classes
Key HKCU\Software\Microsoft\Windows\ShellNoRoam
Key HKCU\Software\Microsoft\Windows\ShellNoRoam\MUICac he
Key HKLM\SOFTWARE\Microsoft\Internet Explorer
Key HKCU\Software\Microsoft\Office\10.0\Word\UserInfo
Key HKCU\Software\Microsoft\Office\10.0\Common\General
Key HKCU\Software\Microsoft\Office\10.0\Common
Key HKCU\Software\Microsoft\Office\Common\Assistant
Key HKCU\Software\Classes
Key HKLM\SOFTWARE\Microsoft\Office\10.0\Common\Install Root
Key HKLM\SOFTWARE\Microsoft\Shared\HTML
Key HKLM\SOFTWARE\Microsoft\Shared\MHTML
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer
Key HKCU
Key HKLM\SOFTWARE\Microsoft\Office\10.0\Common\General
Key HKCU\Software\Microsoft\Shared
Key HKU
Key HKCU\Software\Microsoft\Office\10.0\Word
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Locale\Alter nate Sorts
Key HKLM\SYSTEM\ControlSet001\Control\Nls\Language Groups
Key HKLM\SOFTWARE\Microsoft\Office\10.0\Common\Languag eResources
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer\User Shell Folders
Key HKCU\Software\Microsoft\Windows NT\CurrentVersion\Windows
Key HKCU\Software\Microsoft\Office\10.0\Word\Wizards
Key HKCU\Software\Microsoft\Office\10.0\Common\Languag eResources
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer
Key HKCU\Software\Microsoft\Office\10.0\Word\Options
Key HKCU\Software\Microsoft\Office\10.0\Word\UserInfo
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Exp lorer
Key HKCR\Word.Document\CurVer
Key HKCU\Control Panel\International
Key HKCU\Software\Microsoft\Windows\CurrentVersion\Pol icies\Explorer
Key HKCR\CLSID\{00020906-0000-0000-C000-000000000046}\LocalServer32
KeyedEvent \KernelObjects\CritSecOutOfMemoryEvent
Mutant \BaseNamedObjects\Mso97SharedDg20321006839Mutex
Mutant \BaseNamedObjects\CTF.LBES.MutexDefaultS-1-5-21-2000478354-1229272821-839522115-500
Mutant \BaseNamedObjects\CTF.Compart.MutexDefaultS-1-5-21-2000478354-1229272821-839522115-500
Mutant \BaseNamedObjects\CTF.Asm.MutexDefaultS-1-5-21-2000478354-1229272821-839522115-500
Mutant \BaseNamedObjects\CTF.Layouts.MutexDefaultS-1-5-21-2000478354-1229272821-839522115-500
Mutant \BaseNamedObjects\CTF.TMD.MutexDefaultS-1-5-21-2000478354-1229272821-839522115-500
Mutant \BaseNamedObjects\Mso97SharedDg19521006839Mutex
Mutant \BaseNamedObjects\OfficeAssistantStateMutex
Mutant \BaseNamedObjects\ShimCacheMutex
Mutant \BaseNamedObjects\MSO97SharedMemMutex
Mutant \BaseNamedObjects\MSO97BStripMutex
Mutant \BaseNamedObjects\Mso97SharedDg19211006839Mutex
Port \RPC Control\OLEDA74A76514C544E7A33C9DBDEE07
Section \BaseNamedObjects\CiceroSharedMemDefaultS-1-5-21-2000478354-1229272821-839522115-500
Section \BaseNamedObjects\RotHintTable
Section \BaseNamedObjects\Mso97SharedDg19521006839
Section \BaseNamedObjects\ShimSharedMemory
Section \BaseNamedObjects\Mso97SharedDg19211006839
Section \BaseNamedObjects\PrimaryWord10SharedMemoryArea
Section \BaseNamedObjects\Mso97SharedDg20321006839
Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Semaphore \BaseNamedObjects\shell.{210A4BA0-3AEA-1069-A2D9-08002B30309D}
Semaphore \BaseNamedObjects\shell.{7CB834F0-527B-11D2-9D1F-0000F805CA57}
Semaphore \BaseNamedObjects\shell.{A48F1A32-A340-11D1-BC6B-00A0C90312E1}
Thread WINWORD.EXE(956): 968
Thread WINWORD.EXE(956): 968
Thread WINWORD.EXE(956): 976
Thread WINWORD.EXE(956): 976
Thread WINWORD.EXE(956): 1080
Thread WINWORD.EXE(956): 960
Thread WINWORD.EXE(956): 960
WindowStation \Windows\WindowStations\WinSta0
WindowStation \Windows\WindowStations\WinSta0