auf der Suche nach Verbesserung der Systemleistung meines Systems mit Sysinternals Procmon fiel mir folgendes auf:
Der Prozess Vmware-authd fragt zyklisch (alle paar Millisekunden) Werte in der Registry ab. Das erzeugt zweifelsohne Systemlast.
Um das nachzuverfolgen benötigt man Sysinternals Procmon.
Dann stellt man ein Filter auf "Result" "contains" "NOT FOUND" "Include"
Ein weiteres Filter stellt man auf "Process Name" "is" "Vmware-authd" "Include"
Ein kleiner Auszug der sich ständigen wiederholenden Registryzugriffe:
"08:53:45.5289591","vmware-authd.exe","1256","RegDeleteValue","HKLM\System\CurrentControlSet\Services\PerfOS\Performance\Error Count","NAME NOT FOUND",""
"08:53:45.5290172","vmware-authd.exe","1256","RegQueryValue","HKLM\System\CurrentControlSet\Services\PerfProc\Performance\Disable Performance Counters","NAME NOT FOUND","Length: 20"
"08:53:45.5329484","vmware-authd.exe","1256","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perfproc.dll","NAME NOT FOUND","Desired Access: Read"
"08:53:45.5329911","vmware-authd.exe","1256","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\EventLogLevel","NAME NOT FOUND","Length: 144"
"08:53:45.5332642","vmware-authd.exe","1256","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\TotalInstanceName","NAME NOT FOUND","Length: 1.024"
"08:53:45.5333216","vmware-authd.exe","1256","RegQueryValue","HKLM\System\CurrentControlSet\Services\PerfProc\Performance\DisplayHeapPerfObject","NAME NOT FOUND","Length: 19"
"08:53:45.5333350","vmware-authd.exe","1256","RegQueryValue","HKLM\System\CurrentControlSet\Services\PerfProc\Performance\ProcessNameFormat","NAME NOT FOUND","Length: 19"
"08:53:45.5333449","vmware-authd.exe","1256","RegQueryValue","HKLM\System\CurrentControlSet\Services\PerfProc\Performance\ThreadNameFormat","NAME NOT FOUND","Length: 19"
"08:53:45.5333676","vmware-authd.exe","1256","RegDeleteValue","HKLM\System\CurrentControlSet\Services\PerfProc\Performance\Error Count","NAME NOT FOUND",""
"08:53:50.5202487","vmware-authd.exe","1256","RegQueryValue","HKLM\System\CurrentControlSet\Services\PerfOS\Performance\Disable Performance Counters","NAME NOT FOUND","Length: 20"
"08:53:50.5237861","vmware-authd.exe","1256","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perfos.dll","NAME NOT FOUND","Desired Access: Read"
"08:53:50.5238562","vmware-authd.exe","1256","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\EventLogLevel","NAME NOT FOUND","Length: 144"
"08:53:50.5240747","vmware-authd.exe","1256","RegQueryValue","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Perflib\TotalInstanceName","NAME NOT FOUND","Length: 1.024"
"08:53:50.5241994","vmware-authd.exe","1256","RegDeleteValue","HKLM\System\CurrentControlSet\Services\PerfOS\Performance\Error Count","NAME NOT FOUND",""
"08:53:50.5242552","vmware-authd.exe","1256","RegQueryValue","HKLM\System\CurrentControlSet\Services\PerfProc\Performance\Disable Performance Counters","NAME NOT FOUND","Length: 20"
"08:53:50.5280746","vmware-authd.exe","1256","RegOpenKey","HKLM\Software\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\perfproc.dll","NAME NOT FOUND","Desired Access: Read"
Frage:
Wie kann man das abstellen?
-----
Vware Workstation 6 oder 7; Wuindows 7 oder XP:
