I was wondering if there is some way resolve the issue of WmiPrvSE.exe consuming from 4-6 percent of my CPU constantly? I have a new installation of Windows 2008 Enterprise running on a Quad Core with 4GB ram and the Windows Management Instrumentation will not settle down.
I have another 2008 installation that does not exhibit this behavior. What might be causing this process to consume my CPU? I have tried disabling various services to no avail. Is there a specific service or role that can cause this? Any way to dig in on what's running in the process?
Thanks!
---UPDATE---
I downloaded Process Monitor from Sys Internals and I am seeing that wmiprvse.exe is running a CreateFile process on C:\WIndows\System32\tzres.dll over and over constantly.
Code Snippet
1115321 10:20:34.5323064 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115324 10:20:34.5324188 PM wmiprvse.exe 2724 QueryStandardInformationFile C:\Windows\System32\tzres.dll SUCCESS AllocationSize: 4,096, EndOfFile: 2,048, NumberOfLinks: 1, DeletePending: False, Directory: False
1115328 10:20:34.5325959 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115329 10:20:34.5326125 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\en-US\tzres.dll.mui SUCCESS Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115332 10:20:34.5327013 PM wmiprvse.exe 2724 QueryStandardInformationFile C:\Windows\System32\en-US\tzres.dll.mui SUCCESS AllocationSize: 20,480, EndOfFile: 18,944, NumberOfLinks: 2, DeletePending: False, Directory: False
1115336 10:20:34.5333601 PM wmiprvse.exe 2724 QueryOpen C:\Windows\System32\tzres.dll FAST IO DISALLOWED
1115337 10:20:34.5336879 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\en-US\tzres.dll.mui SUCCESS
1115339 10:20:34.5340095 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115340 10:20:34.5340912 PM wmiprvse.exe 2724 QueryBasicInformationFile C:\Windows\System32\tzres.dll SUCCESS CreationTime: 1/18/2008 10:59:11 PM, LastAccessTime: 1/19/2008 2:24:58 AM, LastWriteTime: 11/2/2006 12:05:07 AM, ChangeTime: 3/5/2008 2:29:13 PM, FileAttributes: A
1115341 10:20:34.5341305 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115343 10:20:34.5341950 PM wmiprvse.exe 2724 QueryOpen C:\Windows\System32\tzres.dll FAST IO DISALLOWED
1115344 10:20:34.5345423 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115345 10:20:34.5345949 PM wmiprvse.exe 2724 QueryBasicInformationFile C:\Windows\System32\tzres.dll SUCCESS CreationTime: 1/18/2008 10:59:11 PM, LastAccessTime: 1/19/2008 2:24:58 AM, LastWriteTime: 11/2/2006 12:05:07 AM, ChangeTime: 3/5/2008 2:29:13 PM, FileAttributes: A
1115346 10:20:34.5346293 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115348 10:20:34.5346913 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115350 10:20:34.5347922 PM wmiprvse.exe 2724 QueryStandardInformationFile C:\Windows\System32\tzres.dll SUCCESS AllocationSize: 4,096, EndOfFile: 2,048, NumberOfLinks: 1, DeletePending: False, Directory: False
1115352 10:20:34.5348427 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115356 10:20:34.5349242 PM wmiprvse.exe 2724 QueryStandardInformationFile C:\Windows\System32\tzres.dll SUCCESS AllocationSize: 4,096, EndOfFile: 2,048, NumberOfLinks: 1, DeletePending: False, Directory: False
1115357 10:20:34.5351181 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115362 10:20:34.5353233 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115364 10:20:34.5360080 PM wmiprvse.exe 2724 QueryOpen C:\Windows\System32\tzres.dll FAST IO DISALLOWED
1115365 10:20:34.5360208 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\en-US\tzres.dll.mui SUCCESS Desired Access: Generic Read, Disposition: Open, Options: , Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115367 10:20:34.5362581 PM wmiprvse.exe 2724 QueryStandardInformationFile C:\Windows\System32\en-US\tzres.dll.mui SUCCESS AllocationSize: 20,480, EndOfFile: 18,944, NumberOfLinks: 2, DeletePending: False, Directory: False
1115368 10:20:34.5362947 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened
1115371 10:20:34.5363607 PM wmiprvse.exe 2724 QueryBasicInformationFile C:\Windows\System32\tzres.dll SUCCESS CreationTime: 1/18/2008 10:59:11 PM, LastAccessTime: 1/19/2008 2:24:58 AM, LastWriteTime: 11/2/2006 12:05:07 AM, ChangeTime: 3/5/2008 2:29:13 PM, FileAttributes: A
1115373 10:20:34.5363872 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\tzres.dll SUCCESS
1115375 10:20:34.5364900 PM wmiprvse.exe 2724 CloseFile C:\Windows\System32\en-US\tzres.dll.mui SUCCESS
1115377 10:20:34.5366723 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened1115320 10:20:34.5322271 PM wmiprvse.exe 2724 CreateFile C:\Windows\System32\tzres.dll SUCCESS Desired Access: Read Data/List Directory, Synchronize, Disposition: Open, Options: Synchronous IO Non-Alert, Non-Directory File, Attributes: n/a, ShareMode: Read, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\SYSTEM, OpenResult: Opened