Dulo23
Messages postés3Date d'inscriptiondimanche 8 mai 2011StatutMembreDernière intervention23 mai 2011
-
10 mai 2011 à 03:17
Utilisateur anonyme -
10 mai 2011 à 03:20
Bonjour,
info.txt logfile of random's system information tool 1.08 2011-05-09 18:01:32
======Uninstall list======
Adobe Flash Player 10 ActiveX-->C:\Windows\system32\Macromed\Flash\FlashUtil10p_ActiveX.exe -maintain activex
Apple Application Support-->MsiExec.exe /I{2DC94AFD-A6E2-4AB4-9132-4A3F8E07B386}
Apple Mobile Device Support-->MsiExec.exe /I{CACAEB5F-174D-4C7C-AC56-A33289A807CA}
Apple Software Update-->MsiExec.exe /I{C41300B9-185D-475E-BFEC-39EF732F19B1}
Atheros for Acer Driver v7.2.0.208_Foxconn Installation Program-->C:\Program Files\InstallShield Installation Information\{28006915-2739-4EBE-B5E8-49B25D32EB33}\setup.exe -runfromtemp -l0x0009 -removeonly
Bonjour-->MsiExec.exe /X{2A981294-F14C-4F0F-9627-D793270922F8}
Intel(R) Graphics Media Accelerator Driver-->C:\Windows\system32\igxpun.exe -uninstall
Intel(R) TV Wizard-->C:\Windows\system32\TVWizudlg.exe -uninstall
iTunes-->MsiExec.exe /I{2A697B53-0DE3-42DA-B41D-C3F804B1C538}
Microsoft Antimalware Service FR-FR Language Pack-->MsiExec.exe /X{0450B7B0-AC71-44A4-AB40-4DD678DF3A8C}
Microsoft Antimalware Service FR-FR Language Pack-->MsiExec.exe /X{A4526B5A-89C0-4F4B-9E6E-4F883374D5F9}
Microsoft Antimalware-->MsiExec.exe /X{774088D4-0777-4D78-904D-E435B318F5D2}
Microsoft Office Access MUI (English) 2007-->MsiExec.exe /X{90120000-0015-0409-0000-0000000FF1CE}
Microsoft Office Access Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0117-0409-0000-0000000FF1CE}
Microsoft Office Enterprise 2007-->"C:\Program Files\Common Files\Microsoft Shared\OFFICE12\Office Setup Controller\setup.exe" /uninstall ENTERPRISE /dll OSETUP.DLL
Microsoft Office Enterprise 2007-->MsiExec.exe /X{90120000-0030-0000-0000-0000000FF1CE}
Microsoft Office Excel MUI (English) 2007-->MsiExec.exe /X{90120000-0016-0409-0000-0000000FF1CE}
Microsoft Office Groove MUI (English) 2007-->MsiExec.exe /X{90120000-00BA-0409-0000-0000000FF1CE}
Microsoft Office Groove Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0114-0409-0000-0000000FF1CE}
Microsoft Office InfoPath MUI (English) 2007-->MsiExec.exe /X{90120000-0044-0409-0000-0000000FF1CE}
Microsoft Office OneNote MUI (English) 2007-->MsiExec.exe /X{90120000-00A1-0409-0000-0000000FF1CE}
Microsoft Office Outlook MUI (English) 2007-->MsiExec.exe /X{90120000-001A-0409-0000-0000000FF1CE}
Microsoft Office PowerPoint MUI (English) 2007-->MsiExec.exe /X{90120000-0018-0409-0000-0000000FF1CE}
Microsoft Office Proof (English) 2007-->MsiExec.exe /X{90120000-001F-0409-0000-0000000FF1CE}
Microsoft Office Proof (French) 2007-->MsiExec.exe /X{90120000-001F-040C-0000-0000000FF1CE}
Microsoft Office Proof (Spanish) 2007-->MsiExec.exe /X{90120000-001F-0C0A-0000-0000000FF1CE}
Microsoft Office Proofing (English) 2007-->MsiExec.exe /X{90120000-002C-0409-0000-0000000FF1CE}
Microsoft Office Publisher MUI (English) 2007-->MsiExec.exe /X{90120000-0019-0409-0000-0000000FF1CE}
Microsoft Office Shared MUI (English) 2007-->MsiExec.exe /X{90120000-006E-0409-0000-0000000FF1CE}
Microsoft Office Shared Setup Metadata MUI (English) 2007-->MsiExec.exe /X{90120000-0115-0409-0000-0000000FF1CE}
Microsoft Office Word MUI (English) 2007-->MsiExec.exe /X{90120000-001B-0409-0000-0000000FF1CE}
Microsoft Security Client FR-FR Language Pack-->MsiExec.exe /I{859B9BCA-5376-4566-9F88-C6C9DAA7A925}
Microsoft Security Client-->MsiExec.exe /I{77A776C4-D10F-416D-88F0-53F2D9DCD9B3}
Microsoft Security Essentials-->C:\Program Files\Microsoft Security Client\Setup.exe /x
QuickTime-->MsiExec.exe /I{57752979-A1C9-4C02-856B-FBB27AC4E02C}
======Security center information======
AS: Windows Defender
======System event log======
Computer Name: Instructor-PC
Event Code: 4374
Message: Windows Servicing identified that package KB974571(Security Update) is not applicable for this system
Record Number: 2088
Source Name: Microsoft-Windows-Servicing
Time Written: 20110510010041.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 4374
Message: Windows Servicing identified that package KB974571(Security Update) is not applicable for this system
Record Number: 2089
Source Name: Microsoft-Windows-Servicing
Time Written: 20110510010041.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 4374
Message: Windows Servicing identified that package KB974571(Security Update) is not applicable for this system
Record Number: 2090
Source Name: Microsoft-Windows-Servicing
Time Written: 20110510010041.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 4374
Message: Windows Servicing identified that package KB951978(Update) is not applicable for this system
Record Number: 2112
Source Name: Microsoft-Windows-Servicing
Time Written: 20110510010052.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 4374
Message: Windows Servicing identified that package KB951978(Update) is not applicable for this system
Record Number: 2113
Source Name: Microsoft-Windows-Servicing
Time Written: 20110510010052.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
=====Application event log=====
Computer Name: Instructor-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-4134636282-1512834369-3856581858-1000_Classes:
Process 976 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-4134636282-1512834369-3856581858-1000_CLASSES
Record Number: 365
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110510000340.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 381
Source Name: Microsoft-Windows-WMI
Time Written: 20110510000651.000000-000
Event Type: Error
User:
Computer Name: Instructor-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-4134636282-1512834369-3856581858-1000:
Process 880 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-4134636282-1512834369-3856581858-1000
Record Number: 420
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110510003903.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 1530
Message: Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-4134636282-1512834369-3856581858-1000_Classes:
Process 880 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-4134636282-1512834369-3856581858-1000_CLASSES
Record Number: 421
Source Name: Microsoft-Windows-User Profiles Service
Time Written: 20110510003904.000000-000
Event Type: Warning
User: NT AUTHORITY\SYSTEM
Computer Name: Instructor-PC
Event Code: 10
Message: Event filter with query "SELECT * FROM __InstanceModificationEvent WITHIN 60 WHERE TargetInstance ISA "Win32_Processor" AND TargetInstance.LoadPercentage > 99" could not be reactivated in namespace "//./root/CIMV2" because of error 0x80041003. Events cannot be delivered through this filter until the problem is corrected.
Record Number: 441
Source Name: Microsoft-Windows-WMI
Time Written: 20110510004153.000000-000
Event Type: Error
User:
=====Security event log=====
Computer Name: Instructor-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 539
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110510010129.882435-000
Event Type: Audit Failure
User:
Computer Name: Instructor-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 540
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110510010129.898035-000
Event Type: Audit Failure
User:
Computer Name: Instructor-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 541
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110510010129.913635-000
Event Type: Audit Failure
User:
Computer Name: Instructor-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 542
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110510010129.929235-000
Event Type: Audit Failure
User:
Computer Name: Instructor-PC
Event Code: 5038
Message: Code integrity determined that the image hash of a file is not valid. The file could be corrupt due to unauthorized modification or the invalid hash could indicate a potential disk device error.
File Name: \Device\HarddiskVolume2\Windows\System32\drivers\tcpip.sys
Record Number: 543
Source Name: Microsoft-Windows-Security-Auditing
Time Written: 20110510010129.944835-000
Event Type: Audit Failure
User:
Logfile of random's system information tool 1.08 (written by random/random)
Run by Instructor at 2011-05-09 18:00:12
Microsoft® Windows Vista(TM) Home Basic Service Pack 1
System drive C: has 15 GB (45%) free of 33 GB
Total RAM: 2549 MB (63% free)
Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 6:01:31 PM, on 5/9/2011
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal