Dans Categorie de la tache,il a "Analyse des performances d'arret" niveau Critique:
Nom du journal :Application
Source : Microsoft-Windows-User Profiles Service
Date : 04/01/2009 11:39:11
ID de l'événement :1530
Catégorie de la tâche :Aucun
Niveau : Avertissement
Mots clés : Classique
Utilisateur : SYSTEM
Ordinateur : GASC
Description :
Windows a détecté que votre fichier de Registre est toujours utilisé par d'autres applications ou services. Le fichier va être déchargé. Les applications ou services qui ont accès à votre Registre risquent de ne pas fonctionner correctement après cela.
DÉTAIL -
9 user registry handles leaked from \Registry\User\S-1-5-21-3385339315-1571848522-2860814242-1000:
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\My
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\CA
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\trust
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Policies\Microsoft\SystemCertificates
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Policies\Microsoft\SystemCertificates
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\Root
XML de l’événement :
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2009-01-04T10:39:11.000Z" />
<EventRecordID>21163</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>GASC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">9 user registry handles leaked from \Registry\User\S-1-5-21-3385339315-1571848522-2860814242-1000:
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\My
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\CA
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\trust
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Policies\Microsoft\SystemCertificates
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Policies\Microsoft\SystemCertificates
Process 1608 (\Device\HarddiskVolume1\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-3385339315-1571848522-2860814242-1000\Software\Microsoft\SystemCertificates\Root
</Data>
</EventData>
</Event>
Donc le plus long est l'évènement "Shutdown Kernel Time"
Que faire??