Ветеран

Сообщения: 4566
Благодарности: 1090
|
Профиль
|
Отправить PM
| Цитировать
Цитата NickM:
Вы же пытаетесь установить 32-разрядную версию Office в 64-х разрядной операционной системе и »
|
Да, что-то тут не то...
Интересно, а это что-нибудь значит?
Т.е. не блокирует ли защитное ПО создание задачи?
Код: 
"Time of Day","Process Name","PID","Operation","Path","Result","Detail"
"15:30:48,5983896","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\СИСТЕМА"
"15:30:48,5986823","svchost.exe","524","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read"
"15:30:48,6027411","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","SUCCESS","Desired Access: Generic Write, Read Attributes, Disposition: OverwriteIf, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, AllocationSize: 0, Impersonating: NT AUTHORITY\СИСТЕМА, OpenResult: Created"
"15:30:48,6039762","svchost.exe","524","WriteFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","SUCCESS","Offset: 0, Length: 2, Priority: Normal"
"15:30:48,6041592","svchost.exe","524","WriteFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","SUCCESS","Offset: 2, Length: 3*330, Priority: Normal"
"15:30:48,6269935","svchost.exe","524","CloseFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","SUCCESS",""
"15:30:48,6287378","svchost.exe","524","WriteFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","SUCCESS","Offset: 0, Length: 4*096, I/O Flags: Non-cached, Paging I/O, Synchronous Paging I/O, Priority: Normal"
"15:30:48,6323147","dwengine.exe","2172","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\officetelemetryagentlogon2016","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Synchronous IO Non-Alert, Random Access, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\СИСТЕМА"
"15:30:52,0122975","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read Control, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a"
"15:30:52,0146245","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\СИСТЕМА"
"15:30:52,0163500","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read Attributes, Disposition: Open, Options: Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\СИСТЕМА"
"15:30:52,0165950","svchost.exe","524","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read"
"15:30:52,0170506","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Generic Read, Disposition: Open, Options: Sequential Access, Synchronous IO Non-Alert, Non-Directory File, Attributes: N, ShareMode: Read, Delete, AllocationSize: n/a"
"15:30:52,0183335","svchost.exe","524","CreateFile","C:\Windows\System32\Tasks\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read Attributes, Delete, Disposition: Open, Options: Non-Directory File, Open Reparse Point, Attributes: n/a, ShareMode: Read, Write, Delete, AllocationSize: n/a, Impersonating: NT AUTHORITY\СИСТЕМА"
"15:30:52,0185780","svchost.exe","524","RegOpenKey","HKLM\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Office\OfficeTelemetryAgentLogOn2016","NAME NOT FOUND","Desired Access: Read"
|