Yujiro
2011-03-29 10:48:24 UTC
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 3/29/2011 5:29:43 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: ChernovDurka-PC
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
3 user registry handles leaked from \Registry\User\S-1-5-21-15112769-3578701772-2425534087-1002:
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Process 1116 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Event Xml:
3 user registry handles leaked from \Registry\User\S-1-5-21-15112769-3578701772-2425534087-1002:
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Process 1116 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers