Question:
possible security risk, event viewer log / windows vista..?
Yujiro
2011-03-29 10:48:24 UTC
This concerns me, searched it online... cant figure out what it means.. I let someone use my comp and questioned their motives.. anyone able to translate?


Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 3/29/2011 5:29:43 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: ChernovDurka-PC
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
3 user registry handles leaked from \Registry\User\S-1-5-21-15112769-3578701772-2425534087-1002:
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Process 1116 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers

Event Xml:



1530
0
3
0
0
0x80000000000000

30164


Application
ChernovDurka-PC



3 user registry handles leaked from \Registry\User\S-1-5-21-15112769-3578701772-2425534087-1002:
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002
Process 384 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Process 1116 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-15112769-3578701772-2425534087-1002\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers


Three answers:
soupfine
2011-03-29 11:14:02 UTC
What's missing (got cut off with...) is the file(s) that opened the registry key



HarddiskVolume1\Windows\System3… has opened key \REGISTRY



see what I mean? If you could post what's missing that would help
?
2016-08-21 19:21:52 UTC
2
Sly_Old_Mole
2011-03-29 11:09:36 UTC
If you turn off windows defender does it go away ?



@soupfine - I agree, I'm going on EVENT_HIVE_LEAK


This content was originally posted on Y! Answers, a Q&A website that shut down in 2021.
Loading...