Warnings "user profile service" each shutdown or logoff

Discussion in 'Windows Vista General Discussion' started by Faelan, Apr 3, 2007.

  1. Faelan

    Faelan Guest

    Hello !

    Each time I shutdown or logoff, there is a warning in the event viewer
    (applications).
    Using "tasklist" just before the shutdown, I determined the responsible
    software is Windows Defender (process 964 in the example).
    If the computer stays on during the whole day, I get 150 to 300 "user
    registry handles" (160 in the example)...
    If I stop (manually) the "windows defender service" before the
    shutdown, there is no warning in the event viewer.

    Any idea to correct this problem ?

    Thanks.

    ------------------

    Nom du journal :Application
    Source : Microsoft-Windows-User Profiles Service
    Date : 31/03/2007 17:05:27
    ID de l'événement (ID of the event):1530
    Catégorie de la tâche :Aucun
    Niveau : Avertissement (warning)
    Mots clés : Classique
    Utilisateur (user) : SYSTEM
    Ordinateur (computer) : PC-DELL
    Description :
    Windows a détecté que votre fichier de Registre est toujours utilisé
    par d'autres applications ou services. Le fichier va être déchargé. Les
    applications ou services qui ont accès à votre Registre risquent de ne
    pas fonctionner correctement après cela.

    DÉTAIL -
    160 user registry handles leaked from
    \Registry\User\S-1-5-21-3890011088-558206450-2035793013-1000:
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
    Process 964 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has
    opened key \REGISTRY\USER\S-1-5-21-3890011088-558206450-2035793013-1000
     
    Faelan, Apr 3, 2007
    #1
    1. Advertisements

  2. Faelan

    Aaron Oneal Guest

    I'm having the same problem and I also traced it to Windows Defender. Mine
    occurs during normal use, even when the profile is not being logged out.
    What's worse is that it causes me to lose my stored network passwords every
    time it occurs. Who knows what else is getting wiped.

    - <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
    - <System>
    <Provider Name="Microsoft-Windows-User Profiles Service"
    Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
    <EventID Qualifiers="32768">1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x80000000000000</Keywords>
    <TimeCreated SystemTime="2007-04-13T00:14:59.000Z" />
    <EventRecordID>17096</EventRecordID>
    <Correlation />
    <Execution ProcessID="0" ThreadID="0" />
    <Channel>Application</Channel>
    <Computer>Pegasus</Computer>
    <Security UserID="S-1-5-18" />
    </System>
    - <EventData Name="EVENT_HIVE_LEAK">
    <Data Name="Detail">1 user registry handles leaked from
    \Registry\User\S-1-5-21-885596355-2598441921-1701884729-500_Classes: Process
    1180 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key
    \REGISTRY\USER\S-1-5-21-885596355-2598441921-1701884729-500_CLASSES</Data>
    </EventData>
    </Event>
     
    Aaron Oneal, Apr 13, 2007
    #2
    1. Advertisements

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments (here). After that, you can post your question and our members will help you out.