Is there any way to tell who is accessing the registry?

ben07

New member
Power User
Local time
7:58 PM
Messages
111
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 8/26/2009 6:00:03 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: Home01
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000_Classes:
Process 2164 (\Device\HarddiskVolume7\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000_CLASSES

Event Xml:

1530
0
3
0
0
0x8000000000000000

1111

Application
Home01

1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000_Classes:
Process 2164 (\Device\HarddiskVolume7\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000_CLASSES

I'm getting two of these yellow warnings everyday and according to MS it's OK or it's well expected to get these type of warnings in Event Viewer....but just for the sake of it, is there anyway to tell which program/software is causing these yellow warnings?

Thanks.
 

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Last edited:

My Computer My Computer

At a glance

Windows 8.1 PRO3rd Generation Intel Core i7‐3612QM CPU @ 2.1...8GB DDR3NVIDIA GeForce GT 525M (128 bit), 1GB Grpahics
Computer type
PC/Desktop
Computer Manufacturer/Model Number
DELL VOSTRO 3650
OS
Windows 8.1 PRO
CPU
3rd Generation Intel Core i7‐3612QM CPU @ 2.10GHZ
Memory
8GB DDR3
Graphics Card(s)
NVIDIA GeForce GT 525M (128 bit), 1GB Grpahics
Screen Resolution
1920X1080
Hard Drives
750GB 5400RPM
Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 8/26/2009 6:00:03 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: Home01
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000_Classes:
Process 2164 (\Device\HarddiskVolume7\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000_CLASSES
1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000_Classes:
Process 2164 (\Device\HarddiskVolume7\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000_CLASSES

Hi

Nothing fishy about this.

S-1-5-21-783115880-3742272611-1246857717-1000 is a username used by svchost.exe

There is a problem though according to this part of the message:

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

One of your programs is causing a conflict by not releasing a certain service that is using the registry.

Which program we can not tell from this, because several programs that connect to the internet are masked by svchost.exe which is kind of a container for multiple processes.


Try to think back to when it started.
Then uninstall the program's that were installed since then.

A windows repair from DVD might also help.

Greetz
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
Thanks squonksc, TGSoldier.

I really can't think of anything that would cause this...it's a new fresh installation...according to MS, it OK/accepted, but then MS won't tell you why it's OK/accepted,lol:rolleyes:

On a Windows Vista-based client computer, the following event may be logged in the Application log:Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: Date
Event ID: 1530
Task Category: None
Level: Warning
Keywords: Classic
User: SYSTEM
Computer: ComputerName

Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-3112862306-1016156048-4130204762-1000: Process 932 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3112862306-1016156048-4130204762-1000


This behavior occurs because Windows Vista automatically closes any registry handle to a user profile that is left open by an application. Windows Vista does this when Windows Vista tries to close a user profile.

In versions of the Windows operating system that are earlier than Windows Vista, you must install the User Profile Hive Cleanup Service (UPHClean) utility to have the same functionality. However, the UPHClean utility is incompatible with Windows Vista. Additionally, the UPHClean utility is not needed because this functionality is built into Windows Vista.

Note Event ID 1530 is logged as a Warning event. However, this behavior is expected. Usually, you can safely ignore this event.
 

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Ben, I'm on to something.

Would you humor me and uninstall your virusscanner/security suite?

Post back the results.

greetz
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
Hi squonksc, I will and I'll post back.

1) I had MS Security Essentials Beta/updated to the latest version few days ago, but had it uninstalled 2 days ago. (NO longer using)

2) Windows 7's built in Windows Defender (ON)

3) AntiVir (ON)


I'll deactivate the above two, reboot and post back.
 

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Hi squonksc, I will and I'll post back.

1) I had MS Security Essentials Beta/updated to the latest version few days ago, but had it uninstalled 2 days ago. (NO longer using)

2) Windows 7's built in Windows Defender (ON)

3) AntiVir (ON)


I'll deactivate the above two, reboot and post back.

Uninstall Antivir, not deactivate please.

Defender can stay as is for now.

greetz
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
This pseudo problem dates back across multiple OS. Unless you are attempting to isolate a known real problem, I would not bother.
 
This pseudo problem dates back across multiple OS. Unless you are attempting to isolate a known real problem, I would not bother.

Hi Antman

Sounds intriguing, can you direct me to an article about this issue?

Thanks.
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
Well, after deactivated both Windows Defender and AntiVir, I got only one yellow warnings instead of two:).

Reactivated Only Windows Defender and immediately got back two yellow warnings.

Deactivated Windows Defender and reactivated AntiVir, I got only one yellow warnings.

My conclusion, nothing to do with AntiVir, but definitely Windows Defender is causing one of the yellow warnings Event ID 1530.

I think maybe this has something to do with my blocking all Outbound Connections/Traffics in Windows built in Firewall, as I only created rules to allow IE, FireFox, ThunderBird and Windows Updates to pass thru.
 

Attachments

  • FF1.jpg
    FF1.jpg
    32.6 KB · Views: 48

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Well, after deactivated both Windows Defender and AntiVir, I got only one yellow warnings instead of two:).

Reactivated Only Windows Defender and immediately got back two yellow warnings.

Deactivated Windows Defender and reactivated AntiVir, I got only one yellow warnings.

My conclusion, nothing to do with AntiVir, but definitely Windows Defender is causing one of the yellow warnings Event ID 1530.

Well, like I suspected it does have something to do with a security app.

I asked to uninstall Antivir first, because we had to start somewhere.

And best practice is always one by one so you can keep track of what it was you did right.

I do want to ask you to uninstall Antivir anyway.

Disabling it doesn't stop the services it uses.

You can always reinstall it when it doesn't fix the problem.

So please indulge me and uninstall Antivir.

Lets see what happens.

greetz
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
Hi Antman

Sounds intriguing, can you direct me to an article about this issue?

Thanks.
I first noticed this about two years ago in an XP install. I do not have an article to reference. I do have two years experience of being aware of the Event Viewer entry and no other discernable affect.

I believe that the cryptic MS assessment is dead on.
 
I first noticed this about two years ago in an XP install. I do not have an article to reference. I do have two years experience of being aware of the Event Viewer entry and no other discernable affect.

I believe that the cryptic MS assessment is dead on.

Would disabling the audit for that particular process id, at least get rid of the yellow triangles? I suspect it would.

greetz
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
Well, like I suspected it does have something to do with a security app.
greetz

:p

OK, will remove AntiVir completely, reboot, retest and will post back!:D
 

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Would disabling the audit for that particular process id, at least get rid of the yellow triangles? I suspect it would.

greetz

How to disable the audit?
 

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Still got one yellow warning after completely removing AntiVir:(....it's very interesting to find out what is this:

"DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000:
Process 804 (\Device\HarddiskVolume7\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000", in particular the Process 804 (\Device\HarddiskVolume7


Google can't tell me much about Process 804 (\Device\HarddiskVolume7:(
 

My Computer My Computer

At a glance

Windows 7 Pro x64 RTMIntel
OS
Windows 7 Pro x64 RTM
CPU
Intel
Still got one yellow warning after completely removing AntiVir:(....it's very interesting to find out what is this:

"DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000:
Process 804 (\Device\HarddiskVolume7\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000", in particular the Process 804 (\Device\HarddiskVolume7


Google can't tell me much about Process 804 (\Device\HarddiskVolume7:(

One yellow warning?

And defender is on or off?

Audit question was for Antman.

We'll discuss that later.
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
Still got one yellow warning after completely removing AntiVir:(....it's very interesting to find out what is this:

"DETAIL -
1 user registry handles leaked from \Registry\User\S-1-5-21-783115880-3742272611-1246857717-1000:
Process 804 (\Device\HarddiskVolume7\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-783115880-3742272611-1246857717-1000", in particular the Process 804 (\Device\HarddiskVolume7


Google can't tell me much about Process 804 (\Device\HarddiskVolume7:(

If you go into task manager it tells you what the process ID is for each process so at that point in time you could have found out. You do need to go into view select columns and check PID
 
Last edited:

My Computer My Computer

At a glance

Win 8 Release candidate 8400[email protected]4 gigsNvidia 9600M
Computer Manufacturer/Model Number
HP Pavillion dv-7 1005 Tx
OS
Win 8 Release candidate 8400
CPU
[email protected]
Memory
4 gigs
Graphics Card(s)
Nvidia 9600M
Sound Card
HD built-in
Monitor(s) Displays
17" Wxga
Screen Resolution
1440x900
Cooling
none
Internet Speed
45Mb down 5Mb up
I think maybe this has something to do with my blocking all Outbound Connections/Traffics in Windows built in Firewall, as I only created rules to allow IE, FireFox, ThunderBird and Windows Updates to pass thru.

Ben, I just read this. I overlooked this post.

This could be the source of your problems.

You can't block all outbound.
svchost.exe has to be able to make connections.

svchost.exe is a container which contains multiple processes that connect to the internet. Like defender, your virus scanner and many more.

There is little use in blocking outbound anyway.

First disable your firewall just to test if that solves it.

If it does, set the firewall back to default.

Greetz
 

My Computer My Computer

At a glance

Win7 Build 7600 x86Pentium II 300MHz32mb EDO RAMDiamond Viper
OS
Win7 Build 7600 x86
CPU
Pentium II 300MHz
Motherboard
Asus
Memory
32mb EDO RAM
Graphics Card(s)
Diamond Viper
Sound Card
Soundblaster 16
Monitor(s) Displays
14" AOC CRT 16K color
Screen Resolution
800x600
Hard Drives
300mb Quantum fireball
PSU
110 Watts
Cooling
Passive
Keyboard
Trust Ergonomic
Mouse
Generic
Internet Speed
256K u 128K d
...Audit question was for Antman.

We'll discuss that later.
I was down at the playground with the neighborhood. The Antman is always in demand there.

I was doing a bit of research into this when I was called away. I am taking my time on the digging though, as I am convinced that this is simply an resolved condition inherent in multiple Windows OS'. As I noted earlier, I first encountered this a long time ago - and have no negative result from it's existence. My take is: the error code is not valid. Some error codes are returned because of where they fit, or don't fit, in the lookup - they are not always accurate.

Right now, I have a different error code. 18 month old naked baby running around on my $1800 carpets.
 
Back
Top