Система Windows обнаружила, что файл реестра используется другими приложениями – как исправить?

Добрый день. Каждый день появляется в журнале событий это предупреждение. Как решить эту проблему?

Имя журнала:   Application
Источник:      Microsoft-Windows-User Profiles Service
Дата:          26.02.2016 15:57:03
Код события:   1530
Категория задачи:Отсутствует
Уровень:       Предупреждение
Ключевые слова:
Пользователь:  СИСТЕМА
Компьютер:     Windows8
Описание:
Система Windows обнаружила, что файл реестра используется другими приложениями или службами. Файл сейчас будет выгружен, после чего приложения или службы, которые его используют, могут  начать работать неправильно.

 ПОДРОБНО —
 31 user registry handles leaked from RegistryUserS-1-5-21-1714829314-4113709101-513154846-1001:
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionInternet SettingsConnections
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 1012 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionUninstall
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed

Xml события:
<Event xmlns=”http://schemas.microsoft.com/win/2004/08/events/event”>
  <System>
    <Provider Name=”Microsoft-Windows-User Profiles Service” Guid=”{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}” />
    <EventID>1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime=”2016-02-26T13:57:03.381806600Z” />
    <EventRecordID>86553</EventRecordID>
    <Correlation ActivityID=”{A7E05519-6FDF-0000-00DB-E1A7DF6FD101}” />
    <Execution ProcessID=”336″ ThreadID=”3100″ />
    <Channel>Application</Channel>
    <Computer>Windows8</Computer>
    <Security UserID=”S-1-5-18″ />
  </System>
  <EventData Name=”EVENT_HIVE_LEAK”>
    <Data Name=”Detail”>31 user registry handles leaked from RegistryUserS-1-5-21-1714829314-4113709101-513154846-1001:
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionInternet SettingsConnections
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 1012 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionUninstall
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
</Data>
  </EventData>
</Event>

Здравствуйте AlexAlexET

Спасибо за ваше обращение на форумы Microsoft Community.

Насколько я понимаю, возникают проблемы с доступом к файлу реестра.

Попробуйте решение предложенное в этой статье.

Напишите пожалуйста помогло ли вам это решение.

С уважением,
Олег

Если данная информация была полезна, пожалуйста, отметьте её как ответ.

С уважением,
Олег

Источник: https://answers.microsoft.com/ru-ru/windows/forum/all/система-windows/2d55ac97-8c23-4e1b-bd80-e88171a0f6f3

Добавить комментарий