Система Windows обнаружила, что файл реестра используется другими приложениями – как исправить?
Добрый день. Каждый день появляется в журнале событий это предупреждение. Как решить эту проблему?
Имя журнала: Application
Источник: Microsoft-Windows-User Profiles Service
Дата: 26.02.2016 15:57:03
Код события: 1530
Категория задачи:Отсутствует
Уровень: Предупреждение
Ключевые слова:
Пользователь: СИСТЕМА
Компьютер: Windows8
Описание:
Система Windows обнаружила, что файл реестра используется другими приложениями или службами. Файл сейчас будет выгружен, после чего приложения или службы, которые его используют, могут начать работать неправильно.
ПОДРОБНО —
31 user registry handles leaked from RegistryUserS-1-5-21-1714829314-4113709101-513154846-1001:
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionInternet SettingsConnections
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 1012 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionUninstall
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
Xml события:
<Event xmlns=”http://schemas.microsoft.com/win/2004/08/events/event”>
<System>
<Provider Name=”Microsoft-Windows-User Profiles Service” Guid=”{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}” />
<EventID>1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime=”2016-02-26T13:57:03.381806600Z” />
<EventRecordID>86553</EventRecordID>
<Correlation ActivityID=”{A7E05519-6FDF-0000-00DB-E1A7DF6FD101}” />
<Execution ProcessID=”336″ ThreadID=”3100″ />
<Channel>Application</Channel>
<Computer>Windows8</Computer>
<Security UserID=”S-1-5-18″ />
</System>
<EventData Name=”EVENT_HIVE_LEAK”>
<Data Name=”Detail”>31 user registry handles leaked from RegistryUserS-1-5-21-1714829314-4113709101-513154846-1001:
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatestrust
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesCA
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesSmartCardRoot
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionInternet SettingsConnections
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesTrustedPeople
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesRoot
Process 1012 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftWindowsCurrentVersionUninstall
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwarePoliciesMicrosoftSystemCertificates
Process 336 (DeviceHarddiskVolume5WindowsSystem32svchost.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
Process 664 (DeviceHarddiskVolume5WindowsSystem32lsass.exe) has opened key REGISTRYUSERS-1-5-21-1714829314-4113709101-513154846-1001SoftwareMicrosoftSystemCertificatesDisallowed
</Data>
</EventData>
</Event>
Здравствуйте AlexAlexET
Спасибо за ваше обращение на форумы Microsoft Community.
Насколько я понимаю, возникают проблемы с доступом к файлу реестра.
Попробуйте решение предложенное в этой статье.
Напишите пожалуйста помогло ли вам это решение.
С уважением,
Олег
Если данная информация была полезна, пожалуйста, отметьте её как ответ.
С уважением,
Олег
Источник: https://answers.microsoft.com/ru-ru/windows/forum/all/система-windows/2d55ac97-8c23-4e1b-bd80-e88171a0f6f3