Warning - User Profile Service - Event ID 1530 ???

W500/510/520 and W700/710 series specific matters only
Post Reply
Message
Author
Geophyte1
Freshman Member
Posts: 82
Joined: Wed Mar 03, 2010 3:36 pm
Location: Rockdale, Texas

Warning - User Profile Service - Event ID 1530 ???

#1 Post by Geophyte1 » Mon Feb 07, 2011 3:50 pm

Wasn't sure where to put this one.

I am periodically getting these Event log entries
"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-1071416937-1800309502-2446005284-1000:
Process 6036 (\Device\HarddiskVolume3\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-1071416937-1800309502-2446005284-1000
Process 6036 (\Device\HarddiskVolume3\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-1071416937-1800309502-2446005284-1000
"
I have a RAID1 that shows up as disk in Disk Manager. Another 1.37 GB drive I'm not sure what for and a DVD/CD ROM drive. I have, in the past, had another HD in the system in the DVD bay adapter but not recently - maybe two weeks ago.

What should my next step be?

Also, as noted in another post, I have been having, and continue to have, periodic raid1 degrades and I'm wondering if this might be part of the problem.

Why does the machine think there is a HD3? Is it referring to the DVD/CD player/recorder? Does it still think that other HD is in the DVD bay?

Thanks,
Regards,

Geophyte1
Thinkpad W700ds 2757-CTO, T-400 2767AT6, W541 20EFCTO1WW

Geophyte1
Freshman Member
Posts: 82
Joined: Wed Mar 03, 2010 3:36 pm
Location: Rockdale, Texas

Redirected somewhat - Need Registry Help

#2 Post by Geophyte1 » Wed Feb 09, 2011 2:27 pm

How do I safely remove a key in the registry that CCleaner did not get?
How can I make sure they don't return?
I opened regedit and searched on the user number "S-1-5-21-1071416937-1800309502-2446005284-1000" that is shown on the event entry and it is me.
I searched the registry for "HarddiskVolume3" and the first set of instances was at:
"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\". There are 6 keys under this location that reference HarddiskVolume3:
"48dbaaef_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Windows\explorer.exe%b{00000000-0000-0000-0000-000000000000}"
"58006f3f_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files\OpendTect-4.0.1\bin\win64\odmain.exe%b{00000000-0000-0000-0000-000000000000} "
(This one is interesting because I uninstalled this program and actually ran CCleaner last night but it is still listed) (Incidentally I have run CCleaner twice now and both times my RAID1 has degraded not long after - this was happening even before I installed CCleaner but it seems to have exacerbated the problem)
Can I just right click and delete the registry key without fear or are there other considerations?

"64b3d2d_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Windows\System32\vpc.exe%b{00000000-0000-0000-0000-000000000000}"
"73d24423_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\aMy Folders\Computer\CCleaner\SoftonicDownloader_for_ccleaner.exe%b{00000000-0000-0000-0000-000000000000}"
"75151769_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files\PC-Doctor\pcdravi.p5x%b{00000000-0000-0000-0000-000000000000}"
"a88cca73_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files (x86)\Internet Explorer\iexplore.exe%b{00000000-0000-0000-0000-000000000000}"

The second set if instances is at:
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\hivelist". I've listed the ten entries below. I didn't list one that has no information. From this list I see that my Boot drive, which is the second partition or the windows 7 partition on my RAID1 setup, as listed in Disk Manager, is shown as Harddisk2. This makes me wonder if the Lenovo Recovery partition, or the third partition on my RAID1 is Harddisk3.
Does anyone concur with that?
\Device\HarddiskVolume2\Boot\BCD
\Device\HarddiskVolume3\Windows\System32\config\SAM
\Device\HarddiskVolume3\Windows\System32\config\SECURITY
\Device\HarddiskVolume3\Windows\System32\config\SOFTWARE
\Device\HarddiskVolume3\Windows\System32\config\SYSTEM
\Device\HarddiskVolume3\Windows\System32\config\DEFAULT
\Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\NTUSER.DAT
\Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
\Device\HarddiskVolume3\Users\Frankie\NTUSER.DAT
\Device\HarddiskVolume3\Users\Frankie\AppData\Local\Microsoft\Windows\UsrClass.dat

The third set of instances is at:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist". The list of entries is the same as above.

The fourth set of instances are at:
"HKEY_USERS\S-1-5-21-1071416937-1800309502-2446005284-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\"
The list of keys is the same as the first set above but from the entry in the event log it appears that this set is generating the event???
Regards,

Geophyte1
Thinkpad W700ds 2757-CTO, T-400 2767AT6, W541 20EFCTO1WW

Post Reply
  • Similar Topics
    Replies
    Views
    Last post

Return to “ThinkPad W500/510/520 and W7x0 Series”

Who is online

Users browsing this forum: No registered users and 2 guests