Wasn't sure where to put this one.
I am periodically getting these Event log entries
"Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-1071416937-1800309502-2446005284-1000:
Process 6036 (\Device\HarddiskVolume3\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-1071416937-1800309502-2446005284-1000
Process 6036 (\Device\HarddiskVolume3\Program Files (x86)\Common Files\Lenovo\tvt_reg_monitor_svc.exe) has opened key \REGISTRY\USER\S-1-5-21-1071416937-1800309502-2446005284-1000
"
I have a RAID1 that shows up as disk in Disk Manager. Another 1.37 GB drive I'm not sure what for and a DVD/CD ROM drive. I have, in the past, had another HD in the system in the DVD bay adapter but not recently - maybe two weeks ago.
What should my next step be?
Also, as noted in another post, I have been having, and continue to have, periodic raid1 degrades and I'm wondering if this might be part of the problem.
Why does the machine think there is a HD3? Is it referring to the DVD/CD player/recorder? Does it still think that other HD is in the DVD bay?
Thanks,
Warning - User Profile Service - Event ID 1530 ???
Warning - User Profile Service - Event ID 1530 ???
Regards,
Geophyte1
Thinkpad W700ds 2757-CTO, T-400 2767AT6, W541 20EFCTO1WW
Geophyte1
Thinkpad W700ds 2757-CTO, T-400 2767AT6, W541 20EFCTO1WW
Redirected somewhat - Need Registry Help
How do I safely remove a key in the registry that CCleaner did not get?
How can I make sure they don't return?
I opened regedit and searched on the user number "S-1-5-21-1071416937-1800309502-2446005284-1000" that is shown on the event entry and it is me.
I searched the registry for "HarddiskVolume3" and the first set of instances was at:
"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\". There are 6 keys under this location that reference HarddiskVolume3:
"48dbaaef_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Windows\explorer.exe%b{00000000-0000-0000-0000-000000000000}"
"58006f3f_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files\OpendTect-4.0.1\bin\win64\odmain.exe%b{00000000-0000-0000-0000-000000000000} "
(This one is interesting because I uninstalled this program and actually ran CCleaner last night but it is still listed) (Incidentally I have run CCleaner twice now and both times my RAID1 has degraded not long after - this was happening even before I installed CCleaner but it seems to have exacerbated the problem)
Can I just right click and delete the registry key without fear or are there other considerations?
"64b3d2d_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Windows\System32\vpc.exe%b{00000000-0000-0000-0000-000000000000}"
"73d24423_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\aMy Folders\Computer\CCleaner\SoftonicDownloader_for_ccleaner.exe%b{00000000-0000-0000-0000-000000000000}"
"75151769_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files\PC-Doctor\pcdravi.p5x%b{00000000-0000-0000-0000-000000000000}"
"a88cca73_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files (x86)\Internet Explorer\iexplore.exe%b{00000000-0000-0000-0000-000000000000}"
The second set if instances is at:
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\hivelist". I've listed the ten entries below. I didn't list one that has no information. From this list I see that my Boot drive, which is the second partition or the windows 7 partition on my RAID1 setup, as listed in Disk Manager, is shown as Harddisk2. This makes me wonder if the Lenovo Recovery partition, or the third partition on my RAID1 is Harddisk3.
Does anyone concur with that?
\Device\HarddiskVolume2\Boot\BCD
\Device\HarddiskVolume3\Windows\System32\config\SAM
\Device\HarddiskVolume3\Windows\System32\config\SECURITY
\Device\HarddiskVolume3\Windows\System32\config\SOFTWARE
\Device\HarddiskVolume3\Windows\System32\config\SYSTEM
\Device\HarddiskVolume3\Windows\System32\config\DEFAULT
\Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\NTUSER.DAT
\Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
\Device\HarddiskVolume3\Users\Frankie\NTUSER.DAT
\Device\HarddiskVolume3\Users\Frankie\AppData\Local\Microsoft\Windows\UsrClass.dat
The third set of instances is at:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist". The list of entries is the same as above.
The fourth set of instances are at:
"HKEY_USERS\S-1-5-21-1071416937-1800309502-2446005284-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\"
The list of keys is the same as the first set above but from the entry in the event log it appears that this set is generating the event???
How can I make sure they don't return?
I opened regedit and searched on the user number "S-1-5-21-1071416937-1800309502-2446005284-1000" that is shown on the event entry and it is me.
I searched the registry for "HarddiskVolume3" and the first set of instances was at:
"HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\". There are 6 keys under this location that reference HarddiskVolume3:
"48dbaaef_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Windows\explorer.exe%b{00000000-0000-0000-0000-000000000000}"
"58006f3f_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files\OpendTect-4.0.1\bin\win64\odmain.exe%b{00000000-0000-0000-0000-000000000000} "
(This one is interesting because I uninstalled this program and actually ran CCleaner last night but it is still listed) (Incidentally I have run CCleaner twice now and both times my RAID1 has degraded not long after - this was happening even before I installed CCleaner but it seems to have exacerbated the problem)
Can I just right click and delete the registry key without fear or are there other considerations?
"64b3d2d_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Windows\System32\vpc.exe%b{00000000-0000-0000-0000-000000000000}"
"73d24423_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\aMy Folders\Computer\CCleaner\SoftonicDownloader_for_ccleaner.exe%b{00000000-0000-0000-0000-000000000000}"
"75151769_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files\PC-Doctor\pcdravi.p5x%b{00000000-0000-0000-0000-000000000000}"
"a88cca73_0\{0.0.0.00000000}.{3b5b9104-f6f4-47a5-821a-e89058d88618}|\Device\HarddiskVolume3\Program Files (x86)\Internet Explorer\iexplore.exe%b{00000000-0000-0000-0000-000000000000}"
The second set if instances is at:
"HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\hivelist". I've listed the ten entries below. I didn't list one that has no information. From this list I see that my Boot drive, which is the second partition or the windows 7 partition on my RAID1 setup, as listed in Disk Manager, is shown as Harddisk2. This makes me wonder if the Lenovo Recovery partition, or the third partition on my RAID1 is Harddisk3.
Does anyone concur with that?
\Device\HarddiskVolume2\Boot\BCD
\Device\HarddiskVolume3\Windows\System32\config\SAM
\Device\HarddiskVolume3\Windows\System32\config\SECURITY
\Device\HarddiskVolume3\Windows\System32\config\SOFTWARE
\Device\HarddiskVolume3\Windows\System32\config\SYSTEM
\Device\HarddiskVolume3\Windows\System32\config\DEFAULT
\Device\HarddiskVolume3\Windows\ServiceProfiles\LocalService\NTUSER.DAT
\Device\HarddiskVolume3\Windows\ServiceProfiles\NetworkService\NTUSER.DAT
\Device\HarddiskVolume3\Users\Frankie\NTUSER.DAT
\Device\HarddiskVolume3\Users\Frankie\AppData\Local\Microsoft\Windows\UsrClass.dat
The third set of instances is at:
"HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\hivelist". The list of entries is the same as above.
The fourth set of instances are at:
"HKEY_USERS\S-1-5-21-1071416937-1800309502-2446005284-1000\Software\Microsoft\Internet Explorer\LowRegistry\Audio\PolicyConfig\PropertyStore\"
The list of keys is the same as the first set above but from the entry in the event log it appears that this set is generating the event???
Regards,
Geophyte1
Thinkpad W700ds 2757-CTO, T-400 2767AT6, W541 20EFCTO1WW
Geophyte1
Thinkpad W700ds 2757-CTO, T-400 2767AT6, W541 20EFCTO1WW
-
- Similar Topics
- Replies
- Views
- Last post
-
- 23 Replies
- 1311 Views
-
Last post by Thinkpad4by3
Tue May 02, 2017 8:18 am
-
- 2 Replies
- 1220 Views
-
Last post by upgrades
Wed Feb 15, 2017 3:42 pm
-
-
Any X220 or X230 user with Panasonic battery?
by skrble » Fri Mar 31, 2017 2:09 pm » in ThinkPad X200/201/220 and X300/301 Series - 4 Replies
- 1035 Views
-
Last post by skrble
Sat Apr 01, 2017 2:05 pm
-
-
- 16 Replies
- 951 Views
-
Last post by axur-delmeria
Tue May 09, 2017 12:11 pm
Who is online
Users browsing this forum: No registered users and 1 guest



