locked
User Profile Service error 1530 RRS feed

  • Question

  • I have been receiving these errors periodically on our application server that hosts our ERP system, and nothing else.  This is a brand new HP DL380p G8 with server 2008 standard.  There are no server services added to this server.  It is not used for anything else other than our ERP system, which when users login to the system, it uses both native windows and then cmd windows (telnet sessions) depending where in the system people are for various tasks.

    The issue that is puzzling to me is that this SID is a user that has only once logged into the system, so I don't get how this error could be happening since this server has been restarted many times 

    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

     DETAIL -
     13 user registry handles leaked from \Registry\User\S-1-5-21-741211185-3382965498-1137847248-500:
    Process 5272 (\Device\HarddiskVolume1\Windows\System32\wscript.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500
    Process 1036 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500
    Process 5164 (\Device\HarddiskVolume1\Windows\System32\cmd.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500
    Process 5176 (\Device\HarddiskVolume1\Windows\System32\conhost.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Control Panel\International
    Process 5164 (\Device\HarddiskVolume1\Windows\System32\cmd.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Control Panel\International
    Process 5272 (\Device\HarddiskVolume1\Windows\System32\wscript.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Control Panel\International
    Process 5164 (\Device\HarddiskVolume1\Windows\System32\cmd.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Software\Microsoft\Windows NT\CurrentVersion
    Process 5164 (\Device\HarddiskVolume1\Windows\System32\cmd.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Process 3832 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Process 756 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Process 3964 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Process 1036 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
    Process 464 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-741211185-3382965498-1137847248-500\Printers\DevModePerUser


    • Edited by dmcomp Tuesday, September 3, 2013 6:34 PM
    Tuesday, September 3, 2013 2:27 PM

Answers