User Profile Service Event 1530: The Windows operating system detected that your registry file is still in use by other applications or services.
This topic describes event 1530 from the User Profile Service
Applies to: Windows 8.1, Windows 8, Windows 7, Windows Server 2012 R2, Windows Server 2012, Windows Server 2008 R2, Windows Server 2008
Event Details
Product |
Microsoft Windows Operating System |
ID |
1530 |
Source |
Microsoft-Windows-User Profiles Service; |
Version |
6.3, 6.2, 6.1 |
Symbolic Name |
EVENT_HIVE_LEAK |
Message |
The Windows operating system detected that your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. |
Included in the following details are four examples of the type of information that can appear in this event message:
1 user registry handles leaked from \Registry\User\S-1-5-21-3112862306-1016156048-4130204762-1000: Process 932 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-3112862306-1016156048-4130204762-1000
1 user registry handles leaked from \Registry\User\S-1-5-21-4211544788-2274021965-2216582883-1001_Classes: Process 3568 (\Device\HarddiskVolume3\Windows\System32\WUDFHost.exe) has opened key \REGISTRY\USER\S-1-5-21-4211544788-2274021965-2216582883-1001_CLASSES
5 user registry handles leaked from \Registry\User\S-1-5-21-4211544788-2274021965-2216582883-1001: Process 1880 (\Device\HarddiskVolume3\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-4211544788-2274021965-2216582883-1001 Process 1880 (\Device\HarddiskVolume3\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-
4211544788-2274021965-2216582883-1001
Process 1880 (\Device\HarddiskVolume3\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-4211544788-2274021965-2216582883-1001 Process 1880 (\Device\HarddiskVolume3\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-4211544788-2274021965-2216582883-1001 Process 1880 (\Device\HarddiskVolume3\Program Files (x86)\Norton AntiVirus\Engine\18.1.0.37 ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-4211544788-2274021965-2216582883-1001
1 user registry handles leaked from \Registry\User\S-1-5-21-4211544788-2274021965-2216582883-1001: Process 2492 (\Device\HarddiskVolume3\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-4211544788-2274021965-2216582883-1001\Software\Microsoft\Windows\CurrentVersion\Explorer
Cause
This event can be caused by apps that do not release their Registry keys before shutting down. This most often occurs when an app runs in the background and does not release its Registry keys when a user signs off, in which case Windows forces the Registry to unload. There is no impact to users, though in rare cases recent configuration changes in the app might not be saved.
Resolution
No user action is required - this is an acceptable condition.
In Windows 8.1 we changed this to an Information message to help reduce confusion and alarm. This event was a Warning event in prior versions of Windows.
Related Information
- KB 947238 Event ID: 1530 may be logged in the Application log on a Windows 7-based or Windows Vista-based client computer