Level Date and Time Source Event ID Task Category Warning 8/4/2015 8:01:30 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 8/4/2015 8:01:29 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 8/4/2015 7:58:15 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 8/4/2015 7:52:26 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 8/4/2015 7:52:26 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 8/4/2015 7:48:46 AM Microsoft-Windows-Winlogon 6000 None The winlogon notification subscriber was unavailable to handle a notification event. Warning 8/4/2015 7:41:09 AM Microsoft-Windows-User Profiles Service 1530 None "Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 1 user registry handles leaked from \Registry\User\S-1-5-21-1691532600-3665710637-1986773215-1001_Classes: Process 2128 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES " Warning 8/4/2015 7:41:07 AM Microsoft-Windows-User Profiles Service 1530 None "Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 16 user registry handles leaked from \Registry\User\S-1-5-21-1691532600-3665710637-1986773215-1001: Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2128 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\trust Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\TrustedPeople Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\My Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\Disallowed Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\Root Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\CA Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 2240 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates " Warning 8/3/2015 6:42:53 PM Microsoft-Windows-User Profiles Service 1530 None "Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 26 user registry handles leaked from \Registry\User\S-1-5-21-1691532600-3665710637-1986773215-1001_Classes: Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\76\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\195\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\195\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell Process 3816 (\Device\HarddiskVolume3\Program Files\Autodesk\AutoCAD 2013\acad.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001_CLASSES\Local Settings\Software\Microsoft\Windows\Shell\Bags\AllFolders\Shell " Warning 8/3/2015 6:42:49 PM Microsoft-Windows-User Profiles Service 1530 None "Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 27 user registry handles leaked from \Registry\User\S-1-5-21-1691532600-3665710637-1986773215-1001: Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001 Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\trust Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\trust Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\TrustedPeople Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\My Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\My Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\Disallowed Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\Disallowed Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\Root Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\Root Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\CA Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Microsoft\SystemCertificates\CA Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 520 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates Process 2224 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1691532600-3665710637-1986773215-1001\Software\Policies\Microsoft\SystemCertificates " Error 8/3/2015 6:41:04 PM Application Hang 1002 (101) "The program acad.exe version 25.0.55.0 stopped interacting with Windows and was closed. To see if more information about the problem is available, check the problem history in the Action Center control panel. Process ID: ee8 Start Time: 01d0ce1e553b605f Termination Time: 60000 Application Path: C:\Program Files\Autodesk\AutoCAD 2013\acad.exe Report Id: 5b967da4-3a30-11e5-9c7d-7824af82fbf7 " Error 8/3/2015 4:55:25 PM Microsoft-Windows-Search 3079 Gatherer "Notifications for the volume C:\ are not active. Context: Windows Application Details: Insufficient quota to complete the requested service. (HRESULT : 0x800705ad) (0x800705ad) "