Vino's Event Viewer v01c run on Windows 2008 in Dutch Report run at 29/12/2015 17:12:13 Note: All dates below are in the format dd/mm/yyyy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Kritiek Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Fout Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Waarschuwing Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 29/12/2015 15:36:12 Type: Waarschuwing Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Uw registerbestand is nog steeds in gebruik door andere toepassingen of services. Het bestand wordt nu verwijderd. De toepassingen en services die het registerbestand nu gebruiken, werken achteraf mogelijk niet meer goed. DETAIL - 17 user registry handles leaked from \Registry\User\S-1-5-21-1336589620-2417989329-2739323967-1000: Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000 Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000 Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000 Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000 Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Policies\Microsoft\SystemCertificates Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Policies\Microsoft\SystemCertificates Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Policies\Microsoft\SystemCertificates Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Policies\Microsoft\SystemCertificates Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\trust Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\SmartCardRoot Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\Disallowed Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\Root Process 1356 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Piriform\CCleaner Process 1356 (\Device\HarddiskVolume2\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Control Panel\International Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\My Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\CA Process 2460 (\Device\HarddiskVolume2\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-1336589620-2417989329-2739323967-1000\Software\Microsoft\SystemCertificates\TrustedPeople