Vino's Event Viewer v01c run on Windows 2008 in English Report run at 01/07/2016 16:46:45 Note: All dates below are in the format dd/mm/yyyy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Warning Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 01/07/2016 15:01:45 Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 48 user registry handles leaked from \Registry\User\S-1-5-21-2568410734-3031030142-1223416489-1001: Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001 Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\trust Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\trust Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\trust Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\TrustedPeople Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\TrustedPeople Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\TrustedPeople Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\Disallowed Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\Disallowed Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\Disallowed Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\Root Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\Root Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\Root Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\My Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\My Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\My Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\CA Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\CA Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\CA Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Microsoft\SystemCertificates\SmartCardRoot Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 5716 (\Device\HarddiskVolume1\Windows\System32\wbem\WmiPrvSE.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 1360 (\Device\HarddiskVolume1\Program Files\AVAST Software\Avast\AvastSvc.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates Process 4864 (\Device\HarddiskVolume1\Program Files\Dell Update\DellUpService.exe) has opened key \REGISTRY\USER\S-1-5-21-2568410734-3031030142-1223416489-1001\Software\Policies\Microsoft\SystemCertificates