Vino's Event Viewer v01c run on Windows 2008 in English Report run at 20/05/2017 12:20:43 AM Note: All dates below are in the format dd/mm/yyyy ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Critical Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Error Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ 'Application' Log - Warning Type ~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~~ Log: 'Application' Date/Time: 20/05/2017 12:23:41 AM Type: Warning Category: 0 Event: 6003 Source: Microsoft-Windows-Winlogon The winlogon notification subscriber was unavailable to handle a critical notification event. Log: 'Application' Date/Time: 20/05/2017 12:21:40 AM Type: Warning Category: 0 Event: 1530 Source: Microsoft-Windows-User Profiles Service Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 5 user registry handles leaked from \Registry\User\S-1-5-21-1219835080-3833390587-2249361862-1001: Process 692 (\Device\HarddiskVolume2\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-1219835080-3833390587-2249361862-1001 Process 3696 (\Device\HarddiskVolume2\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-1219835080-3833390587-2249361862-1001 Process 3696 (\Device\HarddiskVolume2\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-1219835080-3833390587-2249361862-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections Process 1968 (\Device\HarddiskVolume2\Program Files (x86)\Avira\Antivirus\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-1219835080-3833390587-2249361862-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon Process 3696 (\Device\HarddiskVolume2\Program Files (x86)\Avira\Launcher\Avira.ServiceHost.exe) has opened key \REGISTRY\USER\S-1-5-21-1219835080-3833390587-2249361862-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall