- Thread Author
- #1
I have a new Dell Studio 540. Windows 7 Premium. On looking in the event viewer I see this event frequently. Am concerned since it is registry related. Is this common or something I can fix or should report to someone? Dell? Or can someone on this forum help me out. Would this be related at all to my hard drive access light blinking every second or so even when system is idle?
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">5 user registry handles leaked from \Registry\User\S-1-5-21-4059811508-3310364422-676596053-1000:
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000\Software\Microsoft\SystemCertificates\My
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000\Software\Microsoft\SystemCertificates\CA
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">5 user registry handles leaked from \Registry\User\S-1-5-21-4059811508-3310364422-676596053-1000:
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000\Software\Microsoft\SystemCertificates\My
Process 544 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-4059811508-3310364422-676596053-1000\Software\Microsoft\SystemCertificates\CA