You are not logged in.

Monday, April 21st 2014, 6:33am

Dear visitor, welcome to Avira Support Forum. If this is your first visit here, please read the Help. It explains in detail how this page works. To use all features of this page, you should consider registering. Please use the registration form, to register here or read more information about the registration process. If you are already registered, please login here.

  • "markshim" started this thread

Date of registration:
Oct 29th 2009

Operating System:
windows 7 64bit

  • Send private message

1

Saturday, January 19th 2013, 10:08pm

Event id 1530 warning now in windows 8 as well as windows 7

hi there,

I have made post before about this problem where I get a event id warning 1530 in windows 7 and I kept getting told it was going to be fixed soon, well now its a year later and now I am using windows 8 and still this problem has not been fixed can you please sort this out? this is what I am getting



Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
46 user registry handles leaked from \Registry\User\S-1-5-21-1976859548-2689153353-1438892742-1001:
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Policies\Microsoft\SystemCertificates
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
Process 1656 (\Device\HarddiskVolume1\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\Root
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\Root
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\Root
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\CA
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\CA
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\CA
Process 492 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\trust
Process 660 (\Device\HarddiskVolume1\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\trust
Process 956 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-1976859548-2689153353-1438892742-1001\Software\Microsoft\SystemCertificates\trust

Date of registration:
Apr 16th 2012

Version:
Avira Internet Security

Operating System:
Windows 8 Professional with Media Center x64 bit

  • Send private message

2

Tuesday, January 22nd 2013, 7:13pm

Well, why don't you just reformat your computer? That's what I did. I'm assuming you had a virus infection at one point. So what you should have done was backed everything up, rebooted your PC, boot from CD using the BIOS, Click Custom Install, click Advanced Options, then completely format your C drive. Then reinstall Windows 8 on your computer. And I can guarantee your problem would be solve. Why? Because nobody else has this problem.



EDIT:

Ok, looking through your post, it would actually appear that you DO have a virus. A certain virus likes to rename itself to svchost.exe and dump copies of itself in your System32 folder. Try removing that virus, or better yet, take my suggestion and reformat your C drive. Then rescan your D drive, and any other drive that attaches to your computer for remains of the virus.

This post has been edited 1 times, last edit by "C++ Developer" (Jan 22nd 2013, 7:17pm)


  • "markshim" started this thread

Date of registration:
Oct 29th 2009

Operating System:
windows 7 64bit

  • Send private message

3

Tuesday, January 22nd 2013, 9:09pm

I do not have a virus I scan my pc everyday, I formatted my hard drives to install Windows 8. This problem has been around for ages and a Avira mod has already said they know about this problem and they would fix it but they haven't. I am not the only person to have this problem at all.

I was told it would be fixed ages ago and they have done zip about it. It now happens in both Window 7 and 8. I also have a new ssd and hard drive so its not a virus, like I said I scan every day.

Date of registration:
Apr 16th 2012

Version:
Avira Internet Security

Operating System:
Windows 8 Professional with Media Center x64 bit

  • Send private message

4

Saturday, January 26th 2013, 6:41am

I do not have a virus I scan my pc everyday, I formatted my hard drives to install Windows 8. This problem has been around for ages and a Avira mod has already said they know about this problem and they would fix it but they haven't. I am not the only person to have this problem at all.

I was told it would be fixed ages ago and they have done zip about it. It now happens in both Window 7 and 8. I also have a new ssd and hard drive so its not a virus, like I said I scan every day.

Well, I don't have that problem, and I have Windows 8. So what's that tell you? In the very least, something isn't right here.....

  • "markshim" started this thread

Date of registration:
Oct 29th 2009

Operating System:
windows 7 64bit

  • Send private message

5

Saturday, January 26th 2013, 9:01am

i reinstalled windows 7 again coz i can`t stand windows 8 and still i get this error saying something a bit different

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
16 user registry handles leaked from \Registry\User\S-1-5-21-697159763-3247352247-2633865882-1000:
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000
Process 1912 (\Device\HarddiskVolume1\Program Files (x86)\Avira\AntiVir Desktop\avguard.exe) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\Windows NT\CurrentVersion\Winlogon
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\trust
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\Root
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\Disallowed
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Policies\Microsoft\SystemCertificates
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\TrustedPeople
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\My
Process 2136 (\Device\HarddiskVolume1\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-697159763-3247352247-2633865882-1000\Software\Microsoft\SystemCertificates\CA

i have been told in the past that this is a problem that avira is causing by a forum mod, he told me i can`t disable something in the avira settings to stop this. but i said why should i disable something on my antvirus that i am paying for and make my pc more available to attacks. he said that it would be fixed in the next update and that was well over a year ago now. i want to know why and when this is going to be fixed ???

Date of registration:
Apr 16th 2012

Version:
Avira Internet Security

Operating System:
Windows 8 Professional with Media Center x64 bit

  • Send private message

6

Monday, January 28th 2013, 4:55am

Wait...WHAT????

i have been told in the past that this is a problem that avira is causing by a forum mod, he told me i can`t disable something in the avira settings to stop this. but i said why should i disable something on my antvirus that i am paying for and make my pc more available to attacks. he said that it would be fixed in the next update and that was well over a year ago now. i want to know why and when this is going to be fixed ???

Wait...YOU ARE PAYING FOR THIS??? Then why in the world are you on these forums if you have a Premium version of Avira?? You do realize that phone support for a Premium version of Avira is free.

So, my advice to you? Call Avira's phone support. If you have Avira Premium (or better, including Internet Security), you shouldn't be just relying on these "guess-and-error" forums.

Now, I'm now saying there is anything wrong with forums though. Forums can be very helpful. And you could very well get your problems solved using forums. But when I'm telling you there is nothing wrong with Avira because I'm not having this problem, then that especially means you should call phone support.

NOTE: I'm only recommending phone support because you said you paid for your Avira program. Therefore, you get Premium phone support. Phone support is NOT free if you are using a Avira Free edition.

This post has been edited 1 times, last edit by "C++ Developer" (Jan 28th 2013, 4:58am)