O que é o erro de serviço de perfil de usuário 1530?

4

Eu tenho um laptop com Windows 7 conectado ao domínio. O laptop está localizado em nosso escritório regional na África (estamos no Reino Unido). No entanto, alguns usuários de domínio na África estão reclamando que não conseguem fazer login com suas credenciais.

Então decidi acessar o laptop remotamente para ver se consigo fazer logon. Eu entrei como um administrador de domínio em vez de minhas próprias credenciais, já que carregar meus perfis do Reino Unido para o servidor em Nairóbi levará uma eternidade.

Consegui fazer login com o administrador do domínio para não ver qual era o problema.

Eu olhei nos logs de eventos e encontrei Warning: User Profile Service Error: 1530 .

Foi algo relacionado aos perfis de usuário e ao registro no Windows. Eu tive erros de perfil de usuário antes, mas nunca encontrei este.

The details are below:

Log Name:      Application
Source:        Microsoft-Windows-User Profiles Service
Date:          22/04/2015 16:27:17
Event ID:      1530
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      IH-*PC_NAME*.*DOMAIN_NAME*.ORG.UK
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 16 user registry handles leaked from \Registry\User\S-1-5-21-779955827-3448407892-3122252932-1588:
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\Disallowed
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\TrustedPeople
Process 9600 (\Device\HarddiskVolume3\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\My
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\CA
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\trust
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\Root

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
    <EventID>1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2015-04-22T13:27:17.139891900Z" />
    <EventRecordID>18588</EventRecordID>
    <Correlation />
    <Execution ProcessID="1160" ThreadID="9224" />
    <Channel>Application</Channel>
    <Computer>LAPTOP1.*DOMAIN*.ORG.UK</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData Name="EVENT_HIVE_LEAK">
    <Data Name="Detail">16 user registry handles leaked from \Registry\User\S-1-5-21-779955827-3448407892-3122252932-1588:
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\Disallowed
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\TrustedPeople
Process 9600 (\Device\HarddiskVolume3\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\My
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Policies\Microsoft\SystemCertificates
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\CA
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\trust
Process 1160 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-779955827-3448407892-3122252932-1588\Software\Microsoft\SystemCertificates\Root
</Data>
  </EventData>
</Event>

O que eu gostaria de saber é como resolvo esse problema? Os usuários ainda não conseguem efetuar login. Além disso, como evitá-lo no futuro.

    
por zain.ali 15.06.2015 / 11:59

1 resposta

2

Eu finalmente percebi isso. Eu não sei porque a mensagem de erro ocorreu em primeiro lugar - mas eu resolvi o problema.

Eu excluí o perfil de usuários em C:\Users\%Username% e reiniciei o sistema. Então eu entrei como usuário.

Como o laptop faz parte de um domínio, o laptop procurará no servidor uma nova cópia do perfil de usuários que acaba de ser excluído! Parecia fazer o truque.

    
por 17.06.2015 / 11:54