Notice: This website is an unofficial Microsoft Knowledge Base (hereinafter KB) archive and is intended to provide a reliable access to deleted content from Microsoft KB. All KB articles are owned by Microsoft Corporation. Read full disclaimer for more details.

Event ID: 1530 may be logged in the Application log in Windows

View products that this article applies to.


In Windows, the following event may be logged in the Application log:

[Name] Microsoft-Windows-User Profiles Service
[Guid] {GUID}
[EventSourceName] profsvc

EventID 1530
message similar to
3 user registry handles leaked from \Registry\User\S-1-5-21-1049297961-3057247634-349289542-1004_Classes:
Process 2428 (\Device\HarddiskVolume1\myprocess.exe) has opened key \REGISTRY\USER\S-1-5-21-1123456789-3057247634-349289542-1004
If a service or background service uses a user specific hive because it runs under a specific user identity and the relevant user account logs out.

↑ Back to the top


This behavior occurs because Windows automatically closes any registry handle to a user profile that is left open by an application. Windows does this when Windows tries to close a user profile.

Note Event ID 1530 is logged as a Warning event. The application that is listed in the event detail is leaving the registry handle open and should be investigated.


↑ Back to the top


This behavior is by design.

↑ Back to the top

Keywords: kbexpertiseinter, kbtshoot, kbprb, kb

↑ Back to the top

Article Info
Article ID : 947238
Revision : 6
Created on : 1/20/2020
Published on : 1/20/2020
Exists online : False
Views : 658