G
Guest
I'm having an issue that I've traced to Windows Defender. Periodically I
noticed my stored network passwords were disappearing. After reviewing the
event logs, I think it's occuring each time I get this message. Any
suggestions (other than turn off WD)?
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-User Profiles Service"
Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2007-04-13T00:14:59.000Z" />
<EventRecordID>17096</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Pegasus</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">1 user registry handles leaked from
\Registry\User\S-1-5-21-885596355-2598441921-1701884729-500_Classes: Process
1180 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key
\REGISTRY\USER\S-1-5-21-885596355-2598441921-1701884729-500_CLASSES</Data>
</EventData>
</Event>
noticed my stored network passwords were disappearing. After reviewing the
event logs, I think it's occuring each time I get this message. Any
suggestions (other than turn off WD)?
- <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
- <System>
<Provider Name="Microsoft-Windows-User Profiles Service"
Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2007-04-13T00:14:59.000Z" />
<EventRecordID>17096</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>Pegasus</Computer>
<Security UserID="S-1-5-18" />
</System>
- <EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">1 user registry handles leaked from
\Registry\User\S-1-5-21-885596355-2598441921-1701884729-500_Classes: Process
1180 (\Device\HarddiskVolume1\Windows\System32\svchost.exe) has opened key
\REGISTRY\USER\S-1-5-21-885596355-2598441921-1701884729-500_CLASSES</Data>
</EventData>
</Event>