Results 1 to 6 of 6

Thread: WIN7: Registery Handles

  1. #1
    sodapop554 Guest

    Default WIN7: Registery Handles

    Upon looking into my Windows 7 Event Viewer I noticed several Warnings about a User Profile Service (source). The event ID was 1530 & the general details are as follows.

    "Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

    DETAIL -
    2 user registry handles leaked from \Registry\User\S-1-5-21-2139512326-588032674-43916064-1001:
    Process 1532 (\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\ISWSVC.exe) has opened key \REGISTRY\USER\S-1-5-21-2139512326-588032674-43916064-1001
    Process 1532 (\Device\HarddiskVolume2\Program Files\CheckPoint\ZAForceField\ISWSVC.exe) has opened key \REGISTRY\USER\S-1-5-21-2139512326-588032674-43916064-1001\Software\CheckPoint\ISW\Stats"

    I've noticed these to be happening several times a day. Although I've asked this same question on many other online forums some of the answers I've been receiving either don't make sense or are too brief without enough explanation. What does this warning mean? Is it something I should worry about or can I ignore it completely?

  2. #2
    Join Date
    Nov 2004
    Location
    localhost
    Posts
    17,291

    Default Re: Leaked Registery Handles, Help!

    It should not be a problem just win7 recording about a component of ZA accessing the registry. Meanwhile ensure your are on the latest version of ZA free 10.1.079.000. If not, remove you current version and install the new: Looking for the latest version?

    I don't see any related to forcefield in my log but I see windows ones:

    DETAIL -
    2 user registry handles leaked from \Registry\User\S-1-5-21-198609518-2515847190-2562944558-1005:
    Process 528 (\Device\HarddiskVolume2\Windows\System32\winlogon .exe) has opened key \REGISTRY\USER\S-1-5-21-198609518-2515847190-2562944558-1005
    Process 5192 (\Device\HarddiskVolume2\Windows\System32\msiexec. exe) has opened key \REGISTRY\USER\S-1-5-21-198609518-2515847190-2562944558-1005\Software\Microsoft\Windows\CurrentVersion\Exp lorer\FileExts
    Last edited by fax; January 27th, 2012 at 09:14 AM.

    Click here for ZA Support
    Monday-Saturday 6am to 10pm Central time
    Closed Sundays and Holidays

  3. #3
    sodapop554 Guest

    Default Re: Leaked Registery Handles, Help!

    Quote Originally Posted by fax View Post
    It should not be a problem just win7 recording about a component of ZA accessing the registry. Meanwhile ensure your are on the latest version of ZA free 10.1.079.000. If not, remove you current version and install the new: Looking for the latest version?

    I don't see any related to forcefield in my log but I see windows ones:

    DETAIL -
    2 user registry handles leaked from \Registry\User\S-1-5-21-198609518-2515847190-2562944558-1005:
    Process 528 (\Device\HarddiskVolume2\Windows\System32\winlogon .exe) has opened key \REGISTRY\USER\S-1-5-21-198609518-2515847190-2562944558-1005
    Process 5192 (\Device\HarddiskVolume2\Windows\System32\msiexec. exe) has opened key \REGISTRY\USER\S-1-5-21-198609518-2515847190-2562944558-1005\Software\Microsoft\Windows\CurrentVersion\Exp lorer\FileExts
    Okay now I'm confused, it says my version is up to date but the version is...

    ZoneAlarm Free Firewall version: 10.1.065.000
    vsmon version: 10.1.065.000
    Driver version: 10.0.217.000
    ZoneAlarm Browser Security: 1.5.350.0
    ZoneAlarm ForceField Spyware Scanner: 1.5.53.235
    ZoneAlarm ForceField Anti-Phishing Database: 1.2.104.0
    ZoneAlarm ForceField Spyware Sites Database: 04.155

  4. #4
    Join Date
    Nov 2004
    Location
    localhost
    Posts
    17,291

    Default Re: Leaked Registery Handles, Help!

    Yes, its normal. The autoupdate is turned ON only after weeks or months from the release. For a clean start just remove 65 first and then install the new.

    Thanks

    Click here for ZA Support
    Monday-Saturday 6am to 10pm Central time
    Closed Sundays and Holidays

  5. #5
    sodapop554 Guest

    Default Re: Leaked Registery Handles, Help!

    Quote Originally Posted by fax View Post
    Yes, its normal. The autoupdate is turned ON only after weeks or months from the release. For a clean start just remove 65 first and then install the new.

    Thanks
    Alright thanks I do have another last question though. Since I don't want there to be even a second when my computer is unprotected can I have my internet disconnected while ZoneAlarm installs? Like I had planned to download the latest version to a flash drive. Disconnect my internet completely, uninstall the old 1 then install the new & wait until it's fully installed before getting online. Can I do this or will it not be able to fully install?

  6. #6
    Join Date
    Nov 2004
    Location
    localhost
    Posts
    17,291

    Default Re: Leaked Registery Handles, Help!

    Not reccomended. Better to install with internet for ZA to configure the firewall correctly. Just turn on windows firewall, ZA will take care of turning it off after install. This way everytime ZA is off windows firewall will be automatically turned ON
    Last edited by fax; January 27th, 2012 at 12:06 PM.

    Click here for ZA Support
    Monday-Saturday 6am to 10pm Central time
    Closed Sundays and Holidays

Thread Information

Users Browsing this Thread

There are currently 1 users browsing this thread. (0 members and 1 guests)

Similar Threads

  1. vsdata.sys and 'handles'
    By geoffwood in forum General - Questions that don't fit any other category
    Replies: 0
    Last Post: August 31st, 2009, 05:24 PM
  2. registery
    By frederickdick in forum General - Questions that don't fit any other category
    Replies: 1
    Last Post: November 4th, 2008, 09:08 AM
  3. Invalid file handles, incorrect environment and incorrect boot sector parameters
    By panasher in forum ZoneAlarm Anti-virus & Anti-spyware
    Replies: 27
    Last Post: April 6th, 2008, 05:55 AM
  4. Does ZoneAlarm override Microsoft registery firewall and anti-virus settings
    By stopwatch in forum ZoneAlarm Anti-virus & Anti-spyware
    Replies: 5
    Last Post: February 12th, 2008, 04:52 AM
  5. Understanding How ZA Handles Stealthed, Closed, and Open Ports
    By steerjockey in forum Security Issues
    Replies: 1
    Last Post: October 31st, 2007, 02:09 PM

Bookmarks

Posting Permissions

  • You may not post new threads
  • You may not post replies
  • You may not post attachments
  • You may not edit your posts
  •