Solved

Registry leaks from external hard drive

Posted on 2014-12-29
4
519 Views
Last Modified: 2014-12-30
On my machine WIN7/64, I have a G-Tech mini 500 external hard drive connected by USB. It supplies enough power and I do not have to use the power adapter.

Using Diskpart, I've ID'd the the G-Tech disk as Volume3.

For a while, regularly, I've been getting the following 1530 event in Admin events:

15 user registry handles leaked from \Registry\User\S-1-5-21-2987587682-1074968332-1067063631-1001:
Process 2476 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2987587682-1074968332-1067063631-1001
Process 2476 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2987587682-1074968332-1067063631-1001
Process 2476 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2987587682-1074968332-1067063631-1001
Process 2476 (\Device\HarddiskVolume3\Program Files\Common Files\Microsoft Shared\Windows Live\WLIDSVC.EXE) has opened key \REGISTRY\USER\S-1-5-21-2987587682-1074968332-1067063631-1001

I did not list all 15 events, which are the same, but you get the idea. I've been getting Volume 3 (G-Tech mini) events for quite a while. The number of handle leaks varies, but they are always the same, same volume, same registry key, most especially, same WLIDSVC.EXE interacting with a hard drive that is used for nothing but storage.

Again, I repeat, no programs run from the G-tech; it's just used to backup data files. Why then would it generate so many 1530's involved with Windows Live, which I never use? How does Windows live get involved with an external hard drive? Most of all, what can I do to stop the 1530 events (yes, I know, they are harmless but they fill my admin logs.) And this always occurs at shutdown.

Thanks.
0
Comment
Question by:normanml
4 Comments
 
LVL 9

Accepted Solution

by:
Sean earned 250 total points
ID: 40521933
You could try to disable the windows live services if you are not using it as well as the IE plugin for windows live.
0
 
LVL 3

Expert Comment

by:Glenn M
ID: 40521938
You get those messages when Windows tries to close a profile and some links it uses are still open. I think the best way to deal with these would be to track down the identified application and either remove it if it's not required, or reconfigure it to use another drive.

You might try uninstalling Windows Live Essentials. To do this uninstall from the 'Programs and Features' in Windows 7, select 'Remove', and 'Yes' to confirm. Then start regedit (assuming you're backed up safely, etc) and look for HKEY_LOCAL_MACHINE\ SOFTWARE\Microsoft\ Windows\CurrentVersion\ Uninstall

On the right pane, locate the registry key which contains 'Windows Live Essentials'. Look for the key Uninstall Windows Live Essentials.  The log file is located on the same folder where the software resides. Delete the key containing “Windows Live Essentials”.

You'll need to reboot but Live Essentials will be gone and you should get rid of those 1530 Warning messages.
0
 
LVL 88

Assisted Solution

by:rindi
rindi earned 250 total points
ID: 40522141
The events you get in the eventviewer don't necessarily have anything to do with your USB disk. You just labeled it to "Volume3", but that has nothing directly to do with "(\Device\HarddiskVolume3\...)" you get in the message. That is an internal Windows way of defining partitions, and has nothing to do with the disk's label. If it happened to be the external disk, that would be pure chance.

As Windows live is normally installed to an internal disk, it is far more likely that it actually points to a partition of your internal disk.
0
 

Author Closing Comment

by:normanml
ID: 40523568
So far disabling Windows Live ID Sign-in Assistant seems to work, this instead of uninstalling WL components. And thanks Rindi for an explanation I've seen no where else. I'm guessing there are legions of Win Opsys owners out there who think that :"Volume3" is the same as disk 3 in the disk management list. I did and was baffled the interaction between an ext HD and WinLive components. Anyway, we'll see what happens with WL ID Sign-in service disable. Thanks to all.
0

Featured Post

Is Your Active Directory as Secure as You Think?

More than 75% of all records are compromised because of the loss or theft of a privileged credential. Experts have been exploring Active Directory infrastructure to identify key threats and establish best practices for keeping data safe. Attend this month’s webinar to learn more.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Sometimes drives fill up and we don't know why.  If you don't understand the best way to use the tools available, you may end up being stumped as to why your drive says it's not full when you have no space left!  Here's how you can find out...
OfficeMate Freezes on login or does not load after login credentials are input.
This Micro Tutorial will teach you the basics of configuring your computer to improve its speed. It will also teach you how to disable programs that are running in the background simultaneously. This will be demonstrated using Windows 7 operating…
With the advent of Windows 10, Microsoft is pushing a Get Windows 10 icon into the notification area (system tray) of qualifying computers. There are many reasons for wanting to remove this icon. This two-part Experts Exchange video Micro Tutorial s…

867 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

22 Experts available now in Live!

Get 1:1 Help Now