By using this site, you agree to our updated Privacy Policy and our Terms of Use. Manage your Cookies Settings.
440,375 Members | 1,095 Online
Bytes IT Community
+ Ask a Question
Need help? Post your question and get tips & solutions from a community of 440,375 IT Pros & Developers. It's quick & easy.

NTUSER.DAT locked - User Profile Service

P: 4
I have tried posting everywhere, but no one has given me an answer so far. I am willing to try everything short of a clean install of vista.

My Problem:
Some process has a locking handle on the Users NTUSER.DAT file, so windows attempts to unload it:

Expand|Select|Wrap|Line Numbers
  1. Log Name:      Application
  2. Source:        Microsoft-Windows-User Profiles Service
  3. Date:          6/13/2010 8:54:01 AM
  4. Event ID:      1530
  5. Task Category: None
  6. Level:         Warning
  7. Keywords:      Classic
  8. User:          SYSTEM
  9. Computer:      Den-PC
  10. Description:
  11. Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  
  12.  
  13.  DETAIL - 
  14.  27 user registry handles leaked from \Registry\User\S-1-5-21-3692011518-2094500946-738968334-1001:
  15. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  16. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  17. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  18. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  19. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  20. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\Disallowed
  21. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software
  22. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
  23. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  24. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Internet Explorer\IETld
  25. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\trust
  26. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\TrustedPeople
  27. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\Root
  28. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
  29. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  30. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  31. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  32. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  33. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
  34. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies
  35. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies
  36. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  37. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  38. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\My
  39. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\CA
  40. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  41. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  42.  
  43. Event Xml:
  44. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  45.   <System>
  46.     <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
  47.     <EventID Qualifiers="32768">1530</EventID>
  48.     <Version>0</Version>
  49.     <Level>3</Level>
  50.     <Task>0</Task>
  51.     <Opcode>0</Opcode>
  52.     <Keywords>0x80000000000000</Keywords>
  53.     <TimeCreated SystemTime="2010-06-13T13:54:01.000Z" />
  54.     <EventRecordID>39724</EventRecordID>
  55.     <Correlation />
  56.     <Execution ProcessID="0" ThreadID="0" />
  57.     <Channel>Application</Channel>
  58.     <Computer>Den-PC</Computer>
  59.     <Security UserID="S-1-5-18" />
  60.   </System>
  61.   <EventData Name="EVENT_HIVE_LEAK">
  62.     <Data Name="Detail">27 user registry handles leaked from \Registry\User\S-1-5-21-3692011518-2094500946-738968334-1001:
  63. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  64. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  65. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  66. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  67. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001
  68. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\Disallowed
  69. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software
  70. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
  71. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_LOCALMACHINE_LOCKDOWN
  72. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Internet Explorer\IETld
  73. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\trust
  74. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\TrustedPeople
  75. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\Root
  76. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows NT\CurrentVersion\Network\Location Awareness
  77. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  78. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  79. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  80. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies\Microsoft\SystemCertificates
  81. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts
  82. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies
  83. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Policies
  84. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  85. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
  86. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\My
  87. Process 656 (\Device\HarddiskVolume3\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\SystemCertificates\CA
  88. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  89. Process 4752 (\Device\HarddiskVolume3\Program Files\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3692011518-2094500946-738968334-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings
  90. </Data>
  91.   </EventData>
  92. </Event>
However, windows fails. Then when the user logs on, the User Profile Service cannot load HKEY_CURRENT_USER, because the file that contains this hive, NTUSER.DAT, is locked:

Expand|Select|Wrap|Line Numbers
  1. Log Name:      Application
  2. Source:        Microsoft-Windows-User Profiles Service
  3. Date:          6/13/2010 8:50:30 AM
  4. Event ID:      1508
  5. Task Category: None
  6. Level:         Error
  7. Keywords:      Classic
  8. User:          SYSTEM
  9. Computer:      Den-PC
  10. Description:
  11. Windows was unable to load the registry. This problem is often caused by insufficient memory or insufficient security rights. 
  12.  
  13.  DETAIL - The process cannot access the file because it is being used by another process.  for C:\Users\Elaine\ntuser.dat
  14. Event Xml:
  15. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  16.   <System>
  17.     <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
  18.     <EventID Qualifiers="49152">1508</EventID>
  19.     <Version>0</Version>
  20.     <Level>2</Level>
  21.     <Task>0</Task>
  22.     <Opcode>0</Opcode>
  23.     <Keywords>0x80000000000000</Keywords>
  24.     <TimeCreated SystemTime="2010-06-13T13:50:30.000Z" />
  25.     <EventRecordID>39704</EventRecordID>
  26.     <Correlation />
  27.     <Execution ProcessID="0" ThreadID="0" />
  28.     <Channel>Application</Channel>
  29.     <Computer>Den-PC</Computer>
  30.     <Security UserID="S-1-5-18" />
  31.   </System>
  32.   <EventData Name="EVENT_REGLOADKEYFAILED">
  33.     <Data Name="Error">The process cannot access the file because it is being used by another process. </Data>
  34.     <Data Name="File">C:\Users\Elaine\ntuser.dat</Data>
  35.   </EventData>
  36. </Event>
So then windows cannot load the profile, because the profile is contained in the file windows cannot load. Windows then throws a critical exeption:

Expand|Select|Wrap|Line Numbers
  1. Log Name:      Application
  2. Source:        Microsoft-Windows-User Profiles Service
  3. Date:          6/13/2010 8:50:30 AM
  4. Event ID:      1502
  5. Task Category: None
  6. Level:         Error
  7. Keywords:      Classic
  8. User:          Den-PC\Elaine
  9. Computer:      Den-PC
  10. Description:
  11. Windows cannot load the locally stored profile. Possible causes of this error include insufficient security rights or a corrupt local profile. 
  12.  
  13.  DETAIL - The process cannot access the file because it is being used by another process. 
  14. Event Xml:
  15. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  16.   <System>
  17.     <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
  18.     <EventID Qualifiers="49152">1502</EventID>
  19.     <Version>0</Version>
  20.     <Level>2</Level>
  21.     <Task>0</Task>
  22.     <Opcode>0</Opcode>
  23.     <Keywords>0x80000000000000</Keywords>
  24.     <TimeCreated SystemTime="2010-06-13T13:50:30.000Z" />
  25.     <EventRecordID>39705</EventRecordID>
  26.     <Correlation />
  27.     <Execution ProcessID="0" ThreadID="0" />
  28.     <Channel>Application</Channel>
  29.     <Computer>Den-PC</Computer>
  30.     <Security UserID="S-1-5-21-3692011518-2094500946-738968334-1002" />
  31.   </System>
  32.   <EventData Name="EVENT_FAILED_LOAD_LOCAL">
  33.     <Data Name="Error">The process cannot access the file because it is being used by another process. </Data>
  34.   </EventData>
  35. </Event>
Since windows cannot load the profile, it backs up the profile, and makes this backup the user profile:

Expand|Select|Wrap|Line Numbers
  1. Log Name:      Application
  2. Source:        Microsoft-Windows-User Profiles Service
  3. Date:          6/13/2010 8:50:31 AM
  4. Event ID:      1515
  5. Task Category: None
  6. Level:         Warning
  7. Keywords:      Classic
  8. User:          Den-PC\Elaine
  9. Computer:      Den-PC
  10. Description:
  11. Windows has backed up this user profile. Windows will automatically try to use the backup profile the next time this user logs on.
  12. Event Xml:
  13. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  14.   <System>
  15.     <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
  16.     <EventID Qualifiers="49152">1515</EventID>
  17.     <Version>0</Version>
  18.     <Level>3</Level>
  19.     <Task>0</Task>
  20.     <Opcode>0</Opcode>
  21.     <Keywords>0x80000000000000</Keywords>
  22.     <TimeCreated SystemTime="2010-06-13T13:50:31.000Z" />
  23.     <EventRecordID>39706</EventRecordID>
  24.     <Correlation />
  25.     <Execution ProcessID="0" ThreadID="0" />
  26.     <Channel>Application</Channel>
  27.     <Computer>Den-PC</Computer>
  28.     <Security UserID="S-1-5-21-3692011518-2094500946-738968334-1002" />
  29.   </System>
  30.   <EventData Name="EVENT_PROFILE_DIR_BACKEDUP">
  31.   </EventData>
  32. </Event>
So then windows has to load a temporary profile, because it cannot load the user's profile:

Expand|Select|Wrap|Line Numbers
  1. Log Name:      Application
  2. Source:        Microsoft-Windows-User Profiles Service
  3. Date:          6/13/2010 8:50:31 AM
  4. Event ID:      1511
  5. Task Category: None
  6. Level:         Warning
  7. Keywords:      Classic
  8. User:          Den-PC\Elaine
  9. Computer:      Den-PC
  10. Description:
  11. Windows cannot find the local profile and is logging you on with a temporary profile. Changes you make to this profile will be lost when you log off.
  12. Event Xml:
  13. <Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  14.   <System>
  15.     <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
  16.     <EventID Qualifiers="49152">1511</EventID>
  17.     <Version>0</Version>
  18.     <Level>3</Level>
  19.     <Task>0</Task>
  20.     <Opcode>0</Opcode>
  21.     <Keywords>0x80000000000000</Keywords>
  22.     <TimeCreated SystemTime="2010-06-13T13:50:31.000Z" />
  23.     <EventRecordID>39707</EventRecordID>
  24.     <Correlation />
  25.     <Execution ProcessID="0" ThreadID="0" />
  26.     <Channel>Application</Channel>
  27.     <Computer>Den-PC</Computer>
  28.     <Security UserID="S-1-5-21-3692011518-2094500946-738968334-1002" />
  29.   </System>
  30.   <EventData Name="EVENT_TEMPPROFILEASSIGNED">
  31.   </EventData>
  32. </Event>
Which causes the user to be presented with the default profile with no personalized settings.

After a computer restart the user is able to log on to their normal profile without any problems. But after they log off, the next user has to restart the computer, or they will be presented with the same error.

Please, I have tried posting on multiple forums, and nobody has found a solution. I am desperate to fix this problem. I cannot identify which process has a locking handle on NTUSER.DAT from the windows logs.
Jun 13 '10 #1
Share this Question
Share on Google+
5 Replies


P: 1
Hi Geoff,
For what it's worth I too am having what looks like an identical issue.
My circumstances are a little different but after being assigned a temporary user profile my application cannot use DPAPI calls to decrypt passwords. The Cryp..ProtectData calls fail becasue they need the "Common AppData" value as a key, and it's not there anymore.
To get rid of the temporary profile a reboot is required.

I have raised a support call with Microsoft.
Jun 16 '10 #2

P: 4
Please tell me how to fix the problem; when you get a reply from Microsoft. I would be interested to know how to fix the problem.
Jun 23 '10 #3

P: 1
Have you fixed / found a solution to the problem?

I am having this problem too and can't find a solution on the web. Lots of places tell me how I can get my profile back, but a reboot solves that.
Oct 3 '10 #4

P: 4
Sorry, I had opened multiple threads on diffrent sites for this problem, and had finally found an answer.

The solution is at http://www.google.com/support/forum/...68a22d32&hl=en

(I am the user Geoffish)

And please do post on that topic, so It will get Google's attention.
Oct 3 '10 #5

P: 4
(The topic can be closed now)
Oct 3 '10 #6

Post your reply

Sign in to post your reply or Sign up for a free account.