You may have not missed a thing. This is a common problem, if the source of the event is Userenv, then the 1517 event code is usually associated with an application or service still using the registry during log off.
This can be fixed be installed a free tool from Microsoft called the User Profile Hive Cleanup Service and can be downloaded from here:
http://www.microsoft.com/Downloads/details.aspx?familyid=1B286E6D-8912-4E18-B570-42470E2F3582&displaylang=en Hope this solves your problem,
Jim