CIS causes Windows Event Id 1530 - User profile service malfunction [309]

Source-user profile service, Event ID 1530

The bug/issue

  1. What you did: Looked in Event Viewer log administrative events
  2. What actually happened or you actually saw:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

1 user registry handles leaked from \Registry\User\S-1-5-21-1639307694-603179192-2751088746-1000:
Process 892 (\Device\HarddiskVolume1\Program Files\COMODO\COMODO Internet Security\cmdagent.exe) has opened key \REGISTRY\USER\S-1-5-21-1639307694-603179192-2751088746-1000

  1. What you expected to happen or see: n/a
  2. How you tried to fix it & what happened: n/a
  3. If its an application compatibility problem have you tried these fixes: n/a
  4. Details (exact version) of any application involved with download link: cmdagent.exe version 5.0.31556.1134
  5. Whether you can make the problem happen again, and if so precise steps to make it happen: n/a
  6. Any other information (eg your guess regarding the cause, with reasons):
    It is possible that my previus problem is causing registry trouble and that is the after the
    computer has been shut down(using shut down command and turned off by extender with
    a switch and left shut down for few hours) causing during boot up of computer with only
    desktop background being visible and no icons and no taskbar.After restart of the computer
    (i was able to shut down computer using alt+f4(the screen is still blank) the operating system
    resumes without problems.
    I have searched comodo forum and found similar problem concerning registry problem:;msg222297#msg222297

Files appended

  1. Screenshots illustrating the bug: n/a
  2. Screenshots of related CIS event logs or the Defense+ Active Processes List: logs concerning
    the problems-none.
  3. A CIS config. report or file:
  4. Crash or freeze dump file: No

Your set-up

  1. CIS version, AV database version & configuration used: 5.0.1000.1135, 6770, Proactive config
  2. a) Have you updated (without uninstall) from CIS 3 or 4: No.
    b) if so, have you tried reinstalling (if not please do)?: No.
  3. a) Have you imported a config from a previous version of CIS: No
    b) if so, have U tried a preset config (if not please do)?: No
  4. Other major changes to the default config (eg ticked ‘block all unknown requests’, other egs here.):
    Create rules for safe applications both in defense+ and firewall,image execution control - unticked
    perform cloud behavior analysis for certain applications and automatically scan unrecognized
    files in the cloud,treat unrecognized files as untrusted.
  5. Defense+, Sandbox, Firewall & AV security level: D+=Safe, Sandbox=Enabled, Firewall=Costom Polcy, AV=Stateful,Proactive Security.
  6. OS version, service pack, bits, UAC setting, & account type: Windows 7, 64 bit, Admin account UAC disabled ,data execution prevention disabled.
  7. Other security and utility software installed: None.
  8. Virtual machine used: None.

Hi Leon,

Please file a complete bug report here:

Please follow this guide when posting

I have noticed the same “errors” in my Win7,x32 system btw.