복원도 관리자모드에서 실행해봤는데 복원을 할 수가 없습니다.
아래는 제가 관리자모드로 들어가서 찾은 이벤트 로그 입니다.
혹시 이 로그가 도움이 되지 않을까요?
cvh.exe, svchost.exe, SearchProtocolHost.exe 에 문제가 있다고 나오는데,
어떻게 하면 관리자 권한을 되찾을 수 있을까요?
로그 이름: Application
원본: Microsoft-Windows-User Profiles Service
날짜: 2011-11-29 오전 1:16:44
이벤트 ID: 1530
작업 범주: 없음
수준: 경고
키워드: 클래식
사용자: SYSTEM
컴퓨터: KiGapHan-PC
설명:
다른 응용 프로그램이나 서비스에서 레지스트리 파일을 아직 사용하고 있습니다. 파일을 지금 언로드합니다. 레지스트리 파일을 보관하는 응용 프로그램이나 서비스가 이후에 제대로 작동하지 않을 수도 있습니다.
세부 정보 -
5 user registry handles leaked from \Registry\User\S-1-5-21-2499469742-3748916130-1143240890-1000_Classes:
Process 932 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 2988 (\Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 2988 (\Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 3544 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 3544 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
이벤트 Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
<System>
<Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" EventSourceName="profsvc" />
<EventID Qualifiers="32768">1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x80000000000000</Keywords>
<TimeCreated SystemTime="2011-11-28T16:16:44.000Z" />
<EventRecordID>114421</EventRecordID>
<Correlation />
<Execution ProcessID="0" ThreadID="0" />
<Channel>Application</Channel>
<Computer>KiGapHan-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">5 user registry handles leaked from \Registry\User\S-1-5-21-2499469742-3748916130-1143240890-1000_Classes:
Process 932 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 2988 (\Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 2988 (\Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 3544 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 3544 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
</Data>
</EventData>
</Event>
세부 정보 -
5 user registry handles leaked from \Registry\User\S-1-5-21-2499469742-3748916130-1143240890-1000_Classes:
Process 932 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 2988 (\Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 2988 (\Device\HarddiskVolume2\Windows\System32\SearchProtocolHost.exe) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 3544 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES
Process 3544 (\Device\HarddiskVolume2\Program Files\Common Files\microsoft shared\Virtualization Handler\CVH.EXE) has opened key \REGISTRY\USER\S-1-5-21-2499469742-3748916130-1143240890-1000_CLASSES