09-10-2010 03:38 PM
I have these logs at shutdown on my win7 x64 Dell studio xps 8100 and I need a little help or info THANKS. Here is one of the logs in event viewer.Log Name: Application
Source: Microsoft-Windows-User Profiles Service
Date: 9/10/2010 6:48:27 AM
Event ID: 1530
Task Category: None
Level: Warning
Keywords:
User: SYSTEM
Computer: SavannahMick-PC
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
2 user registry handles leaked from \Registry\User\S-1-5-21-163695203-2985681545-29013
Process 1700 (\Device\HarddiskVolume3\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-163695203-2985681545-29013
Process 1700 (\Device\HarddiskVolume3\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-163695203-2985681545-29013
Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/ev
<System>
<Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
<EventID>1530</EventID>
<Version>0</Version>
<Level>3</Level>
<Task>0</Task>
<Opcode>0</Opcode>
<Keywords>0x8000000000000000</Keywords>
<TimeCreated SystemTime="2010-09-10T10:48:27.883707900Z" />
<EventRecordID>11953</EventRecordID>
<Correlation />
<Execution ProcessID="520" ThreadID="3436" />
<Channel>Application</Channel>
<Computer>SavannahMick-PC</Computer>
<Security UserID="S-1-5-18" />
</System>
<EventData Name="EVENT_HIVE_LEAK">
<Data Name="Detail">2 user registry handles leaked from \Registry\User\S-1-5-21-163695203-2985681545-29013
Process 1700 (\Device\HarddiskVolume3\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-163695203-2985681545-29013
Process 1700 (\Device\HarddiskVolume3\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-163695203-2985681545-29013
</Data>
</EventData>
</Event>
09-11-2010 09:06 PM
I am getting something very similar as well. Any help would be appreciated. Here is event viewer details:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
3 user registry handles leaked from \Registry\User\S-1-5-21-165488792-1791156006-14090
Process 2460 (\Device\HarddiskVolume1\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-165488792-1791156006-14090
Process 2460 (\Device\HarddiskVolume1\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-165488792-1791156006-14090
Process 2460 (\Device\HarddiskVolume1\Program Files (x86)\Norton Internet Security\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-165488792-1791156006-14090
09-15-2010 07:26 AM
Here's another:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
DETAIL -
13 user registry handles leaked from \Registry\User\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Process 2000 (\Device\HarddiskVolume2\Program Files (x86)\Norton Internet Security\Engine\18.1.0.37\ccSvcHst.exe) has opened key \REGISTRY\USER\S-1-5-21-3833584364-3943312004-2874
Is this normal?
09-15-2010 09:30 AM
I see the same 1530 registry leak error messages in my Windows 7 event log. I have NIS 2011.
09-15-2010 09:38 AM
car825 wrote:I see the same 1530 registry leak error messages in my Windows 7 event log. I have NIS 2011.
same warnings here with win 7 prof 32 bit and NIS 18.1.0.37
--- N360 v6.4 on german 64 bit win7, IE9 ---
09-15-2010 10:28 AM - edited 09-15-2010 10:38 AM
I just checked my logs and don't see any similar events.
When you shutdown your system, does it shutdown cleanly or do you have to force a shutdown due to some process not responding? If it does shutdown cleanly, have you had this problem in the past and had the problem fixed by Symantec support?
On a possibly related line of questioning, if you check your Norton product's Security History and Show Norton Error Reporting (near the bottom of the scrolling list), are any there any entries listed?
09-15-2010 10:58 AM
reese_anschultz wrote:I just checked my logs and don't see any similar events.
When you shutdown your system, does it shutdown cleanly or do you have to force a shutdown due to some process not responding? If it does shutdown cleanly, have you had this problem in the past and had the problem fixed by Symantec support?
On a possibly related line of questioning, if you check your Norton product's Security History and Show Norton Error Reporting (near the bottom of the scrolling list), are any there any entries listed?
I see these error messages in the Windows 7 Event Viewer, not the NIS History Log. The error type in the Event Viewer is Warning, the Event ID is 1530, the Source is User Profile Service, and the Log is Application. My PC shuts down cleanly. It was never fixed by Symantec Support.
09-15-2010 11:05 AM - edited 09-15-2010 11:08 AM
Hi Reese,
there is no need to force programms to close by the user.
But when disconnecting WAN and log off, for about 1 second there is a box with this text:
wait for "Task Host Window"
--- N360 v6.4 on german 64 bit win7, IE9 ---
09-15-2010 11:28 AM
car825 wrote:
[...]
I see these error messages in the Windows 7 Event Viewer, not the NIS History Log. The error type in the Event Viewer is Warning, the Event ID is 1530, the Source is User Profile Service, and the Log is Application. My PC shuts down cleanly. It was never fixed by Symantec Support.
I understand that these are in the Windows Event Viewer. I'd like to know if any errors are showing up in Norton's Security History under Norton Error Reporting that might point to the cause of this.
09-15-2010 11:30 AM
mp3jo wrote:
Hi Reese,
there is no need to force programms to close by the user.
But when disconnecting WAN and log off, for about 1 second there is a box with this text:
wait for "Task Host Window"
Thanks Jo for the information, unfortunately it doesn't point toward a smoking gun. Can you check the Norton Error Reporting within the Norton Security History and see if anything is reported there?
