Two errors in Event Viewer

ratePV

=hibernating=
Guru
Local time
9:32 AM
Messages
524
Hello SF!

I have two errors constantly being registered every time reboot(or turn on) my computer that i cant resolve:

The first one is a Event 3006 LoadPerf:
Unable to read the performance counter strings defined for the 01a language ID. The first DWORD in the Data section contains the Win32 error code.

And a second one a Event 1530 User Profile Settings:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
We'll need the information from the Data section of the error in order to get the Win32 error code on the first error.

As for the second error - it's gonna require uninstalling applications until you find out which one is causing it. Or, you can use the free program Process Monitor to see what's doing the registry accesses - but the log file is huge. It's available for free from here: Process Monitor
 

My Computer My Computer

Computer Manufacturer/Model Number
Home built (x64), Lenovo x61s Tablet, Samsung Netbook
OS
Win7 x64 + x86
CPU
Intel i7 920, other Intel chips, and the Atom in the netbook
Motherboard
Asus P6T Deluxe
Memory
12 gB; 4 gB Lenovo; 1 gB Samsung netbook
Graphics Card(s)
ATI 4870
Sound Card
Yes, I have one of these
Monitor(s) Displays
32" Sharp Aquos TV
Screen Resolution
800x600 - I have vision issues
Hard Drives
4 - 150 gB Velociraptors in RAID 5
Promise controller
PSU
1000 watt (can't recall the brand)
Case
Antec 300
Cooling
Big honking cooler that was rated highly at Toms Hardware
Keyboard
Microsoft Natural
Mouse
Logitech Trackman
Internet Speed
Cable
Other Info
GeekSquad UPS
CyberPower UPS
DLink DNS-323 NAS (2 tB)
Netgear wireless router as an access point
Netgear wired router FSV-318
Home network consists of
4 desktop computers (2 Vista, 2 Win7)
1 netbook (Win7)
4 laptop computers (XP, 2-Vista, Win7)
Wii and XBox 360
We'll need the information from the Data section of the error in order to get the Win32 error code on the first error.

As for the second error - it's gonna require uninstalling applications until you find out which one is causing it. Or, you can use the free program Process Monitor to see what's doing the registry accesses - but the log file is huge. It's available for free from here: Process Monitor

I've added a text file with the detail abt. the first error.

View attachment 72123

No need to uninstall, ill just monitor the process number the next time i reboot (the process causing the problem is lsass.exe)
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
Do you use Spybot? That puts all kinds stuff into the lsass.exe. I never figured out why or what. I just got rid of Spybot.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Do you use Spybot? That puts all kinds stuff into the lsass.exe. I never figured out why or what. I just got rid of Spybot.

Nope. Only NOD32 SS :confused:
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
Maybe the Sasser worm has struck you. Open the file "\windows\system32\drivers\etc\hosts" in Notepad. Type or paste:

Notepad \windows\system32\drivers\etc\hosts

into a Run box, and press OK. Normally, it will have one entry for something called "localhost". If in addition you see a list of Anti-Virus sites such as Nod32, then the worm has struck.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
Maybe the Sasser worm has struck you. Open the file "\windows\system32\drivers\etc\hosts" in Notepad. Type or paste:

Notepad \windows\system32\drivers\etc\hosts

into a Run box, and press OK. Normally, it will have one entry for something called "localhost". If in addition you see a list of Anti-Virus sites such as Nod32, then the worm has struck.

This is the 5th system reporting these 2 errors(since 22nd october) so its very unlikely it could strike 5 times a row.

These are the last few lines of hosts file


Code:
# localhost name resolution is handled within DNS itself.
#	127.0.0.1       localhost
#	::1             localhost
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
You are OK - no worm. It was just an additional precaution.
 

My Computer My Computer

Computer Manufacturer/Model Number
HP, Dell, Gateway, Toshiba - 4 laptops and 2 desktops
OS
Vista, Windows7, Mint Mate, Zorin, Windows 8
CPU
from 1.6GHz Duo to i7
Monitor(s) Displays
2x HP w2207
Hard Drives
5x HDD, 7x SSD, 12x Externals
Keyboard
with trackball - no mices
Mouse
Trackball mice
Internet Speed
DSL 6000
I'm unable to locate any info on a Win32 error code of 02000000 (?hex) - but I'm not real concerned over that first error.

The second error concerns me a lot more - why would lsass.exe be leaving registry keys open? AFAIK, lsass.exe is a security component of Windows - so I'd have to wonder what's messing with it.
 

My Computer My Computer

Computer Manufacturer/Model Number
Home built (x64), Lenovo x61s Tablet, Samsung Netbook
OS
Win7 x64 + x86
CPU
Intel i7 920, other Intel chips, and the Atom in the netbook
Motherboard
Asus P6T Deluxe
Memory
12 gB; 4 gB Lenovo; 1 gB Samsung netbook
Graphics Card(s)
ATI 4870
Sound Card
Yes, I have one of these
Monitor(s) Displays
32" Sharp Aquos TV
Screen Resolution
800x600 - I have vision issues
Hard Drives
4 - 150 gB Velociraptors in RAID 5
Promise controller
PSU
1000 watt (can't recall the brand)
Case
Antec 300
Cooling
Big honking cooler that was rated highly at Toms Hardware
Keyboard
Microsoft Natural
Mouse
Logitech Trackman
Internet Speed
Cable
Other Info
GeekSquad UPS
CyberPower UPS
DLink DNS-323 NAS (2 tB)
Netgear wireless router as an access point
Netgear wired router FSV-318
Home network consists of
4 desktop computers (2 Vista, 2 Win7)
1 netbook (Win7)
4 laptop computers (XP, 2-Vista, Win7)
Wii and XBox 360
I'm unable to locate any info on a Win32 error code of 02000000 (?hex) - but I'm not real concerned over that first error.

The second error concerns me a lot more - why would lsass.exe be leaving registry keys open? AFAIK, lsass.exe is a security component of Windows - so I'd have to wonder what's messing with it.

Ill examine the error and find the reg. keys that are being opened.
I tried to recreate this error 2 times but without success.
I will upload the log when i recreate it.
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
Now i had 4 errors: 3 times the Event 3006 LoadPerf, and the second one, but this time it was winlogon.exe:shock:

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

DETAIL -
1 user registry handles leaked from \Registry\User\S-...:
Process 640 (\Device\HarddiskVolume1\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-...
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
Just before shutting down, manually kill anything that's open and kill anything that's running in the System Tray (the Notification Area by the clock).

Then shut down and see if it generates the error again.
 

My Computer My Computer

Computer Manufacturer/Model Number
Home built (x64), Lenovo x61s Tablet, Samsung Netbook
OS
Win7 x64 + x86
CPU
Intel i7 920, other Intel chips, and the Atom in the netbook
Motherboard
Asus P6T Deluxe
Memory
12 gB; 4 gB Lenovo; 1 gB Samsung netbook
Graphics Card(s)
ATI 4870
Sound Card
Yes, I have one of these
Monitor(s) Displays
32" Sharp Aquos TV
Screen Resolution
800x600 - I have vision issues
Hard Drives
4 - 150 gB Velociraptors in RAID 5
Promise controller
PSU
1000 watt (can't recall the brand)
Case
Antec 300
Cooling
Big honking cooler that was rated highly at Toms Hardware
Keyboard
Microsoft Natural
Mouse
Logitech Trackman
Internet Speed
Cable
Other Info
GeekSquad UPS
CyberPower UPS
DLink DNS-323 NAS (2 tB)
Netgear wireless router as an access point
Netgear wired router FSV-318
Home network consists of
4 desktop computers (2 Vista, 2 Win7)
1 netbook (Win7)
4 laptop computers (XP, 2-Vista, Win7)
Wii and XBox 360
Just before shutting down, manually kill anything that's open and kill anything that's running in the System Tray (the Notification Area by the clock).

Then shut down and see if it generates the error again.

The problem is that i do this every time i shutdown(no open windows/apps).
And i dont have many app in my Notification Area(only these which are not closable from there):
View attachment 72752
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
The next step is to start killing things in Task Manager...Processes tab (do it in groups of 5).
 

My Computer My Computer

Computer Manufacturer/Model Number
Home built (x64), Lenovo x61s Tablet, Samsung Netbook
OS
Win7 x64 + x86
CPU
Intel i7 920, other Intel chips, and the Atom in the netbook
Motherboard
Asus P6T Deluxe
Memory
12 gB; 4 gB Lenovo; 1 gB Samsung netbook
Graphics Card(s)
ATI 4870
Sound Card
Yes, I have one of these
Monitor(s) Displays
32" Sharp Aquos TV
Screen Resolution
800x600 - I have vision issues
Hard Drives
4 - 150 gB Velociraptors in RAID 5
Promise controller
PSU
1000 watt (can't recall the brand)
Case
Antec 300
Cooling
Big honking cooler that was rated highly at Toms Hardware
Keyboard
Microsoft Natural
Mouse
Logitech Trackman
Internet Speed
Cable
Other Info
GeekSquad UPS
CyberPower UPS
DLink DNS-323 NAS (2 tB)
Netgear wireless router as an access point
Netgear wired router FSV-318
Home network consists of
4 desktop computers (2 Vista, 2 Win7)
1 netbook (Win7)
4 laptop computers (XP, 2-Vista, Win7)
Wii and XBox 360
Code:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL - 
 1 user registry handles leaked from \Registry\User\S-xxx:
Process 3232 (\Device\HarddiskVolume1\Windows\System32\msiexec.exe) has opened key \REGISTRY\USER\S-xxx\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts

Now its msiexec.exe...:huh:
 

My Computer My Computer

Computer type
PC/Desktop
Computer Manufacturer/Model Number
Custom
OS
Windows 7 SP1 x64
CPU
Intel E8400 3.0 GHz
Motherboard
Gigabyte EP45-DS3R
Memory
4x1 Trascend DDR2 800 Mhz
Graphics Card(s)
Gainward 8800GT 512 Mb
Sound Card
Realtek HD Audio 889A
Monitor(s) Displays
LG L204WS
Screen Resolution
1680x1050
Hard Drives
Intel 520 Series 120Gb SSD (System)
Western Digital 6400AAKS 640Gb (Data)
PSU
Cooler Master 650W
Case
Cooler Master Centurion 532
Cooling
2x 12 cm fans
Keyboard
Logitech Wave
Mouse
Logitech G5
Internet Speed
10 Mbit Cable Flat
Antivirus
NOD32 Smart Security
Browser
Google Chrome
Back
Top