Jump to content

Permanent User Profile Hive Cleaner Solution


Recommended Posts

Guest miketones
Posted

I am using User Profile Hive Cleaner in response to Event ID 1517. I like the

program, but instead of keeping it I would like to solve the root problem.

 

The essence of my problem is that I need "svchost.exe (1304)

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Network\Location

Awareness (0x2d4)" to release the registry when I log off. Is there a way I

can do this?

 

Thanks in advance.

 

Mike

 

Here are my UPHC event log entries. In my case I see this message during

normal UPHC operation:

 

Event Type: Information

Event Source: UPHClean

Event Category: None

Event ID: 1401

Date: 9/12/2007

Time: 4:17:21 PM

User: ROCGROUP\mmientus

Computer: 6KX0X41

Description:

The following handles in user profile hive ROCGROUP\mmientus

(S-1-5-21-1517898522-2714448520-410836879-1287) have been remapped because

they were preventing the profile from unloading successfully:

 

svchost.exe (1304)

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Network\Location

Awareness (0x2d4)

 

 

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp.

 

*****************************************************

***And I see this message with call stack logging turned on: ***

*****************************************************

 

Event Type: Information

Event Source: UPHClean

Event Category: None

Event ID: 1401

Date: 9/12/2007

Time: 5:38:31 PM

User: ROCGROUP\mmientus

Computer: 6KX0X41

Description:

The following handles in user profile hive ROCGROUP\mmientus

(S-1-5-21-1517898522-2714448520-410836879-1287) have been remapped because

they were preventing the profile from unloading successfully:

 

svchost.exe (1020)

HKCU\Software\Microsoft\Windows NT\CurrentVersion\Network\Location

Awareness (0x2d4)

0x77e3b4b7 ADVAPI32!<no symbol>

0x77e0897d ADVAPI32!IsTextUnicode+0xb380

0x77ddebb2 ADVAPI32!RegCreateKeyExA+0xbe

0x71a5b9eb mswsock!NSPStartup+0x10fb

0x71a5b90d mswsock!NSPStartup+0x101d

0x71ab35f2 WS2_32!WSALookupServiceBeginW+0x2eb

0x71ab35ce WS2_32!WSALookupServiceBeginW+0x2c7

0x71ab34c9 WS2_32!WSALookupServiceBeginW+0x1c2

0x71ab338b WS2_32!WSALookupServiceBeginW+0x84

0x42c31783 WININET!InternetOpenUrlA+0x10a6

0x42c316cf WININET!InternetOpenUrlA+0xff2

0x42c1eef5 WININET!InternetCloseHandle+0x146c

0x42c1ee3f WININET!InternetCloseHandle+0x13b6

0x42c1fefa WININET!HttpAddRequestHeadersA+0x375

0x42c50aff WININET!PrivacyGetZonePreferenceW+0xbed

0x42c335e4 WININET!HttpSendRequestExW+0x92

0x5a6e70cc webclnt!DavClose+0x1223

0x5a6eb10e webclnt!DavClose+0x5265

0x5a6e5788 webclnt!<no symbol>

0x7c927545 ntdll!RtlUpcaseUnicodeString+0x159

0x7c927583 ntdll!RtlUpcaseUnicodeString+0x197

0x7c927645 ntdll!RtlUpcaseUnicodeString+0x259

0x7c92761c ntdll!RtlUpcaseUnicodeString+0x230

0x7c80b683 kernel32!GetModuleFileNameA+0x1b4

 

svchost.exe (1712)

HKCU (0x3a4)

0x77e3b4b7 ADVAPI32!<no symbol>

0x77e072b1 ADVAPI32!IsTextUnicode+0x9cb4

0x77dd6b20 ADVAPI32!RegOpenKeyExW+0xa8

0x77dd773e ADVAPI32!RegOpenKeyW+0x2f

0x77ddb2dc ADVAPI32!SaferComputeTokenFromLevel+0x587

0x77ddb296 ADVAPI32!SaferComputeTokenFromLevel+0x541

0x77dd9e9e ADVAPI32!IdentifyCodeAuthzLevelW+0xd9

0x7c819983 kernel32!BasepCheckWinSaferRestrictions+0x17e

0x7c819054 kernel32!GetNlsSectionName+0x10d7

0x77df7838 ADVAPI32!CreateProcessAsUserW+0xc3

0x76a93acd rpcss!<no symbol>

0x76a93849 rpcss!<no symbol>

0x77e79dc9 RPCRT4!CheckVerificationTrailer+0x75

0x77ef321a RPCRT4!NdrStubCall2+0x215

0x77ef36ee RPCRT4!NdrServerCall2+0x19

0x77e7988c RPCRT4!NdrGetTypeFlags+0x1c9

0x77e797f1 RPCRT4!NdrGetTypeFlags+0x12e

0x77e7971d RPCRT4!NdrGetTypeFlags+0x5a

0x77e7bd0d RPCRT4!NdrConformantArrayFree+0x42e

0x77e7bb6a RPCRT4!NdrConformantArrayFree+0x28b

0x77e76784 RPCRT4!I_RpcBCacheFree+0x14c

0x77e76c22 RPCRT4!I_RpcBCacheFree+0x5ea

0x77e76a3b RPCRT4!I_RpcBCacheFree+0x403

0x77e76c0a RPCRT4!I_RpcBCacheFree+0x5d2

0x7c80b683 kernel32!GetModuleFileNameA+0x1b4

 

 

For more information, see Help and Support Center at

http://go.microsoft.com/fwlink/events.asp.

Join the conversation

You can post now and register later. If you have an account, sign in now to post with your account.

Guest
Reply to this topic...

×   Pasted as rich text.   Paste as plain text instead

  Only 75 emoji are allowed.

×   Your link has been automatically embedded.   Display as a link instead

×   Your previous content has been restored.   Clear editor

×   You cannot paste images directly. Upload or insert images from URL.

×
×
  • Create New...