Jump to content

Recommended Posts

Hello,

 

I've just tried 2013 and found it crash on reboot, dumps created in the Kaspersky folder.

I know this old box needs updating and the motherboard is getting old, but if you think it worth uploading the dumps for this error, let me know.

Error as follows after 1 day installed:

 

Log Name:      Application
Source:        Microsoft-Windows-User Profiles Service
Date:          26/04/2013 2:13:21 AM
Event ID:      1530
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      my main box
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

DETAIL - 
15 user registry handles leaked from \Registry\User\S-1-5-21-4006028695-2158132983-4052039910-1001:
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\Root
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\trust
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\My
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\CA

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
    <EventID>1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2013-04-25T18:13:21.301400000Z" />
    <EventRecordID>6133</EventRecordID>
    <Correlation />
    <Execution ProcessID="488" ThreadID="1256" />
    <Channel>Application</Channel>
    <Computer>SkyRock-home-PC</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData Name="EVENT_HIVE_LEAK">
    <Data Name="Detail">15 user registry handles leaked from \Registry\User\S-1-5-21-4006028695-2158132983-4052039910-1001:
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\Root
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Policies\Microsoft\SystemCertificates
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\Disallowed
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\trust
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\My
Process 1388 (\Device\HarddiskVolume2\Program Files (x86)\Kaspersky Lab\Kaspersky Internet Security 2013\avp.exe) has opened key \REGISTRY\USER\S-1-5-21-4006028695-2158132983-4052039910-1001\Software\Microsoft\SystemCertificates\CA
</Data>
  </EventData>
</Event>

Share this post


Link to post

Hi norwegian,

 

Please see the first Important topic. If still no go after that, please send your dumps to Tech Support.

Share this post


Link to post

Thanks for the feedback richbuff, appreciate your thoughts.

 

I will be uninstalling KIS though, and going back to 2012, I won't go into it other than the response of a lot of my system is slow due to this version.

Just uninstalling IE10, (in which the team used to be right on top of with keeping up with Microsoft product) is not worth the troubleshooting for me.

There's too much that needs to be looked at for me.

 

I just asked if they were interested in the dumps.

Share this post


Link to post

×
×
  • Create New...

Important Information

We use cookies to make your experience of our websites better. By using and further navigating this website you accept this. Detailed information about the use of cookies on this website is available by clicking on more information.