|
#1
|
|||
|
|||
|
Using UPHclean to unload the profile files.
But how do I determine what process/program is doing the deed, and how do I stop it so I do not need to use UPHClean? I found many forum messages similar but no clear resolution. UPHClean event log entry The following handles in user profile hive SANDHILL\Jane (S-1-5-21-1214440339-492894223-839522115-1005) have been remapped because they were preventing the profile from unloading successfully: svchost.exe (736) HKCU (0x318) 0x77e3b4b7 ADVAPI32!<no symbol> 0x77e072b1 ADVAPI32!IsTextUnicode+0x9cb4 0x77dd6b20 ADVAPI32!RegOpenKeyExW+0xa8 0x77dd773e ADVAPI32!RegOpenKeyW+0x2f 0x77ddb2dc ADVAPI32!SaferComputeTokenFromLevel+0x587 0x77ddb296 ADVAPI32!SaferComputeTokenFromLevel+0x541 0x77dd9e9e ADVAPI32!IdentifyCodeAuthzLevelW+0xd9 0x7c819653 kernel32!BasepCheckWinSaferRestrictions+0x17e 0x7c818d2c kernel32!GetNlsSectionName+0x10cb 0x77df7838 ADVAPI32!CreateProcessAsUserW+0xc3 0x76a93acd rpcss!<no symbol> 0x76a93849 rpcss!<no symbol> 0x77e79dc9 RPCRT4!CheckVerificationTrailer+0x75 0x77ef321a RPCRT4!NdrStubCall2+0x215 0x77ef36ee RPCRT4!NdrServerCall2+0x19 0x77e7988c RPCRT4!NdrGetTypeFlags+0x1c9 0x77e797f1 RPCRT4!NdrGetTypeFlags+0x12e 0x77e7971d RPCRT4!NdrGetTypeFlags+0x5a 0x77e7bd0d RPCRT4!NdrConformantArrayFree+0x42e 0x77e7bb6a RPCRT4!NdrConformantArrayFree+0x28b 0x77e76784 RPCRT4!I_RpcBCacheFree+0x14c 0x77e76c22 RPCRT4!I_RpcBCacheFree+0x5ea 0x77e76a3b RPCRT4!I_RpcBCacheFree+0x403 0x77e76c0a RPCRT4!I_RpcBCacheFree+0x5d2 0x7c80b50b kernel32!GetModuleFileNameA+0x1b4 ================================================== J |
![]() |
| Thread Tools | Search this Thread |
| Display Modes | |
|