svchost.exe error while shutting down the pc

Hi i have  windows 8 64 bit , while shutting down the pc i am getting svchost.exe  error
please advice
sanjeevkmrsAsked:
Who is Participating?
 
McKnifeConnect With a Mentor Commented:
My approach would be similar to gurutc's: open msconfig and disable all non-Microsoft services. Then open task manager and disable all startup items and reboot to see if any of those softwares caused it. Also try a different user profile (new user).
0
 
xeroxzeroxCommented:
check this error in event viewer for why it's happen
press windows key + W then type event viewer

check error and reply us..
0
 
gurutcCommented:
Yes, do the logs show anything?  How about booting in safe mode and then shutting down.  Does that cause the error?

- gurutc
0
Get your problem seen by more experts

Be seen. Boost your question’s priority for more expert views and faster solutions

 
sanjeevkmrsAuthor Commented:
there are lot of events how can i check this one ?
please advice
0
 
gurutcCommented:
I'd note the time when I get the error, then I'd look in the Application and System logs at that time to see if there's any errors showing at that time.

- gurutc
0
 
sanjeevkmrsAuthor Commented:
please see the below


Log Name:      Application
Source:        Microsoft-Windows-User Profiles Service
Date:          27/01/2014 17:33:05
Event ID:      1530
Task Category: None
Level:         Warning
Keywords:      
User:          SYSTEM
Computer:      Home-PC
Description:
Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.  

 DETAIL -
 32 user registry handles leaked from \Registry\User\S-1-5-21-2956737109-2472759578-1202411323-1002:
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1156 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1156 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\CA
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\CA
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\trust
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\trust
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\MY
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Disallowed
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Disallowed
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\TrustedPeople
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Root
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Root
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall

Event Xml:
<Event xmlns="http://schemas.microsoft.com/win/2004/08/events/event">
  <System>
    <Provider Name="Microsoft-Windows-User Profiles Service" Guid="{89B1E9F0-5AFF-44A6-9B44-0A07A7CE5845}" />
    <EventID>1530</EventID>
    <Version>0</Version>
    <Level>3</Level>
    <Task>0</Task>
    <Opcode>0</Opcode>
    <Keywords>0x8000000000000000</Keywords>
    <TimeCreated SystemTime="2014-01-27T13:33:05.251028900Z" />
    <EventRecordID>7951</EventRecordID>
    <Correlation />
    <Execution ProcessID="1156" ThreadID="4572" />
    <Channel>Application</Channel>
    <Computer>Home-PC</Computer>
    <Security UserID="S-1-5-18" />
  </System>
  <EventData Name="EVENT_HIVE_LEAK">
    <Data Name="Detail">32 user registry handles leaked from \Registry\User\S-1-5-21-2956737109-2472759578-1202411323-1002:
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1156 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002
Process 1156 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\CA
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\CA
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\trust
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\trust
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\MY
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\SmartCardRoot
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Policies\Microsoft\SystemCertificates
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Disallowed
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Disallowed
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\TrustedPeople
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\TrustedPeople
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Root
Process 448 (\Device\HarddiskVolume4\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\SystemCertificates\Root
Process 1264 (\Device\HarddiskVolume4\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2956737109-2472759578-1202411323-1002\Software\Microsoft\Windows\CurrentVersion\Uninstall
</Data>
  </EventData>
</Event>
0
 
gurutcCommented:
Is this a Domain-based PC?  Are there Group Policies being applied on shutdown?  

- gurutc
0
 
gurutcCommented:
This can also be caused by a redirected printer or the Windows Defender service.  Do you have any networked printers configured on this box?  Also, if it's running, turn off and disable the Windows Defender service and see if that fixes things.

- gurutc
0
 
sanjeevkmrsAuthor Commented:
Hi this is a standalone laptop not in domain
0
 
sanjeevkmrsAuthor Commented:
tried all above mentioned points but still getting same SVC HOST error
please advice
0
 
gurutcCommented:
Also have you turned off Windows Update?

- gurutc
0
 
McKnifeCommented:
Did you reboot twice? Because on first reboot, the changes that msconfig required (and those of task manager neither) are NOT yet applied.
0
 
SandyWalveCommented:
Can you get the error screenshot which you get while you shutdown your PC? You may need to use camera of your phone or something else to click it.
0
 
sanjeevkmrsAuthor Commented:
still while restarting it shows svhost.exe pop up error
please advice
0
 
SandyWalveCommented:
I need the screenshot to see if any error code is given in that like 0x0000xxx0 sort of
0
 
sanjeevkmrsAuthor Commented:
thanks
0
 
McKnifeCommented:
Was it solved? If yes, how?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.