Reply
Honored Contributor
NikK
Posts: 834
Registered: ‎22-07-2013

fshoster32.exe registry leak at every shutdown

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

 

DETAIL -  1 user registry handles leaked from \Registry\User\S-1-5-21-1618111713-3398149932-3299968322-1000_Classes: Process 2080 (\Device\HarddiskVolume2\Program Files\F-Secure\fshoster32.exe) has opened key \REGISTRY\USER\S-1-5-21-1618111713-3398149932-3299968322-1000_CLASSES

 

Info from Microsoft about this error:

"Event ID 1530 is logged as a Warning event. The application that is listed in the event detail is leaving the registry handle open and should be investigated. This behavior is by design"

 

It seems I've got this warning every time I shutdown(IS 2012, 2013, 2014). Is this normal?

Please use plain text.
Honored Contributor
Simon
Posts: 994
Registered: ‎20-08-2011

Re: fshoster32.exe registry leak at every shutdown

Doesn't happen to me.  dunno.gif

Please use plain text.
Honored Contributor
Simon
Posts: 994
Registered: ‎20-08-2011

Re: fshoster32.exe registry leak at every shutdown

I wonder if it could be related to your comment here?  Could the previous installation have left some registry entries behind?  Perhaps it might be worth running something like CCleaner, to check for any registry errors?  Always backup your registry before making any changes, though.

Please use plain text.
Honored Contributor
NikK
Posts: 834
Registered: ‎22-07-2013

Re: fshoster32.exe registry leak at every shutdown

Thanks, but I don't think so. I even ran the uninstallationtool after the normal uninstall. And then just like you said CCleaners registry clean. I just checked again: no errors for any f-secure stuff.

 

I actually run CCleaner registry every month along with many other checks like sfc, sigverif, secunia. Guess I'm the paranoid type :smileywink:

Please use plain text.
Honored Contributor
NikK
Posts: 834
Registered: ‎22-07-2013

Re: fshoster32.exe registry leak at every shutdown

Can some more people confirm if you get this or not?

It's logged in Event Viewer as:

 

Level = WARNING

Source = User Profile Service

EventID = 1530

 

And it appears every time I shutdown.

Please use plain text.
F-Secure
Fendy
Posts: 66
Registered: ‎04-09-2012

Re: fshoster32.exe registry leak at every shutdown

Hi NikK,

 

If you have ran the Uninstallation Tool and issue still persists, could you please open up a Support ticket with us?

http://www.f-secure.com/en/web/home_global/support/contact/request

 

To provide better information to our support, also send FSDIAG with your support request as instructed here:
http://www.f-secure.com/en/web/home_global/support/contact/fsdiag

 

Also I wonder, when do you first notice about this fshoster32.exe issue? And what is the OS?

 

---
Best regards,
Fendy

 

Has somebody helped you? Say thanks by giving kudos. Has your issue been solved? Mark the post using "Accept As Solution" button to let others know.

Please use plain text.
Honored Contributor
NikK
Posts: 834
Registered: ‎22-07-2013

Re: fshoster32.exe registry leak at every shutdown

[ Edited ]

Thanks, maybe I'll do that.

I'm running Win 7, 32-bit.

Have had these warnings for about 6 months. They started when I used an ISP version for IS 2012.

 

After going through the event logs some more I noticed older but similar warnings for fssm32.exe, scvhost.exe and several other exe's. And even a warning of a leak where it says 0 leaks in the details, which seems very strange(see details below).

So it's probably something wrong with my OS or perhaps my user account. However, there seem to be no problem with F-Secure, except for this warning.

 

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. 

DETAIL -

0 user registry handles leaked from \Registry\User\S-1-5-21-1618111713-3398149932-3299968322-1004:

(end of message)

Please use plain text.

Topic Closed

This topic has been closed to new replies due to inactivity. We welcome you to share your thoughts by starting a new post or joining any of our ongoing discussions.
Start a new post.

If relevant, please reference this topic in your post by adding this link:
http://community.f-secure.com/t5/Security/fshoster32-exe-registry-leak-at/td-p/33793