Windows 8 and 8.1 Forums


System locks up, hard reboot required after 30-40 sec from startup

  1. #11


    Hi Dave,

    I followed the procedure for checking the event log and it was already set up as you described. I pressed the OK button and tried the Shutdown again and still no log. I cleared the event log as you suggested and then it starting working. I performed two shutdown procedures (with Fast Start up enabled) and logged the results (attached).

    I don't have to Win8 disk with me so I'll do the ScanNow procedure tomorrow evening and send you the results.

    Thanks for sticking with this!

    Ken

      My System SpecsSystem Spec

  2. #12


    Hi Dave,

    I forgot to mention that I disabled all of the tart up programs using task manager and used msconfig to disable all of the non Microsoft services. I did this a few weeks ago and again 2 days ago. I still had the lock up problem with both start up and services disabled.

    Ken
      My System SpecsSystem Spec

  3. #13


    Hi Dave,

    I ran the ScanNow program (option 2) and it was clean.

    Ken
      My System SpecsSystem Spec

  4. #14


    Tropical Island Pair a Dice
    Posts : 3,030
    Windows 8.1 Pro x64/ Windows 7 Ult x64


    All the hardware seems to be good, OS passed the SFC scan.

    This is what happens when you shutdown normally.

    Event[39916]:
    Log Name: Application
    Source: Microsoft-Windows-User Profiles Service
    Date: 2012-09-13T20:40:40.987
    Event ID: 1530
    Task: N/A
    Level: Warning
    Opcode: Info
    Keyword: N/A
    User: S-1-5-18
    User Name: NT AUTHORITY\SYSTEM
    Computer: Ken-Acer
    Description:
    Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

    Code:
    DETAIL - 
     32 user registry handles leaked from \Registry\User\S-1-5-21-2171769479-1788307511-2445753593-1001:
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\TrustedPeople
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\Disallowed
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\Disallowed
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Policies\Microsoft\SystemCertificates
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\trust
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\trust
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
    Process 960 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\Windows\CurrentVersion\Uninstall
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\Root
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\Root
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\CA
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\CA
    Process 608 (\Device\HarddiskVolume2\Windows\System32\lsass.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
    Process 980 (\Device\HarddiskVolume2\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-2171769479-1788307511-2445753593-1001\Software\Microsoft\SystemCertificates\SmartCardRoot
    These are what's causing your lockups after normal shutdowns.
    These are getting corrupted before they are saved to be used to start up the system.

    (\Device\HarddiskVolume2\Windows\System32\lsass.exe)
    "The process lsass.exe is the Local Security Authority Subsystem Service by Microsoft, Inc. It is responsible for the enforcement of security policies within Microsoft's Operating Systems. This process checks whether a users supplied identification is valid or not whenever he or she tries to access the computer system.
    With the execution of the file lsass.exe, the system acquires security by preventing the access of unwanted users to any personal information. The process lsass.exe also handles the password modifications done by the user."

    (\Device\HarddiskVolume2\Windows\System32\svchost.exe)
    "Svchost.exe is a Windows system file. It is the Generic Host Process for Win32 Services. Svchost.exe manages 32-bit DLLs as well as other services. Microsoft runs a lot of software functionality from DLL (dynamic link library) interface. On startup, svchost.exe checks the services in the Registry and makes a list of services it has to load."

    Return from sleep, which is what this type of shutdown is, has always been very difficult to diagnose, this is a known Windows issue for years.
    Only way I know to fix this is to re-install the OS, clean install is recommended.
    Last edited by Dave76; 15 Sep 2012 at 12:09.
      My System SpecsSystem Spec

  5. #15


    Hi Dave,

    I was afraid that was going to be the ultimate answer but I really do appreciate your effort in trying to avoid it. I also learned a great deal from you. I'll probably run a few more days with Fast Start Up disabled until I can work up enough enthusiasm to do a clean install.

    Thank you VERY much for working with me on this!

    Ken
      My System SpecsSystem Spec

  6. #16


    Tropical Island Pair a Dice
    Posts : 3,030
    Windows 8.1 Pro x64/ Windows 7 Ult x64


    Your welcome.

    Glad to help, good to check everything you can but, sometimes it's inevitable.

    Let me know if you have any issues or questions.
      My System SpecsSystem Spec

Page 2 of 2 FirstFirst 12
System locks up, hard reboot required after 30-40 sec from startup
Related Threads
Hi. Recently I am running Windows 8 Enterprise 64-bit, 4 MB ram, Motherboard : MSI H61MU-E35 (MS-7680) (SOCKET 0) 32 C, CPU : Intel Core i5 2400 @ 3.10GHz 51 C Sandy Bridge 32nm Technology, Storage : 2 TB Western Digital WDC WD20EARS-00MVWB0 ATA Device (SATA) (full specification is on...
Hello everyone. I'm at my wit's end here with a computer I assembled around Christmas time last year that has had a large amount of BSODs, crashes, freezes, reboots without BSODs and the like. Though I have apparently managed to fend off a lot of the issues (including IRQL_NOT_LESS_OR_EQUAL, and...
Startup Password required in General Support
my father in law uses his new dell inspiron 15r running on windows 8 when someone phone our home from microsoft and ask him to follow instructions and he did. at the end of there conversations he was asked to pay 49 euros to activate the computer. i tried to reformat but it doesnt allow me to do...
Hello forum, I have a windows 8 laptop and a linux desktop, both connected to the same screen using hdmi - since my screen has only 1 HDMI input, I use an HDMI splitter. Every time I move from the linux to the windows 8 laptop (using a HDMI mini remote control), I get a message from windows...
Hello, I am running two 7950s in crossfire on my computer. Anytime I launch a game, my computer just locks up and this hardcore buzzing sound playing right when it crashes, the sound continues while the computer is frozen. This problem has happened in both Battlefield 3 and Splinter Cell...
Recently, something odd has been happening. On initial start up of my PC, the network fails. It will show the yellow exclamation point and show as limited. When this happens, I cant even ping my directly connected router. It shows as PING: Transmit failed. General Failure. So far since this...
My laptop was frozen and I couldn't get to my start menu to restart it so I did a hard reboot. Now when I try to start the blue windows icon comes up for a few seconds with the rotating dots then the screen goes black. Eventually I hear the windows start up sound, but nothing on the screen.
Eight Forums Android App Eight Forums IOS App Follow us on Facebook