Author: ams
Subject: Looong shutdown
Posted: 26 January 2017 at 8:52pm
Hi:
New to sysinternals so sorry if this has been discussed, though I did search. I have a recently upgraded (from Win7) Lenovo M91 now running Win10 Pro 64. On shutdown the screen goes dark quickly but the power and HDD lights stay on for more than 4 minutes. Used procmon and filtered for events longer than 1 second and found a bunch, including 4 of about 60 second each, all involving Norton Antivirus, plus others of about 10 seconds involving explorer. Here are the Norton ones:
4:22:39.7298471 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_22.8.1.14\NCO CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_LAST_WRITE 60.3120569
4:22:39.9059944 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\yvs88d8q.default CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_LAST_WRITE 60.0264777
4:22:39.9337334 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_LAST_WRITE 59.9986876
4:22:39.9844722 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\ProgramData\Norton\{B7B64E4E-97E8-48AA-AF62-F11B5FF9819D}\E24186529D446B3D4190430EFEE81A2A CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_LAST_WRITE 60.0731771
The logfile has been uploaded, but just in case here are some of the explorer ones.
4:22:49.4859863 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp\sysinternals CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 11.5930047
4:22:49.4864661 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp\sysinternals CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 11.5926372
4:22:49.7276168 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 11.3378949
4:22:49.7284070 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 11.3372209
4:22:50.2151931 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Videos CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8599104
4:22:50.2162217 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Videos CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 10.8589697
4:22:50.2171740 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Music CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8554780
4:22:50.2180986 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Music CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 10.8547141
4:22:50.2191023 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Pictures CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8548467
4:22:50.2201504 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Pictures CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 10.8540138
4:22:50.2210316 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Documents CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8493918
Not sure what do do next, so any suggestions are welcome.
Thanks
Subject: Looong shutdown
Posted: 26 January 2017 at 8:52pm
Hi:
New to sysinternals so sorry if this has been discussed, though I did search. I have a recently upgraded (from Win7) Lenovo M91 now running Win10 Pro 64. On shutdown the screen goes dark quickly but the power and HDD lights stay on for more than 4 minutes. Used procmon and filtered for events longer than 1 second and found a bunch, including 4 of about 60 second each, all involving Norton Antivirus, plus others of about 10 seconds involving explorer. Here are the Norton ones:
4:22:39.7298471 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\ProgramData\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NAV_22.8.1.14\NCO CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_LAST_WRITE 60.3120569
4:22:39.9059944 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\yvs88d8q.default CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_LAST_WRITE 60.0264777
4:22:39.9337334 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\AppData\Local\Google\Chrome\User Data\Default CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_LAST_WRITE 59.9986876
4:22:39.9844722 PM NAV.exe 6772 IRP_MJ_DIRECTORY_CONTROL C:\ProgramData\Norton\{B7B64E4E-97E8-48AA-AF62-F11B5FF9819D}\E24186529D446B3D4190430EFEE81A2A CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_LAST_WRITE 60.0731771
The logfile has been uploaded, but just in case here are some of the explorer ones.
4:22:49.4859863 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp\sysinternals CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 11.5930047
4:22:49.4864661 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp\sysinternals CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 11.5926372
4:22:49.7276168 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 11.3378949
4:22:49.7284070 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\temp CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 11.3372209
4:22:50.2151931 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Videos CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8599104
4:22:50.2162217 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Videos CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 10.8589697
4:22:50.2171740 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Music CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8554780
4:22:50.2180986 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Music CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 10.8547141
4:22:50.2191023 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Pictures CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8548467
4:22:50.2201504 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Pictures CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_FILE_NAME, FILE_NOTIFY_CHANGE_ATTRIBUTES, FILE_NOTIFY_CHANGE_LAST_WRITE 10.8540138
4:22:50.2210316 PM Explorer.EXE 9696 IRP_MJ_DIRECTORY_CONTROL C:\Users\admin\Documents CANCELLED Type: NotifyChangeDirectory, Filter: FILE_NOTIFY_CHANGE_DIR_NAME 10.8493918
Not sure what do do next, so any suggestions are welcome.
Thanks