Windows License is validated 2 times an hour and Remote Desktop Services notifications received, Are These Events Normal?

I have a cycle of events that I can't find much info on.

First off, my Windows Licence is validated 2 times every hour. Around these  license validations are always registry leaks, a "change in the health of Windows Update", Remote Desktop Services: Session logon succeeded, Remote Desktop Services: Shell start notification received... Anyway more examples are below but I don't know what I am readng so if anyone else has a clue as to if these are normal events or not, please let me know!

Initialization status for service objects.
C:\Windows\system32\sppwinob.dll, msft:spp/windowsfunctionality/agent/7.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/phone/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:rm/algorithm/pkey/2005, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/TaskScheduler/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/1.0, 0x00000000, 0x00000000
C:\Windows\system32\sppobjs.dll, msft:spp/volume/services/kms/licenserenewal/1.0, 0x00000000, 0x00000000

The winlogon notification subscriber <SessionEnv> was unavailable to handle a notification event.

Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards.

 4 user registry handles leaked from \Registry\User\S-1-5-21-606917560-43958898-2020908999-1001:
Process 644 (\Device\HarddiskVolume3\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-606917560-43958898-2020908999-1001
Process 732 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-606917560-43958898-2020908999-1001\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Process 1012 (\Device\HarddiskVolume3\Windows\System32\svchost.exe) has opened key \REGISTRY\USER\S-1-5-21-606917560-43958898-2020908999-1001\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers
Process 644 (\Device\HarddiskVolume3\Windows\System32\winlogon.exe) has opened key \REGISTRY\USER\S-1-5-21-606917560-43958898-2020908999-1001\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers

Performance counters for the WmiApRpl (WmiApRpl) service were removed successfully. The Record Data contains the new values of the system Last Counter and Last Help registry entries.

Performance counters for the WmiApRpl (WmiApRpl) service were loaded successfully. The Record Data in the data section contains the new index values assigned to this service.

The Software Protection service has stopped.

The EventSystem sub system is suppressing duplicate event log entries for a duration of 86400 seconds.  The suppression timeout can be controlled by a REG_DWORD value named SuppressDuplicateDuration under the following registry key: HKLM\Software\Microsoft\EventSystem\EventLog.

How does your Secunia software get updated? It seems to be misreporting on Adobe. It may also be responsible for your firewall question.

Norton -Does it appear here?
C:\Documents and Settings\All Users\Application Data\Norton\symdata.xml

Normally you would use a Norton Removal tool to remove a Norton product. Norton causes strange problems so it would be best to remove it.

Are there any startup entries relating to Norton?

To identify what loads when you boot use Autoruns (freeware from Microsoft).

With Autoruns you can uncheck an item, which disables it from starting, or you can right click an item and then delete it. If you uncheck you can recheck to re-enable the item. It is a much safer approach than editing the Registry and better than using msconfig.
Another useful feature of the programme is that you can right click an item and select Search Online to get information about the item selected.


Stourport-on-Severn, Worcestershire, England
