K
Kris Hyde
Hi,
I'm running a fully patched copy of Win2k Pro as Administrator. When I
look in the profile folder, the NTuser.dat.log file is always present.
As I understand it this is a continuity file, which should only be
present when the registry is updating. The date stamp on both the
ntuser.dat and ntuser.dat.log is always at most a minute old,
confirming that the registry is in a constant state of updating, which
is clearly bad. I've exported the HKEY_CURRENT_USER hive into a text
file, repeated the process 1 minute later, and compared them using
WinDiff. There were a few MRU differences, which is fair enough given
that I'd exported a file between the two snap shots of the registry.
But there were some other differences and I was hoping someone would
be able to say whether these were significant:
The were alot of changes to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop
The were alot of changes to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\MISC
HEX CODE\Count
Some Minor Changes to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\NetCache
I'm not sure what these keys do, thus, are any of these changes
unexpected? I've also had some problems with internet slowdown - could
this be related to these keys?
I've tried to isolate which application is changing the NTuser.dat
file by using FileMon.exe, but it doesn't seem to work for that file.
Although, as an aside, it did pick up on the fact that proquota.exe
(the windows program to monitor profile space) scans the entire
profile every 30secs - surely that can't be correct??
Any suggestions would be appreciated.
Kris Hyde
I'm running a fully patched copy of Win2k Pro as Administrator. When I
look in the profile folder, the NTuser.dat.log file is always present.
As I understand it this is a continuity file, which should only be
present when the registry is updating. The date stamp on both the
ntuser.dat and ntuser.dat.log is always at most a minute old,
confirming that the registry is in a constant state of updating, which
is clearly bad. I've exported the HKEY_CURRENT_USER hive into a text
file, repeated the process 1 minute later, and compared them using
WinDiff. There were a few MRU differences, which is fair enough given
that I'd exported a file between the two snap shots of the registry.
But there were some other differences and I was hoping someone would
be able to say whether these were significant:
The were alot of changes to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\Streams\Desktop
The were alot of changes to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\MISC
HEX CODE\Count
Some Minor Changes to:
HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\NetCache
I'm not sure what these keys do, thus, are any of these changes
unexpected? I've also had some problems with internet slowdown - could
this be related to these keys?
I've tried to isolate which application is changing the NTuser.dat
file by using FileMon.exe, but it doesn't seem to work for that file.
Although, as an aside, it did pick up on the fact that proquota.exe
(the windows program to monitor profile space) scans the entire
profile every 30secs - surely that can't be correct??
Any suggestions would be appreciated.
Kris Hyde