home hardware prices news articles forums photos user reviews
Go Back   Tech Support Forums - TechIMO.com > PC Hardware and Tech > Technical Support
Ask a Tech Support Question (free)!

What the?!?!

Reply
Get bargains at  »  Dealighted.com
 
Thread Tools Search this Thread
Currently Active Users: 1409
Discussions: 200,507, Posts: 2,374,396, Members: 245,831
Old July 23rd, 2002, 10:12 AM     #31 (permalink)
Junior Member
 
Join Date: Jul 2002
Posts: 3
Ok.. I tried the tracelog.exe -x , but the file kept coming back when I restarted the system. For Those of you interested, here's a registry hack that works...

HKEY_LOCAL_MACHINE/SYSTEM/CurrentControlSet/
Control/WMI/GlobalLogger

Change the Start Key from 1 to 0, this should stop it from running.

Good Luck!
bjfontai is offline   Reply With Quote
Old July 24th, 2002, 02:15 PM     #32 (permalink)
Member
 
alligator_al's Avatar
 
Join Date: Jul 2002
Location: London, England
Posts: 100
I came to the same conclusion as bjfontai. The culprit seems to be the Global Logger Session, and is documented at:

http://msdn.microsoft.com/library/de...about_2lny.asp

and the relevant registry key is:
HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Contro l\WMI
Start REG_DWORD 0 = Off

It doesn't mention anything about colossal file sizes though. I suppose it must be logging the wrong things in some cases (even my keyboard entry was slower when it was logging)

This does the trick better than the temporary 'tracelog -x' fix.
Just out of interest, I also had a 'security' group under WMI in the registry, which looks suspect. I run Norton AV and Sygate personal firewall. I wonder if there's a conflict there?

(always remember to backup your registry first, kids ;-)
alligator_al is offline   Reply With Quote
Old July 24th, 2002, 03:16 PM     #33 (permalink)
Ultimate Member
 
Join Date: Oct 2001
Posts: 3,235
So essentially what it's supposed to do is allow you to log everything that happens on your comp huh?
EndobioticChaos is offline   Reply With Quote
Old July 24th, 2002, 03:38 PM     #34 (permalink)
Leader of the Crab People
 
Redwolf's Avatar
 
Join Date: Oct 2001
Location: NCSU
Posts: 4,381
Send a message via ICQ to Redwolf Send a message via AIM to Redwolf Send a message via Yahoo to Redwolf
Spyware perhaps?

Just can't see a 2GBfile going over my cable modem though, must have a secret Microsoft burst transmitter in all PIVs
Redwolf is offline   Reply With Quote
Old July 24th, 2002, 06:40 PM     #35 (permalink)
Member
 
alligator_al's Avatar
 
Join Date: Jul 2002
Location: London, England
Posts: 100
Yes it's a logging tool. By default it saves to \system32\logfiles\wmi\trace.log and in my case it was the NT Kernel Logger that was running. I haven't been able to check what it was logging yet, and I don't know how it was started (I didn't even have the necessary software).

Since then, I have also turned off windows error reporting (which, although pointless and irritating, could surely not have generated such huge logs?)

Another thing that occured to me is that I'm running XP home PREINSTALLED on a Dell 4100 laptop. Could this be a proprietary performance log to assist their support people? Is anyone else with this problem running a preinstall of XP?

I just can't understand why this isn't all over the web. There must be some pretty large HDDs out there if people don't miss the odd gigabyte or three!!!
alligator_al is offline   Reply With Quote
Old July 24th, 2002, 07:44 PM     #36 (permalink)
Member
 
++Whiz++'s Avatar
 
Join Date: Jan 2002
Location: Greenfield,Indiana
Posts: 62
Send a message via AIM to ++Whiz++ Send a message via Yahoo to ++Whiz++
sounds like a virus to me but i have WinXP Pro and i don't even have that Logfiles folder in my system32 directory my system is a custom build also no proprietary stuff in it.
__________________
www.utgmc.com
Unreal Tournament Clans
++Whiz++ is offline   Reply With Quote
Old July 24th, 2002, 08:09 PM     #37 (permalink)
mickwish
 
Posts: n/a
I don't understand this, but this link at M$ talks about this logger:

http://msdn.microsoft.com/library/de...h/wmi_3t7r.asp

Anyone explain what it means??

Cheers
Mick
  Reply With Quote
Old July 24th, 2002, 09:06 PM     #38 (permalink)
Not Really a Member
 
Join Date: Oct 2001
Posts: 25,215
WMI = Windows Management Instrumentation
Allows you to quickly and easily access Windows system information through any scripting language or normal language.
Why its making a permanent log I dont know
I didn't read anything in that specified a reason to keep a continuous log in a file unless somebody wanted to write a script looking for a particular event and see how many time it comes up... probably most useful for debugging ... why its in a production system I don't know.
__________________
Helicopters don't fly; they vibrate so much and make so much noise that the earth rejects them.
vass0922 is offline   Reply With Quote
Old July 24th, 2002, 09:23 PM     #39 (permalink)
Ultimate Member
 
Emc2's Avatar
 
Join Date: Oct 2001
Location: Savannah, GA
Posts: 1,752
Send a message via AIM to Emc2
Perhaps someone who's still having the problem could open it up while it's still small and tell us what's in there?
__________________
My R&D machine:

AMD 2100+ @ 2700+
Asus A7N8X-E
1GB Kingston PC333
2xWD 74GB Raptor's in SATA RAID
ATI 9700Pro w/ Zalman Heat Pipe
Emc2 is offline   Reply With Quote
Old July 26th, 2002, 01:51 PM     #40 (permalink)
Member
 
alligator_al's Avatar
 
Join Date: Jul 2002
Location: London, England
Posts: 100
I just thought of a potential culprit.

Has anyone with these symptoms used microsoft's 'bootvis.exe' at any time? It's a tool designed to optimise boot times and uses logging to trace drivers, etc. It has the option to save the log as a .bin (in my case 28meg), but it must keep it somewhere first.

I used it a few months ago, and my suspicions were roused when i saw this new note on their website:

Note: This version of BootVis.exe is compatible with final release of Windows XP (build 2600) and resolves a compatibility issue when using third-party IDE drivers.

I have intel IDE drivers (does that count as third-party? ) Suppose it didn't stop logging?
BTW it's here if anyone's interested (it did shave a few valuable seconds off my boot time )
alligator_al is offline   Reply With Quote
Reply
Thread Tools Search this Thread
Search this Thread:

Advanced Search


Currently Active Users Viewing This Thread: 1 (0 members and 1 guests)
 
Most Active Discussions
Is It Just Me? (1635)
FT HOOD attack: 7 killed 12 injured (66)
Review My Build (5)
HELP!!! What do you think of this s.. (16)
Looking for a graphic card that wil.. (30)
Assosiations (21496)
My 1st pc build (40)
Aero in Vista (7)
PC Modern Warfare 2: it's much wors.. (12)
core i7 extreme 975, nvidia 9400gt (9)
How to Ship a PC (16)
Building my first computer (13)
slaving laptop drive (7)
[F@H SPAM 11/1/09]New month . . . n.. (33)
Recent Discussions
sell cvv us-uk-eu-au...very good. who.. (0)
how to convert mod to wmv/avi/mp4/mov.. (0)
FAT32 to NTFS file system in Win2kpro (3)
Motherboards and my curse... (25)
Review My Build (5)
HELP!!! What do you think of this sys.. (16)
New Processor, Monitor will not turn .. (2)
2009 Build (4)
Internet very slow since updating AVG.. (7)
My 1st pc build (40)
Freezing During Music/Movies (1)
Windows Experience Index is screwed u.. (2)
ext. sound card laptop to stereo syst.. (2)
Remote Desktop via SSH and error mess.. (2)
Help and Support disappeared from my .. (0)
[F@H SPAM 11/1/09]New month . . . new.. (33)
Basic applications needed for "r.. (1)
core i7 extreme 975, nvidia 9400gt (9)
hard drive problem (2)
Win7 TrustedInstaller Permissions (2)
Speed up Win 7 boot time a bit (1)
Hard Drive test program (2)
wireless westell versalink model 327w (1)
New build 10 second reboot cycle! Won.. (3)
New Linksys Routers (2)


All times are GMT -4. The time now is 05:07 AM.
TechIMO Copyright 2008 All Enthusiast, Inc.



1 2 3 4 5 6 7 8 9 10 11 12 13 14 15 16 17 18 19 20 21 22 23 24 25 26 27 28