How to delete .LOG1 and .LOG2 user files when logged in as that user?

Discussion in 'Windows 10' started by OpenSourceGhost, Oct 28, 2022.

  1. OpenSourceGhost

    OpenSourceGhost MDL Member

    Feb 14, 2022
    170
    24
    10
    I need to delete ntuser.dat.log1 and ntuser.dat.log2 files along with all .regtrans and .blf files while logged in to user account to which files I mention belong. Such files store user information and registry backup. So far using another account or mounting Windows system partition offline (from bootable OS on USB) were the only methods I found to delete such files, but I was unable to delete them while logged in as the user to which files I mention belong. How can I delete those files while logged in to user account to which files I mention belong? Running explorer with TrustedInstaller privileges didn't work...
     
  2. abbodi1406

    abbodi1406 MDL KB0000001

    Feb 19, 2011
    17,209
    90,791
    340
    You cannot delete registry hive associated files when it's loaded, and you cannot unload it when the logged User is... using it
     
  3. OpenSourceGhost

    OpenSourceGhost MDL Member

    Feb 14, 2022
    170
    24
    10
    LOG1 and LOG2 files are hive backup files, not hives (NTUSER) themselves. Is there some app that can remove LOG1 and LOG2 fikes during bootup? My OS drive is encrypted with DiskCryptor and I have no way to load another Windows OS on USB drive to manipoular contents of the encrypted drive...
     
  4. Dolmatov

    Dolmatov MDL Addicted

    Aug 16, 2017
    558
    486
    30
    Stop hovering to collapse... Click to collapse... Hover to expand... Click to expand...