Video Screencast Help
Search Video Help Close Back
to help
Not able to make it to Vision this year? Get a sampling in the Best of Vision on Demand group.

SEP on 2003 Terminal Services causing ntuser.dat problems

Updated: 28 Jul 2010 | 7 comments
tcraighenry's picture
0 0 Votes
Login to vote

Hi all,

We're having some problems with SEP locking each user's NTUSER.DAT file in Terminal Services. End result is, without rebooting the server, the user's cannot login the next day because the registry hive is still "open."  We've installed the User Profile Hive Cleanup Service from Microsoft and added the executable to the exceptions list. (We still get the tamper protection warnings though.) However, we're still stuck on nightly reboots. Anyone fixed this?

Comments

RAJP's picture
22
Jan
2010
0 Votes 0
Login to vote

Did you install it follwing

Did you install it follwing the directions in Symantec's Terminal Server and Citrix Best Practices White Paper?

What version of SEP are you on? From that somewhat old doc, you should be on at least MR3.

Ray

tcraighenry's picture
22
Jan
2010
0 Votes 0
Login to vote

It was installed in console

It was installed in console mode with the local administrator account as an unmanaged client. We also had a fair few problems wth SEP locking up the print spooler folder initially as well.

Version is SEP 11.04

tcraighenry's picture
22
Jan
2010
0 Votes 0
Login to vote

Sorry, MR4. Got cut off. I

Sorry, MR4. Got cut off. I did check the forums as well and the accepted solution is to add NTUSER.DAT to the exceptions list? That seems like a terrible idea.

According to this, MR4-MP2 did not actually correct this problem:
https://www-secure.symantec.com/connect/forums/end...

tcraighenry's picture
22
Jan
2010
0 Votes 0
Login to vote

And adding the wildcard

And adding the wildcard %userprofile%\ntuser.dat to the exceptions gives me some bizarre message about the file being in use.

tcraighenry's picture
22
Jan
2010
0 Votes 0
Login to vote

Vikram, I did mention this

Vikram, I did mention this above so your post is not new information. That second link is the one I already posted. And the one on top is almost identical information.

But I don't know that it's crossed anyone's mind that NTUSER.DAT is HKCU? So by excluding it, does that also exclude SEP from detecting registry tampering for that user?

AravindKM's picture
23
Jan
2010
0 Votes 0
Login to vote

In the server first you

In the server first you confirm that the exclusion is got affected. Below doc can help you in this

How to Verify if an Endpoint Client has
Automatically Excluded an Application or Directory

 

Please don't forget to mark your thread solved with whatever answer helped you : ) Thanks & Regards Aravind