📎 AI Summary:
The original poster attempts to access the `ntuser.dat.log` file within the NETWORK services folder, even in Safe Mode as Administrator, but is denied access. Despite troubleshooting via Task Manager and Safe Mode with minimal services, the user defaults to ending processes involving `SVCHOST.exe`, which leads to automatic Windows shutdowns. Ultimately, the user successfully accesses the file by booting from a system rescue disk and operating through command-line mode.

tsunami

Member
Joined
Jan 24, 2015
Messages
4
Thread Author #1
I am attempting to accessntuser.dat.log in NETWORK services folder even in SAFE MODE but get denied. I am logged on as ADMINISTRATOR. I would assume this would be the case as well if I were logged on as any other USER?

I looked in the TASK MGR to try & identify what process is blocking this, but I am at a loss. Anyone know what hoops I need to jump through to be able to view this file?
 

tsunami

Member
Joined
Jan 24, 2015
Messages
4
Thread Author #2
I tried to boot in SAFE mode with minimal services running & still cannot access ntuser.dat. I then booted back up in NORMAL mode and selectively ended processes associated with NETWORK services & it appears that SVCHOST.exe is using ntuser.dat. Terminating that process then causes WINDOWS to automatically shutdown within 60 seconds.
 

tsunami

Member
Joined
Jan 24, 2015
Messages
4
Thread Author #3
I was eventually able to access the file via booting up on a system rescue disk and operate via cmd mode.
 

Solution