Using FBWF instead of EWF

  • Thread starter Thread starter Godzilla
  • Start date Start date
G

Godzilla

Hello,

I have been using EWF for some time, and after several months of
usage, the RAM usage is slowly but surely being eaten away, requiring
a reboot of the system for it to resume its normal operation. After
running filemon, I found the OS log system is still writing to C$
hidden files and also to C:\Windows\System32\config\*log files...

This lead me to think of using FBWF in place of EWF. Can anyone tell
me what files I should include for FBWF write through? The list below
is some I think it should be included:

C$ (all hidden log files ???)
C:\Windows\System32\config\default.LOG
C:\Windows\System32\config\SAM.LOG
C:\Windows\System32\config\SECURITY.LOG
C:\Windows\System32\config\software.LOG
C:\Windows\System32\config\system.LOG
C:\Windows\System32\config\TempKey.LOG
C:\Windows\System32\config\userdiff.LOG
IIS: HTTP and FTP log files redirected to unprotected drive
All event logs redirected to unprotected drive
All Internet Temporary files redirected to unprotected drive
User specific temp files have been redirected to unprotected drive

I need further advise as I do not know whether the list above is the
correct way of configuring FBWF so that the RAM usage will not creep.
 
Hello,

I have been using EWF for some time, and after several months of
usage, the RAM usage is slowly but surely being eaten away, requiring
a reboot of the system for it to resume its normal operation. After
running filemon, I found the OS log system is still writing to C$
hidden files and also to C:\Windows\System32\config\*log files...

This lead me to think of using FBWF in place of EWF. Can anyone tell
me what files I should include for FBWF write through? The list below
is some I think it should be included:

C$ (all hidden log files ???)
C:\Windows\System32\config\default.LOG
C:\Windows\System32\config\SAM.LOG
C:\Windows\System32\config\SECURITY.LOG
C:\Windows\System32\config\software.LOG
C:\Windows\System32\config\system.LOG
C:\Windows\System32\config\TempKey.LOG
C:\Windows\System32\config\userdiff.LOG
IIS: HTTP and FTP log files redirected to unprotected drive
All event logs redirected to unprotected drive
All Internet Temporary files redirected to unprotected drive
User specific temp files have been redirected to unprotected drive

I need further advise as I do not know whether the list above is the
correct way of configuring FBWF so that the RAM usage will not creep.

Well, found an article about adding common files to the write-through
filter.

URL: http://blogs.msdn.com/embedded/archive/2007/03/08/common-fbwf-write-through-directories.aspx
 
Back
Top