Solved

Windows 7 C:\Logs Directory and "Bitree_obtain_mutex"

Posted on 2013-05-30
10
1,110 Views
Last Modified: 2013-06-19
I have noticed on my Windows 7 laptop with an SSD drive that i have a directory called C:\Logs. Inside is 100's of files that consume 25 GB of my 100 GB drive. They all start with Tree_xxxxx.log. I have never seen this directory on Windows XP. The files range in size from 1 kb to 400 MB. They all contain variations of ..

Oct 02 08:55:32.511 thread: 10036 bitree_obtain_mutex() waiting for mutex

I have searched Microsoft site for information but found nothing. I assume they are safe to delete but not sure where they are coming from and why they are being created and if there is any way to stop creating these files.

Here is sample
Tree-264.log
0
Comment
Question by:mjburgard
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 5
  • 4
10 Comments
 
LVL 19

Accepted Solution

by:
strivoli earned 500 total points
ID: 39209972
If the files are recent there could be an always running process that writes these log files. Auditing will help you understand what is writing these logs. You could also consider Process Monitor in order to understand what is writing these logs. The main difference between the two approaches (auditing and Process Monitor) is that the 1st allows you to inspect historical data (depending on the max Windows Security Log size) while the 2nd is mostly Real-Time.

Once you discovered which process writes these logs, consider stopping it or modify it's behavior in order to avoid these log files.
0
 
LVL 19

Expert Comment

by:strivoli
ID: 39209974
Forgot to give you the Process Monitor link.
0
 
LVL 1

Author Comment

by:mjburgard
ID: 39210948
Ok,

I am running Process Monitor and finding out that 5 or 6 programs I run are writing a log file to C:\Logs. This includes CHrome, outlook, SearchProtocol, explorer, and a few other specific programs. Best that I can determine each program is making some sort of regular call or attempt to update itself. For example, one program checks every minute to see the status of my employees. Another connects my e-mail to my CRM program and links e-mails. However, some of these programs run on other computers and they don't create the log files so that is interesting.  I am doing more checking. I deleted all the logs and they start up again immediately.
0
Salesforce Has Never Been Easier

Improve and reinforce salesforce training & adoption using WalkMe's digital adoption platform. Start saving on costly employee training by creating fast intuitive Walk-Thrus for Salesforce. Claim your Free Account Now

 
LVL 19

Expert Comment

by:strivoli
ID: 39211004
How is the TEMP/TMP System and/or User Variable set to? If it is set to c:\logs that explains why so many programs access the folder.
0
 
LVL 1

Author Comment

by:mjburgard
ID: 39211939
Ok,

Temp and Tmp are set to C:\WIndows|TEMP as they should be. When I turn off Chrome or other programs, the Proc Monitor shows these programs no longer write the logs. Explorer appears to write them all the time. Over 50 MB of files were created in less than 10 minutes. This means about 250 MB an hour. Appears to a natural limit of around 25 GB before they seem to self delete - although that is not confirmed at this time. I noticed no files earlier than 22 April on my system. The quest continues. Don't really know where to go. The contents of the logs don't show up in a google search - if I pick pieces of the log and try to search on them.
0
 
LVL 19

Expert Comment

by:strivoli
ID: 39214346
Is your system virus/malware free?
0
 
LVL 19

Expert Comment

by:strivoli
ID: 39228900
Kindly help us keep EE clean. If you need more help, please ask. If I/we didn't help, please delete the question. Thank you.
0
 
LVL 1

Author Comment

by:mjburgard
ID: 39260275
I use SAV and MWB and both run all the time and say I am virus free. I will likely just accept your answer and move on. No one seems to have any info on these log files. I will look into it some more.
0
 
LVL 30

Expert Comment

by:serialband
ID: 39260472
It seems that the mutex may be part of the system threading used by .Net 4.

http://msdn.microsoft.com/en-us/library/system.threading.mutex.aspx


Do you have some application that's opening the mutex and not closing it?  What did you install on April 22?
0
 
LVL 1

Author Comment

by:mjburgard
ID: 39260939
answer is I have a program that will write logs in the C:\logs file if it exists (Which Windows 7 creates). If I delete C:\logs, it will not create the logs. Go figure.
0

Featured Post

Salesforce Made Easy to Use

On-screen guidance at the moment of need enables you & your employees to focus on the core, you can now boost your adoption rates swiftly and simply with one easy tool.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Article by: Lee
Windows 7 Ultimate and Enterprise (and 2008 R2) introduced a new feature you may not be aware of - Boot from VHD.   Boot from VHD (or what Microsoft refers to asNative Boot allows you to install Windows to a VHD (Virtual Hard Disk) file that is t…
If you get continual lockouts after changing your Active Directory password, there are several possible reasons.  Two of the most common are using other devices to access your email and stored passwords in the credential manager of windows.
This Micro Tutorial will give you basic overview of the control panel section on Windows 7. It will depth in Network and Internet, Hardware and Sound, etc. This will be demonstrated using Windows 7 operating system.
This Micro Tutorial will give you a basic overview of Windows DVD Burner through its features and interface. This will be demonstrated using Windows 7 operating system.
Suggested Courses

627 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question