I'm having a problem where some users reboot at the end of the day, and
the next day when they try logging in they get logged in with their temp
profile as something has a lock on their own ntuser.dat. If they reboot
again, sometimes a couple of times, then things start working correctly.
I've told the AV to exclude C:\Documents and Settings but that hasn't
helped. I know there are some sysinternals tools I can use to see what
currently has a lock on a file, but is there any way of logging this
access so that I can log everything that happens during the boot and
login process?

