Windows 2000 Restarting after being left idle

A client computer here at work continues to restart when it is left alone for a few minutes.. I have checked the power options and everything there is set to never.   He said it only happens when he goes to lunch, or leave the computer idle  for a few minutes and then he comes back and the login screen is there and everything needs to load up again. Also, I made sure hibernation was set to off.. Should I run HijackThis on the client computer?? What else can i check to try and sort this problem out?? Thanks in advance!!
PaigePeopleAsked:
Who is Participating?

Improve company productivity with a Business Account.Sign Up

x
 
SheharyaarSaahilConnect With a Mentor Commented:
orrrr..... is it some kind of Group Policy running on his system,,,,, something like discussed here >> http://www.experts-exchange.com/Operating_Systems/Win2000/Q_20860048.html
0
 
SheharyaarSaahilCommented:
Hello PaigePeople =)

Well are u sure its ACTUALLY restarting,,,, and not just giving the LoginBox after a certain period of time, like after the mniutes u have set for screen saver,,,, it starts screen saver, and on resume its gives the password or login box ??
0
 
PaigePeopleAuthor Commented:
I am pretty sure I looked and that option was not checked (On resume password protect)    He goes to lunch in 30 mins to an hr.. I will hop on his machine and double check to make sure that is not the case... I would feel pretty dumb if that is what it is.. Well more lazy then dumb... Ok i will let you know in a few...
0
Free Tool: SSL Checker

Scans your site and returns information about your SSL implementation and certificate. Helpful for debugging and validating your SSL configuration.

One of a set of tools we are providing to everyone as a way of saying thank you for being a part of the community.

 
PaigePeopleAuthor Commented:
OK, I did just check his computer, On resume was checked,   however, he said usually when he goes to lunch, he comes back and enters in his user name/ password    it has to reboot everything.. Any windows he left open are completely closed (all programs closed)   So, if it was the screensaver on resume passwr4od protection, then those programs would not close.  Any other suggestions?
0
 
SheharyaarSaahilCommented:
ok so when u hit the POWER button in ScreenSaver section, is the ALWAYS ON scheme selected ??
and in Advanced setion, the Ask me for Password when resumes from Standby shudn't be chekced !!!!!

Im sure its the settings of something like this,,,,coz his system is not restarting but just logging him off when its idle for some time,,, and as he gets log off, he needs to login back and thus the all programs starts again from scratch :)
0
 
PaigePeopleAuthor Commented:
OK, i went to the power scheme and ALWAYS ON was not selected, but, everything was set to never.. I changed it to ALWAYS ON and kept everything at never (monitor NEVER shuts off, hard disk NEVER shuts off, Etc....)  

"""Advanced setion, the Ask me for Password when resumes from Standby shudn't be chekced !!!!!"""  

THAT WAS CHECKED, I unchecked it there as well... I am gonna go get lunch and when i come back, hopefully his computer is still on and you get the points!!! Thanks again... you rule!!!  
0
 
SheharyaarSaahilCommented:
ok fingers crossed :)
0
 
PaigePeopleAuthor Commented:
darn, his programs still closed after i changed all those settings... I will make sure the settings were applied..(Pretty Positive that they were) He is pretty busy today, so I told him tomorrow I would look at it....  I will look over the group policy link as well... Any other ideas?
0
 
SheharyaarSaahilCommented:
hmmmmmmm i was afraid of that,,,,, but never mind u can still check the group policy settings, and if by chance its also not applicable, then we will trace out some background applications and will trace out the one which is initiating this behaviour :-?
0
 
PaigePeopleAuthor Commented:
OK, it was not the group policy settings either... I will run HiJack This and post the log?? IS that what you are thinking my next step should be?? I will run that on his comouter in about 2 hrs when he goes to lunch... If you want me to run anything else or check anything else, please let me know... Thanks...
0
 
SheharyaarSaahilCommented:
yes just post the LOG file,,,, may be there is a bakcground application that is causing this behaviour :-?
0
 
PaigePeopleAuthor Commented:
Here comes the Log, Work your Magic!!! I hope this works...


Logfile of HijackThis v1.98.0
Scan saved at 12:19:47 PM, on 8/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WFXSVC.EXE
C:\dmi\win32\bin\Win32sl.exe
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\faxsvc.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\PROGRA~1\IBM\CLIENT~1\Emulator\pcsws.exe
C:\PROGRA~1\IBM\CLIENT~1\Emulator\PCSCM.EXE
C:\PROGRA~1\IBM\CLIENT~1\cwblmsrv.exe
C:\Program Files\IBM\Client Access\Emulator\pcsws.exe
C:\Program Files\IBM\Client Access\Emulator\pcsws.exe
C:\Program Files\Symantec\ACT\ACT.EXE
C:\Program Files\AIM95\aim.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINNT\msagent\AgentSvr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\SYSTEM32\RUNDLL32.EXE
C:\WINNT\system32\ssstars.scr
C:\Documents and Settings\jayf\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\CwbSvStr.Exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1224060a756e40270315/netzip/RdxIE601.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pecd01.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D95CABA-868E-4497-8699-1CD4218D7E2F}: NameServer = 10.3.1.33,207.99.0.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pecd01.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = pecd01.com
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll

0
 
PaigePeopleAuthor Commented:
Ok, I had someone come check out the group policies, apparently they missed the Auologoff was enabled.. I disabled that, But now that i posted his hijack this log, maybe you see some stuff in there that i should get rid of too...
0
 
SheharyaarSaahilCommented:
hmmmmm nothing bad, but what is this entry >> C:\WINNT\system32\ssstars.scr
i mean it shud be a screen saver.... but suaually screen savers dont run in backgrounds..... so why it is, i mean have u  installed it or..... ??
0
 
PaigePeopleAuthor Commented:
I probably should havemade sure his computer does not log off after inactivity... I accepted your answer banking on that being the issue.. It was enabled, so It just got to be the issue.. I will let you know how it goes regardless... LEt me know of any suspicious stuff in his hijackthis log....
0
 
PaigePeopleAuthor Commented:
I have no idea what that program is.... Should i virus check that file??? I will google it too see if it comes up as anything.... He is out to lunch now   so i have no idea what he has installed...
0
 
PaigePeopleAuthor Commented:
NAME "Starfield"      VALUE "C:\WINNT\System32\ssstars.scr"


I guess its the starfield screensaver???

http://www.winnetmag.com/Files/3799/Listing_02.txt
0
 
PaigePeopleAuthor Commented:
That is the screensaver he is using... So everything looks ok??? I will let you know in an hr or so how everything worked out.... Thanks again.. You Rock...
0
 
SheharyaarSaahilCommented:
ok then that's ok :)
u can check for the problem and post back the results..... fingers crossed again ;-)
0
 
PaigePeopleAuthor Commented:
No good.... Still brought him to login screen, entered in usr/pwd  and loaded up all his programs that run during startup.. When I left for lunch everything was still there... Maybe I need to watch this happen as it happens.. I almost don't want to believe him, haha..  Ack, that should have worked damn it!!! Now i don't even know what to do next... :/
0
 
SheharyaarSaahilCommented:
that's bad indeed =(

its shud be related to group policy.... as it was enabled.... did u ask him if his Administrator put this settings and which cannot be disabled by normal users :-?
0
Question has a verified solution.

Are you are experiencing a similar issue? Get a personalized answer when you ask a related question.

Have a better answer? Share it in a comment.

All Courses

From novice to tech pro — start learning today.