Solved

Windows 2000 Restarting after being left idle

Posted on 2004-08-24
21
409 Views
Last Modified: 2010-04-12
A client computer here at work continues to restart when it is left alone for a few minutes.. I have checked the power options and everything there is set to never.   He said it only happens when he goes to lunch, or leave the computer idle  for a few minutes and then he comes back and the login screen is there and everything needs to load up again. Also, I made sure hibernation was set to off.. Should I run HijackThis on the client computer?? What else can i check to try and sort this problem out?? Thanks in advance!!
0
Comment
Question by:PaigePeople
  • 12
  • 9
21 Comments
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11882181
Hello PaigePeople =)

Well are u sure its ACTUALLY restarting,,,, and not just giving the LoginBox after a certain period of time, like after the mniutes u have set for screen saver,,,, it starts screen saver, and on resume its gives the password or login box ??
0
 

Author Comment

by:PaigePeople
ID: 11882657
I am pretty sure I looked and that option was not checked (On resume password protect)    He goes to lunch in 30 mins to an hr.. I will hop on his machine and double check to make sure that is not the case... I would feel pretty dumb if that is what it is.. Well more lazy then dumb... Ok i will let you know in a few...
0
 

Author Comment

by:PaigePeople
ID: 11883576
OK, I did just check his computer, On resume was checked,   however, he said usually when he goes to lunch, he comes back and enters in his user name/ password    it has to reboot everything.. Any windows he left open are completely closed (all programs closed)   So, if it was the screensaver on resume passwr4od protection, then those programs would not close.  Any other suggestions?
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11883672
ok so when u hit the POWER button in ScreenSaver section, is the ALWAYS ON scheme selected ??
and in Advanced setion, the Ask me for Password when resumes from Standby shudn't be chekced !!!!!

Im sure its the settings of something like this,,,,coz his system is not restarting but just logging him off when its idle for some time,,, and as he gets log off, he needs to login back and thus the all programs starts again from scratch :)
0
 
LVL 65

Accepted Solution

by:
SheharyaarSaahil earned 500 total points
ID: 11883758
orrrr..... is it some kind of Group Policy running on his system,,,,, something like discussed here >> http://www.experts-exchange.com/Operating_Systems/Win2000/Q_20860048.html
0
 

Author Comment

by:PaigePeople
ID: 11883874
OK, i went to the power scheme and ALWAYS ON was not selected, but, everything was set to never.. I changed it to ALWAYS ON and kept everything at never (monitor NEVER shuts off, hard disk NEVER shuts off, Etc....)  

"""Advanced setion, the Ask me for Password when resumes from Standby shudn't be chekced !!!!!"""  

THAT WAS CHECKED, I unchecked it there as well... I am gonna go get lunch and when i come back, hopefully his computer is still on and you get the points!!! Thanks again... you rule!!!  
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11884729
ok fingers crossed :)
0
 

Author Comment

by:PaigePeople
ID: 11884736
darn, his programs still closed after i changed all those settings... I will make sure the settings were applied..(Pretty Positive that they were) He is pretty busy today, so I told him tomorrow I would look at it....  I will look over the group policy link as well... Any other ideas?
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11884882
hmmmmmmm i was afraid of that,,,,, but never mind u can still check the group policy settings, and if by chance its also not applicable, then we will trace out some background applications and will trace out the one which is initiating this behaviour :-?
0
 

Author Comment

by:PaigePeople
ID: 11903060
OK, it was not the group policy settings either... I will run HiJack This and post the log?? IS that what you are thinking my next step should be?? I will run that on his comouter in about 2 hrs when he goes to lunch... If you want me to run anything else or check anything else, please let me know... Thanks...
0
Top 6 Sources for Identifying Threat Actor TTPs

Understanding your enemy is essential. These six sources will help you identify the most popular threat actor tactics, techniques, and procedures (TTPs).

 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11903890
yes just post the LOG file,,,, may be there is a bakcground application that is causing this behaviour :-?
0
 

Author Comment

by:PaigePeople
ID: 11904745
Here comes the Log, Work your Magic!!! I hope this works...


Logfile of HijackThis v1.98.0
Scan saved at 12:19:47 PM, on 8/26/2004
Platform: Windows 2000 SP4 (WinNT 5.00.2195)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINNT\System32\smss.exe
C:\WINNT\SYSTEM32\winlogon.exe
C:\WINNT\system32\services.exe
C:\WINNT\system32\lsass.exe
C:\WINNT\system32\svchost.exe
C:\WINNT\system32\spoolsv.exe
C:\WINNT\System32\3Com_DMI\3CDMINIC.EXE
C:\Program Files\Dell\OpenManage\Client\ActionAgent.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\DefWatch.exe
C:\DMI\WIN32\bin\DellDmi.exe
C:\Program Files\Dell\OpenManage\Client\EventAgt.exe
C:\Program Files\Dell\OpenManage\Client\DLT.exe
C:\WINNT\System32\svchost.exe
C:\Program Files\Dell\OpenManage\Client\Iap.exe
C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe
C:\Program Files\Symantec_Client_Security\Symantec AntiVirus\Rtvscan.exe
C:\WINNT\system32\regsvc.exe
C:\WINNT\system32\MSTask.exe
C:\WINNT\System32\WFXSVC.EXE
C:\dmi\win32\bin\Win32sl.exe
C:\Program Files\Symantec\WinFax\WFXMOD32.EXE
C:\WINNT\system32\svchost.exe
C:\WINNT\Explorer.EXE
C:\WINNT\system32\SxgTkBar.exe
C:\Program Files\QuickTime\qttask.exe
C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
C:\Program Files\Common Files\Real\Update_OB\realsched.exe
C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe
C:\Program Files\HP\hpcoretech\hpcmpmgr.exe
C:\WINNT\system32\faxsvc.exe
C:\Program Files\Webroot\Washer\wwDisp.exe
C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe
C:\WINNT\system32\ctfmon.exe
C:\Program Files\Symantec\ACT\ACTLDR.EXE
C:\PROGRA~1\IBM\CLIENT~1\Emulator\pcsws.exe
C:\PROGRA~1\IBM\CLIENT~1\Emulator\PCSCM.EXE
C:\PROGRA~1\IBM\CLIENT~1\cwblmsrv.exe
C:\Program Files\IBM\Client Access\Emulator\pcsws.exe
C:\Program Files\IBM\Client Access\Emulator\pcsws.exe
C:\Program Files\Symantec\ACT\ACT.EXE
C:\Program Files\AIM95\aim.exe
C:\Program Files\Microsoft Office\Office10\OUTLOOK.EXE
C:\Program Files\Microsoft Office\Office10\WINWORD.EXE
C:\WINNT\msagent\AgentSvr.exe
C:\WINNT\System32\svchost.exe
C:\WINNT\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\WINNT\SYSTEM32\RUNDLL32.EXE
C:\WINNT\system32\ssstars.scr
C:\Documents and Settings\jayf\Desktop\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sb/*http://www.yahoo.com/search/ie.html
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/sp/*http://www.yahoo.com
R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://red.clientapps.yahoo.com/customize/ycomp_wave/defaults/su/*http://www.yahoo.com
O2 - BHO: Yahoo! Companion BHO - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINNT\system32\msdxm.ocx
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: Yahoo! Companion - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn\ycomp5_3_19_0.dll
O4 - HKLM\..\Run: [Synchronization Manager] mobsync.exe /logon
O4 - HKLM\..\Run: [TCASUTIEXE] TCAUDIAG -off
O4 - HKLM\..\Run: [SxgTkBar] SxgTkBar.exe
O4 - HKLM\..\Run: [Client Access Service] "C:\Program Files\IBM\Client Access\CwbSvStr.Exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [HPDJ Taskbar Utility] C:\WINNT\system32\spool\drivers\w32x86\3\hpztsb09.exe
O4 - HKLM\..\Run: [vptray] C:\PROGRA~1\SYMANT~1\SYMANT~1\vptray.exe
O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe"  -osboot
O4 - HKLM\..\Run: [DeviceDiscovery] C:\Program Files\Hewlett-Packard\Digital Imaging\bin\hpotdd01.exe
O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hewlett-Packard\HP Software Update\HPWuSchd.exe"
O4 - HKLM\..\Run: [HP Component Manager] "C:\Program Files\HP\hpcoretech\hpcmpmgr.exe"
O4 - HKCU\..\Run: [Window Washer] C:\Program Files\Webroot\Washer\wwDisp.exe
O4 - HKCU\..\Run: [SpySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe /0
O4 - HKCU\..\Run: [ctfmon.exe] ctfmon.exe
O4 - Startup: ACT! Speed Loader.lnk = C:\Program Files\Symantec\ACT\ACTLDR.EXE
O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE
O8 - Extra context menu item: &Google Search - res://c:\program files\google\GoogleToolbar2.dll/cmsearch.html
O8 - Extra context menu item: Backward Links - res://c:\program files\google\GoogleToolbar2.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://c:\program files\google\GoogleToolbar2.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://c:\program files\google\GoogleToolbar2.dll/cmsimilar.html
O8 - Extra context menu item: Translate into English - res://c:\program files\google\GoogleToolbar2.dll/cmtrans.html
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM95\aim.exe
O16 - DPF: {2B323CD9-50E3-11D3-9466-00A0C9700498} (Yahoo! Audio Conferencing) - http://us.chat1.yimg.com/us.yimg.com/i/chat/applet/v43/yacscom.cab
O16 - DPF: {41F17733-B041-4099-A042-B518BB6A408C} - http://a1540.g.akamai.net/7/1540/52/20021205/qtinstall.info.apple.com/borris/us/win/QuickTimeInstaller.exe
O16 - DPF: {56336BCB-3D8A-11D6-A00B-0050DA18DE71} (RdxIE Class) - http://software-dl.real.com/1224060a756e40270315/netzip/RdxIE601.cab
O16 - DPF: {F7DC2A2E-FC34-11D3-B1D9-00A0C99B41BB} (Zoom Class) - http://www.zoomify.com/download/zoomify305.cab
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = pecd01.com
O17 - HKLM\System\CCS\Services\Tcpip\..\{8D95CABA-868E-4497-8699-1CD4218D7E2F}: NameServer = 10.3.1.33,207.99.0.1
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = pecd01.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = pecd01.com
O18 - Protocol: cetihpz - {CF184AD3-CDCB-4168-A3F7-8E447D129300} - C:\Program Files\HP\hpcoretech\comp\hpuiprot.dll

0
 

Author Comment

by:PaigePeople
ID: 11904785
Ok, I had someone come check out the group policies, apparently they missed the Auologoff was enabled.. I disabled that, But now that i posted his hijack this log, maybe you see some stuff in there that i should get rid of too...
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11904815
hmmmmm nothing bad, but what is this entry >> C:\WINNT\system32\ssstars.scr
i mean it shud be a screen saver.... but suaually screen savers dont run in backgrounds..... so why it is, i mean have u  installed it or..... ??
0
 

Author Comment

by:PaigePeople
ID: 11904822
I probably should havemade sure his computer does not log off after inactivity... I accepted your answer banking on that being the issue.. It was enabled, so It just got to be the issue.. I will let you know how it goes regardless... LEt me know of any suspicious stuff in his hijackthis log....
0
 

Author Comment

by:PaigePeople
ID: 11904848
I have no idea what that program is.... Should i virus check that file??? I will google it too see if it comes up as anything.... He is out to lunch now   so i have no idea what he has installed...
0
 

Author Comment

by:PaigePeople
ID: 11904894
NAME "Starfield"      VALUE "C:\WINNT\System32\ssstars.scr"


I guess its the starfield screensaver???

http://www.winnetmag.com/Files/3799/Listing_02.txt
0
 

Author Comment

by:PaigePeople
ID: 11904912
That is the screensaver he is using... So everything looks ok??? I will let you know in an hr or so how everything worked out.... Thanks again.. You Rock...
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11904938
ok then that's ok :)
u can check for the problem and post back the results..... fingers crossed again ;-)
0
 

Author Comment

by:PaigePeople
ID: 11905723
No good.... Still brought him to login screen, entered in usr/pwd  and loaded up all his programs that run during startup.. When I left for lunch everything was still there... Maybe I need to watch this happen as it happens.. I almost don't want to believe him, haha..  Ack, that should have worked damn it!!! Now i don't even know what to do next... :/
0
 
LVL 65

Expert Comment

by:SheharyaarSaahil
ID: 11906911
that's bad indeed =(

its shud be related to group policy.... as it was enabled.... did u ask him if his Administrator put this settings and which cannot be disabled by normal users :-?
0

Featured Post

Complete Microsoft Windows PC® & Mac Backup

Backup and recovery solutions to protect all your PCs & Mac– on-premises or in remote locations. Acronis backs up entire PC or Mac with patented reliable disk imaging technology and you will be able to restore workstations to a new, dissimilar hardware in minutes.

Join & Write a Comment

NTFS file system has been developed by Microsoft that is widely used by Windows NT operating system and its advanced versions. It is the mostly used over FAT file system as it provides superior features like reliability, security, storage, efficienc…
In this article, I will show you HOW TO: Install VMware Tools for Windows on a VMware Windows virtual machine on a VMware vSphere Hypervisor 6.5 (ESXi 6.5) Host Server, using the VMware Host Client. The virtual machine has Windows Server 2016 instal…
Get a first impression of how PRTG looks and learn how it works.   This video is a short introduction to PRTG, as an initial overview or as a quick start for new PRTG users.
Polish reports in Access so they look terrific. Take yourself to another level. Equations, Back Color, Alternate Back Color. Write easy VBA Code. Tighten space to use less pages. Launch report from a menu, considering criteria only when it is filled…

757 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question

Need Help in Real-Time?

Connect with top rated Experts

21 Experts available now in Live!

Get 1:1 Help Now