Solved

User gets logged off and logged on to windows 2003 domain and pc locks for a minute

Posted on 2008-06-26
4
242 Views
Last Modified: 2013-12-04
I have a user who's Windows XP Pro PC  (dell Optiplex 755 less than 4 months old.) locks up 3 to 4 times daily for about a minute each time.  It happens when the user is running a variety of programs and I cannot find any patterns. I have found an event in te security log that happens at the time of system freezes.

Event Type:      Success Audit
Event Source:      Security
Event Category:      Logon/Logoff
Event ID:      538
Date:            6/20/2008
Time:            9:36:55 AM
User:            DOMAIN\PCNAME$
Computer:      SRVR1
Description:
User Logoff:
       User Name:      ########PV$
       Domain:            ************
       Logon ID:            (0x0,0x70E4325)
       Logon Type:      3

I have checked all of the logon timeouts for the user and any access restrictions and nohing appears out of the ordinary. I have other PCs that are connected to the domian with similar configurations and no one else has these issues. As far as I can tell it looks like something forces the PC to logoff and it immediately logs back on, and the system appears to the user like it is freezing up during this proccess.
0
Comment
Question by:rjs990cts
[X]
Welcome to Experts Exchange

Add your voice to the tech community where 5M+ people just like you are talking about what matters.

  • Help others & share knowledge
  • Earn cash & points
  • Learn & ask questions
  • 2
4 Comments
 
LVL 23

Expert Comment

by:TheCleaner
ID: 21880764
Does it appear to happen at the same time each day or totally random?  Can the user keep a log for a day or two of the apps that are running when it happens and see if there is a pattern there?

Make sure you check the application log during the same times as well.

A logoff would have to be followed by a CTRL-ALT-DEL sequence which I don't think a program has the ability to pass to the OS, only the keyboard, so I don't think it's really doing what you are thinking it is (logging off and back on without notice).
0
 
LVL 38

Expert Comment

by:ChiefIT
ID: 21882276
All 538 means is you have logged off the computer and the token was destroyed. This should be normal when you log off.

This is the best explaination I can find on 538:
http://support.microsoft.com/kb/828857

So, it appears you have a third party process that is disturbing your system.

Have you checked any memory dumps to see if you have a stop error. Some services could be set to logoff in the event of failure. Hypothetically speaking, maybe this third party software is creating a stop error on a service that is designed to logg you off if it fails. Can you elaborate on the software you suspect on this computer?
0
 

Author Comment

by:rjs990cts
ID: 21885827
One of the strange symptoms occurs when the user is not prompted to logon after they are apparently logged off- it just logs in automatically (when the system freezes for a minute).  I am going to get a list of programs running on the PC (I'm currently off site).  Off of the top of my head they use office 2007 SBE, Quickbooks, Turbo Tax, AOL (I've been trying to get them away from AOL for years).   I'lll get back to you with a full list- in your opinions would older applications cause something like this?
0
 
LVL 38

Accepted Solution

by:
ChiefIT earned 500 total points
ID: 21887355
They could, these applications may not be able to hold an access token from kerberos. In that case it is called a TOKEN LEAK.
0

Featured Post

Simplifying Server Workload Migrations

This use case outlines the migration challenges that organizations face and how the Acronis AnyData Engine supports physical-to-physical (P2P), physical-to-virtual (P2V), virtual to physical (V2P), and cross-virtual (V2V) migration scenarios to address these challenges.

Question has a verified solution.

If you are experiencing a similar issue, please ask a related question

Suggested Solutions

Many of us in IT utilize a combination of roaming profiles and folder redirection to ensure user information carries over from one workstation to another; in my environment, it was to enable virtualization without needing a separate desktop for each…
No security measures warrant 100% as a "silver bullet". The truth is we also cannot assume anything but a defensive and vigilance posture. Adopt no trust by default and reveal in assumption. Only assume anonymity or invisibility in the reverse. Safe…
Are you ready to implement Active Directory best practices without reading 300+ pages? You're in luck. In this webinar hosted by Skyport Systems, you gain insight into Microsoft's latest comprehensive guide, with tips on the best and easiest way…

761 members asked questions and received personalized solutions in the past 7 days.

Join the community of 500,000 technology professionals and ask your questions.

Join & Ask a Question