slow login "applying personal settings", can't find domain controller?

We have one computer on the network (windows xp pro) which is logging users on very slowly.

The computer hangs at the "Applying Personal Settings" stage. After about two minutes it goes through.

I think there's some problem in talkign with the domain controller, and it is timing out. Event log has sone interesting items in it.

What can I do to fix this?



Event log below:


Userenv:
   Windows cannot determine the user or computer name. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.  For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Userenv:
Windows cannot obtain the domain controller name for your computer network. (The specified domain either does not exist or could not be contacted. ). Group Policy processing aborted.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.

Autoenrollment:
Automatic certificate enrollment for local system failed to contact the active directory (0x8007054b).  The specified domain either does not exist or could not be contacted.
  Enrollment will not be performed.

For more information, see Help and Support Center at http://go.microsoft.com/fwlink/events.asp.
LVL 31
Frosty555Asked:
Who is Participating?

[Product update] Infrastructure Analysis Tool is now available with Business Accounts.Learn More

x
I wear a lot of hats...

"The solutions and answers provided on Experts Exchange have been extremely helpful to me over the last few years. I wear a lot of hats - Developer, Database Administrator, Help Desk, etc., so I know a lot of things but not a lot about one thing. Experts Exchange gives me answers from people who do know a lot about one thing, in a easy to use platform." -Todd S.

overcld9Commented:
Normally, this is a simple DNS issue, Check TCP/IP settings and make sure that the only DNS server is a DNS server in the domain, or the DC itself. ISP DNS should only be entered as your DNS servers forwarder.
0

Experts Exchange Solution brought to you by

Your issues matter to us.

Facing a tech roadblock? Get the help and guidance you need from experienced professionals who care. Ask your question anytime, anywhere, with no hassle.

Start your 7-day free trial
rjdennisCommented:
Question: Does this machine have APC PowerChute software on it?  I very recently had this issue and it was related to APC PowerChute.  I had to install an update to PowerChute to resolve it.  
0
Tsun4mi7Commented:
Try removing the computer from the domain and rejoining the domain (essentially re-registering the computer account's credentials on the network).

Also, check your network seurity settings (i.e. are you using IPSEC for all network traffic, hence the certificate autoenrolment for the computer account)?

Try / check the above and post your findings
0
Determine the Perfect Price for Your IT Services

Do you wonder if your IT business is truly profitable or if you should raise your prices? Learn how to calculate your overhead burden with our free interactive tool and use it to determine the right price for your IT services. Download your free eBook now!

Frosty555Author Commented:
The only strange software on this machine is Symantec Endpoint, pcAnywhere, and Microsoft Dynamics. The rest is the usual stuff - office, msn, etc.

overcld9 - the dns server is set the same as the gateway, which is 192.168.2.1. However, I suspect this might actually be the router, not the domain controller. I suspect the router is also our dhcp server. Should the DC also be a dns server which forwards to 192.168.2.1?

rjdennis - we do actually have an APC UPS. The powerchute software is not on this client, but it might be on the domain controller or fileserver, I would need to check.

tsun4mi7 - I'll try that. One question though, once I leave the domain, can I just join back to it or is there something special I'll have to do on the DC first to "allow" the computer to join? Or would it work if I just specified the admin password for the DC?
0
overcld9Commented:
Frosty,
            You should change the DNS to be a local DNS sever, does not have to be a DC just a member of the domain with a copy of the zone. I would not forward DNS to my router to then be forwarded again to your isps DNS settings. Just make sure that the forwarder in DNS is setup with your ISPs DNS settings. If your router is doing DHCP then change the published DNS address in your router to be a local DNS server that is authorized on the domain.
0
Ryan_RIT Systems AdministratorCommented:
I had this issue with a few PCs today. It appeared that a large amount of data was being copied to the computer via the network.

What I did was type in the login credentials, then unplug the network cable, so that the PC would login straight away.

Just before the user went home, I asked them to log off, and then log on again, so that the computer would have all night to do whatever it's trying to do.
0
MrMintanetCommented:
I wonder if it was also slow when you opened programs such as ADUC and/or any other domain specific MMCs that may cause a bit of lag whilst propogating...  
0
It's more than this solution.Get answers and train to solve all your tech problems - anytime, anywhere.Try it for free Edge Out The Competitionfor your dream job with proven skills and certifications.Get started today Stand Outas the employee with proven skills.Start learning today for free Move Your Career Forwardwith certification training in the latest technologies.Start your trial today
Windows XP

From novice to tech pro — start learning today.