Jump to content
EduGeek EdSec 2026 is Go! 27th Oct in Derby! Join us for a day of EdTech security focused talks, networking, and an evening social ×

Recommended Posts

Posted

I have tried searching for this and found similar, but sufficiently different to believe that the reports were not the same. So, I post about our problem.

 

We are starting to apparently randomly see Windows 7 hang at the 'Welcome' screen when logging in. I do not believe that it is terminal, as I have left a machine over the weekend with the 'Welcome' screen spinning icon constantly rotating only to find the machine fully fit the following Monday. Last this week we left one of the machines for over 5 hours with the icon rotating before we had to crash it out.

 

Unfortunately, being random and a small school, the small percentage of times that a machine logs in having the issue and these things do not get reported in a timely manner or simply being grouped under 'machine didn't work', its been difficult to get an exact idea of when this problem started occuring. The ICT servers and clients were a new in the summer, so it was a clean build. However, about a month back, the network topology was changed and it is possible that the issue crept in with this, masked with another issue since probably resolved (no reported re-occurrence) - however, that week was a major update from Microsoft plus Java, Flash, Acrobat all wanted to do their updates, so alot was going on that week.

 

The network topology change was a change to the routing. The 4 subnets we originally routed using RRAS on the main server, but this has since changed to doing to routing on a TMG Firewall box as part of Forefront TMG. As a result, default gateways changed and initially we incorrectly has a routing issue with the AD machine having multiple NIC's causing intermittent LDAP failures. This has since been resolved and the AD server just now has the single NIC.

 

However, whilst random blank desktops and the like have now gone away, the hang on Welcome screen persists. As routing is now done in TMG, we have all the routing logs available and, apart from IGMP multicast packets to (off the top of my head) 224.0.0.22 being blocked by the firewall, everything seems explainable. No errors as such appear in the Windows machines event logs either.

 

I do however have some theories:

 

1. The IGMP routing packets are needed for something.

2. Machines go to standby and there are issues with it cleanly waking up

3. User error

 

A couple of weeks back, by luck, I was in the ICT suite alone running some tests. Then about 7 users appeared wanting an impromptu use of the room which I said that they could. Of the seven or so users, most machines logged in in a matter of ten seconds or so, but two failed (hung with rotating icon at 'Welcome') to log in first time and a second time and one of these a third time. What I noticed from this was that one of the failed users had incorrectly used on at least one occasion used an incorrect password, yet it still hung. This may also corroborate my experience that when a machine hangs at welcome and is then crashed out, the previous users credentials are prompted at next login, not the failed user. I also notice that even log is clean, no evidence of much activity at all, but, possibly all noting a major time change due to coming out of standby.

 

Machines are Dell Optiplex running Windows 7 Pro. Latest service patches. They have the fix for slow windows startup due to solid background fixed in April and, unrelated to the issue as the issue occurred before it was installed, they have the new hotfix for preventing the occasional double login prompt.

 

Servers are Windows 2008R7 running physical (AD,DNS etc) and virtual (TMG firewall and routing).

 

Going back to my theories...

 

1. I do not believe that the IGMP:0 multicast packets are anything useful and can legitimately be blocked, hence TMG does this by defaults (I have yet to find a way of enabling these in TMG 2010 otherwise I would have tried this already). However, we had multiple failures in the office last week and I thoroughly cross referenced the firewall/router logs - I believe that our firewall/router logs are a complete list of all intra-subnet requests. On one day, one of the three office machines failed and, checking the router logs, this was the only machine that put out a IGMP:0 multicast request. However, on a different day, all the machines put out the multicast request yet all successfully logged on. So if IGMP:0 is needed, its not critical in some cases, or, the request is being satisfied by something on the same subnet.

 

2. I'm slowly trying different permutations of standby and hibernate timeout settings, but am not making too much progress. However, I have had reported that one of the office machines failed to start even after it had been previously rebooted. Am currently trailing some machines with auto shut-down at night but its too early to see if this improves matters.

 

3. Whilst I witnessed this happen to the same two users one at least two logon occasions, I have also has this happen to me when logging into the domain admin account.

 

Please, any suggestions...

Posted

Forgot to mention...

 

Do not believe performance is an issue. Have logged in all 21 ICT machines sucessfully when performing performance testing.

 

Network switches indicate every link is error free so do not believe anything is being lost in physical network transmission.

Posted

First things first, enable verbose messages on startup and logon in group policy so that you can easily see which phase of the logon process it is hanging at. Second try to get the pings working as IGMP pings are used to determine link speed between the client and host, if this method fails then it may put the client into slow link mode and not process certain policies.

 

When we have had random issues with logons hanging at applying user settings it has been to do with corrupted profiles. If there are any cached corrupted profiles on the systems or it is faulting during the download then this could cause such a hangup.

 

Did you go with routing via TMG as a solution to add additional security? A propper layer 3 switch would probably be much faster for handeling internal traffic if one is avalible.

  • Thanks 1
Posted

Thanks for the prompt reply. My main priority is to get the IGMP requests working, but the only documentation I have seen for this is on older versions of TMG/ISA and the TMG forums are not the most frequented.

 

Interesting the bit about IGMP being used for link speed. Had not found any reference until now of IGMP packets being important at Windows login so will perceiver with getting these enabled on TMG.

 

As for TMG doing the routing, its down to cost and simplicity. We already had it and appears to be more than up to the job for which we need.

Posted (edited)

As per this Configure the Forefront TMG 2010 to allow DPM 2010 communication - WSSRA ping is still an allowed protocol under TMG 2010 so you should just be able to create an allow rule that lets ping through from any of the internal source networks to any of the internal source networks under the locations. You must specify ping as it looks not to be included by default under the all protocols set (sure I read this somewhere).

 

Here is a ref on slow link detection http://support.microsoft.com/kb/227260 they may have cleaned up the implementation in Server 2008 but it could still be hanging around.

Edited by SYNACK
Posted

Yes I've had this issue, I had a case open with MS about it but we never really got anywhere with it, we eventually narrowed it down to the corruption of the windows repository. To test if this is the fault you have then try disabling WMI service and then restart the PC to see if the logon nolonger hangs.

 

To repair any PCs showing the issue I stopped the WMI service and then renamed the repository folder (C:\Windows\System32\wbem\repository) to repository.old and then restarted the PC, this rebuilds the repository. To prevent the issues from reoccuring I found that disabling RSoP logging through a GPO stopped the error from reappearing. Never did anymore investigation into the problem after this.

  • Thanks 1
Posted

Hi Synack

 

Im a bit confused. Reading both the articles you passed about ping and slow link detection/DPM, are you sure these are not talking about ICMP rather than IGMP? If slow link detection uses ICMP PING, then I don't see how that can be the issue as ICMP ping works fine across subnets.

 

Thanks

Posted

mounters

 

How often were you getting this? Was it random or specific to particular PC's or user account?

 

Our problem appear not to need any repair as a reboot 99/100 usually cures the issue without any need to stop WMI. Still interested though - what is RSoP logging and how do I disable it - found plenty of info about World Series of Poker ;)

Posted

It was generally random machines, we think it was when machines were uncleanly shutdown by pupils as it was only in suites we saw it and not on staff laptops.

 

RSoP - Resultant Set of Policy Microsoft Corporation

 

To disable through GPO: Computer Config -> Policies -> Administrative Templates -> System -> Group Policy -> Turn off resultant set of policy logging

  • Thanks 1
Posted

Since a few weeks we have seen this issue too on random computers. There are quiet a few similarities between your environment and ours:

We too use Dell Optiplex (from 745 to 780 ) running Windows 7 Pro, we use 2008R2 servers and Forefront TMG.

 

To get a hanging computer to respond again i've done the following:

-Start services.msc on another computer, connect to the computer in question,

-Check that the "Multimedia Class scheduler" and/or the "Shell Hardware Detection" service are running.

You may find that although set to start automatically, they're not running. Starting them immediatly makes

the computer respond again and continue to the login screen.

 

To permanently fix it, i've had success with:

-Start a command prompt as Administrator

-Type "netsh interface tcp set global autotuninglevel=disabled"

-reboot

 

I have no clue whatsoever what these things have to do with each other or why these services

do not start (no indications or errors in eventlog) but this is what fixes it for us.

  • Thanks 1
Posted (edited)

rvdmast

 

Thanks for the input. Looks promising with similar setup and problem only starting a few weeks back.

 

Unfortunately coincidental, but Microsoft did a big set of updates which came through for us overnight Tue/Wed of that week. It was that Wednesday when I had reports of machines hanging, but it may have happened earlier. At that point, everything was blamed on the updates even though they should have completed during the night and rebooted the machines. Made worse were updates which also started coming through from Adobe and Java. I changed the frequency of updates and it still occurred, even after I went through each machine to ensure that all the updates had installed and machine cleanly rebooted. The good news is that after this is resolved, I should be able to reinstate the automatic updates.

 

Unfortunately, we did have a random login issue due to the topology change and incorrect multi NIC on AD server (left over from previous topology) but this is now resolved. So I think this issue is hazed with that, lack of pertinent reporting from staff - "some machines machine crashed yesterday and also last week".

 

I have always had suspicions with the updates that came along that week. Irrespective of the root cause which we may never know, I now have two concrete avenues to explore irrespective of the underlying cause. I have told the school to leave alone any machine hanging and to phone me so that I can come in and see if I can recover the machine without a reboot.

Edited by ianh64
Posted

I did slowly fluff up my network by blocking incoming IGMP via GPO for all PCs, windows uses this for netbios etc, What I found after random machines were not processing their logons properly it turned out that some of my older switches ARP tables were filling up! I enabled IGMP and the problem went away! I was using wireshark and could see thousands of request being sent from PCs but none of them were answering.

 

On a side note to fixing my problems and I'm not 100% on networking, I was confused to see that windows it's self keeps ARP records?

Posted

We had it happen again on two machines last week. Unfortunately they were not enabled for remote management so I was unable to interrogate them when hung. I have now enabled remote management so next time, I will hopefully get some more positive info.

 

But I have rolled out the autotuninglevel=disabled to the office machines and two ICT machines and will continue to monitor - will probably roll out to half the ICT machines in a few days and see if the problem is confined to remaining half with autotuning on.

Posted

Its just been reported to me today that two of the office machines hung yesterday morning even though I had applied the autotuning=disabled/reboot fix which is unfortunate. The day after was too late to check anything but one also hung today so I took the opportunity to remotely interrogate.

 

Whilst it responds to ping requests in a timely manner, remote management fails with error 1722, "Windows was unable to open service control manager database on office1... RPC Server is unavailable". I also tried to remotely reboot this machine and again, it failed, this time with error (53). I checked that the other machine that hung yesterday that it was still remotely manageable and could be rebooted using exactly the same commands which it did, so it would appear that when machine is hung at 'Welcome' screen, something is not quite right on it/to it.

 

I have now enabled verbose logging and will see what that reveals in future hangs.

 

Could lack of RPC availability when machine is in this state be any form of clue? ie, are there any known issues that may prevent some services, such as RPC from apparently starting or being unavailable?

Posted (edited)

I had the same machine hang this morning. I was able to look through the log slightly more extended files and found the following. This seems to correlate with rvdmast's comment about checking "Multimedia Class scheduler" and/or the "Shell Hardware Detection".

 

There was very little activity when the system started up - the user hit keyboard to bring machine out of sleep at about 08:20 then started to login at about 08:25. There are a few events but significantly, very shortly before events log went quiet, the Multimedia Class Scheduler stopped with the following event log.

 

Any ideas would be appreciated on how to work out whether this service stopping is legitimate or what is causing this to stop. Unfortunately disabling autotuning had no effect but multimedia class scheduler being stopped seems to be in common with rvdmasts experience, even though on a previous attempt, I was unable to remotely connect to services to start it. Whether it is the cause of the hang in this case, but with rvsmast, they were able to kick the machine back in to life by restarting the service.

 

Log Name:      System
Source:        Service Control Manager
Date:          24/11/2010 08:25:24
Event ID:      7036
Task Category: None
Level:         Information
Keywords:      Classic
User:          N/A
Computer:      office1.xyz.school
Description:
The Multimedia Class Scheduler service entered the stopped state.
Event Xml:

 
   
   7036
   0
   4
   0
   0
   0x8080000000000000
   
   24742
   
   
   System
   office1.xyz.school
   
 
 
   Multimedia Class Scheduler
   stopped
   4D004D004300530053002F0031000000
 

 

 

Machines are Dell Optiplex 380 running Windows 7 Professional Dell OEM. This particular machine was rebuilt from Dell's recovery disc, other machines with same/similar issue were as shipped from Dell but all with Windows updates applied.

 

I guess I need to see if there are any recommended updates for drivers etc. Other forums indicate hangs possibly associated to this service stopping, some associated with hibernate/sleep.

 

I may try completely disabling sleep mode, not ideal.

Edited by ianh64
Added machine info
Posted (edited)
I may try completely disabling sleep mode, not ideal.

 

All i can say is, we've always had sleep/hibernate turned off but have the issue nonetheless.

Meanwhile i also found out restarting the Multimedia Class scheduler and/or Shell HW detection does not always bring the machine back to life.

On machines where i disabled autotuninglevel the issue did not come back, but then again this might be coincidence...

All in all i didn't get much further, quiet the contrary...

 

Btw, are you seeing events 6006 (Winlogon) in the application eventlog?

Edited by rvdmast
  • Thanks 1
Posted

Hi, we're having the same problem with a computer here.

We have just received one new Dell OptiPlex 380 and installed Windows 7 on it.

Everything seemed to have been installing fine, joined it to our domain, logged in as the user who is getting the desktop.

Tried logging as myself (domain admin) and hung on Welcome screen.

Pressed power button, you can see an error regarding Adobe Flash ActiveX install.

We guessed this was a Group Policy error as we recently added a Flash install to our Group Policy, however, this is the only computer with that problem.

Since the user's account wasn't having any problems we ignored it at first.

After setting the computer up with specialised software we realised the user needed administrative rights to run it so we logged in to the local admin account and elevated the user's privileges. Upon attempting to log in with said user - now with local administrator privileges we were stuck at the welcome screen again.

 

I feel it might have something to do with being a domain account with local admin privileges and having a newer version of flash than our Group policy attempts to install.

 

For what it's worth, Adobe Reader has recently been updated to version X which most of our other computers don't have yet. Perhaps this may be related.

 

Our next step is disabling group policy and seeing how it goes.

Posted
Btw, are you seeing events 6006 (Winlogon) in the application eventlog?

No. I have attached output from event log below, partially annotated around the hang and lead up to it. The pertinent bit is 08:29:43 when the last thing logged before machine hangs at Welcome is "The Shell Hardware Detection service entered the stopped state." so things look similar, but as this machine is autotuning=disabled, its not exactly the same.

 

Apologies for the long bit, but hopefully someone may look through and notice something.

 

Successful login etc - logging omitted

Information	24/11/2010 08:50:04	Service Control Manager	7036	None
Information	24/11/2010 08:49:52	Time-Service	35	None
Information	24/11/2010 08:49:50	Winlogon	7001	(1101)		User Logon Notification for Customer Experience Improvement Program

User probably logs in at this point

Information	24/11/2010 08:49:44	Service Control Manager	7036	None	The CNG Key Isolation service entered the running state.
Information	24/11/2010 08:49:43	Service Control Manager	7036	None	The Windows Defender service entered the running state.
Information	24/11/2010 08:49:38	Time-Service	37	None		The time provider NtpClient is currently receiving valid time data from griffin.xxx.school (ntp.d|0.0.0.0:123->192.168.2.1:123).
Information	24/11/2010 08:49:36	Service Control Manager	7036	None
Information	24/11/2010 08:49:34	Service Control Manager	7036	None
Information	24/11/2010 08:49:34	Service Control Manager	7036	None
...
other similar messages omitted to shorten post
...
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	DHCPv6-Client	51046	Service State Event
Information	24/11/2010 08:49:29	Dhcp-Client	50036	Service State Event
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:29	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	FilterManager	6	None
Information	24/11/2010 08:49:28	FilterManager	6	None
Information	24/11/2010 08:49:28	FilterManager	6	None
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:28	UserPnp	20010	(7010)
Information	24/11/2010 08:49:28	Service Control Manager	7036	None
Information	24/11/2010 08:49:20	k57nd60x	11	None
Information	24/11/2010 08:49:16	k57nd60x	15	None
Information	24/11/2010 08:49:16	Kernel-Processor-Power	26	(4)
Information	24/11/2010 08:49:16	Kernel-Processor-Power	26	(4)
Critical	24/11/2010 08:49:14	Kernel-Power	41	(63)
Information	24/11/2010 08:49:28	EventLog	6013	None
Information	24/11/2010 08:49:28	EventLog	6005	None
Information	24/11/2010 08:49:28	EventLog	6009	None
Error		24/11/2010 08:49:28	EventLog	6008	None
Information	24/11/2010 08:49:10	FilterManager	6	None
Information	24/11/2010 08:49:08	Kernel-General	12	None


Machine rebooted and power cycled
	24/11/2010 08:47:37	

Information	24/11/2010 08:46:12	Service Control Manager	7036	None
Information	24/11/2010 08:46:11	k57nd60x	11	None
Information	24/11/2010 08:46:10	Power-Troubleshooter	1	None
Information	24/11/2010 08:46:07	Service Control Manager	7036	None
Information	24/11/2010 08:46:07	Service Control Manager	7042	None
Information	24/11/2010 08:46:06	Kernel-General	1	None

Again, machine 'rebooted' - actually mistakenly put in sleep mode by user

Information	24/11/2010 08:45:41	Kernel-Power	42	(64)

Machine hangs - not sure what screen it hung on

Information	24/11/2010 08:39:27	Service Control Manager	7036	None
Information	24/11/2010 08:39:25	k57nd60x	11	None
Information	24/11/2010 08:39:23	Power-Troubleshooter	1	None
Information	24/11/2010 08:39:21	Service Control Manager	7036	None
Information	24/11/2010 08:39:21	Service Control Manager	7042	None	
Information	24/11/2010 08:39:20	Kernel-General	1	None		The system time has changed to ?2010?-?11?-?24T08:39:20.500000000Z from ?2010?-?11?-?24T08:38:06.804269500Z.

Machine 'rebooted' - actually mistakenly put in sleep mode by user

Information	24/11/2010 08:38:05	Kernel-Power	42	(64)		The system is entering sleep. Sleep Reason: Button or Lid

*** Machine hangs at welcome screen ***

Information	24/11/2010 08:29:43	Service Control Manager	7036	None	The Shell Hardware Detection service entered the stopped state.
Information	24/11/2010 08:27:43	Service Control Manager	7036	None	The Shell Hardware Detection service entered the running state.

User enters username/password and attempts to log in

Information	24/11/2010 08:25:24	Service Control Manager	7036	None	The Multimedia Class Scheduler service entered the stopped state.
Information	24/11/2010 08:21:25	Service Control Manager	7036	None	The Windows Media Center Scheduler Service service entered the running state.
Information	24/11/2010 08:20:29	Power-Troubleshooter	1	None	The system has resumed from sleep. Sleep Time: ?2010?-?11?-?24T04:09:22.649743500Z Wake Time: ?2010?-?11?-?24T08:20:22.968000900Z Wake Source: Device -Intel(R) 82801G (ICH7 Family) USB Universal Host Controller - 27C9
Information	24/11/2010 08:20:28	Service Control Manager	7036	None	The TCP/IP NetBIOS Helper service entered the running state.
Information	24/11/2010 08:20:27	k57nd60x	11	None		Broadcom NetLink (TM) Gigabit Ethernet: Network controller configured for 1Gb full-duplex link.
Information	24/11/2010 08:20:23	Service Control Manager	7036	None	The Multimedia Class Scheduler service entered the running state.
Information	24/11/2010 08:20:22	Kernel-General	1	None		The system time has changed to ?2010?-?11?-?24T08:20:22.500000000Z from ?2010?-?11?-?24T04:09:24.426203000Z.

Machine wakes to check to install updates

Information	24/11/2010 04:09:24	Service Control Manager	7036	None	The TCP/IP NetBIOS Helper service entered the stopped state.
Information	24/11/2010 04:09:24	Service Control Manager	7042	None	The TCP/IP NetBIOS Helper service was successfully sent a stop control. The reason specified was: 0x40030011 [Operating System: Network Connectivity (Planned)] Comment: None
Information	24/11/2010 04:09:23	Kernel-Power	42	(64)		The system is entering sleep. Sleep Reason: System Idle
Information	24/11/2010 04:09:22	Kernel-General	1	None		The system time has changed to ?2010?-?11?-?24T04:09:22.679000000Z from ?2010?-?11?-?24T04:09:22.679826900Z.
Information	24/11/2010 04:07:52	Time-Service	37	None		The time provider NtpClient is currently receiving valid time data from griffin.xxx.school (ntp.d|0.0.0.0:123->192.168.2.1:123).
Information	24/11/2010 04:07:32	Service Control Manager	7036	None	The TCP/IP NetBIOS Helper service entered the running state.
Information	24/11/2010 04:07:32	Power-Troubleshooter	1	None	The system has resumed from sleep. Sleep Time: ?2010?-?11?-?23T18:48:25.753775300Z Wake Time: ?2010?-?11?-?24T04:07:25.968000800Z Wake Source: Timer - Windows will execute '\Microsoft\Windows\Media Center\mcupdate_scheduled' scheduled task that requested waking the computer.
Information	24/11/2010 04:07:32	Service Control Manager	7036	None	The WinHTTP Web Proxy Auto-Discovery Service service entered the running state.
Information	24/11/2010 04:07:32	Service Control Manager	7036	None	The TCP/IP NetBIOS Helper service entered the stopped state.
Information	24/11/2010 04:07:30	k57nd60x	11	None		Broadcom NetLink (TM) Gigabit Ethernet: Network controller configured for 1Gb full-duplex link.
Information	24/11/2010 04:07:25	Service Control Manager	7042	None	The TCP/IP NetBIOS Helper service was successfully sent a stop control. The reason specified was: 0x40030011 [Operating System: Network Connectivity (Planned)] Comment: None
Information	24/11/2010 04:07:25	Kernel-General	1	None		The system time has changed to ?2010?-?11?-?24T04:07:25.500000000Z from ?2010?-?11?-?23T18:48:31.821410500Z.

Machine enters sleep previous night

Information	23/11/2010 18:48:27	Kernel-Power	42	(64)		The system is entering sleep. Sleep Reason: System Idle
Information	23/11/2010 18:48:25	Kernel-General	1	None
Information	23/11/2010 18:48:25	Service Control Manager	7036	None

 

Unfortunately the user had a couple of false starts trying to reboot the machine (with the 'power' button on the front) where they actually put it back in standby mode and not powered down. I have included it here as this is the most comprehensive example so far of an event log that I have.

 

Yesterday I turned off auto standby mode on all machines and whilst this machine started fine this morning, the intermittent nature of this issue meant that just because a machine is fine one day, it may not be another.

 

Interestingly, this machine I believe had done it every day this week whilst the other two in the office we I think fine on all but one of the days. However since last week, I had been suggesting that the user logs off each night and I had set a scheduled command to shut the machine down at 9pm each night, not quite sure why it does not show in this machine but I guess something to do with it already being in standby mode at the scheduled shutdown time.

Posted (edited)
Hi, we're having the same problem with a computer here.

We have just received one new Dell OptiPlex 380 and installed Windows 7 on it.

Everything seemed to have been installing fine, joined it to our domain, logged in as the user who is getting the desktop.

Tried logging as myself (domain admin) and hung on Welcome screen.

Pressed power button, you can see an error regarding Adobe Flash ActiveX install.

We guessed this was a Group Policy error as we recently added a Flash install to our Group Policy, however, this is the only computer with that problem.

Since the user's account wasn't having any problems we ignored it at first...

I'm still suspicious about the adobe and java updates. This problem unfortunately coincided with a network topology change, firewall authentication change, a large set of microsoft updates (October) and flash and adobe update requests.

 

However I do not believe that this is user account related as I have seen accounts log in fine one time and hung another. We also have a couple of generic year groups year1, year2, year3 for the younger children etc and it hangs for some children and not others even though they are effectively logging in simultaneously.

 

Personally, my money is on the "The Shell Hardware Detection service entered the stopped state." but what the resolution is I do not know so far. The only people to come out of the woodwork with this are Dell Optiplex owners. Have looked on their website but nothing. Not sure how to progress diagnostics of why service is stopping.

Edited by ianh64
Is Dell a coincidence?
Posted

ianh64, just to be sure, are the computers hanging after entering login credentials, or do they hang before the CTRL-ALT-DEL screen?

Perhaps i should have mentioned that in our case the problem appears before users can login...

Posted

The computers hang after entering login credentials, ie they can hit ctrl-alt-del. I believe, from looking at the logs and by last user login state after a reboot that the hang occurs before the login is recognised.

 

So its not the same, but I am convinced that the shell hardware detection is fundamental to this. I believe that the multimedia service is a red-herring as it appears not to be a critical service and apparently can be stopped and started at will by OS.

Posted

Well, we got around this problem by disabling group policy for installing an Adobe Flash update.

Currently we don't really have time to investigate this issue further but might in the coming month or so.

Posted

Right this error must be contagouus, just had it here on a hp nw9440 running Windows 7 Enterprise 32bit. We have a bunch of these running 64bit which are totally fine though with the exact same hardware bar the CPU (stupid intel and their criminally late start with x64).

 

Have tried all sorts, first got around it by disabling the NLA service but then that stopped working, tried all of the above and still no life from it so I am going to nuke it and start again.

 

Weird thing is that looking through the logs it does actually complete the logon and all of the event logs indicate that it should be at the desktop but it isn't.

 

I am looking at drivers along with some hotfix that stired the whole thing up as a cause because this system worked fine until a coupel of weeks ago. Whether this is related to some filthy drivers or a hotfix it does only seem to effect the 32bit platform which makes me even more motivated to get rid of all of our old 32bit rubbish as soon as possible.

Create an account or sign in to comment

You need to be a member in order to leave a comment

Create an account

Sign up for a new account in our community. It's easy!

Register a new account

Sign in

Already have an account? Sign in here.

Sign In Now



×
×
  • Create New...