scan causing desktop login problems

David DEZ's picture

I'm running SEPM v11 with a weekly system scan set to run on users' machines on Monday nights.  Each Tuesday morning when users try to login, they just get their walpaper with no icons.  Using CTRL-ALT-DEL they are able to logoff then log back on again correctly.  Does anyone know why this only happens the morning after a scan completes?

Dave

Knottyropes's picture

I have had same issues with some clients as well. 90% of the time M$ update is running during logon.:smileysurprised:
 
Repeat M$ update not windows update.:smileywink:
 
I am begging to hate all updates now.:smileysad:
David DEZ's picture

I ran the Microsoft Update, but this did not resolve the issue.  When I arrived at work this morning, the same thing happened again.

doctortt's picture

Hi there. Can you clarify a bit? M$ - Are you referring to Microsoft? Not Windows Update? I'm a bit confused.
 
"Repeat M$ update not windows update."



Message Edited by doctortt on 05-19-2008 07:10 AM

Knottyropes's picture

Windows update is the normal one for the OS mostly.
 
You can change it to M$ Update. (Microsoft Update) This one willscan your PC on every boot up looking for updates on everything and takes forever.
 
Changing it back to Windows Update usually fixes slowness during boot if it is enabled.
David DEZ's picture

As I mentioned, I did try the Microsoft Update option with the same results.  I still get the walpaper with no icons or taskbar after I logon for the first time after a SEP scan. 

doctortt's picture

Where do you change it? Thanks
Knottyropes's picture

 
Tells how to do it.:smileyvery-happy:
Knottyropes's picture

Any luck with it?
David DEZ's picture

Luck with the Microsoft Update, yes... Luck with the original problem, no.

Knottyropes's picture

Ok so now the client is on windows update only?
 
Client has 512 ram?
 
All other scans are not enabled with SEPM?
 
quick scan and scan when new def arrives caused fun with logons as well.
 
 
David DEZ's picture

Actually,
  This is only happening with some of the newest machines I've installed.  All of them have either 2 or 3 GB of RAM.  What do you mean by "All other scans are not enabled with SEPM?"  Also, new definitions arrive almost daily, but I only have this trouble once a week.

Knottyropes's picture

The two scans I mentioned are in SEPM.
When activated it causes lots of trouble when logging in for first time.
 
 
Sandeep Cheema's picture

Policies > AntiVirus and AntiSpyware > Auto Protect > Advanced
 
Load "Auto Protect" when "Symantec Endpoint Protection" starts rather than when "computer starts"
 
Does that help ?
 
 
 
 
 
David DEZ's picture

No, that didn't do the trick.   This morning, when all the users complained about the same problem I noticed something in the log that differed from the few users that didn't have the problem.  The ones that did have the problem had this entry about once an hour from the time of the scan until the time they restarted their PC's:


Event Type:        Information
Event Source:      Service Control Manager
Event Category:    None
Event ID:          7035
Date:              5/21/2008
Time:              1:45:03 AM
User:              NT AUTHORITY\SYSTEM
Computer:          XXXX###
Description:
The COH_Mon service was successfully sent a start control.

COH_Mon is listed online as a Symantec driver.  Can you tell me more about how this might be a part of my issue?


Knottyropes's picture

Scanned for it on my PC, no find.
 
Maybe it is a legacy app that was not removed.
David DEZ's picture

I didn't even think to scan for it.  I must be loosing my mind.  Anyway, here's the info on it.  All of the affected PC's have had norton installed fresh since about December. Mine in particular is a new PC as of March 2008.


;
; COH_Mon INF File
;
; Copyright (c) 2001-2007 Symantec Corporation. All rights reserved.
;
; NOTE: Only use this installation file in conjunction with the
; Microsoft Windows Hardware Compatibility Test (HCT) kit.
;
[Version]
signature   = "$Windows NT$"
Class       = "ActivityMonitor"
ClassGuid   = {b86dff51-a31e-4bac-b3cf-e8cfe75c9fc2}
Provider    = %Symc%
DriverVer   = 05/24/2007,6.1.2.3
CatalogFile = COH_Mon.cat

[SourceDisksNames]
1 = %Disk1%

[SourceDisksFiles]
COH_Mon.sys = 1

[DestinationDirs]
DefaultDestDir = 01,temp.^^^

[DefaultInstall]
CopyFiles = @COH_Mon.sys

[DefaultUninstall]

[Strings]
Symc = "Symantec Corporation"
Disk1 = "COH_Mon Source Media"

Paul Murgatroyd's picture

COH_Mon is the TRUSCAN driver, otherwise called SONAR in the consumer product and previously Confidence Online Heavy from the WholeSecurity product line

Paul Murgatroyd
Principal Regional Product Manager, Enterprise Security Group, Symantec
Endpoint twitter feed: http://twitter.com/symc_endpoint

B's picture

Is there a resolution to this?  We are having the same issue on our newer PCs that have 2 GB of RAM.  most users see it as a minor inconvenience, but the natives are starting to get restless. 
Situation:  user logs on in the morning.  Gets the generic blue Windows background, with no icons, start menu, etc.  If I have them ctrl+alt+del and then launch task manager, and then launch "explorer", their desktop loads instantly.  otherwise it sits with the windows blue bacground until they cycle the power or log off and then back on.  Please advise on the fix - i saw reference to changing from Windows update and Microsoft update - but did not see any definitive resolution.
 
Thank you.
David DEZ's picture

No, I have not been able to solve this.  It is also happening with our newer computers which have 2-3 GB of RAM.

pacholke's picture

Bump...

 

We are experiencing this same issue intermittently at my company also.  The system will boot, user will login, system appears to be loading but never gets past the blank background.  Performing a Ctrl+Alt+Del and then running Explorer will load the desktop and the system performs normally after that.  System and Application logs do not show anything out of the ordinary that I can see.  This is starting to occur more and more frequently since the installation of SEP MR3 and users are starting to get irritated.

 

Any help or suggestions will be appreciated!

Chris

pacholke's picture

found this article on the Symantec support site....

 

http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/a1bc009c2a17abf488257424006ab6a3?OpenDocument

 

doesn't seem like much of an answer since everything was working fine prior to the install.

Chris

chrish1's picture

found this article on the

found this article on the Symantec support site....

 http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/a1bc009c2a17abf488257424006ab6a3?OpenDocument

 doesn't seem like much of an answer since everything was working fine prior to the install.

Has anyone tried the script change mentioned in the above article to resolve this problem? 

chrish1's picture

I too would like to know if

I too would like to know if anyone has tried the script change.  We are having this problem on nearly 170 computers here.. it did not happen during testing on smaller groups of computers. 

Chris

found this article on the Symantec support site....

 http://service1.symantec.com/support/ent-security.nsf/854fa02b4f5013678825731a007d06af/a1bc009c2a17abf488257424006ab6a3?OpenDocument

 doesn't seem like much of an answer since everything was working fine prior to the install.

Has anyone tried the script change mentioned in the above article to resolve this problem? 

David DEZ's picture

I'd given up...

Wow,
I'd given up on this thread.  A few months back, the natives got so restless that I ended up removing the script and manually configuring the network drives on all of my machines.  Once I get my current definition update issues resolved, I'm going to try that fix.

David

David DEZ's picture

The problem returns

Well,
We got 2 new Dell Windows XP Pro SP 3 PC's in and they're both doing the same thing again.  They had 4 GB of RAM installed, which I pulled down to 2 GB upon report of the problem.  However, the problem still remains.  I am not running any startup scripts on these computers, and no other machines have this issue.

David

NOJ's picture

Almost same problem: COH_Mon doesn't start during Backup

Hi.

I also have almost the same problem in my company: Some mornings when I arrive, my computer is "dead". I can see the desktop and move the mouse pointer. The desktop is empty (no icons - only the background picture), and the keyboard is responding on Num-lock, Caps-lock, Print-screen (mouse pointer briefly dissapears), etc..

But - I cannot do ANYTHING. Ctrl+Alt+Delete doesn't respond, nor pressing Enter or inputting password and pressing Enter (if the login dialog should be invisible). Also the computer will not power down by pressing the power button for a short while (as it usually can).

The error can happen weeks apart or every day.

In the event log I can see that the last executed application before the computer "freezes" is Microsoft Backup (which I'm running every evening at 20:00 - it takes about 2 hours) and in the eventlog's System folder, the last event is (at 20:55) 

Event source: Service Control Manager
Event-id: 7035
Service COH_Mon received a start-control.   (BUT IT DOESN'T START)

The only thing for me to do is to reset the PC (turn off (hold power button for 7+ seconds)+turn on).

I run SEP 11.0.4014.26 on Windows XP SP3 (all service packs applied).

PLEASE HELP !!