Remote Desktop, remote shutdown/restart

G

Guest

2 WinXP Pro SP2 Dell systems/NTFS/. Until this evening, have always been
able to utilize Remote Desktop and to use shutdown -r to remotely restart the
second system, to which I regularly connect under the primary user's account
to do routine maintenance. This date, found BearShare and the usual
accompanying malware installed. Uninstalled same, AdAware, Spybot, thorough
disk check, defrag, thorough disk cleanup (including unnecessary SP2 files
per instructions at http://forum.aumha.org/viewtopic.php?t=7265), attempt to
shutdown and restart and...

Now unable to use shutdown -r to restart. Instead get message "The machine
is locked and can not be shut down without the force option." Using shutdown
-r -f, I can force a shutdown, but this wasn't necessary until today. I also
don't see the usual System Shutdown popup window with the countdown timer
like I did before, so unless I attempt to run another shutdown command and
wait for the "a system shutdown is in progress" notification, it's impossible
to tell whether the initial shutdown -r -f command is working.

In Task Manager on the remote system, the only User showing is the name
under which I'm logged in, with my system on this end (with me) as the Client
Name. No new processes/apps added before this started, just the removal of
BearShare/WhenUShop/WeatherCast (and if I find out who installed that, heads
will indeed roll :-0). No other changes that I've been able to detect that
might be causing this.

Many thanks to anyone able to help me track the cause of this down.
 
L

Lanwench [MVP - Exchange]

FloobyMcT said:
2 WinXP Pro SP2 Dell systems/NTFS/. Until this evening, have always
been able to utilize Remote Desktop and to use shutdown -r to
remotely restart the second system, to which I regularly connect
under the primary user's account to do routine maintenance. This
date, found BearShare and the usual accompanying malware installed.
Uninstalled same, AdAware, Spybot, thorough disk check, defrag,
thorough disk cleanup (including unnecessary SP2 files per
instructions at http://forum.aumha.org/viewtopic.php?t=7265), attempt
to shutdown and restart and...

Now unable to use shutdown -r to restart. Instead get message "The
machine is locked and can not be shut down without the force option."
Using shutdown -r -f, I can force a shutdown, but this wasn't
necessary until today. I also don't see the usual System Shutdown
popup window with the countdown timer like I did before, so unless I
attempt to run another shutdown command and wait for the "a system
shutdown is in progress" notification, it's impossible to tell
whether the initial shutdown -r -f command is working.

In Task Manager on the remote system, the only User showing is the
name under which I'm logged in, with my system on this end (with me)
as the Client Name. No new processes/apps added before this started,
just the removal of BearShare/WhenUShop/WeatherCast (and if I find
out who installed that, heads will indeed roll :-0). No other
changes that I've been able to detect that might be causing this.

Many thanks to anyone able to help me track the cause of this down.

Check the event logs for clues?

Also, OT, but to make your maintenance less painful, take away the local
admin rights from the users if they have them....that's the usual cause of
spyware infection. Change the local admin pw to something only you know. Log
in as that admin acct or another password-protected admin-equivalent account
when you do Remote Desktop. Leave the IE security settings on high. Try
using Spybot's TeaTimer to guard the system....and make sure you're using
the latest versions of AdAware (SE 1.05) and Spybot (1.3), both updated
before scanning.
 

Ask a Question

Want to reply to this thread or ask your own question?

You'll need to choose a username for the site, which only take a couple of moments. After that, you can post your question and our members will help you out.

Ask a Question

Top