Deckard's System Scanner v20071014.68 Extra logfile - please post this as an attachment with your post. -------------------------------------------------------------------------------- -- System Information ---------------------------------------------------------- Microsoft(R) Windows(R) Server 2003 for Small Business Server (build 3790) SP 1.0 Architecture: X86; Language: English CPU 0: Intel(R) Xeon(TM) CPU 2.66GHz CPU 1: Intel(R) Xeon(TM) CPU 2.66GHz Percentage of Memory in Use: 26% Physical Memory (total/avail): 3582.93 MiB / 2624.4 MiB Pagefile Memory (total/avail): 4964.99 MiB / 3990.11 MiB Virtual Memory (total/avail): 2047.88 MiB / 1924.05 MiB A: is Removable (No Media) C: is Fixed (NTFS) - 39.06 GiB total, 19.84 GiB free. D: is Fixed (NTFS) - 97.66 GiB total, 8.51 GiB free. E: is CDROM (No Media) N: is Network (NTFS) S: is Network (NTFS) T: is Network (NTFS) W: is Network (Unformatted) Y: is Network (NTFS) \\.\PHYSICALDRIVE0 - ADAPTEC RAID-5 SCSI Disk Device - 136.73 GiB - 2 partitions \PARTITION0 (bootable) - Installable File System - 39.06 GiB - C: \PARTITION1 - Extended w/Extended Int 13 - 97.66 GiB - D: \\.\PHYSICALDRIVE1 - ADAPTEC RAID-5 SCSI Disk Device - 136.73 GiB - 1 partition \PARTITION0 - Logical Disk Manager - 136.73 GiB -- Security Center ------------------------------------------------------------- AUOptions is set to notify before download. Windows Internal Firewall is disabled. [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\DomainProfile\AuthorizedApplications\List] [HKLM\System\CurrentControlSet\Services\SharedAccess\Parameters\FirewallPolicy\StandardProfile\AuthorizedApplications\List] -- Environment Variables ------------------------------------------------------- ALLUSERSPROFILE=C:\Documents and Settings\All Users APPDATA=C:\Documents and Settings\Administrator\Application Data CLASSPATH=C:\PVSW\BIN\PVJDBC2X.JAR;C:\PVSW\BIN\PVJDBC2.JAR;C:\Program Files\VERITAS\Backup Exec\NT\ECM\bumodule.jar;C:\Program Files\VERITAS\Backup Exec\NT\ECM\LOG4J-CORE.JAR;C:\Program Files\VERITAS\Backup Exec\NT\ECM\LOG4J.JAR;. ClusterLog=C:\WINDOWS\Cluster\cluster.log CommonProgramFiles=C:\Program Files\Common Files COMPUTERNAME=SERVER ComSpec=C:\WINDOWS\system32\cmd.exe EXCHICONS=C:\Program Files\Exchsrvr\bin\maildsmx.dll FP_NO_HOST_CHECK=NO HOMEDRIVE=C: HOMEPATH=\Documents and Settings\Administrator Isuser=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp\{0F86FD09-BA63-4E45-A70B-604C1106C2F2}\_isuser.dll LOGONSERVER=\\SERVER NUMBER_OF_PROCESSORS=2 OS=Windows_NT Path=C:\Program Files\Windows Resource Kits\Tools\;D:\PROGRAM FILES\TIMBERLINE OFFICE\SHARED\;D:\PROGRAM FILES\TIMBERLINE OFFICE\SHARED;C:\Program Files\Timberline Office\Shared;C:\PVSW\BIN;C:\WINDOWS\system32;C:\WINDOWS;C:\WINDOWS\System32\Wbem;C:\Program Files\Microsoft SQL Server\80\Tools\Binn\;C:\Program Files\Symantec\pcAnywhere\;C:\Program Files\Common Files\Crystal Decisions\2.0\bin;C:\Program Files\Common Files\Crystal Decisions\2.5\bin;C:\Program Files\Microsoft Windows Small Business Server\Networking\ PATHEXT=.COM;.EXE;.BAT;.CMD;.VBS;.VBE;.JS;.JSE;.WSF;.WSH PROCESSOR_ARCHITECTURE=x86 PROCESSOR_IDENTIFIER=x86 Family 15 Model 2 Stepping 5, GenuineIntel PROCESSOR_LEVEL=15 PROCESSOR_REVISION=0205 ProgramFiles=C:\Program Files PROMPT=$P$G SBSProgramDir=C:\Program Files\Microsoft Windows Small Business Server SESSIONNAME=Console Shared_Path=C:\Program Files\Timberline Office\Shared\ SystemDrive=C: SystemRoot=C:\WINDOWS TEMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp TMP=C:\DOCUME~1\ADMINI~1\LOCALS~1\Temp USERDNSDOMAIN=DOWNEY.LOCAL USERDOMAIN=DOWNEY USERNAME=Administrator USERPROFILE=C:\Documents and Settings\Administrator VSL=C:\PVSW\BIN windir=C:\WINDOWS winsbprogramdir=C:\Program Files\Windows for Small Business Server -- User Profiles --------------------------------------------------------------- katie [I](new local, admin, net ready)[/I] lynn [I](admin)[/I] pcad [I](admin)[/I] efitchett [I](admin)[/I] Administrator [I](admin)[/I] -- Add/Remove Programs --------------------------------------------------------- --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{99445080-D411-11D3-A31A-0090270F380F}\setup.exe" --> rundll32.exe setupapi.dll,InstallHinfSection DefaultUninstall 132 C:\WINDOWS\INF\PCHealth.inf Accounting Server --> MsiExec.exe /X{81491026-A6A2-4EA3-BA18-F373E2AC541A} Adaptec Storage Manager --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{B6131A80-CAAB-11D3-8246-00C0DFE13AD2}\setup.exe" Adobe Reader 7.1.0 --> MsiExec.exe /I{AC76BA86-7AD7-1033-7B44-A71000000002} AMS --> MsiExec.exe /X{0DF7F3F5-5B15-44b8-B5C6-0C81B955A428} APC PowerChute Business Edition Agent --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{BCE9F441-9027-4911-82E0-5FB28057897D}\setup.exe" -l0x9 AnyText APC PowerChute Business Edition Console --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{0F86FD09-BA63-4E45-A70B-604C1106C2F2}\setup.exe" -l0x9 AnyText APC PowerChute Business Edition Server --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{A6491A4A-AAA0-4892-BFEF-ECD6CECE2FF3}\setup.exe" -l0x9 AnyText BuilderMT - Workflow Management Suite Server Install --> D:\PROGRA~1\TIMBER~1\BUILDE~1\BUILDE~1\UNWISE.EXE D:\PROGRA~1\TIMBER~1\BUILDE~1\BUILDE~1\WMSSER~1.LOG Cac7 --> C:\ClientApps\CAC7\Uninstaller.exe CCleaner (remove only) --> "C:\Program Files\CCleaner\uninst.exe" CodeTwo Exchange Rules --> MsiExec.exe /I{8C78A92C-8406-490F-BAEB-FF6E501AB9FF} Crystal XI Runtime --> MsiExec.exe /I{B53E9ED4-20A7-4A0A-ACA0-C434BEC99D38} CrystalPatch --> MsiExec.exe /I{4DD0C9EE-0342-461A-9354-47F44860F651} Device drivers for removable storage --> C:\WINDOWS\system32\DRVWUNIN.exe /DELCDB Easysoft JDBC-ODBC Bridge --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Easysoft\Easysoft JDBC-ODBC Bridge\Uninst.isu" -c"C:\Program Files\Easysoft\Easysoft JDBC-ODBC Bridge\esjun.dll" Exchange SDK Development Tools --> MsiExec.exe /I{48F2931F-6275-4E98-8F9C-2200BC3968DE} Firebird .NET Data Provider 2.0.1 (.NET 2.0) --> "C:\Program Files\FirebirdClient\Uninstall.exe" "C:\Program Files\FirebirdClient\install.log" HijackThis 2.0.2 --> "C:\Program Files\Trend Micro\HijackThis\HijackThis.exe" /uninstall Hotfix 2050 for SQL Server 2000 ENU (KB948110) --> "C:\WINDOWS\$SQLUninstallSQL2000-KB948110-v8.00.2050-x86-ENU$\spuninst\spuninst.exe" Ipswitch WS_FTP Professional 2007 --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\PROFES~1\RunTime\11\50\Intel32\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{AD88355B-A4E0-4DA1-BAC3-EA4FEA930691}\setup.exe" -l0x9 -removeonly J2SE Runtime Environment 5.0 Update 6 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0150060} Java 2 Runtime Environment Standard Edition v1.2.2 --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\JavaSoft\JRE\1.2\Uninst.isu" Java(TM) 6 Update 2 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160020} Java(TM) 6 Update 3 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160030} Java(TM) 6 Update 5 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160050} Java(TM) SE Runtime Environment 6 Update 1 --> MsiExec.exe /I{3248F0A8-6813-11D6-A77B-00B0D0160010} Keyfinder Package Trial --> C:\WINDOWS\Keyfinder Package Trial Uninstaller.exe LiveReg (Symantec Corporation) --> C:\Program Files\Common Files\Symantec Shared\LiveReg\VcSetup.exe /REMOVE LiveUpdate 2.6 (Symantec Corporation) --> C:\Program Files\Symantec\LiveUpdate\LSETUP.EXE /U Local Port Scanner v1.2.2 --> "C:\Program Files\LPS\unins000.exe" Macromedia Flash Player 8 --> RunDll32 advpack.dll,LaunchINFSection C:\WINDOWS\INF\swflash.inf,DefaultUninstall,5 Microsoft .NET Framework 1.1 -- Device Update 4.0 --> MsiExec.exe /X{A34AC564-B4A3-4D45-B969-403BC39F0E6A} Microsoft .NET Framework 2.0 Service Pack 1 --> MsiExec.exe /I{B508B3F1-A24A-32C0-B310-85786919EF28} Microsoft Data Access Components KB870669 --> C:\WINDOWS\muninst.exe C:\WINDOWS\INF\KB870669.inf Microsoft Easy Assist --> MsiExec.exe /I{4FC19392-E4A5-4CCB-B45A-AB7E8126D3C9} Microsoft Exchange Server Best Practices Analyzer Tool --> MsiExec.exe /X{BB61AAF2-11B9-404D-938A-91AFD145BC02} Microsoft Group Policy Management Console with SP1 --> MsiExec.exe /I{CA3553E0-191B-4E2F-AD3C-82E33CB9D4E4} Microsoft Health Monitor 2.1 --> "C:\WINDOWS\system32\WBEM\HealthMonitor\UNINSTAL.EXE" "C:\WINDOWS\system32\WBEM\HealthMonitor\INSTALL.LOG" "Microsoft Health Monitor 2.1 Uninstall" Microsoft Office Excel Viewer 2003 --> MsiExec.exe /I{90840409-6000-11D3-8CFE-0150048383C9} Microsoft Outlook Web Access Administration Tool --> MsiExec.exe /X{B7979C15-E2A5-4738-B1FF-386640E8FB4A} Microsoft SQL Server Desktop Engine --> MsiExec.exe /X{689404D2-1C94-44B3-9203-BEC5594FDA7A} Microsoft SQL Server Desktop Engine (BKUPEXEC) --> MsiExec.exe /X{E09B48B5-E141-427A-AB0C-D3605127224A} Microsoft SQL Server Desktop Engine (SBSMonitoring) --> MsiExec.exe /X{B7300824-E68F-45F1-BAC1-5F15636C346F} Microsoft SQL Server Desktop Engine (SHAREPOINT) --> MsiExec.exe /X{65657C59-23A8-4974-B8E0-BA04EBD04E4F} Microsoft Windows SharePoint Services 2.0 --> MsiExec.exe /I{91140409-7000-11D3-8CFE-0150048383C9} MightyFax --> C:\PROGRA~1\MIGHTY~1\UnMighty.EXE MSXML 4.0 SP2 (KB927978) --> MsiExec.exe /I{37477865-A3F1-4772-AD43-AAFC6BCFF99F} MSXML 4.0 SP2 (KB936181) --> MsiExec.exe /I{C04E32E0-0416-434D-AFB9-6969D703A9EF} NVIDIA Drivers --> C:\WINDOWS\system32\nvudisp.exe UninstallGUI Peachtree Premium Accounting 2005 --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\7\INTEL3~1\IDriver.exe /M{97B7F6A8-266B-4CCF-BE08-64263F2B4381} Pervasive System Analyzer --> C:\WINDOWS\IsUninst.exe -f"C:\Program Files\Common Files\Pervasive Software Shared\PSA\psa.isu" Pervasive.SQL NT Server v8.10 --> C:\WINDOWS\IsUninst.exe -fC:\PVSW\DeIsL1.isu -a -c"C:\PVSW\W32PTKUN.DLL" -mpsql.mif -ppNTSRV Sage Timberline Estimating --> C:\PROGRA~1\COMMON~1\INSTAL~1\Driver\11\INTEL3~1\IDriver.exe /M{891C9EDF-2D84-441B-94B6-53106F903C52} Security Update for CAPICOM (KB931906) --> MsiExec.exe /I{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for CAPICOM (KB931906) --> MsiExec.exe /X{0EFDF2F9-836D-4EB7-A32D-038BD3F1FB2A} Security Update for Exchange Server 2003 (KB912442) --> "C:\WINDOWS\$ExchUninstallKB912442$\spuninst\spuninst.exe" Security Update for Exchange Server 2003 (KB916803) --> "C:\WINDOWS\$ExchUninstallKB916803$\spuninst\spuninst.exe" Security Update for Exchange Server 2003 (KB931832) --> "C:\WINDOWS\$ExchUninstallKB931832$\spuninst\spuninst.exe" Security Update for Exchange Server 2003 (KB950159) --> "C:\WINDOWS\$ExchUninstallKB950159$\spuninst\spuninst.exe" Sentinel LM 7.3.0.2 Server --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\Ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{2A5B8F47-5B1E-4D56-BAB9-8C188950B64B}\Setup.exe" Sentinel LM Server 8.0.2 --> MsiExec.exe /I{CFB49CBA-62E6-4949-8179-85F68149847E} Sentinel Protection Installer 7.1.1 --> MsiExec.exe /I{D2E7A6EA-5853-426A-920D-12F4F250927E} Stamps.com --> C:\PROGRA~1\STAMPS~1.COM\Uninst.exe C:\PROGRA~1\STAMPS~1.COM\UNWISE.EXE C:\PROGRA~1\STAMPS~1.COM\INSTALL.LOG Supero Doctor III --> RunDll32 C:\PROGRA~1\COMMON~1\INSTAL~1\engine\6\INTEL3~1\ctor.dll,LaunchSetup "C:\Program Files\InstallShield Installation Information\{79918EFC-5E93-4798-A8F6-F43851D01456}\setup.exe" Symantec AntiVirus --> MsiExec.exe /I{46B63F23-2B4A-4525-A827-688026BE5E40} Symantec AntiVirus Quarantine Console Snap-in --> MsiExec.exe /X{86A46236-C44B-4217-81E9-6B691C82E1DD} Symantec pcAnywhere --> MsiExec.exe /I{D05E8183-866A-11D3-97DF-0000F8D8F2E9} Symantec System Center --> MsiExec.exe /I{A502B8B6-5601-4DE7-B0E4-2A52641DD3C7} Symantec System Center --> MsiExec.exe /I{A502B8B6-5601-4DE7-B0E4-2A52641DD3C7} U.S. Robotics V.92 PCI Faxmodem --> C:\Program Files\CONEXANT\USR_MODEM_PCI_VEN_14F1&DEV_2F30&SUBSYS_200014F1\HXFSETUP.EXE -U -IVEN_14F1&DEV_2F30&SUBSYS_200014F1&REV_01 Update for Exchange Server 2003 (KB924334) --> "C:\WINDOWS\$ExchUninstallKB924334$\spuninst\spuninst.exe" Update for Exchange Server 2003 (KB926666) --> "C:\WINDOWS\$ExchUninstallKB926666$\spuninst\spuninst.exe" Update for Windows SBS 2003 (KB891193) --> Update for Windows Small Business Server 2003 (KB926505) --> "C:\WINDOWS\$NtUninstallKB926505$\spuninst\spuninst.exe" User Profile Hive Cleanup Service --> MsiExec.exe /I{FF77941A-2BFA-4A18-BE2E-69B9498E4D55} VERITAS Backup Exec for Windows Servers --> C:\WINDOWS\Installer\{201E698C-B88E-41AE-8C46-3BBACADCD6E7}\setup.exe /X VERITAS Backup Exec for Windows Servers --> MsiExec.exe /X{201E698C-B88E-41AE-8C46-3BBACADCD6E7} VERITAS Device Driver Install --> MsiExec.exe /X{94855341-3D77-4C89-8BD4-A5A97C38298F} VERITAS Update --> MsiExec.exe /I{EFE295A9-C617-4ECE-A191-14265F5BD7ED} Windows Live OneCare safety scanner --> RunDll32.exe "C:\Program Files\Windows Live Safety Center\wlscCore.dll",UninstallFunction WLSC_SCANNER_PRODUCT Windows Resource Kit Tools --> MsiExec.exe /I{FA237125-51FF-408C-8BB8-30C2B3DFFF9C} Windows Server 2003 Service Pack 1 --> C:\WINDOWS\$NtServicePackUninstall$\spuninst\spuninst.exe Windows Small Business Server 2003 --> C:\Program Files\Microsoft Integration\Windows Small Business Server 2003\setup.exe Windows Small Business Server 2003 Hotfix - KB 833992 --> "C:\WINDOWS\$NtUninstallKB833992$\spuninst\spuninst.exe" Windows Small Business Server 2003 Hotfix - KB 835734 --> "C:\WINDOWS\$NtUninstallKB835734$\spuninst\spuninst.exe" Windows Small Business Server 2003 Hotfix - KB 872769 --> Windows Small Business Server 2003 Hotfix - KB 884032 --> Windows Small Business Server 2003 Service Pack 1 --> -- Application Event Log ------------------------------------------------------- Event Record #/Type7622 / Error Event Submitted/Written: 07/20/2008 04:58:33 PM Event ID/Source: 2114 / MSExchangeDSAccess Event Description: Process INETINFO.EXE (PID=996). Topology Discovery failed, error 0x800706ba. For more information, click http://www.microsoft.com/contentredirect.asp. Event Record #/Type7621 / Error Event Submitted/Written: 07/20/2008 04:57:33 PM Event ID/Source: 2114 / MSExchangeDSAccess Event Description: Process INETINFO.EXE (PID=996). Topology Discovery failed, error 0x800706ba. For more information, click http://www.microsoft.com/contentredirect.asp. Event Record #/Type7620 / Error Event Submitted/Written: 07/20/2008 04:56:33 PM Event ID/Source: 2114 / MSExchangeDSAccess Event Description: Process INETINFO.EXE (PID=996). Topology Discovery failed, error 0x800706ba. For more information, click http://www.microsoft.com/contentredirect.asp. Event Record #/Type7619 / Error Event Submitted/Written: 07/20/2008 04:55:48 PM Event ID/Source: 1053 / Userenv Event Description: Windows cannot determine the user or computer name. (The RPC server is unavailable. ). Group Policy processing aborted. Event Record #/Type7618 / Error Event Submitted/Written: 07/20/2008 04:55:33 PM Event ID/Source: 2114 / MSExchangeDSAccess Event Description: Process INETINFO.EXE (PID=996). Topology Discovery failed, error 0x800706ba. For more information, click http://www.microsoft.com/contentredirect.asp. -- Security Event Log ---------------------------------------------------------- No Errors/Warnings found. -- System Event Log ------------------------------------------------------------ Event Record #/Type2400 / Warning Event Submitted/Written: 07/20/2008 09:21:05 PM Event ID/Source: 1011 / W3SVC Event Description: A process serving application pool 'ExchangeApplicationPool' suffered a fatal communication error with the World Wide Web Publishing Service. The process id was '4080'. The data field contains the error number. Event Record #/Type2399 / Warning Event Submitted/Written: 07/20/2008 09:16:43 PM Event ID/Source: 1011 / W3SVC Event Description: A process serving application pool 'ExchangeApplicationPool' suffered a fatal communication error with the World Wide Web Publishing Service. The process id was '5480'. The data field contains the error number. Event Record #/Type2391 / Warning Event Submitted/Written: 07/20/2008 04:38:48 PM Event ID/Source: 3019 / MRxSmb Event Description: \Device\LanmanRedirectorDOWNEYNetbiosSmb%%22 Event Record #/Type2390 / Warning Event Submitted/Written: 07/20/2008 04:38:48 PM Event ID/Source: 3019 / MRxSmb Event Description: \Device\LanmanRedirectorDOWNEYNetbiosSmb%%22 Event Record #/Type2387 / Error Event Submitted/Written: 07/20/2008 03:55:19 PM Event ID/Source: 1011 / SBCore Event Description: Multiple domain controllers running Windows Server 2003 for Small Business Server have been detected in your domain. To prevent this computer from shutting down in the future, you must remove all but one of these from the domain. -- End of Deckard's System Scanner: finished at 2008-07-21 00:53:23 ------------