RE: Startup Message





"Scott" wrote:

Hi,
Please try these cleaning steps before trying the troubleshooting below:
Go through these Cleaning steps:
1... First, try to clean up your caches, Internet files and delete cookies
by doing this:
Click Start >> Control Panel >> Double click Network and Internet
Connections >> Double click Internet Options.
On the IE properties windows you will see these Tabs:
General | Security | Privacy | Content | Connections | Programs |
Advanced
Under General Tab clear your History, Internet Files and Cookies.
Then click on Advanced tab and scroll down to under the Browsing Option:
[&] Browsing
[ ] Enable Third-Party browser extensions (Req Rest) uncheck this box.
Then click on Programs Tab and click Manage Add-Ons and Disable all non
Verified Add-Ons (You should Renable them later one-by-one and see the
culprit and update it or remove it.
How to manage Add-Ons:
http://support.microsoft.com/kb/883256
Scan for malware from here:
SuperAntispyware - Free
http://www.superantispyware.com/superantispywarefreevspro.html

Run a scan from here on-line:
http://security.symantec.com/sscv6/default.asp?langid=ie&venid=sym
http://www3.ca.com/securityadvisor/virusinfo/scan.aspx
Download Avast Cleaner (offline scanner) from here:
http://www.avast.com/eng/avast-virus-cleaner.html

Lots of tools to download and disinfect your machine (offline scanner):
http://www.bitdefender.co.uk/site/Downloads/browseFreeRemovalTool/

After the scan run disk cleanup on your drive.

Open a run command and type in:
ipconfig /flushdns click [OK]
ipconfig /renew click [OK]
netsh winsock reset click [OK]
Reboot your machine and see if your connection will behave itself and the
access and download from the Internet is also okay.
Or tey this tool for winsock fix:
http://www.nasstec.co.uk/tools.html
Download it and execute and it will prompt you to Restart your machine
please do so.


Black Viper's Top tweaks for a faster PC
http://www.blackviper.com/WinXP/supertweaks.htm

StartupList Index
http://www.castlecops.com/StartupList.html



APPLICATION

1.
Event Type: Error
Event Source: comHost
Event Category: None
Event ID: 65535
Date: 1/19/2008
Time: 1:03:10 PM
User: N/A
Computer: SCOTT123
Description:
The description for Event ID ( 65535 ) in Source ( comHost ) cannot be
found. The local computer may not have the necessary registry information or
message DLL files to display messages from a remote computer. You may be able
to use the /AUXSOURCE= flag to retrieve this description; see Help and
Support for details. The following information is part of the event: Cannot
get Components key from ccSettings Manager.Is it really there? Error code:
0x80000205.

Do you have Norton AV installed adn is it up2date and current?.
COM Host (comHost) - Symantec Corporation - C:\Program Files\Norton Internet
Security\comHost.exe

================================================================================================
2.
Event Type: Error
Event Source: Microsoft Office 12
Event Category: None
Event ID: 1000
Date: 1/9/2008
Time: 12:07:43 PM
User: N/A
Computer: SCOTT123
Description:
Faulting application winword.exe, version 12.0.6211.1000, stamp 46d4a7df,
faulting module kernel32.dll, version 5.1.2600.3119, stamp 46239bd5, debug?
0, fault address 0x00012a5b.

Try to Repair/Install Office by going to the Add/Remove and click on Remove
button. Three options will show up one of them Repair select repsir to repair
office.

Problems opening Word
http://word.mvps.org/FAQs/AppErrors/ProbsOpeningWord.htm

http://www.eventid.net/display.asp?eventid=1000&eventno=984&source=Microsoft%20Office%2010&phase=1

http://www.microsoft.com/communities/newsgroups/en-us/default.aspx?dg=microsoft.public.word.application.errors&tid=3a29ac55-d827-4c9d-aa03-9030dd554998&p=1

====================================================================================================================
3.
Event Type: Error
Event Source: crypt32
Event Category: None
Event ID: 8
Date: 12/22/2007
Time: 10:22:56 AM
User: N/A
Computer: SCOTT123
Description:
Failed auto update retrieval of third-party root list sequence number from:
<http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootseq.txt>
with error: This operation returned because the timeout period expired.

Event ID 8 is logged in the Application log
http://support.microsoft.com/kb/317541

================================================================================================
SECURITY (FAILURE AUDIT)

1.
Event Type: Failure Audit
Event Source: Security
Event Category: Logon/Logoff
Event ID: 529
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon Failure:
Reason: Unknown user name or bad password
User Name: j scott
Domain: SCOTT123
Logon Type: 2
Logon Process: User32
Authentication Package: Negotiate
Workstation Name: SCOTT123

Kerberos Event ID: 529 is logged when you use a local user account to verify
security access or group membership on a Windows Server 2003-based Kerberos
client
http://support.microsoft.com/kb/811082
http://support.microsoft.com/kb/890477

http://www.eventid.net/display.asp?eventid=529&eventno=1&source=Security&phase=1

====================================================================================================
2.
Event Type: Failure Audit
Event Source: Security
Event Category: Account Logon
Event ID: 680
Date: 1/20/2008
Time: 12:50:59 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
Logon attempt by: MICROSOFT_AUTHENTICATION_PACKAGE_V1_0
Logon account: j scott
Source Workstation: SCOTT123
Error Code: 0xC000006A

In Windows Server 2003, a random extra character appears at the end of the
Source Workstation field in event ID 680
http://support.microsoft.com/kb/936182
Failure Events Are Logged When the Welcome Screen Is Enabled
http://support.microsoft.com/?kbid=305822
http://technet2.microsoft.com/windowsserver2008/en/library/18b28a83-3822-4084-8ddb-df01cdab9b261033.mspx?mfr=true
http://www.eventid.net/display.asp?eventid=680&eventno=2267&source=Security&phase=1
=====================================================================================================
SYSTEM

1.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7000
Date: 1/20/2008
Time: 12:54:22 PM
User: N/A
Computer: SCOTT123
Description:
The PCAMPR5 NDIS Protocol Driver service failed to start due to the
following error:
The system cannot find the file specified.

PCAMPR5 NDIS is referring to a wireless adapter which is your NIC?.

"Event ID: 7000" or "Event ID: 7013" Error Message When You Attempt to Start
a Service
http://support.microsoft.com/kb/314357
=======================================================================================
2.
Event Type: Error
Event Source: sr
Event Category: None
Event ID: 1
Date: 1/20/2008
Time: 12:50:17 PM
User: N/A
Computer: SCOTT123
Description:
The System Restore filter encountered the unexpected error '0xC0000034'
while processing the file '_filelst.cfg' on the volume 'HarddiskVolume2'. It
has stopped monitoring the volume.


http://bertk.mvps.org/html/error.html
How to Disable and Enable System Restore in Windows XP
http://bertk.mvps.org/html/disablesr.html
http://bertk.mvps.org/html/drivedisable.html
======================================================================================
3.

Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7034
Date: 1/19/2008
Time: 1:16:25 PM
User: N/A
Computer: SCOTT123
Description:
The LiveUpdate service terminated unexpectedly. It has done this 1 time(s).

Run the LiveUpdate manually for the software.
https://forums.symantec.com/syment/board/message?board.id=115&thread.id=19135
======================================================================================

4.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7009
Date: 1/19/2008
Time: 1:15:59 PM
User: N/A
Computer: SCOTT123
Description:
Timeout (30000 milliseconds) waiting for the LiveUpdate service to connect.

http://service1.symantec.com/SUPPORT/sharedtech.nsf/d3c44a1678bd8f45852566aa005902cb/2fbcfd593d25210988256e2000757d35?OpenDocument&src=bar_sch_nam
============================================================================================================
5.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10005
Date: 1/19/2008
Time: 1:15:46 PM
User: NT AUTHORITY\SYSTEM
Computer: SCOTT123
Description:
DCOM got error "The service did not respond to the start or control request
in a timely fashion. " attempting to start the service LiveUpdate with
arguments "" in order to run the server:
{0D4C11A3-6BD0-11D3-B542-00902771A435}

This for Norton anti-virus. Does your version is up2date and current?.
http://www.eventid.net/display.asp?eventid=10005&eventno=612&source=dcom&phase=1
===============================================================
6.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7023
Date: 1/19/2008
Time: 1:03:56 PM
User: N/A
Computer: SCOTT123
Description:
The COM Host service terminated with the following error:
Catastrophic failure


http://support.microsoft.com/kb/892501

http://www.eventid.net/display.asp?eventid=7023&eventno=345&source=Service%20Control%20Manager&phase=1
======================================================================================================
7.
Event Type: Error
Event Source: DCOM
Event Category: None
Event ID: 10010
Date: 1/15/2008
Time: 7:16:05 PM
User: SCOTT123\j scott
Computer: SCOTT123
Description:
The server {0002DF01-0000-0000-C000-000000000046} did not register with DCOM
within the required timeout.

http://www.eventid.net/display.asp?eventid=10010+

==========================================================================================================
8.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7031
Date: 1/9/2008
Time: 12:07:17 PM
User: N/A
Computer: SCOTT123
Description:
The Print Spooler service terminated unexpectedly. It has done this 1
time(s). The following corrective action will be taken in 60000
milliseconds: Restart the service.

The Print Spooler service stops frequently, Dr. Watson logs an error message,
http://support.microsoft.com/kb/888196
============================================================================================================
9.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1001
Date: 1/6/2008
Time: 12:17:16 PM
User: N/A
Computer: SCOTT123
Description:
Your computer was not assigned an address from the network (by the DHCP
Server) for the Network Card with network address 0004E27C4906. The
following error occurred:
The operation was canceled by the user. . Your computer will continue to try
and obtain an address on its own from the network address (DHCP) server.

Event ID 1001 — DHCP Client Lease Validity
http://technet2.microsoft.com/windowsserver2008/en/library/d24302c4-0bb4-49e4-92be-aabad0f45d6d1033.mspx?mfr=true

How to use automatic TCP/IP addressing without a DHCP server
http://support.microsoft.com/kb/220874

=============================================================================================================
10.
Event Type: Error
Event Source: Application Popup
Event Category: None
Event ID: 877
Date: 1/5/2008
Time: 9:46:00 AM
User: N/A
Computer: SCOTT123
Description:
There was error [DATABASE OPEN FAILED] processing the driver database.

http://www.windowsbbs.com/showthread.php?t=36682
http://www.eventid.net/display.asp?eventid=877&eventno=1992&source=Application%20Popup&phase=1
============================================================================================================

11.
Event Type: Error
Event Source: Dhcp
Event Category: None
Event ID: 1002
Date: 12/27/2007
Time: 3:30:50 PM
User: N/A
Computer: SCOTT123
Description:
The IP address lease 64.195.65.187 for the Network Card with network address
0007E95E0E3F has been denied by the DHCP server 192.168.1.1 (The DHCP Server
sent a DHCPNACK message).

Your machine should get an Ip address in the range of 192.168.1.X not
64.195.X.X?.
Try to make sure the machine get an Auto IP address from the DHCP (which is
your router).

DHCP Event ID 1002: DHCP Received an Unknown Option 006 of Length 007
http://support.microsoft.com/kb/q181024/

===============================================================================================================

12.
Event Type: Error
Event Source: Service Control Manager
Event Category: None
Event ID: 7026
Date: 12/26/2007
Time: 11:40:14 AM
User: N/A
Computer: SCOTT123
Description:
The following boot-start or system-start driver(s) failed to load:
SYMTDI

DHCP Client Initializes Improperly and Causes an Invalid IP Address
http://support.microsoft.com/kb/812335

Good luck.
nass
----
http://www.nasstec.co.uk

.