Hi Krish,
Here is the ngctw32.log of that machine with client inventory collected successfully. Our machines are identical though. Thanks for your help.
----------------------------------------
C:\Program Files\Symantec\Ghost\ngctw32.exe 11.0.0.1502
11:55:25 AM Thursday, May 17, 2007
11:55:30 AM 10.0.0.1:1346 polling for server named [server name]
11:55:40 AM 10.0.0.1:1346 polling for server named [server name]
11:55:43 AM 10.0.0.1:1346 sending status to [IP address]:1347
11:56:23 AM 10.0.0.1:1346 sending status to [IP address]:1347
11:57:03 AM 10.0.0.1:1346 sending status to [IP address]:1347
11:57:43 AM 10.0.0.1:1346 lost contact with [IP address]:1347
11:58:03 AM 10.0.0.1:1346 polling for bound server [server name
11:58:43 AM 10.0.0.1:1346 polling for bound server [server name
11:58:45 AM 10.0.0.1:1346 sending status to [IP address]:1347
12:00:45 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:02:45 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:04:45 PM 10.0.0.1:1346 lost contact with [IP address]:1347
C:\Program Files\Symantec\Ghost\ngctw32.exe 11.0.0.1502
12:05:18 PM Thursday, May 17, 2007
------------- Shutting down ------------
----------------------------------------
C:\Program Files\Symantec\Ghost\ngctw32.exe 11.0.0.1502
12:05:18 PM Thursday, May 17, 2007
12:05:23 PM 10.0.0.1:1346 polling for bound server [server name]
12:05:33 PM 10.0.0.1:1346 polling for bound server [server name]
12:05:35 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:05:35 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:05:35 PM 10.0.0.1:1346 TCP connecting to [IP address]:1347
Received message Message<Folder>{}
Received message Message<HasGhostBootPartition>{}
Received message Message<Open>{ What = Configuration, Mode = Read }
Checking for Sysprep. Process id: 872, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SMSS.EXE
Checking for Sysprep. Process id: 960, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\CSRSS.EXE
Checking for Sysprep. Process id: 1008, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\WINLOGON.EXE
Checking for Sysprep. Process id: 1076, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SERVICES.EXE
Checking for Sysprep. Process id: 1088, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\LSASS.EXE
Checking for Sysprep. Process id: 1280, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SVCHOST.EXE
Checking for Sysprep. Process id: 1352, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SVCHOST.EXE
Checking for Sysprep. Process id: 1436, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SVCHOST.EXE
Checking for Sysprep. Process id: 1480, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SVCHOST.EXE
Checking for Sysprep. Process id: 1512, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SVCHOST.EXE
Checking for Sysprep. Process id: 1608, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCSETMGR.EXE
Checking for Sysprep. Process id: 1628, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\MIT\KERBEROS\BIN\KRBCC32S.EXE
Checking for Sysprep. Process id: 1660, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCEVTMGR.EXE
Checking for Sysprep. Process id: 1800, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SPOOLSV.EXE
Checking for Sysprep. Process id: 2024, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\BIGFIX ENTERPRISE\BES CLIENT\BESCLIENT.EXE
Checking for Sysprep. Process id: 120, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SYMANTEC ANTIVIRUS\DEFWATCH.EXE
Checking for Sysprep. Process id: 228, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\DELL\OPENMANAGE\CLIENT\IAP.EXE
Checking for Sysprep. Process id: 328, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\MICROSOFT SQL SERVER\MSSQL\BINN\SQLSERVR.EXE
Checking for Sysprep. Process id: 540, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SYMANTEC ANTIVIRUS\RTVSCAN.EXE
Checking for Sysprep. Process id: 716, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SYNCHRONEYES STUDENT 5.1\SYNCHRONEYESSRV.EXE
Checking for Sysprep. Process id: 736, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\OPENAFS\CLIENT\PROGRAM\AFSD_SERVICE.EXE
Checking for Sysprep. Process id: 796, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\WDFMGR.EXE
Checking for Sysprep. Process id: 824, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\WEBROOT\SPY SWEEPER\SPYSWEEPER.EXE
Checking for Sysprep. Process id: 2360, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\ALG.EXE
Checking for Sysprep. Process id: 3024, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\WBEM\WMIPRVSE.EXE
Checking for Sysprep. Process id: 3556, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\EXPLORER.EXE
Checking for Sysprep. Process id: 2288, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\CYBERLINK\POWERDVD\DVDLAUNCHER.EXE
Checking for Sysprep. Process id: 3256, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\COMMON FILES\SYMANTEC SHARED\CCAPP.EXE
Checking for Sysprep. Process id: 3732, name: \DEVICE\HARDDISKVOLUME2\PROGRA~1\SYMANT~1\VPTRAY.EXE
Checking for Sysprep. Process id: 3476, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\ADOBE\ACROBAT 7.0\DISTILLR\ACROTRAY.EXE
Checking for Sysprep. Process id: 3468, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\KEYACC32.EXE
Checking for Sysprep. Process id: 4088, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\HKCMD.EXE
Checking for Sysprep. Process id: 1332, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\IGFXPERS.EXE
Checking for Sysprep. Process id: 3500, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\SPOOL\DRIVERS\W32X86\3\FPPDIS1.EXE
Checking for Sysprep. Process id: 2216, name: \DEVICE\HARDDISKVOLUME2\WINDOWS\SYSTEM32\CTFMON.EXE
Checking for Sysprep. Process id: 3420, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\STANFORD\DESKTOP TOOLS\STANFORD DESKTOP TOOLS.EXE
Checking for Sysprep. Process id: 316, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\MIT\KERBEROS\BIN\NETIDMGR.EXE
Checking for Sysprep. Process id: 180, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\MIT\KERBEROS\BIN\KRBCC32S.EXE
Checking for Sysprep. Process id: 3952, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SYMANTEC\GHOST\NGTRAY.EXE
Checking for Sysprep. Process id: 3736, name: \DEVICE\HARDDISKVOLUME2\PROGRAM FILES\SYMANTEC\GHOST\NGCTW32.EXE
12:05:57 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:05:57 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:06:57 PM 10.0.0.1:1346 TCP connecting to [IP address]:1347
Received message Message<HasGhostBootPartition>{}
Received message Message<WarnShutdown>{ Shutdown = 1, Timeout = 10, Platform = DOS, Cancel = 0 }
12:06:57 PM 10.0.0.1:1346 disconnecting from [IP address]:1347
12:07:17 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:07:17 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:07:17 PM 10.0.0.1:1346 TCP connecting to [IP address]:1347
Received message Message<WarnShutdown>{ Shutdown = 1, Timeout = 10, Platform = DOS, Cancel = 0 }
Received message Message<DoesClientFileExist>{ Name = "GHCONFIG.EXE" }
Received message Message<DoesClientFileExist>{ Name = "GHSTWALK.EXE" }
Received message Message<Open>{ Name = "GHSTWALK.EXE", What = File, Mode = Write }
Received message Message<DoesClientFileExist>{ Name = "GHOST.EXE" }
Received message Message<Open>{ Name = "GHOST.EXE", What = File, Mode = Write }
Received message Message<GetNetworkDriverCRC>{ Name = "incoming\\dos" }
Received message Message<DeleteClientDirectory>{ Name = "incoming\\dos" }
Received message Message<GetNetworkDriverCRC>{ Name = "incoming\\dos" }
Received message Message<Open>{ Name = "incoming\\dos\\IBMDOS.COM", What = File, Mode = Write }
Received message Message<Open>{ Name = "incoming\\dos\\IBMBIO.COM", What = File, Mode = Write }
Received message Message<Open>{ Name = "incoming\\dos\\command.com", What = File, Mode = Write }
Received message Message<Open>{ Name = "incoming\\dos\\bootsect.dat", What = File, Mode = Write }
Received message Message<Open>{ Name = "incoming\\dos\\bootsect-floppy.dat", What = File, Mode = Write }
Received message Message<GetNetworkDriverCRC>{ Name = "incoming\\template" }
Received message Message<DeleteClientDirectory>{ Name = "incoming\\template" }
Received message Message<GetNetworkDriverCRC>{ Name = "incoming\\template" }
Received message Message<Open>{ Name = "incoming\\template\\protocol.ini", What = File, Mode = Write }
Received message Message<Open>{ Name = "incoming\\template\\mcassist.cfg", What = File, Mode = Write }
Received message Message<Open>{ Name = "incoming\\template\\B57.dos", What = File, Mode = Write }
Received message Message<UpdateProtocolIni>{ Name = "incoming\\template/protocol.ini", ServerConnectionDeviceId = "{2550594B-8EC0-436E-A184-5B920E92DC68}" }
Received message Message<Shutdown>{ Name = DOS, VirtualPartitionSize = 20, ServerConnectionDeviceId = "{2550594B-8EC0-436E-A184-5B920E92DC68}", Timeout = 0 }
Received message Message<taskInProgess>{ Cancel = 1 }
Received message Message<PreventLoginTask>{ DisableLogin = 0 }
Received message Message<Shutdown>{ Name = () }
12:07:21 PM 10.0.0.1:1346 disconnecting from [IP address]:1347
12:07:37 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:07:37 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:35:17 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:35:17 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:35:17 PM 10.0.0.1:1346 TCP connecting to [IP address]:1347
Received message Message<HasGhostBootPartition>{}
Received message Message<WarnShutdown>{ Shutdown = 1, Timeout = 10, Platform = DOS, Cancel = 0 }
Received message Message<DoesClientFileExist>{ Name = "GHCONFIG.EXE" }
Received message Message<DoesClientFileExist>{ Name = "GHSTWALK.EXE" }
Received message Message<DoesClientFileExist>{ Name = "GHOST.EXE" }
Received message Message<GetNetworkDriverCRC>{ Name = "incoming\\dos" }
Received message Message<GetNetworkDriverCRC>{ Name = "incoming\\template" }
Received message Message<UpdateProtocolIni>{ Name = "incoming\\template/protocol.ini", ServerConnectionDeviceId = "{2550594B-8EC0-436E-A184-5B920E92DC68}" }
Received message Message<Shutdown>{ Name = DOS, VirtualPartitionSize = 20, ServerConnectionDeviceId = "{2550594B-8EC0-436E-A184-5B920E92DC68}", Timeout = 0 }
12:35:55 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:35:56 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:36:15 PM 10.0.0.1:1346 sending status to [IP address]:1347
12:36:15 PM 10.0.0.1:1346 acknowledged by [IP address]:1347
12:36:35 PM 0.0.0.0:1346 sending status to [IP address]:1347
12:36:35 PM 0.0.0.0:1346 acknowledged by [IP address]:1347
Message Edited by M Q on 06-15-200712:14 PM