makingithappen
asked on
all machines in a network freezing
This is probably the trickiest issue I've ever come across so lots of good karma coming your way if you help me resolve.
OK, we have 4 notebooks in a network, all of them are different hardware spec, bought at different times.
They all keep freezing intermittently. I don't just mean a crash, I mean they just freeze, no mouse activity, no warnings, no error messages in event log. The only way to recover is to power off the machine and reboot.
They share this in common:
-Run Windows XP SP3 (recently updated from previous service packs)
-All connect to a Windows SBS Server 2003 (the server was recently upgraded but the issue began over a year ago)
-All run Office 2007 (recently upgraded from 2003 but the issue existed before this)
-Running McAfee Antivirus (but the issue was occurring prior to this, before this they were running Trend Micro)
The entire network is new, as we began to suspect the problem was network related, so we replaced the switch, router and server earlier in the year (after the problems began).
We've removed all common software that they don't need such as an instant messaging program that they all used.
The freezes happen randomly, though recently i've been advised it tends to happen when saving a document such as Excel or Word.
The freezes happen both when they are inside the network, or externally, though it's not established if they are connected to the VPN at the time.
2 of the machines were completely replaced under hardware warranty, our initial thought was this is probably RAM but that's not the case, as all have had the RAM removed and had new modules installed from a different source.
Lastly, the issue is now happening to a brand new machine that has only been introduced into the network in the past 2 weeks.
As you can see, this has been an ongoing drama for some time and it would be brilliant to know if anybody has experienced and resolved a similar problem before.
Appreciated.
OK, we have 4 notebooks in a network, all of them are different hardware spec, bought at different times.
They all keep freezing intermittently. I don't just mean a crash, I mean they just freeze, no mouse activity, no warnings, no error messages in event log. The only way to recover is to power off the machine and reboot.
They share this in common:
-Run Windows XP SP3 (recently updated from previous service packs)
-All connect to a Windows SBS Server 2003 (the server was recently upgraded but the issue began over a year ago)
-All run Office 2007 (recently upgraded from 2003 but the issue existed before this)
-Running McAfee Antivirus (but the issue was occurring prior to this, before this they were running Trend Micro)
The entire network is new, as we began to suspect the problem was network related, so we replaced the switch, router and server earlier in the year (after the problems began).
We've removed all common software that they don't need such as an instant messaging program that they all used.
The freezes happen randomly, though recently i've been advised it tends to happen when saving a document such as Excel or Word.
The freezes happen both when they are inside the network, or externally, though it's not established if they are connected to the VPN at the time.
2 of the machines were completely replaced under hardware warranty, our initial thought was this is probably RAM but that's not the case, as all have had the RAM removed and had new modules installed from a different source.
Lastly, the issue is now happening to a brand new machine that has only been introduced into the network in the past 2 weeks.
As you can see, this has been an ongoing drama for some time and it would be brilliant to know if anybody has experienced and resolved a similar problem before.
Appreciated.
ASKER CERTIFIED SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
Oh, it's related to Office. MPECSInc probably got it...
ASKER
ok i'll try office but i'm not so sure. The reason being is that the staff were all running 2003, and we recently upgraded their machines to 2007.
OK so maybe some settings have come along to the 2007 party but, that doesn't explain the new PC having an identical issue.
Willing to try anything at this stage!!
OK so maybe some settings have come along to the 2007 party but, that doesn't explain the new PC having an identical issue.
Willing to try anything at this stage!!
Depending on your Active Directory setup and how Office was delivered to the workstations, anything is possible.
I have seen some pretty funky behaviours in Office 2003/7 that were related to plug-ins/add-ins and the like causing all sorts of havoc.
You may need to download SysInternal's ProcessExplorer and Network Monitor to get a better idea of what is causing the problem too.
Philip
I have seen some pretty funky behaviours in Office 2003/7 that were related to plug-ins/add-ins and the like causing all sorts of havoc.
You may need to download SysInternal's ProcessExplorer and Network Monitor to get a better idea of what is causing the problem too.
Philip
How you are deliverying Office to the PC's? Remove Office completely from a PC and install from a CD/DVD.
Also place a PC into an OU in Active Directory with no Group Policies.
Also place a PC into an OU in Active Directory with no Group Policies.
what network do you use? wired or wireless ? if wireless, you may have radiation around causing the problems.
or it can simply be bad AC, making the router (or network hardware) loosing it's breath
ASKER
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:11:55 AM, on 13/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e xe
C:\WINDOWS\system32\winlog on.exe
C:\WINDOWS\system32\servic es.exe
C:\WINDOWS\system32\lsass. exe
C:\WINDOWS\system32\svchos t.exe
C:\WINDOWS\System32\svchos t.exe
C:\WINDOWS\system32\spools v.exe
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
C:\Program Files\Bonjour\mDNSResponde r.exe
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Kaseya\Agent\AgentMo n.exe
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Optus\Connect\BMip\b in\MipCfgS rv.exe
C:\Program Files\Optus\Connect\BMip\b in\MipServ ice.exe
C:\WINDOWS\system32\svchos t.exe
C:\Program Files\RealVNC\VNC4\WinVNC4 .exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtr ay.exe
C:\WINDOWS\system32\hkcmd. exe
C:\WINDOWS\system32\igfxsr vc.exe
C:\WINDOWS\system32\igfxpe rs.exe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynT PEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Kaseya\Agent\KaUsrTs k.exe
C:\Program Files\Hewlett-Packard\Shar ed\hpqWmiE x.exe
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper. exe
C:\WINDOWS\system32\ctfmon .exe
C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
C:\Program Files\Picasa2\PicasaMediaD etector.ex e
C:\program files\reuters\rmc\RunRM.ex e
C:\Program Files\Skype\Phone\Skype.ex e
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Optus\Connect\BMip\b in\MipCont roller.exe
C:\Program Files\Optus\Connect\AutoUp dateSrv.ex e
C:\Program Files\iPod\bin\iPodService .exe
c:\program files\reuters\rmc\rmc.exe
C:\Program Files\Hewlett-Packard\Shar ed\HpqToas ter.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EX E
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ ice.exe
C:\Program Files\Internet Explorer\iexplore.exe
c:\OnsightTMP\KRlyCLis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\TanM\Desktop\HiJa ckThis.exe
C:\Program Files\Trend Micro\HijackThis\HijackThi s.exe
R0 - HKCU\Software\Microsoft\In ternet Explorer\Main,Start Page = http://d-cyphatrade.com.au/
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Page _URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Default_Sear ch_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\In ternet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\In ternet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Wi ndows\Curr entVersion \Internet Settings,ProxyOverride = *.local;<local>
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7 84B7D6BE0B 3} - C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEHe lper.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F A578C2EBDC 3} - C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEHe lperShim.d ll
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A 0F997BA588 C} - C:\Program Files\Skype\Toolbars\Inter net Explorer\SkypeIEPlugin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C F10577473F 7} - c:\program files\google\googletoolbar 1.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0 445EE16191 0} - C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C E66B5AD205 D} - C:\Program Files\Google\GoogleToolbar Notifier\3 .1.807.174 6\swg.dll
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-6 65D8EE6A07 7} - C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0 819E2EAAC9 3} - C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0 09027A5CD4 F} - c:\program files\google\googletoolbar 1.dll
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr ay.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd. exe
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe rs.exe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe /tray
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT PEnh.exe
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs ync.exe /logon
O4 - HKLM\..\Run: [Kaseya Agent Service Helper] C:\Program Files\Kaseya\Agent\KaUsrTs k.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe "
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe " -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper. exe"
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon .exe
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar Notifier\G oogleToolb arNotifier .exe
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD etector.ex e
O4 - HKCU\..\Run: [RMC] c:\program files\reuters\rmc\RunRM.ex e
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex e" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON .EXE (User 'Default user')
O4 - Global Startup: Add Mobile IP Profile.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Mobile IP Controller.lnk = ?
O4 - Global Startup: Update Agent.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l/AcroIEAp pendSelLin ks.html
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l/AcroIEAp pend.html
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l/AcroIECa ptureSelLi nks.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active X\AcroIEFa vClient.dl l/AcroIECa pture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3 \Office12\ EXCEL.EXE/ 3000
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D 32B190E9B0 7} - C:\Program Files\Skype\Toolbars\Inter net Explorer\SkypeIEPlugin.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3 C9C571A826 3} - C:\PROGRA~1\MICROS~3\Offic e12\REFIEB AR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f 2ba3849658 3} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0 0C04F79568 3} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {474F00F5-3853-492C-AC3A-4 76512BBC33 6} (UploadListView Class) - http://picasaweb.google.com.au/s/v/e/38.05/57go2Ejy5T0/uploader2.cab
O17 - HKLM\System\CCS\Services\T cpip\Param eters: Domain = DCYPHA.local
O17 - HKLM\Software\..\Telephony : DomainName = DCYPHA.local
O17 - HKLM\System\CCS\Services\T cpip\..\{3 6137873-06 DB-4787-98 87-2068FA7 D3014}: NameServer = 61.88.88.88
O17 - HKLM\System\CS1\Services\T cpip\Param eters: Domain = DCYPHA.local
O17 - HKLM\System\CS1\Services\T cpip\..\{3 6137873-06 DB-4787-98 87-2068FA7 D3014}: NameServer = 61.88.88.88
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1 830C7DD7F5 D} - C:\PROGRA~1\COMMON~1\Skype \SKYPE4~1. DLL
O20 - AppInit_DLLs: mdvvsm.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev iceService .exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde r.exe
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ ice.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterServi ce.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shar ed\hpqWmiE x.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver \11\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService .exe
O23 - Service: OnSight (KaseyaAgent) - Kaseya - C:\Program Files\Kaseya\Agent\AgentMo n.exe
O23 - Service: Mobile IP Configuration Server (MipCfgSrv) - Unknown owner - C:\Program Files\Optus\Connect\BMip\b in\MipCfgS rv.exe
O23 - Service: Mobile IP Client Service (MipService) - Unknown owner - C:\Program Files\Optus\Connect\BMip\b in\MipServ ice.exe
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4 .exe
--
End of file - 10499 bytes
Scan saved at 11:11:55 AM, on 13/11/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.5730.0013)
Boot mode: Normal
Running processes:
C:\WINDOWS\System32\smss.e
C:\WINDOWS\system32\winlog
C:\WINDOWS\system32\servic
C:\WINDOWS\system32\lsass.
C:\WINDOWS\system32\svchos
C:\WINDOWS\System32\svchos
C:\WINDOWS\system32\spools
C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
C:\Program Files\Bonjour\mDNSResponde
C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
C:\Program Files\Kaseya\Agent\AgentMo
C:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\mdm.exe
C:\Program Files\Optus\Connect\BMip\b
C:\Program Files\Optus\Connect\BMip\b
C:\WINDOWS\system32\svchos
C:\Program Files\RealVNC\VNC4\WinVNC4
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\igfxtr
C:\WINDOWS\system32\hkcmd.
C:\WINDOWS\system32\igfxsr
C:\WINDOWS\system32\igfxpe
C:\Program Files\Analog Devices\Core\smax4pnp.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Synaptics\SynTP\SynT
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe
C:\Program Files\Kaseya\Agent\KaUsrTs
C:\Program Files\Hewlett-Packard\Shar
C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe
C:\Program Files\iTunes\iTunesHelper.
C:\WINDOWS\system32\ctfmon
C:\Program Files\Google\GoogleToolbar
C:\Program Files\Picasa2\PicasaMediaD
C:\program files\reuters\rmc\RunRM.ex
C:\Program Files\Skype\Phone\Skype.ex
C:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exe
C:\Program Files\Optus\Connect\BMip\b
C:\Program Files\Optus\Connect\AutoUp
C:\Program Files\iPod\bin\iPodService
c:\program files\reuters\rmc\rmc.exe
C:\Program Files\Hewlett-Packard\Shar
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EX
C:\Program Files\Microsoft Office\Office12\EXCEL.EXE
C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
C:\Program Files\Internet Explorer\iexplore.exe
c:\OnsightTMP\KRlyCLis.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\TanM\Desktop\HiJa
C:\Program Files\Trend Micro\HijackThis\HijackThi
R0 - HKCU\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R1 - HKLM\Software\Microsoft\In
R0 - HKLM\Software\Microsoft\In
R1 - HKCU\Software\Microsoft\Wi
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-7
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-F
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-C
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0
O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-C
O2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-6
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-0
O4 - HKLM\..\Run: [IgfxTray] C:\WINDOWS\system32\igfxtr
O4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.
O4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpe
O4 - HKLM\..\Run: [SoundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe
O4 - HKLM\..\Run: [SoundMAX] C:\Program Files\Analog Devices\SoundMAX\Smax4.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [Cpqset] C:\Program Files\HPQ\Default Settings\cpqset.exe
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynT
O4 - HKLM\..\Run: [QlbCtrl.exe] C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [Synchronization Manager] %SystemRoot%\system32\mobs
O4 - HKLM\..\Run: [Kaseya Agent Service Helper] C:\Program Files\Kaseya\Agent\KaUsrTs
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "c:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe
O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbar
O4 - HKCU\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaD
O4 - HKCU\..\Run: [RMC] c:\program files\reuters\rmc\RunRM.ex
O4 - HKCU\..\Run: [Skype] "C:\Program Files\Skype\Phone\Skype.ex
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON
O4 - Global Startup: Add Mobile IP Profile.lnk = ?
O4 - Global Startup: Bluetooth.lnk = ?
O4 - Global Startup: Mobile IP Controller.lnk = ?
O4 - Global Startup: Update Agent.lnk = ?
O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active
O8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active
O8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\Active
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-0
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-0
O16 - DPF: {474F00F5-3853-492C-AC3A-4
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\Software\..\Telephony
O17 - HKLM\System\CCS\Services\T
O17 - HKLM\System\CS1\Services\T
O17 - HKLM\System\CS1\Services\T
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1
O20 - AppInit_DLLs: mdvvsm.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDev
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponde
O23 - Service: Bluetooth Service (btwdins) - Broadcom Corporation. - C:\Program Files\WIDCOMM\Bluetooth Software\bin\btwdins.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingServ
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shar
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService
O23 - Service: OnSight (KaseyaAgent) - Kaseya - C:\Program Files\Kaseya\Agent\AgentMo
O23 - Service: Mobile IP Configuration Server (MipCfgSrv) - Unknown owner - C:\Program Files\Optus\Connect\BMip\b
O23 - Service: Mobile IP Client Service (MipService) - Unknown owner - C:\Program Files\Optus\Connect\BMip\b
O23 - Service: VNC Server Version 4 (WinVNC4) - RealVNC Ltd. - C:\Program Files\RealVNC\VNC4\WinVNC4
--
End of file - 10499 bytes
SOLUTION
membership
This solution is only available to members.
To access this solution, you must be a member of Experts Exchange.
ASKER
thanks for the reply.
VNC is built into our MSP software (Kaseya) to manage our client remotely. The rest we'll check out straight away.
Thanks!
VNC is built into our MSP software (Kaseya) to manage our client remotely. The rest we'll check out straight away.
Thanks!
Bummer on the remote management ... do you not use the Remote Web Workplace?
Philip
Philip
ASKER
hi, sorry no we manage quite a few hundred machines and this is how we do it. It can be switched off but this is the enterprise version of the product and we've had no other problems on any other network with it.
In Office 2007, you can click on the jewel then Word/Excel Options down near the Exit button. From there you can click on Add-Ins and manage any add-ins that are there.
Look for software that is no longer installed such as PDF creator type printers and the like. A/V poorly removed could also be the culprit ... yes, even on the new system.
Do you have software delivered to your systems via Group Policy or start up scripts?
Start Excel or Word in Safe Mode for a week on all machines to see if the behaviour disappears. If stability happens, then the problem is definitely somewhere with an add-in.
http://office.microsoft.com/en-gb/word/HP030823931033.aspx
Note the method for starting the program in safe mode.
Philip