Jump to content

uTorrent crashing on Win 2k3


T4ndeta

Recommended Posts

I have been using uTorrent quite long on XP. But I have a big torrent to download, about 60gb, and I started uTorrent on a server with Windows 2003. Before installing SP2 uTorrent was working perfectly, at least it never crashed. But after SP installation I am suffering from random and continues uTorrent crashes. Mostly it happens at start and keep on crushing until i remove setting and start uTorrent manually, but not always. To me it looks like problem with memory allocation or problem with reading data.

Other interesting things: Server is using about 1,4Gb memory but most of it is kept in swap file, so there is always about 100MB of free ram. Another strange thing is that server is making huge amount of I/O operations (saw in ProcessExplorer) from 10MB/s to 100MB/s but not Reads/Writes.

ISP: Polish Telecom

Connection speed: 2048/256 Kbit

Router: D-Link 624+ Rev. B Firmware 2.10Beta

TCP/IP patch: no

Software firewalls: ISA Server

Antivirus software: MksVir (disabled)

µTorrent settings: almost everything as default (I disabled NAT-PMP and Firewall rules, and enabled scheduler)

Hardware: Celeron 2,8Ghz 1GB Ram, 2xNIC, System: Win 2k3 SP2 SBS

Here are all my crash dumps (over 50):

http://rapidshare.com/files/50248075/uTorrent.rar.html

Sorry for using rapid, if needed I will send it somewhere else.

Hijackhis log:

Logfile of HijackThis v1.99.1
Scan saved at 02:01:40, on 2007-08-21
Platform: Windows 2003 Dodatek SP2 (WinNT 5.02.3790)
MSIE: Internet Explorer v6.00 SP2 (6.00.3790.3959)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\System32\dns.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\system32\tcpsvcs.exe
C:\WINDOWS\system32\Dfssvc.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\grovel.exe
C:\WINDOWS\system32\inetsrv\inetinfo.exe
C:\Program Files\MKS_VIR_2006\mksmonsv.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING\Binn\sqlservr.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Binn\sqlservr.exe
C:\Program Files\Microsoft Analysis Services\Bin\msmdsrv.exe
C:\WINDOWS\system32\ntfrs.exe
C:\Program Files\Microsoft SQL Server\MSSQL$SBSMONITORING\Binn\sqlagent.EXE
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\tftpd.exe
C:\Program Files\UPS Monitor\UPSmonCsrv.exe
C:\Program Files\UPS Monitor\UPSmonSsrv.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\wins.exe
C:\Program Files\Exchsrvr\bin\exmgmt.exe
C:\Program Files\Exchsrvr\bin\mad.exe
C:\Program Files\Common Files\System\MSSearch\Bin\mssearch.exe
C:\WINDOWS\System32\svchost.exe
C:\PROGRA~1\Microsoft ISA Server\mspadmin.exe
C:\PROGRA~1\Microsoft ISA Server\wspsrv.exe
C:\PROGRA~1\Microsoft ISA Server\w3proxy.exe
C:\PROGRA~1\Microsoft ISA Server\W3Prefch.exe
C:\Program Files\Exchsrvr\bin\store.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\rdpclip.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\UPS Monitor\UPSmonC.exe
C:\Program Files\UPS Monitor\UPSmonS.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
C:\PROGRA~1\MICROS~3\MSSQL\binn\sqlservr.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Documents and Settings\Administrator.SBSMENIS\Pulpit\ProcessExplorer\procexp.exe
C:\Program Files\MKS_VIR_2006\mks2006.exe
C:\Program Files\MKS_VIR_2006\mks_mail.exe
C:\Program Files\MKS_VIR_2006\mks_scan.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\UTILITY\hijackthis_199\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.pl/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://companyweb
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = sbs2004:8080
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
O4 - HKLM\..\Run: [UPS Monitor Client 3.0] C:\Program Files\UPS Monitor\Client.exe /start
O4 - HKLM\..\Run: [UPS Monitor Server 3.0] C:\Program Files\UPS Monitor\Server.exe /start
O4 - HKLM\..\Run: [MKS_VIR_2006] C:\Program Files\MKS_VIR_2006\mks2006.exe
O4 - HKLM\..\Run: [mks_agent] C:\Program Files\MKS_VIR_2006\runMksAdmin.exe
O4 - HKLM\..\Run: [DWPersistentQueuedReporting] C:\PROGRA~1\COMMON~1\MICROS~1\DW\DWTRIG20.EXE -a
O4 - HKLM\..\Run: [UserFaultCheck] %systemroot%\system32\dumprep 0 -u
O4 - HKCU\..\Run: [MailScanner] C:\Program Files\MKS_VIR_2006\Mks_mail.exe
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - Global Startup: Service Manager.lnk = C:\Program Files\Microsoft SQL Server\80\Tools\Binn\sqlmangr.exe
O6 - HKCU\Software\Policies\Microsoft\Internet Explorer\Control Panel present
O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2006\mksfirewall.dll
O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2006\mksfirewall.dll
O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2006\mksfirewall.dll
O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2006\mksfirewall.dll
O10 - Unknown file in Winsock LSP: c:\program files\mks_vir_2006\mksfirewall.dll
O14 - IERESET.INF: START_PAGE_URL=http://companyweb
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=34738&clcid=0x409
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = sbsmenis.edu.pl
O17 - HKLM\Software\..\Telephony: DomainName = sbsmenis.edu.pl
O17 - HKLM\System\CCS\Services\Tcpip\..\{08F017DB-1986-423E-A1CA-6D2DD29E7AD1}: NameServer = 192.168.1.250
O17 - HKLM\System\CCS\Services\Tcpip\..\{38320E50-12EF-41EF-A62F-6A909CBB7992}: NameServer = 192.168.61.2
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = sbsmenis.edu.pl
O17 - HKLM\System\CS1\Services\Tcpip\..\{08F017DB-1986-423E-A1CA-6D2DD29E7AD1}: NameServer = 192.168.1.250
O20 - Winlogon Notify: dimsntfy - C:\WINDOWS\SYSTEM32\dimsntfy.dll
O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxsrvc.dll
O23 - Service: Microsoft H.323 Gatekeeper (GKSVC) - Unknown owner - svchost.exe (file missing)
O23 - Service: MkS_Vir Monitor (MksVirMonSvc) - Unknown owner - C:\Program Files\MKS_VIR_2006\mksmonsv.exe
O23 - Service: MkS_Scan - Unknown owner - C:\Program Files\MKS_VIR_2006\mks_scan.exe
O23 - Service: MSSQL$SHAREPOINT - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Binn\sqlservr.exe" -sSHAREPOINT (file missing)
O23 - Service: Sandra Data Service (SandraDataSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcDataSrv.exe
O23 - Service: Sandra Service (SandraTheSrv) - SiSoftware - C:\Program Files\SiSoftware\SiSoftware Sandra Lite 2005.SR1\RpcSandraSrv.exe
O23 - Service: SQLAgent$SHAREPOINT - Unknown owner - C:\Program Files\Microsoft SQL Server\MSSQL$SHAREPOINT\Binn\sqlagent.EXE" -i SHAREPOINT (file missing)
O23 - Service: UPS Monitor Klient 3.0 (UPS Monitor Client 3.0 XP) - Fideltronik Imel Sp. z o.o. - C:\Program Files\UPS Monitor\UPSmonCsrv.exe
O23 - Service: UPS Monitor Serwer 3.0 (UPS Monitor Server 3.0 XP) - Fideltronik Imel Sp. z o.o. - C:\Program Files\UPS Monitor\UPSmonSsrv.exe

Nothing suspicious found on HijackThis.de

Hope this will help tracking bug ;-)

EDIT: Forgot to mension im using uTorrent 1.7.2

T4

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...