ghost14201 Posted October 5, 2007 Report Share Posted October 5, 2007 I am not getting anywhere with this one day it worked fine the next it didn't and I can't figure out why. The only thing i did was take out my connection wires to my pc and restart it after like 3 months of never turning it off. Now u torrent opens but when u try to dl it says not responding and makes u end task on it. no firewall stopping it and i ran virus scan no virus. help me please tried uninstall and reinstallAlso it say dht waiting to login at the bottom and I get no red yellow or green indicator at the bottom either Link to comment Share on other sites More sharing options...
Firon Posted October 5, 2007 Report Share Posted October 5, 2007 Post a process list with HijackThis.And when exactly is it freezing? Link to comment Share on other sites More sharing options...
ghost14201 Posted October 5, 2007 Author Report Share Posted October 5, 2007 hijackthis ??????????? what's that a web site?also freezes when i try to start downloading a utorrent file any utorrent fileLogfile of Trend Micro HijackThis v2.0.2Scan saved at 6:56:25 PM, on 10/5/2007Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16512)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exeC:\Program Files\iolo\Common\Lib\ioloDMVSvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Analog Devices\Core\smax4pnp.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\WINDOWS\System32\Rundll32.exeC:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exeC:\Program Files\QuickTime\qttask.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\iAVEmailScanner.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Webroot\Spy Sweeper\SSU.EXEC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\WINDOWS\system32\wbem\wmiprvse.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Skyblueads browser optmizer - {7DB476DD-EA1E-4c91-880F-DCD1888740A1} - C:\WINDOWS\system32\cpmrotate.dllO2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLLO3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLLO4 - HKLM\..\Run: [soundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [securityUpdate] rundll32.exe C:\WINDOWS\system32\hhmczfr.dll,TurnOn2O4 - HKLM\..\Run: [adstart] "C:\WINDOWS\System32\Rundll32.exe" "C:\WINDOWS\system32\cpmrotate.dll" DllVerifyO4 - HKLM\..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [spySweeper] C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe /startintrayO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJO9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO15 - Trusted Zone: http://click.getmirar.com (HKLM)O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186223168312O17 - HKLM\System\CCS\Services\Tcpip\..\{3CAAA71A-A68B-4CA4-BC4E-EA24D62C635F}: NameServer = 63.162.197.69,63.162.197.99O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exeO23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exeO23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe--End of file - 6292 bytesO4 - HKLM\..\Run: [securityUpdate] rundll32.exe C:\WINDOWS\system32\hhmczfr.dll,TurnOn2that one is always detected by my virus scanner and dissinfected hhmczfr.dllalso I never use iolo firewall and never have it running. windows firewall only. and I have ran spyware and virus scanneralso ran lsdfix and it found no new entries and no new anything is what it said Link to comment Share on other sites More sharing options...
Switeck Posted October 6, 2007 Report Share Posted October 6, 2007 I put a HIGH probability that at least one of these is dangerous (spyware/adware/trojan) software:R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Skyblueads browser optmizer - {7DB476DD-EA1E-4c91-880F-DCD1888740A1} - C:\WINDOWS\system32\cpmrotate.dllO2 - BHO: Ask Toolbar BHO - {F0D4B231-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLLO3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)O3 - Toolbar: Ask Toolbar - {F0D4B239-DA4B-4daf-81E4-DFEE4931A4AA} - C:\Program Files\AskSBar\bar\1.bin\ASKSBAR.DLLO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dll Link to comment Share on other sites More sharing options...
Firon Posted October 6, 2007 Report Share Posted October 6, 2007 The System Mechanic Professional firewall is known to be problematic. Uninstall it and get something better like Sygate, Outpost or Comodo.Plus, it seems like your LSP chain has been trashed. You'll need LSPfix to remove invalid entries from it. Link to comment Share on other sites More sharing options...
ghost14201 Posted October 7, 2007 Author Report Share Posted October 7, 2007 Any ideas? re check last edit Link to comment Share on other sites More sharing options...
Switeck Posted October 7, 2007 Report Share Posted October 7, 2007 It's still a mess for the same reasons I stated before. Link to comment Share on other sites More sharing options...
ghost14201 Posted October 7, 2007 Author Report Share Posted October 7, 2007 what should I do? ran spyware and virus already Link to comment Share on other sites More sharing options...
Firon Posted October 8, 2007 Report Share Posted October 8, 2007 You didn't even read my post. Link to comment Share on other sites More sharing options...
Switeck Posted October 8, 2007 Report Share Posted October 8, 2007 Most antivirus and antispyware won't do a THING for a trashed system registry pointing to 'dead' entries or missing files. ...You need a good registry cleaner (or know how to do it manually) to do that. Link to comment Share on other sites More sharing options...
ghost14201 Posted October 8, 2007 Author Report Share Posted October 8, 2007 I have system machaniac which has a reg. cleaner this is what hijack this is after the reg fixer in sysytem mac.http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: Skyblueads browser optmizer - {7DB476DD-EA1E-4c91-880F-DCD1888740A1} - C:\WINDOWS\system32\cpmrotate.dllO3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)O4 - HKLM\..\Run: [soundMAXPnP] "C:\Program Files\Analog Devices\Core\smax4pnp.exe"O4 - HKLM\..\Run: [igfxTray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [securityUpdate] rundll32.exe C:\WINDOWS\system32\hhmczfr.dll,TurnOn2O4 - HKLM\..\Run: [adstart] C:\WINDOWS\System32\Rundll32.exe "C:\WINDOWS\system32\cpmrotate.dll" DllVerifyO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [iolo AntiVirus] "C:\Program Files\iolo\System Mechanic Professional 7\AntiVirus\ioloAV.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [NBJ] "C:\Program Files\Ahead\Nero BackItUp\NBJ.exe"O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')O8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZJO9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO15 - Trusted Zone: http://click.getmirar.com (HKLM)O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1186223168312O17 - HKLM\System\CCS\Services\Tcpip\..\{3CAAA71A-A68B-4CA4-BC4E-EA24D62C635F}: NameServer = 63.162.197.69,63.162.197.99O23 - Service: DvpApi (dvpapi) - Authentium, Inc. - C:\Program Files\Common Files\Authentium\AntiVirus\dvpapi.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: iolo DMV Service (ioloDMV) - Unknown owner - C:\Program Files\iolo\Common\Lib\ioloDMVSvc.exeO23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exe--End of file - 6120 bytesso no new changes I guess ummmmmmmm please help I really love my utorrent and now I can't use it. I am really stumped if u need my number i'll give my # to call me on weds. oct 10th or set up some place to chat live via internet at some common time?and firon i did read ur post. I have had the iolo firewall the whole 4 months i was using utorrent b4 this happened and running ur lspfix did nothing found nothing so Link to comment Share on other sites More sharing options...
ajones81 Posted October 8, 2007 Report Share Posted October 8, 2007 Sounds like your system's just about bought it... :/Try Spybot Search & Destroy. You could also give PC Tools' Spyware Doctor and Registry Mechanic a spin, but those aren't free.Maybe you'd do better starting over i.e. reinstall Windows etc., and this time use a good AV, firewall and anti-spyware, along with uTorrent, of course! Link to comment Share on other sites More sharing options...
ghost14201 Posted October 8, 2007 Author Report Share Posted October 8, 2007 I don't think anythings really that wrong b/c everything else works Link to comment Share on other sites More sharing options...
Switeck Posted October 8, 2007 Report Share Posted October 8, 2007 At one time, your system had spyware/adware on it...as proof of this is here:R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLL (file missing)You probably should remove the Yahoo junk unless you really use it...but even if not, this isn't working right anyway:O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)These are almost certainly the sign of HOSTILE activity on your computer unless you specified this yourself:O15 - Trusted Zone: http://click.getmirar.com (HKLM)O15 - Trusted Zone: http://click.mirarsearch.com (HKLM)O15 - Trusted Zone: http://redirect.mirarsearch.com (HKLM)O15 - Trusted Zone: http://awbeta.net-nucleus.com (HKLM)Search redirects are often a way to steal personal info that you enter into a website.System Mechanic 7 Professional's Antivirus and/or firewall is what created these:O10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\program files\iolo\common\firewall\ifw_xfilter.dllO10 - Unknown file in Winsock LSP: c:\windows\system32\iavlsp.dllOn top of at least the remains of Yahoo Toolbar, you also seem to have Google's too!:O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe Link to comment Share on other sites More sharing options...
ghost14201 Posted October 9, 2007 Author Report Share Posted October 9, 2007 sry about being hard headed it was my system mechanic that was stopping utorrent from d/l ing anything so if u run accross this problem witha anyone else tell them they can use the programs together just don't run an update with system mechanic and if they do just del. the .dll from lspfix and it will work fine so it's possible to run both on pc just a certain way. don't know how something can just stop working but it did now its fixed thanks a million guys and next i won't be such a dip. keep rocking guys Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.