myowneq Posted October 24, 2007 Report Share Posted October 24, 2007 Greetings,I have uTorrent 1.7.5 running on Vista Premium. I've noticed that uTorrent does not want to shut down after it's been running for more than a few hours. Lately, it seems to be getting worse, but it could be my imagination or frustration. My shut down and restart times are much higher when uTorrent has been open. If I attempt to close it, it clears off the taskbar but the process continues to run. I can't kill it or end it. Everything else runs fine. I've got a HiJack This log and a Procexp log. These log were taken after uTorrent ran for three hours, attempted to close the program, and it froze. At this point, I ran both programs. Any ideas or suggestions?Thanks,TimothyLogfile of Trend Micro HijackThis v2.0.2Scan saved at 12:22:01 AM, on 10/24/2007Platform: Windows Vista (WinNT 6.00.1904)MSIE: Internet Explorer v7.00 (7.00.6000.16546)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exeC:\Windows\System32\rundll32.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Program Files\Motorola\SMSERIAL\sm56hlpr.exeC:\Program Files\SiteAdvisor\6172\SiteAdv.exeC:\Program Files\Zone Labs\ZoneAlarm\zlclient.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exeC:\Windows\ehome\ehtray.exeC:\Program Files\Spybot\TeaTimer.exeC:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exeC:\Windows\ehome\ehmsas.exeC:\Program Files\WIDCOMM\Bluetooth Software\BTTray.exeC:\Program Files\WIDCOMM\Bluetooth Software\BtStackServer.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exeC:\PROGRA~1\ZONELA~1\ZONEAL~1\MAILFR~1\mantispm.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Windows Media Player\wmplayer.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Microsoft Office\Office12\OUTLOOK.EXEC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Winamp\winamp.exeC:\Windows\system32\SearchFilterHost.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.gateway.com/g/startpage.html?Ch=Consumer&Br=GTW&Loc=ENG_US&Sys=PTB&M=NX860XLR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gateway.com/g/startpage.html?Ch=Consumer&Br=GTW&Loc=ENG_US&Sys=PTB&M=NX860XLR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = http://www.gateway.com/g/sidepanel.html?Ch=Consumer&Br=GTW&Loc=ENG_US&Sys=PTB&M=NX860XLR0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_01\bin\ssv.dllO2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dllO3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStartO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [sMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exeO4 - HKLM\..\Run: [NapsterShell] C:\Program Files\Napster\napster.exe /systrayO4 - HKLM\..\Run: [bigFix] c:\program files\Bigfix\bigfix.exe /atstartupO4 - HKLM\..\Run: [siteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exeO4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [CloneCDTray] "C:\Program Files\SlySoft\CloneCD\CloneCDTray.exe" /sO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [Media Codec Update Service] C:\Program Files\Essentials Codec Pack\update.exe -silentO4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenterO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot\TeaTimer.exeO4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O4 - Startup: Bluetooth.lnk = ?O4 - Global Startup: Bluetooth.lnk = ?O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Send image to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie_ctx.htmO8 - Extra context menu item: Send page to &Bluetooth Device... - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_01\bin\npjpi160_01.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLLO9 - Extra button: @btrez.dll,-4015 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra 'Tools' menuitem: @btrez.dll,-12650 - {CCA281CA-C863-46ef-9331-5C8D4460577F} - C:\Program Files\WIDCOMM\Bluetooth Software\btsendto_ie.htmO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dllO9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exeO9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6\ICQ.exeO13 - Gopher Prefix: O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://upload.mediamax.com/Upload/XUpload.ocxO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - C:\Program Files\Spybot\SDWinSec.exeO23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6172\SAService.exeO23 - Service: SigmaTel Audio Service (STacSV) - SigmaTel, Inc. - C:\Program Files\SigmaTel\C-Major Audio\WDM\STacSV.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exe--End of file - 8304 bytesProcess PID CPU Description Company NameSystem Idle Process 0 91.32 Interrupts n/a 0.75 Hardware Interrupts DPCs n/a 1.50 Deferred Procedure Calls System 4 0.75 smss.exe 512 Windows Session Manager Microsoft Corporationcsrss.exe 580 Client Server Runtime Process Microsoft Corporationwininit.exe 632 Windows Start-Up Application Microsoft Corporation services.exe 676 0.75 Services and Controller app Microsoft Corporation svchost.exe 888 Host Process for Windows Services Microsoft Corporation ehmsas.exe 4060 Media Center Media Status Aggregator Service Microsoft Corporation BTStackServer.exe 1048 Bluetooth Stack COM Server Broadcom Corporation. NMIndexStoreSvr.exe 2208 Nero Home Nero AG dllhost.exe 4612 COM Surrogate Microsoft Corporation svchost.exe 944 Host Process for Windows Services Microsoft Corporation svchost.exe 1088 Host Process for Windows Services Microsoft Corporation audiodg.exe 1248 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1136 Host Process for Windows Services Microsoft Corporation dwm.exe 2044 2.25 Desktop Window Manager Microsoft Corporation svchost.exe 1168 Host Process for Windows Services Microsoft Corporation taskeng.exe 2036 Task Scheduler Engine Microsoft Corporation taskeng.exe 2912 Task Scheduler Engine Microsoft Corporation SLsvc.exe 1284 Microsoft Software Licensing Service Microsoft Corporation svchost.exe 1324 Host Process for Windows Services Microsoft Corporation svchost.exe 1504 Host Process for Windows Services Microsoft Corporation vsmon.exe 1528 TrueVector Service Check Point Software Technologies LTD ScanningProcess.exe 1840 ScanningProcess.exe 1516 spoolsv.exe 1992 Spooler SubSystem App Microsoft Corporation svchost.exe 2028 Host Process for Windows Services Microsoft Corporation AppleMobileDeviceService.exe 3060 Apple Mobile Device Service Apple, Inc. svchost.exe 2416 Host Process for Windows Services Microsoft Corporation IAANTmon.exe 3228 RAID Monitor Intel Corporation svchost.exe 3436 Host Process for Windows Services Microsoft Corporation SAService.exe 1404 SiteAdvisor McAfee, Inc. stacsv.exe 3568 STacSV Module SigmaTel, Inc. svchost.exe 3776 Host Process for Windows Services Microsoft Corporation svchost.exe 3824 Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 2000 Microsoft Windows Search Indexer Microsoft Corporation SearchProtocolHost.exe 1060 Microsoft Windows Search Protocol Host Microsoft Corporation SearchFilterHost.exe 1412 Microsoft Windows Search Filter Host Microsoft Corporation SDWinSec.exe 2336 Spybot-S&D Security Center integration Safer Networking Ltd. NMIndexingService.exe 3448 Nero Home Nero AG iPodService.exe 4012 iPodService Module Apple Inc. lsass.exe 688 Local Security Authority Process Microsoft Corporation lsm.exe 696 Local Session Manager Service Microsoft Corporationcsrss.exe 644 Client Server Runtime Process Microsoft Corporationwinlogon.exe 804 Windows Logon Application Microsoft Corporationexplorer.exe 532 0.75 Windows Explorer Microsoft Corporation IAAnotif.exe 2352 Event Monitor User Notification Tool Intel Corporation SynTPEnh.exe 2528 Synaptics TouchPad Enhancements Synaptics, Inc. sm56hlpr.exe 2620 Application executable file Motorola Inc. SiteAdv.exe 2644 SiteAdvisor McAfee, Inc. zlclient.exe 2728 ZoneAlarm Client Check Point Software Technologies LTD mantispm.exe 3656 Spam Filter iTunesHelper.exe 3124 iTunesHelper Module Apple Inc. NMBgMonitor.exe 3888 Nero Home Nero AG ehtray.exe 3912 Media Center Tray Applet Microsoft Corporation TeaTimer.exe 3924 0.75 System settings protector Safer Networking Limited BTTray.exe 1456 Bluetooth Tray Application Broadcom Corporation. BTTray.exe 2140 Bluetooth Tray Application Broadcom Corporation. iexplore.exe 156 Internet Explorer Microsoft Corporation uTorrent.exe 2668 OUTLOOK.EXE 3520 Microsoft Office Outlook Microsoft Corporation iexplore.exe 6000 Internet Explorer Microsoft Corporation procexp.exe 4300 1.50 Sysinternals Process Explorer Sysinternalsrundll32.exe 2520 Windows host process (Rundll32) Microsoft Corporationwmplayer.exe 2156 Windows Media Player Microsoft Corporation mfpmp.exe 1780 Media Foundation Protected Pipeline EXE Microsoft Corporationwinamp.exe 4972 Winamp Nullsoft Link to comment Share on other sites More sharing options...
Switeck Posted October 24, 2007 Report Share Posted October 24, 2007 My guess is Zone Alarm is causing the problems.This stuff I don't recognize, but hopefully you do:O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [bigFix] c:\program files\Bigfix\bigfix.exe /atstartupO4 - HKLM\..\Run: [siteAdvisor] C:\Program Files\SiteAdvisor\6172\SiteAdv.exeO4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenterO4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O16 - DPF: {E87F6C8E-16C0-11D3-BEF7-009027438003} (Persits Software XUpload) - http://upload.mediamax.com/Upload/XUpload.ocxI am always wary of BHO's: (sometimes even for KNOWN ones!)O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6172\SiteAdv.dllO2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\google\BAE.dll Link to comment Share on other sites More sharing options...
cpc197c Posted October 24, 2007 Report Share Posted October 24, 2007 -SynTPEnh is Synaptics Touchpad drivers. He must be on a laptop-rundll32.exe oobefldr.dll,ShowWelcomeCenter is what it says there, the welcome center. That can be deleted unless you like the welcome center for some strange reason Link to comment Share on other sites More sharing options...
myowneq Posted October 24, 2007 Author Report Share Posted October 24, 2007 I am on a laptop. It's a new Gateway and i haven't completely used some of the preinstalled stuff to see if I want to keep it or not.Things I know for sure are BigFix. Welcome Center and Big Fix fall into that category of yet to explore.Whats a BHO? Link to comment Share on other sites More sharing options...
Switeck Posted October 25, 2007 Report Share Posted October 25, 2007 Browser Helper Object. Basically a mini-program that runs "inside" your internet browser. Link to comment Share on other sites More sharing options...
myowneq Posted October 25, 2007 Author Report Share Posted October 25, 2007 Well, that explains something then. The Google BHO that redirects my browser when it can't locate something because ZA is legitimately blocking it. Can I just remove that one from the registry and delete the files? As for the McAfee Site Advisor, same thing? Thanks. Link to comment Share on other sites More sharing options...
Firon Posted October 26, 2007 Report Share Posted October 26, 2007 Sure, but I doubt anything besides Zone Alarm is causing problems. Link to comment Share on other sites More sharing options...
myowneq Posted October 26, 2007 Author Report Share Posted October 26, 2007 I can understand ZA may be the problem, but I'll change uTorrent before I change ZA. I'm not ready to throw the two year subscription I just bought two months ago. I understand BitTorrent is somewhat like uTorrent? Link to comment Share on other sites More sharing options...
Firon Posted October 26, 2007 Report Share Posted October 26, 2007 BT is identical. And seriously, ZA is just awful. Azureus has a wiki page detailing all sorts of problems with it, and if you look at ZA's own forums, there's tons of posts of people having trouble with just about every P2P app in existence.Toss the subscription and get a better firewall. Link to comment Share on other sites More sharing options...
PacmanLopez Posted October 31, 2007 Report Share Posted October 31, 2007 Any recommended firewall? Link to comment Share on other sites More sharing options...
Legal Eagle Posted October 31, 2007 Report Share Posted October 31, 2007 I have exactly the same problem and am not using Zone Alarm. I am currently using Eset Secutity Suite. Any other suggestions would be appreciated. Link to comment Share on other sites More sharing options...
Firon Posted November 2, 2007 Report Share Posted November 2, 2007 Sygate, Outpost, and Comodo are all good choices. Link to comment Share on other sites More sharing options...
Legal Eagle Posted November 5, 2007 Report Share Posted November 5, 2007 Since the error occurs with both Zone Alarm and NOD32, it appears that the problem is probably not caused by the firewall. It seems to fall back on there being a problem with uTorrent 1.7.5 Link to comment Share on other sites More sharing options...
DreadWingKnight Posted November 5, 2007 Report Share Posted November 5, 2007 Occurs with both, but not with neither.This issue isn't caused by uT. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.