Kleftidis Posted December 10, 2007 Report Posted December 10, 2007 Dear reader,I recently bought a new computer and since then Utorrent freezes the whole computer everytime it runs for a couple of ours. I tried all the solutions described in this forum but still no improvement. Please help cause I dont want another torrentclient. This is my hijack log file:Logfile of Trend Micro HijackThis v2.0.0 (BETA)Scan saved at 8:27:56 PM, on 12/11/2007Platform: Windows XP SP2 (WinNT 5.01.2600)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Cisco Systems\VPN Client\cvpnd.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Google\Gmail Notifier\gnotify.exeC:\Program Files\Java\jre1.6.0_03\bin\jusched.exeC:\PROGRA~1\Grisoft\AVG7\avgcc.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\DVD Decrypter\DVDDecrypter.exeC:\Program Files\DVD Decrypter\DVDDecrypter.exeC:\Downloads\HiJackThis_v2.exeR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: Adobe PDF Reader Help bij koppelingen - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"O4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUPO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hiddenO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXEO4 - Global Startup: VPN Client.lnk = ?O8 - Extra context menu item: E&xporteren naar Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dllO9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exeO9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exeO9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dllO22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dllO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: Cisco Systems, Inc. VPN Service (CVPND) - Cisco Systems, Inc. - C:\Program Files\Cisco Systems\VPN Client\cvpnd.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)--End of file - 6522 bytes
jewelisheaven Posted December 10, 2007 Report Posted December 10, 2007 OK so to be clear, which is crashing while running? Is it uTorrent, and then the OS? Is it The OS and therefore uT?Also is there any system slowdown experienced prior to the crash? By crash do you mean BSOD? Are any of the interface elements in uT responding to input, or mouseover after this occurs.What version of uT are you running?
Kleftidis Posted December 10, 2007 Author Report Posted December 10, 2007 at first: thank you for responding.I have version 1.7.5 and the freeze happens to the OS and Ut simultanously. I cant really tell which one is first. I do now that it only happens when running uT. There is no slowing down prior to the freeze, neither a sudden peak in cpu usage. When the freeze occurs nothing works, the screen freezes including the mouse pointer and I have to reboot the pc. I'v run spyware programs and optimized the uT settings in 1 million ways. And everytime it freezes.... Very annoying.kind regards
jewelisheaven Posted December 10, 2007 Report Posted December 10, 2007 OK, on this new XP SP2 system, have you changed any of the default settings in uT relating to concurrent number of connections or applied any of the recommended patches for using p2p applications such as modifying your tcpip.sys ?
Kleftidis Posted December 10, 2007 Author Report Posted December 10, 2007 I changed the settings downwards. no patches.
jewelisheaven Posted December 10, 2007 Report Posted December 10, 2007 Then it is possible the computer is hanging with all of the concurrent connection attempts. Have you tried disabling DHT, LPD, and lowering the connections per second.
Kleftidis Posted December 10, 2007 Author Report Posted December 10, 2007 yes did that all.any other suggestions?
jewelisheaven Posted December 10, 2007 Report Posted December 10, 2007 Hmm. Other than starting at the beginning with minimal settings enabled and / or full verbose logging to see what's going on just prior to the crash I'm not sure.Also forgive me but are you expecting some sort of Nero "indexing" service... sounds similar to windows indexer.O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeAny type of indexer will interfere with uT's ability to process files due to locked handles.Does this freeze occur when uploading only? or both when uploading and upload/downloading.Also if you want to try more in-depth analysis.. If you can get a feel for what is happening when uT freezes, try Process Explorer from http://sysinternals.com.It allows you to see open DLL or file-handles per open process. It may give you more information relevant to this.
Kleftidis Posted December 10, 2007 Author Report Posted December 10, 2007 ok, i'll try uninstall the nero app. will come back on it tomorrow. thanx man!
jewelisheaven Posted December 10, 2007 Report Posted December 10, 2007 No no, not the whole Nero application. I was asking specifically about the SERVICE it added.I'm still using v 5.5 so I'm not up-to-date on all the bells-and-whistles.Are you expecting Nero to have an indexer running (which I presume keeps a lock on open / changed files).I wouldn't want to keep your burning application from working. :/
Kleftidis Posted December 11, 2007 Author Report Posted December 11, 2007 Im sorry. I don't think my computer knowledge reaches far enough to understand your last posts. I uninstalled Nero , didn't help a bit. Is there any other clue in my hijackthis file leading to the problem? Maybe someone else?
Switeck Posted December 11, 2007 Report Posted December 11, 2007 You could try posting your new, shortened hijackthis log by editing your old post, just so we know how your system looks like with Nero gone....Otherwise, we might still think a poorly-named Nero service that is long-gone now is still a potential problem.
Kleftidis Posted December 11, 2007 Author Report Posted December 11, 2007 thank u for your time.I replaced the Hijack this file. Could you take a look please?kind regards
jewelisheaven Posted December 11, 2007 Report Posted December 11, 2007 Something I didn't mention before, but if it's a new computer how did you get pre-release SP3 on it.Even after the uninstall of that it is possible system files necessary for uT to run were modified (checked tcpip.sys ?).I don't see any of the offenders now, so that's good.
Kleftidis Posted December 12, 2007 Author Report Posted December 12, 2007 I have automatic updates running. Maybe that's wy I have sp3. I never installed it myself. I installed sp2 in an old version.Think that's it?
jewelisheaven Posted December 12, 2007 Report Posted December 12, 2007 Hmm, well firstly like i said before, any modifications to the networking subsystem should be performed first, especially if you migrated configurations from an older windows. SP2 starts out with a limited half-open and concurrent connection limit suitable for browsing the internet.
Kleftidis Posted December 12, 2007 Author Report Posted December 12, 2007 what do you mean with: should be performed first?
jewelisheaven Posted December 12, 2007 Report Posted December 12, 2007 Without asking you for your specific connection and bittorrent information under Ctrl-P I was assuming that you had "extraordinarily high" numbers according to what microsoft says the tcp/ip stack should support.Specifically I was referring to this post in the How-To link in my signature.
Switeck Posted December 12, 2007 Report Posted December 12, 2007 Google toolbar is basically adware and/or spyware, and probably a minor resource hog. Do you really use it/need it?:O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.0.301.7164\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeWhat's this doing? (almost seems like an indexer!):O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"Maybe this is intentional stuff you have, but likewise having it always-loading could be trouble:O9 - Extra button: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exeO9 - Extra 'Tools' menuitem: CDPoker - {A68FC757-51CF-4f3c-B13A-BFB8CA69BB99} - C:\Poker\CDPoker\casino.exeANY time HijackThis! finds registry references to now-missing files, you're likely to have trouble. You need to remove these entries and make sure there's not more leftover pieces from whatever created them:O9 - Extra button: (no name) - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - (no file)O9 - Extra button: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra 'Tools' menuitem: PartyPoker.com - {B7FE5D70-9AA2-40F1-9C6B-12A255F085E1} - C:\Program Files\PartyGaming\PartyPoker\RunApp.exe (file missing)O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O23 - Service: UPS - Unknown owner - C:\WINDOWS\System32\ups.exe (file missing)
jewelisheaven Posted December 12, 2007 Report Posted December 12, 2007 Yea I'm almost tempted to try out this new nero 8 suite to see what all of these services we're seeing lately are.. but it's 400 MB!!!!Nero 5.5 was only ~ 30
ajones81 Posted December 15, 2007 Report Posted December 15, 2007 Yup, Nero's gone to the dogs. 400 MB just to burn a CD/DVD? Ridiculous. Talk about bloatware! :/DeepBurner Pro rocks!
Recommended Posts
Archived
This topic is now archived and is closed to further replies.