Jump to content

uTorrent is eating up my memory (while using Windows Firewall)


treyevans

Recommended Posts

Posted

I have read through some of the issues and i see that some were having this problem using NVIDIA Firewall, but I don't use it (nor have I ever).

I run windows vista on a dual core amd with 2 gig ram.

I tried temporarily disabling Windows Firewall to identify the problem, but my RAM usage was still at around 91%. If I have to I will use another firewall (perhaps Kaspersky), but do y'all think it is Windows Firewall that is the problem?

I switched from Azureus to uTorrent about a week ago, and haven't had any problems until today. I have fallen in love with uTorrent, and I really don't want to have to switch back. Can any of y'all help me?

Thanks! -- trey

UPDATE:

also, i run over a wireless network (i know, its unstable) using a d-link WBR-2310 router. i checked the incompatibility page; none of the software I run nor the router i use seems to be listed.

Posted

huh? Oh so you're experiencing uT using alot of RAM. How much RAM is it using according to WTM (windows task manager)? Would you be so kind as to paste the HiJackThis log requested in Ultima's How-To? Also pasting a DLL mode list from Process Explorer (farther down in the How-To)... open procexp.exe, Ctrl-L, Ctrl-D, click on utorrent's exe, Ctrl-A, and copy/paste the txt logfile.

Posted

well since i don't know what that means, can I assume that I have never patched my TCPIP.sys?

"How much RAM is it using according to WTM (windows task manager)?"

8,908 K

"Would you be so kind as to paste the HiJackThis log requested in Ultima's How-To?"

Logfile of Trend Micro HijackThis v2.0.0 (BETA)

Scan saved at 3:10:45 AM, on 1/8/2008

Platform: Windows Vista (WinNT 6.00.1904)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\Adobe\Acrobat 8.0\Acrobat\acrotray.exe

C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

C:\Program Files\Microsoft IntelliPoint\ipoint.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\TOSHIBA\TOSCDSPD\TOSCDSPD.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Program Files\Synaptics\SynTP\SynToshiba.exe

C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe

C:\Program Files\Thunderbird-Tray\TBTray.exe

C:\Program Files\YPOPs\YPOPs.exe

C:\Program Files\Windows Sidebar\sidebar.exe

C:\Program Files\Mozilla Thunderbird\thunderbird.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Users\Trey\Desktop\HiJackThis_v2.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll

O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dll

O4 - HKLM\..\Run: [synTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe

O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"

O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe

O4 - HKLM\..\Run: [HSON] %ProgramFiles%\TOSHIBA\TBS\HSON.exe

O4 - HKLM\..\Run: [synTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe

O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe"

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"

O4 - HKLM\..\Run: [MSConfig] "C:\Windows\system32\msconfig.exe" /auto

O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun

O4 - HKCU\..\Run: [TOSCDSPD] C:\Program Files\TOSHIBA\TOSCDSPD\toscdspd.exe

O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')

O4 - Startup: TB-Tray.lnk = C:\Program Files\Thunderbird-Tray\TBTray.exe

O4 - Startup: YPOPs.lnk = ?

O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?

O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html

O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html

O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html

O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\SCIEPlgn.dll

O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~3\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0\r3hook.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\Windows\system32\browseui.dll

O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll

O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft AB - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe

O23 - Service: Adobe Version Cue CS3 - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\Adobe Version Cue CS3\Server\bin\VersionCueCS3.exe

O23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exe

O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe

O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe

O23 - Service: Kaspersky Anti-Virus 7.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 7.0\avp.exe

O23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - C:\Windows\system32\bgsvcgen.exe

O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe

O23 - Service: MATLAB Server (matlabserver) - Unknown owner - C:\Program Files\MATLAB71\webserver\bin\win32\matlabserver.exe

O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exe

O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exe

O23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exe

O23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exe

O23 - Service: TOSHIBA Navi Support Service (TNaviSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA DVD PLAYER\TNaviSrv.exe

O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe

--

End of file - 9205 bytes

"Also pasting a DLL mode list from Process Explorer"

Process PID CPU Description Company Name

System Idle Process 0 78.52

Interrupts n/a 0.75 Hardware Interrupts

DPCs n/a 0.75 Deferred Procedure Calls

System 4 1.50

smss.exe 524 Windows Session Manager Microsoft Corporation

csrss.exe 592 Client Server Runtime Process Microsoft Corporation

wininit.exe 644 Windows Start-Up Application Microsoft Corporation

services.exe 688 0.75 Services and Controller app Microsoft Corporation

svchost.exe 904 Host Process for Windows Services Microsoft Corporation

svchost.exe 960 Host Process for Windows Services Microsoft Corporation

Ati2evxx.exe 1088 ATI External Event Utility EXE Module ATI Technologies Inc.

Ati2evxx.exe 1456 ATI External Event Utility EXE Module ATI Technologies Inc.

svchost.exe 1132 Host Process for Windows Services Microsoft Corporation

audiodg.exe 1276 Windows Audio Device Graph Isolation Microsoft Corporation

svchost.exe 1180 Host Process for Windows Services Microsoft Corporation

dwm.exe 1928 2.99 Desktop Window Manager Microsoft Corporation

svchost.exe 1192 Host Process for Windows Services Microsoft Corporation

taskeng.exe 2004 Task Scheduler Engine Microsoft Corporation

taskeng.exe 3672 Task Scheduler Engine Microsoft Corporation

SLsvc.exe 1312 Microsoft Software Licensing Service Microsoft Corporation

svchost.exe 1368 Host Process for Windows Services Microsoft Corporation

svchost.exe 1560 Host Process for Windows Services Microsoft Corporation

aawservice.exe 1740 Ad-Aware 2007 Service Lavasoft AB

spoolsv.exe 1968 Spooler SubSystem App Microsoft Corporation

svchost.exe 2036 Host Process for Windows Services Microsoft Corporation

agrsmsvc.exe 2288 Agere Soft Modem Call Progress Service Agere Systems

avp.exe 2308 8.97 Kaspersky Anti-Virus Kaspersky Lab

bgsvcgen.exe 2320 B's Recorder GOLD Service Library B.H.A Corporation

mDNSResponder.exe 2360 Bonjour Service Apple Computer, Inc.

NBService.exe 2672 Nero BackItUp Nero AG

pinger.exe 2820

svchost.exe 2832 Host Process for Windows Services Microsoft Corporation

svchost.exe 2852 Host Process for Windows Services Microsoft Corporation

swupdtmr.exe 2872

TNaviSrv.exe 2924 TOSHIBA Navi Support Service TOSHIBA Corporation

TosCoSrv.exe 2960 TOSHIBA Power Saver TOSHIBA Corporation

svchost.exe 3028 Host Process for Windows Services Microsoft Corporation

SearchIndexer.exe 3048 Microsoft Windows Search Indexer Microsoft Corporation

SearchProtocolHost.exe 3036 Microsoft Windows Search Protocol Host Microsoft Corporation

SearchFilterHost.exe 4092 Microsoft Windows Search Filter Host Microsoft Corporation

FNPLicensingService.exe 3796 Activation Licensing Service Macrovision Europe Ltd.

alg.exe 3912 Application Layer Gateway Service Microsoft Corporation

wmpnetwk.exe 2088 Windows Media Player Network Sharing Service Microsoft Corporation

lsass.exe 704 Local Security Authority Process Microsoft Corporation

lsm.exe 712 Local Session Manager Service Microsoft Corporation

csrss.exe 656 Client Server Runtime Process Microsoft Corporation

winlogon.exe 764 Windows Logon Application Microsoft Corporation

explorer.exe 2028 Windows Explorer Microsoft Corporation

acrotray.exe 2164 AcroTray Adobe Systems Inc.

SynTPEnh.exe 2192 Synaptics TouchPad Enhancements Synaptics, Inc.

SynToshiba.exe 2304 Toshiba Custom PlugIn Application Synaptics, Inc.

avp.exe 892 Kaspersky Anti-Virus Kaspersky Lab

ipoint.exe 724 0.75 IPoint.exe Microsoft Corporation

dpupdchk.exe 2200 dpupdchk.exe Microsoft Corporation

sidebar.exe 2268 Windows Sidebar Microsoft Corporation

sidebar.exe 3816 Windows Sidebar Microsoft Corporation

TOSCDSPD.exe 684 CD/DVD Drive Acoustic Silencer TOSHIBA

wmpnscfg.exe 324 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation

TBTray.exe 2148 Thunderbird-Tray Felix 'SniperBeamer' Geyer

thunderbird.exe 3784 Mozilla Thunderbird Mozilla Corporation

ypops.exe 2212 Free POP3/SMTP access to Yahoo! Mail http://YPOPsEmail.com/

firefox.exe 3496 Firefox Mozilla Corporation

uTorrent.exe 1528

procexp.exe 256 5.23 Sysinternals Process Explorer Sysinternals

Process: uTorrent.exe Pid: 1528

Name Description Company Name Version

uTorrent.exe

ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6000.16386

kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6000.16386

ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6000.16386

RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6000.16525

COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6000.16386

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6000.16386

GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6000.16386

USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6000.16438

SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6000.16386

comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6000.16386

SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6000.16513

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6000.16386

NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6000.16386

IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6000.16386

MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6000.16386

LPK.DLL Language Pack Microsoft Corporation 6.00.6000.16386

USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6000.16386

r3hook.dll Kaspersky Anti-Virus Ring 3 Hooker Kaspersky Lab 7.00.0000.0125

PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386

ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6000.16386

uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6000.16386

SETUPAPI.dll Windows Setup API Microsoft Corporation 6.00.6000.16386

OLEAUT32.dll Microsoft Corporation 6.00.6000.16386

USERENV.dll Userenv Microsoft Corporation 6.00.6000.16386

Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6000.16386

PROPSYS.dll Microsoft Property System Microsoft Corporation 6.00.6000.16386

CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6930.16386

FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.00.6000.16501

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.00.6000.16386

mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6000.16386

wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6000.16386

Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6000.16386

dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6000.16512

DNSAPI.dll DNS Client API DLL Microsoft Corporation 6.00.6000.16386

WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6000.16386

dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6000.16512

dnsq.dll DNSQ Kaspersky Lab 7.00.0000.0125

NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6000.16386

winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386

Posted

If ut itself is using no RAM, and no process is using tons of RAM either, then it's just the Windows system cache eating memory. If it's not paging anything to disk, then it's not an issue.

Posted

Firon, thanks for the reply. I dont really understand what you mean, however. All I know is that when I start uTorrent, after a few minutes memory usage continues to build and build until it is at about 95%, and even when I close out uTorrent, it continues at that level until I have to restart. Are you saying that it isn't uTorrent that is causing the problem?

trey

btw: it is an issue in the sense that my computer is running so sluggishly like it never has before.

Posted

If no process is using tons of RAM, then the Windows system cache is being stupid.

What you can do is try the 1.8 alpha and enable the system cache bypass, which can help your issue.

  • 2 weeks later...

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...