Jump to content

uTorrent 1.7.5 handles leak (XP SP2)


evgbal

Recommended Posts

Hi!

The program loses handles it is visible in the TaskManager of problems after long continuous work. Speed of outflow makes somewhere 1-3 handles in a second. After resources of system come to an end under abnormal condition process svchost.exe comes to the end.

How this problem can be solved?

Best regals, Evgeniy

Link to comment
Share on other sites

Have you checked for http://utorrent.com/faq.php#Incompatible_software . . . Also before it closed, you weren't re-checking or hashing a large file were you? File Handles are extensively used during those processes.

As far as the tutorial linked, HiJackThis is rather simple. But for Process Explorer to get it to look, and paste what they are looking for you need to: download the zip, unzip the zip, open procexp.exe, Ctrl-L, Ctrl-D, click on utorrent.exe, Ctrl-A to save logfile. After that, copy-paste below :D

Link to comment
Share on other sites

To: Firon

XP Std Firewall disabled and other firewall not used.

To: Support

1. hijackthis.log

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 22:13:05, on 09.01.2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16574)

Boot mode: Normal

Running processes:

Q:\WINDOWS\System32\smss.exe

Q:\WINDOWS\system32\winlogon.exe

Q:\WINDOWS\system32\services.exe

Q:\WINDOWS\system32\lsass.exe

Q:\WINDOWS\system32\svchost.exe

Q:\WINDOWS\System32\svchost.exe

Q:\WINDOWS\system32\spoolsv.exe

Q:\WINDOWS\Explorer.EXE

Q:\Program Files\DrWeb AV-Desk\drwagnui.exe

Q:\Program Files\DrWeb AV-Desk\spiderml.exe

Q:\PROGRA~1\DRWEBA~1\spiderui.exe

Q:\Program Files\Java\jre1.6.0_03\bin\jusched.exe

Q:\WINDOWS\system32\drivers\CDAC11BA.EXE

Q:\WINDOWS\system32\ctfmon.exe

Q:\WINDOWS\system32\cisvc.exe

Q:\WINDOWS\system32\inetsrv\inetinfo.exe

Q:\Program Files\Total Commander\Totalcmd.exe

Q:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXE

Q:\WINDOWS\system32\tcpsvcs.exe

Q:\WINDOWS\System32\snmp.exe

Q:\PROGRA~1\DRWEBA~1\spidernt.exe

Q:\WINDOWS\system32\mqsvc.exe

Q:\WINDOWS\system32\mqtgsvc.exe

Q:\Program Files\DrWeb AV-Desk\drwagntd.exe

Q:\Program Files\uTorrent\uTorrent.exe

Q:\WINDOWS\system32\cidaemon.exe

Q:\WINDOWS\system32\cidaemon.exe

Q:\Program Files\Internet Explorer\iexplore.exe

Q:\Program Files\Internet Explorer\iexplore.exe

Q:\PROGRA~1\ICQ6\ICQ.exe

Q:\Program Files\Total Commander\Totalcmd.exe

Q:\WINDOWS\system32\taskmgr.exe

Q:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Ссылки

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - Q:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: TBSB00196 - {1236D836-E9BA-4175-894F-2072A14D5A26} - Q:\Program Files\WebMoney Advisor\wmadvisor.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - Q:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O3 - Toolbar: WebMoney Advisor - {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - Q:\Program Files\WebMoney Advisor\wmadvisor.dll

O4 - HKLM\..\Run: [DrWebAgentUI] "Q:\Program Files\DrWeb AV-Desk\drwagnui.exe"

O4 - HKLM\..\Run: [spIDerMail] "Q:\Program Files\DrWeb AV-Desk\spiderml.exe"

O4 - HKLM\..\Run: [spIDerNT] Q:\PROGRA~1\DRWEBA~1\spiderui.exe /agent

O4 - HKLM\..\Run: [NBKeyScan] "Q:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"

O4 - HKLM\..\Run: [NeroFilterCheck] Q:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "Q:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"

O4 - HKLM\..\Run: [MsmqIntCert] regsvr32 /s mqrt.dll

O4 - HKCU\..\Run: [CTFMON.EXE] Q:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "Q:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020

O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] Q:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')

O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] Q:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] Q:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] Q:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - Startup: Total Commander.lnk = Q:\Program Files\Total Commander\Totalcmd.exe

O4 - Startup: vpn.spb.corbina.net.lnk = ?

O4 - Startup: µTorrent.lnk = Q:\Program Files\uTorrent\uTorrent.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = Q:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe

O4 - Global Startup: Adobe Reader Synchronizer.lnk = Q:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exe

O8 - Extra context menu item: &Экспорт в Microsoft Excel - res://J:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Q:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - Q:\Program Files\Java\jre1.6.0_03\bin\ssv.dll

O9 - Extra button: WebMoney Advisor - {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - Q:\Program Files\WebMoney Advisor\wmadvisor.dll

O9 - Extra 'Tools' menuitem: WebMoney Advisor - {3AFFD7F7-FD3D-4C9D-8F83-03296A1A8840} - Q:\Program Files\WebMoney Advisor\wmadvisor.dll

O9 - Extra button: Справочные материалы - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - J:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - Q:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - Q:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - Q:\Program Files\ICQ6\ICQ.exe

O9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - Q:\Program Files\ICQ6\ICQ.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Q:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - Q:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: q:\windows\system32\nwprovau.dll

O15 - Trusted Zone: http://cf-charts.iitech.dk

O15 - Trusted Zone: http://www.saxobank.com

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1199823989773

O17 - HKLM\System\CCS\Services\Tcpip\..\{F078E569-BC5B-4196-9C73-3072631715AA}: NameServer = 195.14.50.1 195.14.50.21

O23 - Service: C-DillaCdaC11BA - Macrovision - Q:\WINDOWS\system32\drivers\CDAC11BA.EXE

O23 - Service: Dr.Web® AV-Desk Agent (drwagntd) - Doctor Web, Ltd. - Q:\Program Files\DrWeb AV-Desk\drwagntd.exe

O23 - Service: Dr.Web® AV-Desk Upgrade Service (drwupgrade) - Doctor Web, Ltd. - Q:\Program Files\DrWeb AV-Desk\0\drwupgrade.exe

O23 - Service: Журнал событий (Eventlog) - Корпорация Майкрософт - Q:\WINDOWS\system32\services.exe

O23 - Service: Служба COM записи компакт-дисков IMAPI (ImapiService) - Корпорация Майкрософт - Q:\WINDOWS\system32\imapi.exe

O23 - Service: NetMeeting Remote Desktop Sharing (mnmsrvc) - Корпорация Майкрософт - Q:\WINDOWS\system32\mnmsrvc.exe

O23 - Service: Plug and Play (PlugPlay) - Корпорация Майкрософт - Q:\WINDOWS\system32\services.exe

O23 - Service: Диспетчер сеанса справки для удаленного рабочего стола (RDSessMgr) - Корпорация Майкрософт - Q:\WINDOWS\system32\sessmgr.exe

O23 - Service: Смарт-карты (SCardSvr) - Корпорация Майкрософт - Q:\WINDOWS\System32\SCardSvr.exe

O23 - Service: Служба SNMP (SNMP) - Корпорация Майкрософт - Q:\WINDOWS\System32\snmp.exe

O23 - Service: SpIDer Guard for Windows (SPIDERNT) - Doctor Web, Ltd. - Q:\PROGRA~1\DRWEBA~1\spidernt.exe

O23 - Service: Журналы и оповещения производительности (SysmonLog) - Корпорация Майкрософт - Q:\WINDOWS\system32\smlogsvc.exe

O23 - Service: Теневое копирование тома (VSS) - Корпорация Майкрософт - Q:\WINDOWS\System32\vssvc.exe

O23 - Service: Адаптер производительности WMI (WmiApSrv) - Корпорация Майкрософт - Q:\WINDOWS\system32\wbem\wmiapsrv.exe

--

End of file - 7682 bytes

2. Process Explorer reported:

Process PID CPU Description Company Name

System Idle Process 0 90.29

Interrupts n/a Hardware Interrupts

DPCs n/a Deferred Procedure Calls

System 4

smss.exe 592 Диспетчер сеанса Windows NT Корпорация Майкрософт

csrss.exe 648 Client Server Runtime Process Microsoft Corporation

winlogon.exe 672 Программа входа в систему Windows NT Корпорация Майкрософт

services.exe 716 0.97 Приложение служб и контроллеров Корпорация Майкрософт

svchost.exe 924 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 972 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1076 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1168 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1252 Generic Host Process for Win32 Services Microsoft Corporation

spoolsv.exe 1448 Spooler SubSystem App Microsoft Corporation

msdtc.exe 1948 MS DTC console program Microsoft Corporation

CDAC11BA.EXE 256 Macrovision RTS Service Macrovision

cisvc.exe 336 4.85 Content Index service Microsoft Corporation

cidaemon.exe 3496 Indexing Service filter daemon Microsoft Corporation

cidaemon.exe 3520 Indexing Service filter daemon Microsoft Corporation

inetinfo.exe 448 Internet Information Services Корпорация Майкрософт (Microsoft Corp.)

MDM.EXE 480 Machine Debug Manager Microsoft Corporation

tcpsvcs.exe 1260 TCP/IP Services Application Microsoft Corporation

snmp.exe 1360 Служба SNMP Корпорация Майкрософт

SPIDERNT.EXE 1544 SpIDer Guard Service Doctor Web, Ltd.

wdfmgr.exe 1696 Windows User Mode Driver Manager Microsoft Corporation

mqsvc.exe 1896 Message Queuing Service Microsoft Corporation

mqtgsvc.exe 2420 Windows NT MSMQ Trigger Service Microsoft Corporation

DRWAGNTD.EXE 2612 Dr.Web® AV-Desk Agent Doctor Web, Ltd.

alg.exe 2920 Application Layer Gateway Service Microsoft Corporation

lsass.exe 728 LSA Shell (Export Version) Microsoft Corporation

explorer.exe 1816 1.94 Проводник Корпорация Майкрософт

DRWAGNUI.EXE 2020 Dr.Web® AV-Desk Agent UI Doctor Web, Ltd.

SPIDERML.EXE 2032 SpIDer Mail ® for Windows Workstation Doctor Web, Ltd.

SPIDERUI.EXE 192 SpIDer Guard UI Agent Doctor Web, Ltd.

jusched.exe 220 Java Platform SE binary Sun Microsystems, Inc.

ctfmon.exe 280 CTF Loader Microsoft Corporation

Totalcmd.exe 456 Total Commander 32 bit international version, file manager replacement for Windows C. Ghisler & Co.

procexp.exe 3576 0.97 Sysinternals Process Explorer Sysinternals

uTorrent.exe 3268 0.97

iexplore.exe 3880 Internet Explorer Microsoft Corporation

iexplore.exe 584 Internet Explorer Microsoft Corporation

Totalcmd.exe 3472 Total Commander 32 bit international version, file manager replacement for Windows C. Ghisler & Co.

cmd.exe 3872 Обработчик команд Windows Корпорация Майкрософт

iexplore.exe 620 Internet Explorer Microsoft Corporation

taskmgr.exe 1120 Диспетчер задач Windows Корпорация Майкрософт

ICQ.exe 1276 ICQ Library ICQ, Inc.

HijackThis.exe 1932 HijackThis Trend Micro Inc.

Process: uTorrent.exe Pid: 3268

Name Description Company Name Version

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

<Pagefile Backed>

ACTIVEDS.dll Библиотека DLL уровня маршрутизатора AD Корпорация Майкрософт 5.01.2600.2180

adsldpc.dll Библиотека DLL поставщика LDAP AD Корпорация Майкрософт 5.01.2600.2180

ADVAPI32.dll Расширенная библиотека API Windows 32 Корпорация Майкрософт 5.01.2600.2180

ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000

CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0308

COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982

comdlg32.dll Библиотека общих диалоговых окон Корпорация Майкрософт 6.00.2900.2180

COMRes.dll Корпорация Майкрософт 2001.12.4414.0258

ctype.nls

DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.2938

DRWEBSP.DLL Dr.Web Winsock Provider Hook Doctor Web, Ltd. 4.44.0000.11060

GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3159

hnetcfg.dll Диспетчер конфигурации домашней сети Корпорация Майкрософт 5.01.2600.2180

IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180

Iphlpapi.dll API модуля поддержки IP Корпорация Майкрософт 5.01.2600.2912

kernel32.dll Библиотека клиента Windows NT BASE API Корпорация Майкрософт 5.01.2600.3119

locale.nls

MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180

MSCTF.dll Библиотека (DLL) MSCTF-сервера Корпорация Майкрософт 5.01.2600.2180

msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180

mswsock.dll Расширение поставщика службы API Microsoft Windows Sockets 2.0 Корпорация Майкрософт 5.01.2600.2180

NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2180

ntdll.dll Системная библиотека NT Корпорация Майкрософт 5.01.2600.2180

ole32.dll Microsoft OLE для Windows Корпорация Майкрософт 5.01.2600.2726

oleaut32.dll Microsoft Corporation 5.01.2600.3139

pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 5.01.2600.2180

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938

RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173

rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180

SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180

Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180

SETUPAPI.dll Windows Setup API Корпорация Майкрософт 5.01.2600.2180

SHELL32.dll Общая библиотека оболочки Windows Корпорация Майкрософт 6.00.2900.3241

SHLWAPI.dll Библиотека небольших программ оболочки Корпорация Майкрософт 6.00.2900.3231

sortkey.nls

sorttbls.nls

unicode.nls

USER32.dll Библиотека клиента USER API Windows XP Корпорация Майкрософт 5.01.2600.3099

uTorrent.exe

uxtheme.dll Библиотека тем UxTheme (Microsoft) Корпорация Майкрософт 6.00.2900.2180

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180

winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.2180

WLDAP32.dll Win32 LDAP API DLL Корпорация Майкрософт 5.01.2600.2180

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180

WS2HELP.dll Модуль поддержки Windows Socket 2.0 для Windows NT Корпорация Майкрософт 5.01.2600.2180

wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180

3. No Crash dump

4. Task Manager in column "Handles" show 7500 per 1 hour after restart and incrementing this value all time.

Windows Task Manager -> View -> Select columns -> "Handle Count"

In Grid column "Handles"

Link to comment
Share on other sites

Would it be possible to tell your AV to not inject itself:

relevant line is DRWEBSP.DLL Dr.Web Winsock Provider Hook Doctor Web, Ltd. 4.44.0000.11060 .

Also things you may or may not be aware of: you have layered service provider injection: O10 - Unknown file in Winsock LSP: q:\windows\system32\nwprovau.dll

And I'm amazed you let C-Dilla live on your computer. I guess you let WebMoney advisor help you with your saxobank account so that's OK.

See if you can add uTorrent to an exception list for your AV "winsock hook", it's not necessary. :)

Link to comment
Share on other sites

If nothing else unexpected shows up for an injected DLL list of the utorrent process in Process Explorer and you are still showing handles increasing, as Ultima said both User and GDI Objects had leaks which were fixed in 1.8. If you are still experiencing them with 1.8 it is most certainly another program still injected.

Link to comment
Share on other sites

  • 2 weeks later...

I'm also having this problem with the handles continually climbing. I had Dr.Web installed, but never used it so uninstalled it. Restarted Firefox and uTorrent, still having the same problem. I had this problem with version 1.7.5 and now with 1.7.6 build (7859). Handle count was over 200k after running for around 30 hours.

HijackThis:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 8:12:47 PM, on 1/20/2008
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16574)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Windows Defender\MsMpEng.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
C:\Program Files\Alwil Software\Avast4\ashServ.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Windows Defender\MSASCui.exe
C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
C:\Program Files\DAEMON Tools\daemon.exe
C:\Program Files\ATI Technologies\ATI.ACE\CLI.EXE
C:\WINDOWS\System32\cisvc.exe
C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
C:\WINDOWS\system32\ctfmon.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\WINDOWS\system32\cidaemon.exe
C:\WINDOWS\system32\SearchIndexer.exe
C:\Program Files\AutoGK\AutoGK.exe
C:\Program Files\Windows Desktop Search\WindowsSearch.exe
C:\Program Files\PeerGuardian2\pg2.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\WINDOWS\system32\SearchProtocolHost.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
O2 - BHO: (no name) - -{7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 8\SnagItBHO.dll
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~2\Office12\GRA8E1~1.DLL
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll
O3 - Toolbar: Zend Studio - {95188727-288F-4581-A48D-EAB3BD027314} - C:\PROGRA~1\Zend\ZENDST~1.0\bin\ZENDIE~1.DLL
O3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 8\SnagItIEAddin.dll
O3 - Toolbar: BeInSync - {4F2530BA-8C1D-4A6A-8BA0-74E93ADC9B12} - C:\PROGRA~1\BeInSync\BISShellEx.dll
O4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hide
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\CLIStart.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe"
O4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKCU\..\Run: [PeerGuardian] C:\Program Files\PeerGuardian2\pg2.exe
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKUS\S-1-5-18\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [DWQueuedReporting] "C:\PROGRA~1\COMMON~1\MICROS~1\DW\dwtrig20.exe" -t (User 'Default user')
O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe
O4 - Startup: MagicDisc.lnk = C:\Program Files\MagicDisc\MagicDisc.exe
O4 - Global Startup: Windows Desktop Search.lnk = C:\Program Files\Windows Desktop Search\WindowsSearch.exe
O8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_03\bin\ssv.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MIC273~1\Office12\REFIEBAR.DLL
O9 - Extra button: Bodog Poker - {F47C1DB5-ED21-4dc1-853E-D1495792D4C5} - C:\Program Files\Bodog Poker\BPGame.exe
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/SharedContent/vc/bin/AvSniff.cab
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1162297001306
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1162785635640
O16 - DPF: {C9386579-3C0F-4713-82C6-5BA8088C7C8D} (Windows Live SkyDrive Upload Tool) - https://cid-c31d6e21bd734b43.skydrive.live.com/Microsoft.Live.Folders.RichUpload.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O17 - HKLM\System\CS1\Services\Tcpip\Parameters: SearchList = int.callwave.com,callwave.com
O17 - HKLM\System\CS2\Services\Tcpip\Parameters: SearchList = int.callwave.com,callwave.com
O17 - HKLM\System\CS3\Services\Tcpip\Parameters: SearchList = int.callwave.com,callwave.com
O17 - HKLM\System\CCS\Services\Tcpip\Parameters: SearchList = int.callwave.com,callwave.com
O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\PROGRA~1\MICROS~2\Office12\GR99D3~1.DLL
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe

--
End of file - 9113 bytes

Process Explorer

Process    PID    CPU    Description    Company Name    Handles
System Idle Process 0 96.92 0
Interrupts n/a Hardware Interrupts 0
DPCs n/a Deferred Procedure Calls 0
System 4 1,987
smss.exe 660 Windows NT Session Manager Microsoft Corporation 21
csrss.exe 724 Client Server Runtime Process Microsoft Corporation 640
winlogon.exe 752 Windows NT Logon Application Microsoft Corporation 1,705
services.exe 804 Services and Controller app Microsoft Corporation 430
ati2evxx.exe 968 ATI External Event Utility EXE Module ATI Technologies Inc. 84
svchost.exe 980 Generic Host Process for Win32 Services Microsoft Corporation 216
svchost.exe 1068 Generic Host Process for Win32 Services Microsoft Corporation 362
MsMpEng.exe 1180 Service Executable Microsoft Corporation 300
svchost.exe 1220 Generic Host Process for Win32 Services Microsoft Corporation 2,259
svchost.exe 1252 Generic Host Process for Win32 Services Microsoft Corporation 105
svchost.exe 1396 Generic Host Process for Win32 Services Microsoft Corporation 121
svchost.exe 1496 Generic Host Process for Win32 Services Microsoft Corporation 287
aswUpdSv.exe 1676 avast! Antivirus updating service ALWIL Software 27
ashServ.exe 1724 avast! antivirus service ALWIL Software 285
spoolsv.exe 1896 Spooler SubSystem App Microsoft Corporation 147
cisvc.exe 1132 Content Index service Microsoft Corporation 227
cidaemon.exe 2480 Indexing Service filter daemon Microsoft Corporation 167
DkService.exe 1164 Diskeeper Service Diskeeper Corporation 322
svchost.exe 2408 Generic Host Process for Win32 Services Microsoft Corporation 122
ashMaiSv.exe 2696 avast! e-Mail Scanner Service ALWIL Software 96
ashWebSv.exe 2768 avast! Web Scanner ALWIL Software 193
alg.exe 3300 Application Layer Gateway Service Microsoft Corporation 108
searchindexer.exe 3020 Microsoft Windows Search Indexer Microsoft Corporation 1,585
lsass.exe 816 LSA Shell (Export Version) Microsoft Corporation 449
ati2evxx.exe 1316 ATI External Event Utility EXE Module ATI Technologies Inc. 103
explorer.exe 484 1.54 Windows Explorer Microsoft Corporation 59,641
MSASCui.exe 608 Windows Defender User Interface Microsoft Corporation 532
ashDisp.exe 472 avast! service GUI component ALWIL Software 189
daemon.exe 424 Virtual DAEMON Manager DT Soft Ltd. 374
ctfmon.exe 1332 CTF Loader Microsoft Corporation 198
AutoGK.exe 5736 AVI conversion front-end autogk.net 24,097
WindowsSearch.exe 4988 Windows Desktop Search System Tray Microsoft Corporation 301
pg2.exe 4000 PeerGuardian 2 Methlabs 226
utorrent.exe 3472 214,562
procexp.exe 4964 1.54 Sysinternals Process Explorer Sysinternals 349
CLI.exe 928 CLI Application (Command Line Interface) ATI Technologies Inc. 451
CLI.exe 2176 CLI Application (Command Line Interface) ATI Technologies Inc. 300
firefox.exe 5460 Firefox Mozilla Corporation 328
WinRAR.exe 500 239

Process: utorrent.exe Pid: 3472

Name Description Company Name Version
ACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.2180
adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.2180
ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180
appHelp.dll Application Compatibility Client Library Microsoft Corporation 5.01.2600.2180
ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000
ATL80.DLL ATL Module for Windows (Unicode) Microsoft Corporation 8.00.50727.0042
browseui.dll Shell Browser UI Library Microsoft Corporation 6.00.2900.2995
CFGMGR32.dll Configuration Manager Forwarder DLL Microsoft Corporation 5.01.2600.2180
CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0308
COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982
comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.2180
COMRes.dll Microsoft Corporation 2001.12.4414.0258
CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.2180
CRYPTUI.dll Microsoft Trust UI Provider Microsoft Corporation 5.131.2600.2180
CSCDLL.dll Offline Network Agent Microsoft Corporation 5.01.2600.2180
cscui.dll Client Side Caching UI Microsoft Corporation 5.01.2600.2180
ctype.nls
davclnt.dll Web DAV Client DLL Microsoft Corporation 5.01.2600.2180
DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.2938
drprov.dll Microsoft Terminal Server Network Provider Microsoft Corporation 5.01.2600.2180
fsshext.8.1.0178.00.dll Messenger File Sharing Shell Extensions Microsoft Corporation 8.01.0178.0000
GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3159
gdiplus.dll Microsoft GDI+ Microsoft Corporation 5.01.3102.2180
GR99D3~1.DLL GrooveSystemServices Module Microsoft Corporation 12.00.4518.1014
GRA8E1~1.DLL GrooveShellExtensions Module Microsoft Corporation 12.00.4518.1014
GrooveNew.DLL GrooveNew Module Microsoft Corporation 12.00.4518.1014
GrooveUtil.DLL GrooveUtil Module Microsoft Corporation 12.00.4518.1014
hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.2180
ieframe.dll Internet Explorer Microsoft Corporation 7.00.6000.16574
iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6000.16574
IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 5.01.2600.2180
IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180
index.dat
index.dat
index.dat
Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2912
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.3119
LINKINFO.dll Windows Volume Tracking Microsoft Corporation 5.01.2600.2751
locale.nls
mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001
MPR.dll Multiple Provider Router DLL Microsoft Corporation 5.01.2600.2180
MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180
MpShHook.dll Shell Execution Monitor Microsoft Corporation 1.01.1592.0000
MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.2180
MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.01.2600.2180
msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180
MSGINA.dll Windows NT Logon GINA DLL Microsoft Corporation 5.01.2600.2180
MSImg32.dll GDIEXT Client DLL Microsoft Corporation 5.01.2600.2180
MSNLNamespaceMgr.dll Windows Desktop Search Namespace Manager Microsoft Corporation 6.00.6000.16431
MSVCP80.dll Microsoft® C++ Runtime Library Microsoft Corporation 8.00.50727.1378
MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.00.50727.1378
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.2180
msxml3.dll MSXML 3.0 SP9 Microsoft Corporation 8.90.1101.0000
msxml3r.dll XML Resources Microsoft Corporation 8.20.8730.0001
NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2976
NETRAP.dll Net Remote Admin Protocol DLL Microsoft Corporation 5.01.2600.2180
NETUI0.dll NT LM UI Common Code - GUI Classes Microsoft Corporation 5.01.2600.2180
NETUI1.dll NT LM UI Common Code - Networking classes Microsoft Corporation 5.01.2600.2180
Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.00.5441.0000
ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180
ntlanman.dll Microsoft® Lan Manager Microsoft Corporation 5.01.2600.2180
ntshrui.dll Shell extensions for sharing Microsoft Corporation 5.01.2600.2180
ODBC32.dll Microsoft Data Access - ODBC Driver Manager Microsoft Corporation 3.525.1117.0000
odbcint.dll Microsoft Data Access - ODBC Resources Microsoft Corporation 3.525.1117.0000
ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726
oleaut32.dll Microsoft Corporation 5.01.2600.3139
PortableDeviceApi.dll Windows Portable Device API Components Microsoft Corporation 5.02.5721.5145
PSAPI.DLL Process Status Helper Microsoft Corporation 5.01.2600.2180
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938
RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173
rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 5.01.2600.2161
rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180
SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180
Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180
SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.2180
shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation 6.00.2900.2987
SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.3241
SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.2995
sortkey.nls
sorttbls.nls
sti.dll Still Image Devices client DLL Microsoft Corporation 5.01.2600.2180
unicode.nls
urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.00.6000.16574
USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.3099
USERENV.dll Userenv Microsoft Corporation 5.01.2600.2180
utorrent.exe
uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180
VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180
WININET.dll Internet Extensions for Win32 Microsoft Corporation 7.00.6000.16574
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.2180
WINSTA.dll Winstation Library Microsoft Corporation 5.01.2600.2180
WINTRUST.dll Microsoft Trust Verification APIs Microsoft Corporation 5.131.2600.2180
WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180
WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180
WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180
wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180
xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.01.2600.2180

Link to comment
Share on other sites

!!!! OMG we may have an authentic problem of a non-injected uT climbing. :D Thanks be to Drew42. Now I can't advise further as I have no ruddy clue where to go from here. All those DLLs look to be authentic and from Microsoft, lol.

Unfortunately you also have multiple search entries and are using the non-AV portion of Avast as well as Windows Defender. All of which MAY muck with "proper" (as in, I don't have them installed and I don't have problems :P) operation of your uT.

Link to comment
Share on other sites

Would a new Process Explorer DLL log to verify nothing new be out of the question?? Like I said if you have found some bug, it will take private testing to resolve <3 Thank you for being so understanding and helpful Drew42. To verify you're talking about the "Handles" column in Procexp.exe, not "User Objects" or "GDI Objects" right?

Link to comment
Share on other sites

C:\WINDOWS\System32\cisvc.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

Just to knock off possibilities, can you try killing off these search indexing processes and checking if the problem persists? Can you try 1.8 to see if it still has leaks? Finally, if you're referring to just handles in general, try checking GDIView to make sure it's not a GDI leak (which would come in the form of handle counts just increasing for µTorrent in GDIView).

Link to comment
Share on other sites

Yes, the Handles column in Procexp.exe or Windows Taskmanager. User Objects = 59 and GDI = 123. Handles is currently over 11k and has been running for around 90 minutes.

Killed off one by one:

C:\WINDOWS\System32\cisvc.exe

C:\WINDOWS\system32\cidaemon.exe

C:\WINDOWS\system32\SearchIndexer.exe

C:\Program Files\Windows Desktop Search\WindowsSearch.exe

C:\WINDOWS\system32\SearchProtocolHost.exe

No change after each.

After upgrading to 1.8, here's the results:

Handles continue to climb. Over 1k in 7 minutes. User Objects = 73 and GDI Objects =129.

Don't know if this helps, but in PE's Handle window, the Handle that repeats thousands of times is this:

uTorrent_Handle.gif

You're welcome. I don't mind helping out.

Here's a fresh PE:

Process    PID    CPU    Description    Company Name    Handles    Start Time    USER Objects    GDI Objects
System Idle Process 0 90.77 0 n/a 0 0
Interrupts n/a Hardware Interrupts 0 n/a 0 0
DPCs n/a Deferred Procedure Calls 0 n/a 0 0
System 4 1,019 n/a 0 0
smss.exe 668 Windows NT Session Manager Microsoft Corporation 21 10:02:41 PM 1/20/2008 0 0
csrss.exe 732 3.08 Client Server Runtime Process Microsoft Corporation 563 10:02:45 PM 1/20/2008 58 61
winlogon.exe 760 Windows NT Logon Application Microsoft Corporation 606 10:02:47 PM 1/20/2008 14 46
services.exe 812 1.54 Services and Controller app Microsoft Corporation 299 10:02:48 PM 1/20/2008 2 4
ati2evxx.exe 976 ATI External Event Utility EXE Module ATI Technologies Inc. 84 10:02:48 PM 1/20/2008 6 11
svchost.exe 988 Generic Host Process for Win32 Services Microsoft Corporation 216 10:02:48 PM 1/20/2008 1 4
svchost.exe 1076 Generic Host Process for Win32 Services Microsoft Corporation 301 10:02:48 PM 1/20/2008 1 4
MsMpEng.exe 1188 Service Executable Microsoft Corporation 288 10:02:49 PM 1/20/2008 1 4
svchost.exe 1228 Generic Host Process for Win32 Services Microsoft Corporation 1,761 10:02:49 PM 1/20/2008 36 11
svchost.exe 1264 Generic Host Process for Win32 Services Microsoft Corporation 105 10:02:49 PM 1/20/2008 1 4
svchost.exe 1448 Generic Host Process for Win32 Services Microsoft Corporation 100 10:02:50 PM 1/20/2008 1 4
svchost.exe 1556 Generic Host Process for Win32 Services Microsoft Corporation 229 10:02:50 PM 1/20/2008 1 4
spoolsv.exe 1676 Spooler SubSystem App Microsoft Corporation 148 10:02:50 PM 1/20/2008 5 4
svchost.exe 1920 Generic Host Process for Win32 Services Microsoft Corporation 123 10:03:24 PM 1/20/2008 2 4
alg.exe 3112 Application Layer Gateway Service Microsoft Corporation 100 10:03:48 PM 1/20/2008 2 4
DkService.exe 3616 1.54 Diskeeper Service Diskeeper Corporation 293 11:37:21 PM 1/20/2008 9 9
svchost.exe 2164 Generic Host Process for Win32 Services Microsoft Corporation 92 11:41:07 PM 1/20/2008 1 4
lsass.exe 824 LSA Shell (Export Version) Microsoft Corporation 367 10:02:48 PM 1/20/2008 2 6
ati2evxx.exe 1324 ATI External Event Utility EXE Module ATI Technologies Inc. 102 10:02:49 PM 1/20/2008 5 11
explorer.exe 2032 Windows Explorer Microsoft Corporation 3,661 10:02:58 PM 1/20/2008 277 415
MSASCui.exe 332 Windows Defender User Interface Microsoft Corporation 330 10:03:00 PM 1/20/2008 98 107
daemon.exe 384 Virtual DAEMON Manager DT Soft Ltd. 63 10:03:00 PM 1/20/2008 6 17
pg2.exe 524 PeerGuardian 2 Methlabs 117 10:03:00 PM 1/20/2008 107 58
ctfmon.exe 564 CTF Loader Microsoft Corporation 122 10:03:00 PM 1/20/2008 47 99
firefox.exe 3652 Firefox Mozilla Corporation 768 10:09:10 PM 1/20/2008 160 270
PowerDVD.exe 2880 PowerDVD CyberLink Corp. 568 10:42:20 PM 1/20/2008 84 250
taskmgr.exe 176 Windows TaskManager Microsoft Corporation 163 11:30:19 PM 1/20/2008 130 120
SnagIt32.exe 324 SnagIt 8 TechSmith Corporation 378 11:52:34 PM 1/20/2008 302 612
TscHelp.exe 2824 TechSmith HTML Help Helper TechSmith Corporation 47 11:52:36 PM 1/20/2008 6 11
SnagPriv.exe 2820 SnagIt RPC Helper TechSmith Corporation 38 11:52:37 PM 1/20/2008 2 4
procexp.exe 172 1.54 Sysinternals Process Explorer Sysinternals 338 11:57:18 PM 1/20/2008 175 300
CLI.exe 376 CLI Application (Command Line Interface) ATI Technologies Inc. 442 10:03:00 PM 1/20/2008 17 28
CLI.exe 3896 CLI Application (Command Line Interface) ATI Technologies Inc. 298 10:03:53 PM 1/20/2008 6 8
utorrent.exe 1936 1.54 µTorrent BitTorrent, Inc. 2,331 11:40:56 PM 1/20/2008 74 131

Process: utorrent.exe Pid: 1936

Name Description Company Name Version
ACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.2180
adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.2180
ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180
ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000
BISDlgs.dll BeInSync Dialogs BeInSync 3.01.0057.0000
BISGuiEngine.dll BeInSync GUI Engine BeInSync 3.01.0057.0000
BISShellEx.dll BeInSync Shell Extenstion BeInSync 3.01.0057.0000
CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0308
COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982
comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.2180
COMRes.dll Microsoft Corporation 2001.12.4414.0258
credui.dll Credential Manager User Interface Microsoft Corporation 5.01.2600.2180
CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.2180
ctype.nls
DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.2938
DPACE.dll ACE 5.03.0000.0000
DPLib.dll BeInSync Library Dll BeInSync 3.01.0057.0000
DPUtils.dll BeInSync Utilities Dll BeInSync 3.01.0057.0000
DPzlib1.dll zlib data compression library 1.02.0002.0000
GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3159
hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.2180
iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6000.16574
IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180
Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2912
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.3119
locale.nls
log4cpp.dll Log library for C++ DLL Bastiaan Bakker, LifeLine Networks bv 0.03.0002.0001
mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001
MFC71ENU.DLL MFC Language Specific Resources Microsoft Corporation 7.10.3077.0000
MFC71U.DLL MFCDLL Shared Library - Retail Version Microsoft Corporation 7.10.3077.0000
MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180
MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.2180
MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.01.2600.2180
msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180
MSIMG32.dll GDIEXT Client DLL Microsoft Corporation 5.01.2600.2180
MSVCP71.dll Microsoft® C++ Runtime Library Microsoft Corporation 7.10.3077.0000
MSVCR71.dll Microsoft® C Runtime Library Microsoft Corporation 7.10.3052.0004
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.2180
NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2976
netshell.dll Network Connections Shell Microsoft Corporation 5.01.2600.2180
Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.00.5441.0000
ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180
ODBC32.dll Microsoft Data Access - ODBC Driver Manager Microsoft Corporation 3.525.1117.0000
odbcbcp.dll Microsoft BCP for ODBC Microsoft Corporation 2000.85.1117.0000
ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726
oleaut32.dll Microsoft Corporation 5.01.2600.3139
pdh.dll Windows Performance Data Helper DLL Microsoft Corporation 5.01.2600.2180
psapi.dll Process Status Helper Microsoft Corporation 5.01.2600.2180
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938
RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173
rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180
SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180
SensApi.dll SENS Connectivity API DLL Microsoft Corporation 5.01.2600.2180
SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.2180
SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.3241
shfolder.dll Shell Folder Service Microsoft Corporation 6.00.2900.2180
SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.2995
sortkey.nls
sorttbls.nls
unicode.nls
USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.3099
uTorrent.exe µTorrent BitTorrent, Inc. 1.08.0000.7928
uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180
VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180
WINHTTP.dll Windows HTTP Services Microsoft Corporation 5.01.2600.2180
WININET.dll Internet Extensions for Win32 Microsoft Corporation 7.00.6000.16574
winmm.dll MCI API DLL Microsoft Corporation 5.01.2600.2180
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.2180
WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180
WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180
WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180
wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180
xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.01.2600.2180

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...