BSOD on Windows Vista SP 1 (1.7.7 *and* 1.8 beta)


Whenever I open uTorrent, after a few minutes, I always get a BSOD with the message PAGE_ERROR_IN_NONPAGED_AREA. I've tested my RAM, it seems fine. I think the problem may be that at one point I used Wine 0.9.59 on Ubuntu 8.04 to open uTorrent. I've tried reinstalling uTorrent (stable and beta) to no avail.


Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:21:23 AM, on 5/10/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Program Files\Common Files\microsoft shared\ink\TabTip.exe
C:\Program Files\HP\HP Software Update\hpwuSchd2.exe
C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exe
C:\Program Files\iTunes\iTunesHelper.exe
C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe
C:\Program Files\Microsoft IntelliPoint\ipoint.exe
C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
C:\Program Files\Microsoft IntelliPoint\dpupdchk.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exe
C:\Program Files\Common Files\Microsoft Shared\Ink\InputPersonalization.exe
C:\Program Files\uTorrent\uTorrent.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blank
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Internet Explorer provided by Dell
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [dscactivate] c:\dell\dsca.exe 3
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [IntelliPoint] "C:\Program Files\Microsoft IntelliPoint\ipoint.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [ISUSPM Startup] C:\PROGRA~1\COMMON~1\INSTAL~1\UPDATE~1\ISUSPM.exe -startup
O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exe
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\npjpi160_05.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {5F8469B4-B055-49DD-83F7-62B522420ECC} (Facebook Photo Uploader Control) - http://upload.facebook.com/controls/FacebookPhotoUploader.cab
O16 - DPF: {80AEEC0E-A2BE-4B8D-985F-350FE869DC40} (HPDDClientExec Class) - http://h30155.www3.hp.com/ediags/dd/install/HPDriverDiagnosticsVista.cab
O16 - DPF: {814EA0DA-E0D9-4AA4-833C-A1A6D38E79E9} (DASWebDownload Class) - http://das.microsoft.com/activate/cab/x86/i486/NTANSI/retail/DASAct.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Andrea RT Filters Service (AERTFilters) - Andrea Electronics Corporation - C:\Windows\system32\AERTSrv.exe
O23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe
O23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: Symantec Lic NetConnect service (CLTNetCnService) - Unknown owner - C:\Program Files\Common Files\Symantec Shared\ccSvcHst.exe (file missing)
O23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exe
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe
O23 - Service: stllssvr - Unknown owner - C:\Program Files\Common Files\SureThing Shared\stllssvr.exe (file missing)
O23 - Service: TabletServiceWacom - Wacom Technology, Corp. - C:\Windows\system32\Wacom_Tablet.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe

End of file - 7663 bytes

Process explorer:

Process    PID    CPU    Description    Company Name
System Idle Process 0 94.78
Interrupts n/a 0.78 Hardware Interrupts
DPCs n/a 0.78 Deferred Procedure Calls
System 4
smss.exe 436
csrss.exe 576
wininit.exe 628
services.exe 672
svchost.exe 856
WmiPrvSE.exe 2176
ehmsas.exe 156 Media Center Media Status Aggregator Service Microsoft Corporation
svchost.exe 932
svchost.exe 1032
audiodg.exe 1156
svchost.exe 1056 0.78
WUDFHost.exe 3140
wisptis.exe 2252
TabTip.exe 1544
wisptis.exe 3528
TabTip.exe 3796
dwm.exe 1524 Desktop Window Manager Microsoft Corporation
svchost.exe 1072
taskeng.exe 3056
taskeng.exe 3400 Task Scheduler Engine Microsoft Corporation
InputPersonalization.exe 3692 Input Personalization Server Microsoft Corporation
SLsvc.exe 1184
svchost.exe 1220
svchost.exe 1320
aawservice.exe 1412
spoolsv.exe 1764
svchost.exe 1800
AERTSrv.exe 2392
AppleMobileDeviceService.exe 2420
mDNSResponder.exe 2440
svchost.exe 2480
svchost.exe 2500
NMSAccessU.exe 2556
svchost.exe 2648
svchost.exe 2700
svchost.exe 2728
Wacom_Tablet.exe 2752
Wacom_TabletUser.exe 2116 Tablet user module for professional driver Wacom Technology, Corp.
Wacom_Tablet.exe 624
ViewpointService.exe 2804
svchost.exe 2876
SearchIndexer.exe 2904
SearchProtocolHost.exe 3644
SearchFilterHost.exe 1788
wmpnetwk.exe 3696
iPodService.exe 3428
lsass.exe 684
lsm.exe 696
csrss.exe 1636
winlogon.exe 3244
explorer.exe 2128 Windows Explorer Microsoft Corporation
RtHDVCpl.exe 2328 HD Audio Control Panel Realtek Semiconductor
hpwuSchd2.exe 2072 Hewlett-Packard Product Assistant Hewlett-Packard Co.
reader_sl.exe 280 Adobe Acrobat SpeedLauncher Adobe Systems Incorporated
iTunesHelper.exe 2112 iTunesHelper Module Apple Inc.
jusched.exe 480 Java(TM) Platform SE binary Sun Microsystems, Inc.
rundll32.exe 900 Windows host process (Rundll32) Microsoft Corporation
ipoint.exe 1668 IPoint.exe Microsoft Corporation
dpupdchk.exe 1288 dpupdchk.exe Microsoft Corporation
ehtray.exe 456 Media Center Tray Applet Microsoft Corporation
GoogleToolbarNotifier.exe 3616 GoogleToolbarNotifier Google Inc.
hpqtra08.exe 2208 HP Digital Imaging Monitor Hewlett-Packard Co.
hpqste08.exe 1132 HP CUE Status Hewlett-Packard Co.
wmpnscfg.exe 808 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
procexp.exe 3292 0.78 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
uTorrent.exe 512 1.55 µTorrent BitTorrent, Inc.
rundll32.exe 2256 Windows host process (Rundll32) Microsoft Corporation

Thanks in advance.

Check your HDD for problems. This can cause PAGE_ERROR_IN_NONPAGED_AREA faults if Windows fails to update the swap/page file on disk.

If you have other HDD or partitions try installing Windows or redirecting the page file to one of them.

I'm pretty sure it's not the RAM - I tested it with multiple programs, and no errors were found. I also checked the HDD (no errors). When I don't open uTorrent I can use my computer for hours at a time without a crash. But once I open uTorrent, the BSOD appears within minutes.

It sounds more like a driver / tablet issue actually. Not crashing when not filesharing and crashing when doing so, usually signifies hardware or drivers which can't handle the load. Comparatively, if you download a HTTP file or FTP file as fast as you are getting from within uT, does your comp crash? Most likely not. Have you tried lowering your connections settings and other features as mentioned in http://forum.utorrent.com/viewtopic.php?id=15992

On Windows Vista SP1 it does create the BSOD within a couple of minutes.. the BSOD mentions something about the tcp\ip.sys. Obviosly, this is caused by the SP1 upgrade as utorrent still has the same settings as used before the SP1 update and all worked just perfectly. This is the case in both 1.7.7 and 1.8

Furthermore, when it's used in Windows Server 2008 it goes to a memory usage of 99% within the same amount of time as the BSOD appears in Vista. Both Vista and Server are 64-bit.

Once more, Microsoft decided to change something that will affect a lot of software and so Microsoft made it a uTorrent issue, wether you like it or not.

In both cases it was a new install of Vista x64 and Server 2008 x64.. with Vista having the SP1 added. Firewal was the default windows firewall with no additional settings.. port used in uTorrent is also opened in the router (both tcp and udp)

max connects is 250

max halfopen is 8

Other programs installed were Mozilla Firefox, uTorrent and Adobe Reader 8.

uTorrent 1.6 works fine though.. no problems there.. :/

I had the same problem as this and after some debugging i found the same problem occurred in azureus. As i had just done some updates (i haddnt done so in a while) and it occurred in a few random fairly high connection applications i decided to do a system restore and hey presto it all seems to work fine now. Probably a problem in a driver or Vista's TCP stack for some drivers.

