dlhappy2 Posted May 11, 2008 Report Share Posted May 11, 2008 I just joined this forum today and decided to post a strange problem that occurred a while ago. I know that if the file(s) in a torrent are moved to another directory/folder, and the torrent is re-loaded, utorrent will look in the designated default download directory for the existence of the file and if it is not there, it will download the file from a 0% status. What happened in my case, though, is a different situation. I believe on three different occasions, I re-opened a torrent that had been deleted from the utorrent listing. In each case, I had the complete file or all of files for that torrent, and with the proper extensions, ie: avi, mpg, etc, and in the proper directory/folder. When I re-opened/loaded the torrent so as to seed the file(s), utorrent checked to see if the file existed and the % indicator in the "done" column did not go to 100%, as is usually the case, but instead stopped at 90 something % and when I immediately checked the actual directory, I saw that the file's extension had been modified so as to go back to the uncompleted !ut state (example... it went from movie.avi back to movie.avi.!ut). Luckily, there were still other peers/seeders and I was able to again get the complete file. Then I became a seeder, as I had originally intended. BTW, the files involved were all large files, so, it is not as though utorrent was actually showing the file going from -0- to 90+ percent because it was showing it as it was being downloaded. It was showing that I only had 90+ percent of the file and then the downloading started, and took a while until I got the remainder of the file.Does anyone know why this happened, that is, why I lost part of a complete file when all I did was try to seed what had been a complete file, and how to prevent it from happening again? Now, if I want to re-load a torrent to seed a file, I first make a backup copy of that file before re-loading the torrent. (Yes, I know, all of my files should be backed up, but, I am very low on hard drive space -- both internal and external drives. -- I hope to get new external drives in the future).Thanks for any info. Link to comment Share on other sites More sharing options...
jewelisheaven Posted May 11, 2008 Report Share Posted May 11, 2008 It's possible there was nothing wrong with the file... where was it stored? Some instances of this happening occur with http://utorrent.com/faq.php#Incompatible_software or RAM / other hardware troubles.Where were the missing pieces from? The beginning/end of the file? That can usually be attributed to a media player/ library/ manager messing with tagging information. Link to comment Share on other sites More sharing options...
dlhappy2 Posted May 11, 2008 Author Report Share Posted May 11, 2008 Thanks for your reply, jewelisheaven. The file was stored on my C: drive in a subdirectory/subfolder -- short folder/filenames so that should not be a problem.....as is the case, in general (not necessarily with bit torrent u/l d/l) if the combo subfolders/filename is too long. I don't remember the actual name but as I said previously, the file was in the correct folder specified in the open torrent pop-up box.As for the incompatible software (NVIDIA in the linked faq)...I don't use a software firewall but instead use a hardware firewall...Verizon's supplied router/firewall for my FIOS internet service. Also, I just looked and I presently have 8 torrents actively u/l and d/l right now and the memory usage for uTorrent.exe is in the range of approx. 19,320K. My computer has 2 GB memory, so that does not seem to be a problem.Also, as I said, the problem only happened three times, and that was a while ago. I think when I lost part of the previously complete file, the part lost was from the end of the movie, but I'm not really sure -- it was not recently, and I didn't really pay too much attention. (I merely copied the re-created !ut file and deleted the .!ut from the copy and played it -- I generally use Media Player Classic but sometimes use other players. Btw, I'm not sure, but I think that I had changed the attribute of the complete file to read-only and nevertheless it was overwritten so that it was no longer a complete file when I re-opened the torrent so as to seed the file.Thanks, again. Link to comment Share on other sites More sharing options...
DreadWingKnight Posted May 11, 2008 Report Share Posted May 11, 2008 Post a hijackthis log and a process explorer process list with the DLL list from the uTorrent process. Link to comment Share on other sites More sharing options...
hermanm Posted May 11, 2008 Report Share Posted May 11, 2008 If you look the Files tab for that torrent, where the missing pieces are will usually tell you what the problem is. If the missing pieces are in the middle of the file, your file and their file does not match up. If the missing pieces are at the start or end of the file, that usually means you're seeding a slightly different torrent and the hash pieces don't match up exactly at the start & end of files. Link to comment Share on other sites More sharing options...
dlhappy2 Posted May 11, 2008 Author Report Share Posted May 11, 2008 I downloaded HiJack This and Systeminternals' Process Explorer.Please note that I have installed and updated a lot of software after the problem...so, any you might notice lots of stuff that I did not have at the time. BTW...on 04/17/2008 I was d/l some freeware that led me to a sight that did a scan and suggested I update Winamp, Quicktime, RealPlayer, I think Shockwave to later versions to eliminate security holes in the earlier versions. I did so...but that site supposedly also said it was creating a system restore point...it did not...instead, all of my system restore points before 04/17/2008 were deleted and now, even my own newly created restore points are not retained...only retained are system check restore points .. one or two only... I checked my system restore points settings and I still have the max. 12% disk space setting for system restore...so, I don't know the problem (I'm low on hd space, but not too low, I don't think).Anyway...here are the logs:1. HIJACK THIS LOG:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 4:41:05 PM, on 05/11/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeC:\WINDOWS\ehome\ehtray.exeC:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltpspd.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\Program Files\HP DigitalMedia Archive\DMAScheduler.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exeC:\WINDOWS\system32\rundll32.exeC:\Program Files\Common Files\AOL\1170987345\ee\AOLSoftware.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\Java\jre1.6.0_05\bin\jusched.exeC:\Program Files\Hp\HP Software Update\HPWuSchd2.exeC:\WINDOWS\eHome\ehRecvr.exeC:\Program Files\Winamp\winampa.exeC:\Program Files\Microsoft Office\Office12\GrooveMonitor.exeC:\WINDOWS\eHome\ehSched.exeC:\PROGRA~1\Grisoft\AVG7\avgcc.exeC:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exeC:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exeC:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exeC:\Program Files\Google\Google Desktop Search\GoogleDesktop.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exeC:\Program Files\QuickTime\QTTask.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program Files\Spyware Doctor\sdhelp.exeC:\Program Files\XDesk95\XDesk95.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Microsoft Office\Office\OSA.EXEC:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeC:\Program Files\Google\Google Desktop Search\GoogleDesktop.exeC:\WINDOWS\system32\WFXSVC.EXEC:\Program Files\Symantec\WinFax\WFXMOD32.EXEC:\WINDOWS\ehome\mcrdsvc.exeC:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exeC:\HP\KBD\KBD.EXEC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeC:\WINDOWS\system32\dllhost.exeC:\WINDOWS\System32\alg.exec:\program files\common files\aol\1170987345\ee\services\antiSpywareApp\ver2_0_32_1\AOLSP Scheduler.exeC:\WINDOWS\eHome\ehmsas.exec:\windows\system\hpsysdrv.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\JGsoft\EditPadLite\EditPadLite.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\Webroot\Spy Sweeper\SSU.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\HardDisk Indicator Light\hdi.exeC:\Program Files\America Online 9.0\waol.exeC:\Program Files\America Online 9.0\shellmon.exeC:\Program Files\zabkat\xplorer2_lite\xplorer2_lite.exeC:\Program Files\Outlook Express\msimn.exeC:\Program Files\Mozilla Firefox\firefox.exeD:\AB\DL\temp\HiJack This\HijackThis.exeC:\WINDOWS\system32\wbem\wmiprvse.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktopR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktopR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iesearch&locale=EN_US&c=64&bd=PAVILION&pf=desktopR0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_US&c=64&bd=PAVILION&pf=desktopR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = :R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR3 - URLSearchHook: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllR3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - (no file)R3 - URLSearchHook: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dllO2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLLO2 - BHO: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dllO2 - BHO: Classical Music Radio Toolbar - {2c9881ab-280a-43df-8e13-8655994b16e9} - C:\Program Files\Classical_Music_Radio\tbClas.dllO2 - BHO: flashget urlcatch - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - C:\Program Files\FlashGet\jccatch.dllO2 - BHO: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO2 - BHO: PCTools Site Guard - {5C8B2A36-3DB1-42A4-A3CB-D426709BBFEB} - C:\PROGRA~1\SPYWAR~1\tools\iesdsg.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: hpWebHelper Class - {AAAE832A-5FFF-4661-9C8F-369692D1DCB9} - C:\WINDOWS\pchealth\helpctr\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\plugin\WebHelper.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dllO2 - BHO: PCTools Browser Monitor - {B56A7D7D-6927-48C8-A975-17DF180C71AC} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dllO2 - BHO: FlashGet GetFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - C:\Program Files\FlashGet\getflash.dllO3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Program Files\Yahoo!\Companion\Installs\cpn0\yt.dllO3 - Toolbar: Verizon Broadband Toolbar - {4E7BD74F-2B8D-469E-D0FC-E57AF4D5FA7D} - C:\WINDOWS\DOWNLO~1\vzbb.dll (file missing)O3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - C:\Program Files\FlashGet\fgiebar.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLLO3 - Toolbar: Freecorder Toolbar - {1392b8d2-5c05-419f-a8f6-b9f15a596612} - C:\Program Files\Freecorder\tbFre1.dllO3 - Toolbar: Classical Music Radio Toolbar - {2c9881ab-280a-43df-8e13-8655994b16e9} - C:\Program Files\Classical_Music_Radio\tbClas.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dllO4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeO4 - HKLM\..\Run: [ftutil2] "rundll32.exe" ftutil2.dll,SetWriteCacheModeO4 - HKLM\..\Run: [iAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"O4 - HKLM\..\Run: [NvCplDaemon] "RUNDLL32.EXE" C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] "nwiz.exe" /installquiet /keeploaded /nodetectO4 - HKLM\..\Run: [DMAScheduler] "c:\Program Files\HP DigitalMedia Archive\DMAScheduler.exe"O4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [HPBootOp] "C:\Program Files\Hewlett-Packard\HP Boot Optimizer\HPBootOp.exe" /runO4 - HKLM\..\Run: [Motive SmartBridge] C:\PROGRA~1\Verizon\SMARTB~1\MotiveSB.exeO4 - HKLM\..\Run: [HostManager] "C:\Program Files\Common Files\AOL\1170987345\ee\AOLSoftware.exe"O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"O4 - HKLM\..\Run: [HP Software Update] "C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe"O4 - HKLM\..\Run: [WinampAgent] "C:\Program Files\Winamp\winampa.exe"O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKLM\..\Run: [spywareBot] C:\Program Files\SpywareBot\SpywareBot.exe -bootO4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [NeroFilterCheck] "C:\Program Files\Common Files\Nero\Lib\NeroCheck.exe"O4 - HKLM\..\Run: [AVG7_CC] "C:\PROGRA~1\Grisoft\AVG7\avgcc.exe" /STARTUPO4 - HKLM\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exeO4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=2 /wO4 - HKLM\..\Run: [Google Desktop Search] "C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exe" /startupO4 - HKLM\..\Run: [Resume copy] copyfstq.exe /startupO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXEO4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\Spy Sweeper\SpySweeperUI.exe" /startintrayO4 - HKCU\..\Run: [TClockEx] "C:\Program Files\TClockEx\TCLOCKEX.EXE"O4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [swg] "C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"O4 - HKCU\..\Run: [MyWebSearch Email Plugin] C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwsoemon.exeO4 - HKCU\..\Run: [AOL Fast Start] "C:\Program Files\America Online 9.0\AOL.EXE" -bO4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [MySpaceIM] C:\Program Files\MySpace\IM\MySpaceIM.exe (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')O4 - .DEFAULT User Startup: Pin.lnk = C:\hp\bin\CLOAKER.EXE (User 'Default user')O4 - .DEFAULT User Startup: PinMcLnk.lnk = C:\hp\bin\cloaker.exe (User 'Default user')O4 - Startup: Office Startup.lnk = C:\Program Files\Microsoft Office\Office\OSA.EXEO4 - Global Startup: Hard Disk Indicator Light.lnk = C:\Program Files\HardDisk Indicator Light\hdi.exeO4 - Global Startup: XDesk95.lnk = C:\Program Files\XDesk95\XDesk95.exeO8 - Extra context menu item: &Download All with FlashGet - C:\Program Files\FlashGet\jc_all.htmO8 - Extra context menu item: &Download with FlashGet - C:\Program Files\FlashGet\jc_link.htmO8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZKxdm021YYUSO8 - Extra context menu item: Append to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert link target to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert link target to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert selected links to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert selection to existing PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra button: Spyware Doctor - {2D663D1A-8670-49D9-A1A5-4C56B4E14E84} - C:\PROGRA~1\SPYWAR~1\tools\iesdpb.dllO9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exeO9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - C:\Program Files\FlashGet\FlashGet.exeO9 - Extra button: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htmO9 - Extra 'Tools' menuitem: Internet Connection Help - {E2D4D26B-0180-43a4-B05F-462D6D54C789} - C:\WINDOWS\PCHEALTH\HELPCTR\Vendors\CN=Hewlett-Packard,L=Cupertino,S=Ca,C=US\IEButton\support.htmO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO15 - Trusted Zone: http://forum.anothersite.co.ukO16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - https://activatemyfios.verizon.net/sdcCommon/download/FIOS/tgctlcm.cabO16 - DPF: {1D4DB7D2-6EC9-47A3-BD87-1E41684E07BB} - http://ak.exe.imgfarm.com/images/nocache/funwebproducts/ei/WebfettiInitialSetup1.0.0.15-3.cabO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {48DD0448-9209-4F81-9F6D-D83562940134} (MySpace Uploader Control) - http://lads.myspace.com/upload/MySpaceUploader.cabO16 - DPF: {55027008-315F-4F45-BBC3-8BE119764741} (Slide Image Uploader Control) - http://static.slide.com/uploader/SlideImageUploader.cabO16 - DPF: {5C6698D9-7BE4-4122-8EC5-291D84DBD4A0} (Facebook Photo Uploader 4 Control) - http://upload.facebook.com/controls/FacebookPhotoUploader3.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dllO20 - AppInit_DLLs: C:\PROGRA~1\Google\GOOGLE~2\GOEC62~1.DLLO23 - Service: AOL Connectivity Service (AOL ACS) - AOL LLC - C:\Program Files\Common Files\AOL\ACS\AOLAcsd.exeO23 - Service: AOL TopSpeed Monitor (AOL TopSpeedMonitor) - America Online, Inc - C:\Program Files\Common Files\AOL\TopSpeed\2.0\aoltsmon.exeO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Intel® Quick Resume technology (ELService) - Intel Corporation - C:\Program Files\Intel\IntelDH\Intel® Quick Resume Technology Drivers\Elservice.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Desktop Manager 5.6.711.24354 (GoogleDesktopManager-112407-114954) - Google - C:\Program Files\Google\Google Desktop Search\GoogleDesktop.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: Intel® Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: PC Tools Spyware Doctor (SDhelper) - PC Tools Research Pty Ltd - C:\Program Files\Spyware Doctor\sdhelp.exeO23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. - C:\Program Files\Webroot\Spy Sweeper\SpySweeper.exeO23 - Service: WinFax PRO (wfxsvc) - Symantec Corporation - C:\WINDOWS\system32\WFXSVC.EXE--End of file - 19931 bytes2. PROCESS EXPLORER LOG FOR UTORRENT:Process PID CPU Description Company NameSystem Idle Process 0 49.23 explorer.exe 2008 Windows Explorer Microsoft Corporationrundll32.exe 672 Run a DLL as an App Microsoft Corporationkbd.exe 3040 KBD EXE Hewlett-Packard Companyhpsysdrv.exe 3268 hpsysdrv Hewlett-Packard CompanyuTorrent.exe 1472 EditPadLite.exe 2748 EditPad Lite Just Great Softwareiexplore.exe 6128 Internet Explorer Microsoft Corporationwaol.exe 4676 America Online America Online, Inc. shellmon.exe 5588 setupdb America Online, Inc.Process: uTorrent.exe Pid: 1472Name Description Company Name VersionACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.2180adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.2180ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180apphelp.dll Application Compatibility Client Library Microsoft Corporation 5.01.2600.2180ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000ATL80.DLL ATL Module for Windows (Unicode) Microsoft Corporation 8.00.50727.0762browseui.dll Shell Browser UI Library Microsoft Corporation 6.00.2900.3199c_936.nls CFGMGR32.dll Configuration Manager Forwarder DLL Microsoft Corporation 5.01.2600.2180CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0308COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.2180COMRes.dll Microsoft Corporation 2001.12.4414.0258CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.2180CRYPTUI.dll Microsoft Trust UI Provider Microsoft Corporation 5.131.2600.2180CSCDLL.dll Offline Network Agent Microsoft Corporation 5.01.2600.2180cscui.dll Client Side Caching UI Microsoft Corporation 5.01.2600.2180ctype.nls davclnt.dll Web DAV Client DLL Microsoft Corporation 5.01.2600.2180DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.3316drprov.dll Microsoft Terminal Server Network Provider Microsoft Corporation 5.01.2600.2180GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3316GrooveNew.DLL GrooveNew Module Microsoft Corporation 12.00.6211.1000GrooveShellExtensions.dll GrooveShellExtensions Module Microsoft Corporation 12.00.6211.1000GrooveSystemServices.dll GrooveSystemServices Module Microsoft Corporation 12.00.6211.1000GrooveUtil.DLL GrooveUtil Module Microsoft Corporation 12.00.6211.1000hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.2180ieframe.dll Internet Explorer Microsoft Corporation 7.00.6000.16640ieframe.dll.mui Internet Explorer Microsoft Corporation 7.00.6000.16414iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6000.16640IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 5.01.2600.2180IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180index.dat index.dat index.dat Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2912kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.3119LINKINFO.dll Windows Volume Tracking Microsoft Corporation 5.01.2600.2751locale.nls LPK.DLL Language Pack Microsoft Corporation 5.01.2600.2180mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.00.0004.0012MPR.dll Multiple Provider Router DLL Microsoft Corporation 5.01.2600.2180MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.2180msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180MSGINA.dll Windows NT Logon GINA DLL Microsoft Corporation 5.01.2600.2180MSImg32.dll GDIEXT Client DLL Microsoft Corporation 5.01.2600.2180msv1_0.dll Microsoft Authentication Package v1.0 Microsoft Corporation 5.01.2600.2180MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.00.50727.1433msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.2180msxml3.dll MSXML 3.0 SP9 Microsoft Corporation 8.90.1101.0000msxml3r.dll XML Resources Microsoft Corporation 8.20.8730.0001mwsoestb.dll My Web Search Plugin Loader MyWebSearch.com 1.02.0003.0002NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2976NETRAP.dll Net Remote Admin Protocol DLL Microsoft Corporation 5.01.2600.2180NETUI0.dll NT LM UI Common Code - GUI Classes Microsoft Corporation 5.01.2600.2180NETUI1.dll NT LM UI Common Code - Networking classes Microsoft Corporation 5.01.2600.2180Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.00.5441.0000ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180ntlanman.dll Microsoft® Lan Manager Microsoft Corporation 5.01.2600.2180NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 5.01.2600.2180ntshrui.dll Shell extensions for sharing Microsoft Corporation 5.01.2600.2180nview.dll NVIDIA nView Desktop and Window Manager 110.60 NVIDIA Corporation 6.14.0010.11060nvwddi.dll NVIDIA nView Display Driver Interface Lib, Version 93.71 NVIDIA Corporation 6.14.0010.9371ODBC32.dll Microsoft Data Access - ODBC Driver Manager Microsoft Corporation 3.525.1117.0000odbcint.dll Microsoft Data Access - ODBC Resources Microsoft Corporation 3.525.1117.0000ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726oleaut32.dll Microsoft Corporation 5.01.2600.3266PortableDeviceApi.dll Windows Portable Device API Components Microsoft Corporation 5.02.5721.5145PSAPI.DLL Process Status Helper Microsoft Corporation 5.01.2600.2180rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938RASAPI32.dll Remote Access API Microsoft Corporation 5.01.2600.2180rasman.dll Remote Access Connection Manager Microsoft Corporation 5.01.2600.2180RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 5.01.2600.2161rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180SBHook.dll SmartBridge Hook Motive Communications, Inc. 5.08.0023.6786Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180sensapi.dll SENS Connectivity API DLL Microsoft Corporation 5.01.2600.2180SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.2180shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation 6.00.2900.3199SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.3241SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.3199sortkey.nls sorttbls.nls sti.dll Still Image Devices client DLL Microsoft Corporation 5.01.2600.2180swpg.dat Spyware Doctor PC Tools 3.06.0000.2080TAPI32.dll Microsoft® Windows Telephony API Client DLL Microsoft Corporation 5.01.2600.2180unicode.nls urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.00.6000.16640USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.3099USERENV.dll Userenv Microsoft Corporation 5.01.2600.2180USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.420.2600.2180uTorrent.exe uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180WfxSeh32.Dll Shell extension for ACT phonebook integration DLL Symantec Corporation 9.00.0098.0727WININET.dll Internet Extensions for Win32 Microsoft Corporation 7.00.6000.16640WINMM.dll MCI API DLL Microsoft Corporation 5.01.2600.2180winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.2180WINSTA.dll Winstation Library Microsoft Corporation 5.01.2600.2180WINTRUST.dll Microsoft Trust Verification APIs Microsoft Corporation 5.131.2600.2180WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.01.2600.2180 Link to comment Share on other sites More sharing options...
jewelisheaven Posted May 12, 2008 Report Share Posted May 12, 2008 PC Tools and Webroot may be at fault. I don't see any injected DLLs other than those that should cause problems.So start there... otherwise, you may need to uninstall O4 - HKLM\..\Run: [ftutil2] "rundll32.exe" ftutil2.dll,SetWriteCacheModeAlso I hope you're aware My WebSearch is commonly classified as ad-ware. It also appears to have added several toolbars to your IE... and added A LOT OF browser BHOs Link to comment Share on other sites More sharing options...
dlhappy2 Posted May 12, 2008 Author Report Share Posted May 12, 2008 Hi jewelisheaven Thanks for the input...I don't want to get too much off topic (not utorrent related), but I actually added most of the toolbars and browers helpers...much more so to Firefox than IE (Freecorder (captures audio from my integrated sound card --other stand-alone programs don't recognize the card), Classical Music Radio (streaming from the internet)- Firefox helpers: active tab in red, a separate download status and history bar (in addition to the pop-up window), two separate streaming video capture helpers, etc.). Btw, if you are interested in any of these, let me know and I'll try and look up the website(s), if possible, and give the link(s) to you. I almost never use IE except as a fallback if there is a problem loading Firefox. However, my wife and daughter use AOL which uses it's own form of IE, although that does not have the various toolbars and browers helpers. (My wife and daughter are supposed to share a notebook computer (Vista -- the desktop is XP Windows Media Center 2005 -- actually XP Pro) that I bought for them....but my sometimes daughter uses my desktop because she can't do certain things with her itunes/itunes store on the notebook --- and my wife finds the desktop more comfortable (I wanted to buy them another desktop..not a notebook, since it is almost never taken from the house..but they wanted a notebook!!). Yes, I heard that about MyWebSearch...that toolbar I did not add. It did so itself...maybe as part of some software install process. It's in the IE that I don't use so it doesn't bother me (although perhaps the IE process runs in the background anyway even if the IE browser is not opened and maybe MyWebSearch is somehow active).Anyway, thanks again. Link to comment Share on other sites More sharing options...
jewelisheaven Posted May 12, 2008 Report Share Posted May 12, 2008 heh, makes sense. I'm amazed computers work with all that installed sometimes Did you get a chance to try running without those two programs installed? Spyware Doctor has some reports of previously being the culprit in cases like this, but there's no sure way to check unless you try uninstalling it. If you've got updates feel free to post them below. Link to comment Share on other sites More sharing options...
dlhappy2 Posted May 13, 2008 Author Report Share Posted May 13, 2008 Hi jewelisheaven --I uninstalled both MyWebSearch and PCTool's Spyware Doctor. I didn't even realize that I still had Spyware Doctor on my computer. Webroot, btw, is Spysweeper, which I actively use and like.I read that System Restore automatically deletes old restore points to free up space when the drive is too full. That could have been the problem that I encountered. I often go from having sufficient room to being almost full when doing video converting, etc. Then I might burn the video(s) to DVD + R DL and, voila, space is freed up!! I have not experienced the uTorrent problem that led me to start this thread for a while now, and besides, I'll try to remember to make an additional copy of any file(s) that that I want to re-seed. So, I guess that everything is really ok.BTW, I have a question: In uTorrent, the IP address of each active/on-line seeder/peer is shown. Is there anyway of easily contacting any them since only their IP addressess and not their email addresses are shown. It seems that only the original seeder can be contacted, but only by a thread post or PM on the torrent's website. Link to comment Share on other sites More sharing options...
jewelisheaven Posted May 13, 2008 Report Share Posted May 13, 2008 Sorry, but no The developers don't plan to make uT any more than a bittorrent client. While I agree with this decision and share the philosophy it does indeed become some of a problem if you want to "talk" to someone on that awesomely rare torrent you run. My best advice is to post a comment as you mention on the site you got the torrent from... and yep even messaging the uploader sometimes gets results. Also remember if it's one of those "super rare" things you like to keep alive you don't have to keep it seeded all the time. You can stop it and start it back up whenever you want / have free bandwidth. I keep most of those types of torrents in PAUSE mode in my client 1) because I always have a uT up 2) because I rarely turn off this computer and 3) because it allows me to see directly when there are peers on the swarm. While the popular open trackers show peers not always are they real/up-to-date. If peers connect to me I can assume they're real and want my data... so I rotate 2 or 3 of them a day. I've even popped onto a torrent before where there were no seeds for MONTHS and people were sitting @ 98% and promptly after seeding all of them there was 1 or more comments at the site saying "thank you" I'm glad you don't have this regularly... just remember this troubleshooting if it does come back. But hopefully it won't come back right Link to comment Share on other sites More sharing options...
dlhappy2 Posted May 13, 2008 Author Report Share Posted May 13, 2008 HI jewelisheaven:Thanks for the information and all of the help that you provided. It is really appreciated!! Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.