Yvonne Posted June 9, 2008 Report Share Posted June 9, 2008 Hi,I am hoping that someone can help me. I have just bought a new computer and had to re-install utorrent. Now that I have done this, I am having trouble. I am getting the following error message (i have tried unistalling utorrent and re-installing it but not luck) "The process cannot access the file because it is being used by another process". Can someone please help me with this problem.Thank you.Yvonne Link to comment Share on other sites More sharing options...
DreadWingKnight Posted June 9, 2008 Report Share Posted June 9, 2008 Post a hijackthis log please. Link to comment Share on other sites More sharing options...
Yvonne Posted June 10, 2008 Author Report Share Posted June 10, 2008 Hello, Sorry I do not know how to post a hijackthis log. Can you please advsie me how I do this. I did however uninstall Roxio and this sems to have fixed the problem but I use Roxio and never had this trouble before with my old computer. It appears that I may still have a problem though as I am getting a yellow triangle instead of a green circle with a tick (which I had yesterday). Yesterday the port said it was open and today it is not. Please help.Thank you. Link to comment Share on other sites More sharing options...
jewelisheaven Posted June 10, 2008 Report Share Posted June 10, 2008 In the Read Me, search "hijack this" It will have a list of installed programs Link to comment Share on other sites More sharing options...
Yvonne Posted June 10, 2008 Author Report Share Posted June 10, 2008 Thank you jewelisheaven but I am really new to all of this. Where do I fnd the "Read Me". I looked in the link in your reply but found nothing. Sorry. :-)P/SI think I may have found it :-) Can you please assist me further. Thanking you.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 8:01:42 PM, on 10/06/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\RUNDLL32.EXEC:\WINDOWS\RTHDCPL.EXEC:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exeC:\Program Files\ScanSoft\PaperPort\pptd40nt.exeC:\Program Files\Brother\Brmfcmon\BrMfcWnd.exeC:\Program Files\Brother\ControlCenter3\brccMCtl.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\CAPPActiveProtection.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Panasonic\LUMIXSimpleViewer\PhLeAutoRun.exeC:\Program Files\Nikon\PictureProject\NkbMonitor.exeC:\WINDOWS\FSScrCtl.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exeC:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exeC:\Program Files\Common Files\LightScribe\LSSrvc.exeC:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\IoctlSvc.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exeC:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\CA\CA Internet Security Suite\ccprovsp.exeC:\Program Files\Windows Live\Messenger\usnsvc.exeC:\Program Files\Messenger\msmsgs.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Internet Explorer\IEXPLORE.EXEC:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://ninemsn.com.au/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Internet Connection Wizard,ShellNext = http://au.yahoo.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKLM\..\Run: [skyTel] SkyTel.EXEO4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXEO4 - HKLM\..\Run: [cctray] "C:\Program Files\CA\CA Internet Security Suite\cctray\cctray.exe"O4 - HKLM\..\Run: [CAVRID] "C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\CAVRID.exe"O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -bootO4 - HKLM\..\Run: [PaperPort PTD] C:\Program Files\ScanSoft\PaperPort\pptd40nt.exeO4 - HKLM\..\Run: [indexSearch] C:\Program Files\ScanSoft\PaperPort\IndexSearch.exeO4 - HKLM\..\Run: [brMfcWnd] C:\Program Files\Brother\Brmfcmon\BrMfcWnd.exe /AUTORUNO4 - HKLM\..\Run: [setDefPrt] C:\Program Files\Brother\Brmfl06a\BrStDvPt.exeO4 - HKLM\..\Run: [ControlCenter3] C:\Program Files\Brother\ControlCenter3\brctrcen.exe /autorunO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exeO4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hiddenO4 - HKCU\..\Run: [bgMonitor_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "C:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exe"O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /backgroundO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - Startup: Screen Saver Control.lnk = C:\WINDOWS\FSScrCtl.exeO4 - Global Startup: LUMIX Simple Viewer.lnk = ?O4 - Global Startup: NkbMonitor.exe.lnk = C:\Program Files\Nikon\PictureProject\NkbMonitor.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1212293453531O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: CaCCProvSP - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\ccprovsp.exeO23 - Service: CAISafe - Computer Associates International, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\ISafe.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: CA Pest Patrol Realtime Protection Service (ITMRTSVC) - CA, Inc. - C:\Program Files\CA\SharedComponents\PPRT\bin\ITMRTSVC.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exeO23 - Service: PPCtlPriv - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Spyware\PPCtlPriv.exeO23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)O23 - Service: VET Message Service (VETMSGNT) - CA, Inc. - C:\Program Files\CA\CA Internet Security Suite\CA Anti-Virus\VetMsg.exe--End of file - 9287 bytes Link to comment Share on other sites More sharing options...
GTHK Posted June 10, 2008 Report Share Posted June 10, 2008 O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeDisable or uninstall this. It comes with Nero, if you use a the custom install option and install without Nero Scout all will probably be well. Link to comment Share on other sites More sharing options...
Switeck Posted June 10, 2008 Report Share Posted June 10, 2008 O23 - Service: LiveShare P2P Server 9 (RoxLiveShare9) - Unknown owner - C:\Program Files\Common Files\Roxio Shared\9.0\SharedCOM\RoxLiveShare9.exe (file missing)Looks like Roxio wasn't properly uninstalled...you probably need to remove that registry entry (using HijackThis!) too. Link to comment Share on other sites More sharing options...
Yvonne Posted June 11, 2008 Author Report Share Posted June 11, 2008 Thank you all very much. I am really new to this so please be patient :-) Do I go back to hijack this and delete all of the O23s or only the ones relating to Nero/Roxio?? I purchased my version of Nero over the internet so I am not sure how to unistall the Nero Scout?? I thought I had deleted all of Roxio grrrr. On my last computer I had no trouble running both Nero and Roxio. New computer, new dramas LOL. Thank you once again. I await your further instructions:-) Link to comment Share on other sites More sharing options...
GTHK Posted June 11, 2008 Report Share Posted June 11, 2008 Mmmmmmmm check add/remove programs for Roxio. For Nero, on add/remove programs, see if it lets you make changes instead of removing it. If you still have your key you can uninstall and reinstall. Start > Run > Services.msc will let you disable, pick the indexer and change the startup type to disabled. Uninstalling is better though. Link to comment Share on other sites More sharing options...
Yvonne Posted June 11, 2008 Author Report Share Posted June 11, 2008 Hi GHTK. Thanks for your assistance. I really appreciate it. I have managed to delete all of Roxio from my system and have taken it off the hijack this. Am having trouble with the Nero part though. As I downloaded this from the internet, I cannot find where I can change the settings. Can I just remove the indexer from 023? I went into the services.msc but did not really know what I was looking for and was not game to touch anything in there. Link to comment Share on other sites More sharing options...
GTHK Posted June 11, 2008 Report Share Posted June 11, 2008 On add/remove programs, when you sometimes it will have the option to change next to the option to remove. From my experience, HJT doesn't actually remove services from there, but it has a build in service deleter. If you can't find it, in services.msc the names might be NMIndexingService, Nero AG, or Nero Scout. Alternatively, disabling it from My Computer might work. Right-click Nero Scout in My Computer and look for the option to disable it.Are you still having the problem with Roxio gone? Link to comment Share on other sites More sharing options...
Yvonne Posted June 12, 2008 Author Report Share Posted June 12, 2008 Hi there GTHK. Yesterday I had no problem (had the green tick in the circle advising that port was opened) and now I am having trouble again andit says I havr a port error!!! I have found Nero Scout and before I disable it, what does Nero Scout actually do?? Will disenabling it give me problems when I want to use Nero? Do you think Nero SCout might eb causing these problems?? Like I said yesterday it all went well and today dramas :-) Once again, thank you for all your help. Also, should I in the preferences of UTorrenttick the box that says "randomize port each time torret starts". At the moment this is unchecked. Link to comment Share on other sites More sharing options...
Firon Posted June 12, 2008 Report Share Posted June 12, 2008 Nero Scout won't give you a port error.But CA Security will. You can try removing and recreating any rules you have for utorrent. Link to comment Share on other sites More sharing options...
Yvonne Posted June 12, 2008 Author Report Share Posted June 12, 2008 Thanks Firon but how do I do what you are suggesting? When it comes to these sort of thing I am a computer dummy :-) I use one all day at work but that is to type :-)I just checked again now and I have an open port. This has me really stumped.P/S I only have anti virus and spyware with CA Security. Link to comment Share on other sites More sharing options...
GTHK Posted June 12, 2008 Report Share Posted June 12, 2008 Well, CA is kinda crappy so.. :/ Link to comment Share on other sites More sharing options...
Yvonne Posted June 13, 2008 Author Report Share Posted June 13, 2008 Thanks GTHK. I am looking at other options in relation to virus protection. Hopefully this will solve my problems. Link to comment Share on other sites More sharing options...
GTHK Posted June 13, 2008 Report Share Posted June 13, 2008 I don't know if it will, but while on the topic, avast! is free and I found it better then other free ones (only install AV component).As a test, try temporarily uninstalling CA first (disabling wont work). Link to comment Share on other sites More sharing options...
Yvonne Posted June 14, 2008 Author Report Share Posted June 14, 2008 Thank you I will give it a go and let you know whathappens :-) Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.