blophyus Posted June 12, 2008 Report Share Posted June 12, 2008 Hi,µTorrent works fine, but when I quit the program, the process continues to run. I've tried to kill it using the Task Manager and tskill without any luck. I can't be sure, but the problem seems to have appeared following my recent upgrade to XP SP 2.OS: Windows XP SP 2µTorrent version: 1.7.7 build 8179Anti-virus: AVG Free 7.5.524I don't have any viruses or spyware, and I haven't installed or upgraded any software (so I know it's not the anti-virus, but I listed it anyway). Again, everything works correctly, it's just that I can't kill the process.Anyone have any ideas? Link to comment Share on other sites More sharing options...
jewelisheaven Posted June 12, 2008 Report Share Posted June 12, 2008 If you turned on bt.graceful_shutdown then it will close when it is ready... though I think some debugging may be helpful to the developers. What are you doing while shutting down? What makes that uT unique? Link to comment Share on other sites More sharing options...
blophyus Posted June 12, 2008 Author Report Share Posted June 12, 2008 OK. I just tried setting bt.graceful_shutdown to true, but that didn't help. The process is still running after 5 minutes, and I still can't kill it. Nor can I restart it, because I get the message that it's already running.I'm not doing anything special. I'm just shutting it down like any old program. But for whatever reason, it won't shut down and it can't be killed. Link to comment Share on other sites More sharing options...
Firon Posted June 12, 2008 Report Share Posted June 12, 2008 Post a HijackThis log please. Link to comment Share on other sites More sharing options...
blophyus Posted June 12, 2008 Author Report Share Posted June 12, 2008 Here you are, sir.<<<Logfile of Trend Micro HijackThis v2.0.2Scan saved at 1:31:50 AM, on 6/12/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\WINDOWS\system32\Ati2evxx.exeC:\WINDOWS\Explorer.EXEC:\windows\system\hpsysdrv.exeC:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeC:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exeC:\HP\KBD\KBD.EXEC:\WINDOWS\system32\CTHELPER.EXEC:\Program Files\Norton Personal Firewall\IAMAPP.EXEC:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeC:\Program Files\Java\jre1.6.0_05\bin\jusched.exeC:\Program Files\Cobian Backup 8\cbInterface.exeC:\Program Files\DAEMON Tools\daemon.exeC:\Program Files\eFax Messenger 4.3\J2GDllCmd.exeC:\Program Files\iTunes\iTunesHelper.exeI:\PROGRA~1\Grisoft\AVG7\avgcc.exec:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnf.exeI:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exeC:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeC:\Program Files\Hawking\Common\RaUI.exeC:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exeI:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeI:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeI:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\WINDOWS\System32\DRIVERS\CDANTSRV.EXEC:\Program Files\Cobian Backup 8\cbService.exeC:\WINDOWS\System32\CTsvcCDA.exeC:\Documents and Settings\Owner\Desktop\progs\FAH504-Console.exec:\xampp\mysql\bin\mysqld-nt.exeC:\Program Files\Norton Personal Firewall\NISUM.EXEC:\Documents and Settings\Owner\Desktop\progs\FahCore_82.exeC:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exeC:\WINDOWS\System32\PnkBstrA.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Norton Personal Firewall\SymProxySvc.exeC:\WINDOWS\system32\taskmgr.exeI:\Program Files\VMware\VMware Workstation\vmware-authd.exeC:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exeC:\WINDOWS\System32\vmnat.exeC:\WINDOWS\wanmpsvc.exeC:\Program Files\Norton Personal Firewall\NISSERV.EXEC:\WINDOWS\System32\vmnetdhcp.exeC:\Program Files\iPod\bin\iPodService.exeC:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Mozilla Thunderbird\thunderbird.exeC:\WINDOWS\system32\cmd.exeC:\Program Files\PeerGuardian2\pg2.exeC:\Program Files\uTorrent\utorrent.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://srch-us7.hpwis.com/R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://us7.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://srch-us7.hpwis.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://srch-us7.hpwis.com/R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://us7.hpwis.com/R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://wpad.ca.com/wpad.datO2 - BHO: ZIBho Class - {029CA12C-89C1-46a7-A3C7-82F2F98635CB} - C:\Program Files\Kontiki\bin\bh304181.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Freedom Popup Killer - {3C060EA2-E6A9-4E49-A530-D4657B8C449A} - C:\Program Files\Zero Knowledge\Freedom\pkR.dllO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - I:\Program Files\AVG\AVG8\avgssie.dll (file missing)O2 - BHO: Freedom BHO - {56071E0D-C61B-11D3-B41C-00E02927A304} - C:\Program Files\Zero Knowledge\Freedom\FreeBHOR.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO2 - BHO: Google Desktop Search Capture - {7c1ce531-09e9-4fc5-9803-1c2956615786} - blank (file missing)O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar3.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dllO2 - BHO: IE DevToolbar BHO - {CC7E636D-39AA-49b6-B511-65413DA137A1} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dllO3 - Toolbar: hp toolkit - {B2847E28-5D7D-4DEB-8B67-05D28BCF79F5} - C:\HP\EXPLOREBAR\HPTOOLKT.DLLO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar3.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dllO4 - HKLM\..\Run: [hpsysdrv] c:\windows\system\hpsysdrv.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\WINDOWS\System32\hkcmd.exeO4 - HKLM\..\Run: [share-to-Web Namespace Daemon] c:\Program Files\Hewlett-Packard\HP Share-to-Web\hpgs2wnd.exeO4 - HKLM\..\Run: [CamMonitor] c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exeO4 - HKLM\..\Run: [KBD] C:\HP\KBD\KBD.EXEO4 - HKLM\..\Run: [storageGuard] "C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" /rO4 - HKLM\..\Run: [Recguard] C:\WINDOWS\SMINST\RECGUARD.EXEO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE NvQTwk,NvCplDaemon initializeO4 - HKLM\..\Run: [WINDVDPatch] CTHELPER.EXEO4 - HKLM\..\Run: [updReg] C:\WINDOWS\UpdReg.EXEO4 - HKLM\..\Run: [PS2] C:\WINDOWS\system32\ps2.exeO4 - HKLM\..\Run: [iamapp] C:\Program Files\Norton Personal Firewall\IAMAPP.EXEO4 - HKLM\..\Run: [ViewMgr] C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [Cobian Backup 8 interface] "C:\Program Files\Cobian Backup 8\cbInterface.exe" -serviceO4 - HKLM\..\Run: [DAEMON Tools] "C:\Program Files\DAEMON Tools\daemon.exe" -lang 1033O4 - HKLM\..\Run: [eFax 4.3] "C:\Program Files\eFax Messenger 4.3\J2GDllCmd.exe" /RO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [AVG7_CC] I:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUPO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKLM\..\Run: [Acrobat Assistant 8.0] "I:\Program Files\Adobe\Acrobat 8.0\Acrobat\Acrotray.exe"O4 - HKCU\..\Run: [NVIEW] rundll32.exe nview.dll,nViewLoadHookO4 - HKCU\..\Run: [symantec NetDriver Monitor] C:\PROGRA~1\Symantec\LIVEUP~1\SNDMon.EXEO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\1.2.1128.5462\GoogleToolbarNotifier.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] I:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [AVG7_Run] I:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] I:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')O4 - HKUS\S-1-5-18\..\RunOnce: [PlayCenter2] "C:\Program Files\Creative\SBAudigy\PlayCenter2\MDEntry.EXE" "C:\Program Files\Creative\SBAudigy\PlayCenter2" (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] I:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - HKUS\.DEFAULT\..\RunOnce: [PlayCenter2] "C:\Program Files\Creative\SBAudigy\PlayCenter2\MDEntry.EXE" "C:\Program Files\Creative\SBAudigy\PlayCenter2" (User 'Default user')O4 - Global Startup: Adobe Acrobat Speed Launcher.lnk = ?O4 - Global Startup: Adobe Acrobat Synchronizer.lnk = I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AdobeCollabSync.exeO4 - Global Startup: Adobe Gamma Loader.exe.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\reader_sl.exeO4 - Global Startup: Adobe Reader Synchronizer.lnk = C:\Program Files\Adobe\Reader 8.0\Reader\AdobeCollabSync.exeO4 - Global Startup: Hawking Wireless Utility.lnk = C:\Program Files\Hawking\Common\RaUI.exeO4 - Global Startup: Monitor Apache Servers.lnk = C:\Program Files\Apache Group\Apache2\bin\ApacheMonitor.exeO8 - Extra context menu item: Append to existing PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert link target to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert link target to existing PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert selected links to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert selected links to existing PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Convert selection to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: Convert selection to existing PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://I:\Program Files\Adobe\Acrobat 8.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra button: MktBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpyO9 - Extra 'Tools' menuitem: MarketBrowser - {17A27031-71FC-11d4-815C-005004D0F1FA} - C:\Program Files\MarketBrowser\lmt\MarketBrowser_Launch.xpyO9 - Extra button: ATI TV - {44226DFF-747E-4edc-B30C-78752E50CD0C} - C:\Program Files\ATI Multimedia\TV\EXPLBAR.DLLO9 - Extra button: IE Developer Toolbar - {48FFE35F-36D9-44bd-A6CC-1D34414EAC0D} - C:\Program Files\Microsoft\Internet Explorer Developer Toolbar\IEDevToolbar.dllO9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exeO9 - Extra button: (no name) - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - (no file)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO15 - Trusted Zone: http://download.windowsupdate.comO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1211572738265O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://www.update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1211574171796O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: Apache2 - Apache Software Foundation - C:\Program Files\Apache Group\Apache2\bin\Apache.exeO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exeO23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exeO23 - Service: Automatic LiveUpdate Scheduler - Symantec Corporation - C:\Program Files\Symantec\LiveUpdate\ALUSchedulerSvc.exeO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - I:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - I:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - I:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: C-DillaSrv - C-Dilla Ltd - C:\WINDOWS\System32\DRIVERS\CDANTSRV.EXEO23 - Service: Cobian Backup 8 service (CobBMService) - Luis Cobian - C:\Program Files\Cobian Backup 8\cbService.exeO23 - Service: Creative Service for CDROM Access - Creative Technology Ltd - C:\WINDOWS\System32\CTsvcCDA.exeO23 - Service: FAH@C:+Documents and Settings+Owner+Desktop+progs+FAH504-Console.exe - Stanford University - C:\Documents and Settings\Owner\Desktop\progs\FAH504-Console.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: MySql - Unknown owner - c:/xampp/mysql/bin/mysqld-nt.exeO23 - Service: Norton Personal Firewall Service (NISSERV) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISSERV.EXEO23 - Service: Norton Personal Firewall Accounts Manager (NISUM) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\NISUM.EXEO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: NVIDIA Driver Helper Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\System32\nvsvc32.exeO23 - Service: PD91Agent - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Agent.exeO23 - Service: PD91Engine - Raxco Software, Inc. - C:\Program Files\Raxco\PerfectDisk2008\PD91Engine.exeO23 - Service: PnkBstrA - Unknown owner - C:\WINDOWS\System32\PnkBstrA.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: Symantec Network Drivers Service (SNDSrvc) - Symantec Corporation - C:\Program Files\Common Files\Symantec Shared\SNDSrvc.exeO23 - Service: Norton Personal Firewall Proxy Service (SymProxySvc) - Symantec Corporation - C:\Program Files\Norton Personal Firewall\SymProxySvc.exeO23 - Service: Ulead Burning Helper (UleadBurningHelper) - Ulead Systems, Inc. - C:\Program Files\Common Files\Ulead Systems\DVD\ULCDRSvr.exeO23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - I:\Program Files\VMware\VMware Workstation\vmware-authd.exeO23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - C:\WINDOWS\System32\vmnetdhcp.exeO23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - C:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exeO23 - Service: VMware NAT Service - VMware, Inc. - C:\WINDOWS\System32\vmnat.exeO23 - Service: WAN Miniport (ATW) Service (WANMiniportService) - America Online, Inc. - C:\WINDOWS\wanmpsvc.exeO23 - Service: X10 Device Network Service (x10nets) - Unknown owner - c:\PROGRA~1\ATIMUL~1\RemCtrl\x10nets.exe (file missing)--End of file - 16380 bytes>>> Link to comment Share on other sites More sharing options...
Firon Posted June 12, 2008 Report Share Posted June 12, 2008 Uninstall the Norton firewall. Link to comment Share on other sites More sharing options...
blophyus Posted June 12, 2008 Author Report Share Posted June 12, 2008 I disabled Norton Firewall and µTorrent quit normally. Looks like that was the issue. Thanks a lot for your help.Any chance this will be addressed in a future version of µTorrent? Link to comment Share on other sites More sharing options...
GTHK Posted June 12, 2008 Report Share Posted June 12, 2008 No, it's a bug created by crappy Norton. Link to comment Share on other sites More sharing options...
blophyus Posted June 12, 2008 Author Report Share Posted June 12, 2008 Can you suggest another firewall that won't interfere with µT? Link to comment Share on other sites More sharing options...
Whoppie Posted June 12, 2008 Report Share Posted June 12, 2008 Fsecure IS 2007 & 2008, used it for 2 years now, no issues at all so far.Symantecs products are really crappy nowadays, too bad, they were kinda good a few years back.Recommend a hardware firewall for serious users anyway, software firewalls are often inaccurate, buggy and easy to pass through (user involvement...).//itconsultant, .se Link to comment Share on other sites More sharing options...
Firon Posted June 12, 2008 Report Share Posted June 12, 2008 Comodo firewall works well. In the firewall configuration thread here, there's information on how to configure it properly.Anyway, it is a Norton bug.. It basically holds the utorrent process hostage and won't let it finish i/o to shutdown, locking it in a wait forever stage. Link to comment Share on other sites More sharing options...
bigmin Posted June 26, 2008 Report Share Posted June 26, 2008 I've got the same problem but I'm using ZoneAlarm and AntiVir.I'll try Fsecure or Comodo as well. Link to comment Share on other sites More sharing options...
n1k3 Posted April 30, 2010 Report Share Posted April 30, 2010 i've got the same problem for the last month. i haven't change anything to my pc. the above didn't help. i have windows 7 and nod32 antivirus for over a year and i didnt have this problem . i tried to disable both antivirus and windows firewall but didn't help. please help me. its very annoying not to be able to quit the program. but its more annoying not to be able to run it because actually it hasnt closed.please help me guys Link to comment Share on other sites More sharing options...
moogly Posted April 30, 2010 Report Share Posted April 30, 2010 @n1k3: Post Hijackthis and Process Explorer logswhen µT is running.Guide: http://forum.utorrent.com/viewtopic.php?id=29748 Link to comment Share on other sites More sharing options...
n1k3 Posted May 1, 2010 Report Share Posted May 1, 2010 ok guys. here you are---------------------------------------------------Hijackthis-------------------------------------------Logfile of Trend Micro HijackThis v2.0.4Scan saved at 12:45:17, on 1/5/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\system32\taskhost.exeC:\Windows\Explorer.EXEC:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesApp32.exeC:\Program Files\ESET\ESET NOD32 Antivirus\egui.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\Windows Live\Contacts\wlcomm.exeC:\Program Files\Sports Interactive\Football Manager 2010\fm.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Trend Micro\HiJackThis\HiJackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dllO2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dllO4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitserviceO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htmO8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htmO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dllO9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dllO10 - Unknown file in Winsock LSP: c:\program files\common files\microsoft shared\windows live\wlidnsp.dllO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dllO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - AppInit_DLLs: acaptuser32.dllO23 - Service: AMD External Events Utility - AMD - C:\Windows\system32\atiesrxx.exeO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: DeviceVM Meta Data Export Service (DvmMDES) - DeviceVM, Inc. - C:\ASUS.SYS\config\DVMExportService.exeO23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exeO23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: GenericMount Helper Service - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\GenericMountHelper.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LiveUpdate - Symantec Corporation - C:\PROGRA~1\Symantec\LIVEUP~1\LUCOMS~1.EXEO23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exeO23 - Service: Norton Ghost - Symantec Corporation - C:\Program Files\Norton Ghost\Agent\VProSvc.exeO23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exeO23 - Service: SymSnapService - Symantec - C:\Program Files\Norton Ghost\Shared\Drivers\SymSnapService.exeO23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exeO23 - Service: @C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exe,-1 (TuneUp.Defrag) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpDefragService.exeO23 - Service: TuneUp Utilities Service (TuneUp.UtilitiesSvc) - TuneUp Software - C:\Program Files\TuneUp Utilities 2010\TuneUpUtilitiesService32.exe--End of file - 7965 bytes-------------------------------------Process Explorer---------------------------------------------------Process PID CPU Private Bytes Working Set Description Company NameSystem Idle Process 0 95.94 0 K 24 K Interrupts n/a 0.78 0 K 0 K Hardware Interrupts DPCs n/a 0 K 0 K Deferred Procedure Calls System 4 68 K 9.748 K smss.exe 372 260 K 752 K Windows Session Manager Microsoft Corporationcsrss.exe 468 1.360 K 3.452 K Client Server Runtime Process Microsoft Corporationwininit.exe 540 892 K 3.328 K Windows Start-Up Application Microsoft Corporation services.exe 588 5.160 K 7.816 K Services and Controller app Microsoft Corporation svchost.exe 780 2.896 K 7.288 K Host Process for Windows Services Microsoft Corporation dllhost.exe 2040 1.532 K 4.936 K COM Surrogate Microsoft Corporation wlcomm.exe 3700 24.196 K 26.752 K Windows Live Communications Platform Microsoft Corporation explorer.exe 1728 11.372 K 25.656 K Windows Explorer Microsoft Corporation svchost.exe 860 2.964 K 6.104 K Host Process for Windows Services Microsoft Corporation atiesrxx.exe 908 824 K 3.056 K AMD External Events Service Module AMD atieclxx.exe 1308 1.272 K 4.352 K AMD External Events Client Module AMD svchost.exe 996 15.592 K 15.752 K Host Process for Windows Services Microsoft Corporation audiodg.exe 2440 1.56 15.672 K 14.636 K Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1036 61.040 K 68.292 K Host Process for Windows Services Microsoft Corporation dwm.exe 1788 31.848 K 28.576 K Desktop Window Manager Microsoft Corporation svchost.exe 1068 19.348 K 31.040 K Host Process for Windows Services Microsoft Corporation svchost.exe 1248 6.328 K 11.748 K Host Process for Windows Services Microsoft Corporation svchost.exe 1384 15.088 K 18.824 K Host Process for Windows Services Microsoft Corporation spoolsv.exe 1540 4.812 K 9.532 K Spooler SubSystem App Microsoft Corporation svchost.exe 1588 11.876 K 12.916 K Host Process for Windows Services Microsoft Corporation taskhost.exe 1852 2.508 K 6.468 K Host Process for Windows Tasks Microsoft Corporation AppleMobileDeviceService.exe 1884 980 K 3.620 K Apple Mobile Device Service Apple Inc. mDNSResponder.exe 1924 1.440 K 4.660 K Bonjour Service Apple Inc. DVMExportService.exe 1972 1.000 K 3.616 K Windows Metadata Export Service DeviceVM, Inc. ekrn.exe 2004 51.352 K 57.152 K ESET Service ESET svchost.exe 248 5.640 K 10.576 K Host Process for Windows Services Microsoft Corporation MSCamS32.exe 416 8.120 K 10.060 K MsCamSvc.exe Microsoft Corporation NBService.exe 1096 2.744 K 7.600 K Nero BackItUp Nero AG VProSvc.exe 1484 30.640 K 2.832 K Service Module Symantec Corporation svchost.exe 1812 2.616 K 5.568 K Host Process for Windows Services Microsoft Corporation TeamViewer_Service.exe 2072 768 K 2.776 K TeamViewer Service TeamViewer GmbH TuneUpUtilitiesService32.exe 2116 5.656 K 12.332 K TuneUp Utilities Service TuneUp Software TuneUpUtilitiesApp32.exe 2400 1.732 K 7.216 K TuneUp Utilities TuneUp Software WLIDSVC.EXE 2172 3.400 K 8.916 K Microsoft® Windows Live ID Service Microsoft Corporation WLIDSVCM.EXE 2680 620 K 2.356 K Microsoft® Windows Live ID Service Monitor Microsoft Corporation iPodService.exe 3240 1.740 K 5.300 K iPodService Module (32-bit) Apple Inc. SymSnapService.exe 3340 3.572 K 8.052 K Symantec Snapshot Service Symantec wmpnetwk.exe 3796 8.808 K 7.956 K Windows Media Player Network Sharing Service Microsoft Corporation svchost.exe 3932 9.132 K 11.520 K Host Process for Windows Services Microsoft Corporation svchost.exe 2780 59.616 K 24.816 K Host Process for Windows Services Microsoft Corporation taskhost.exe 2104 5.656 K 11.364 K Host Process for Windows Tasks Microsoft Corporation lsass.exe 604 3.312 K 8.832 K Local Security Authority Process Microsoft Corporation lsm.exe 612 1.788 K 4.628 K Local Session Manager Service Microsoft Corporationcsrss.exe 548 2.084 K 6.208 K Client Server Runtime Process Microsoft Corporationwinlogon.exe 744 1.936 K 5.044 K Windows Logon Application Microsoft Corporationexplorer.exe 2016 43.052 K 59.628 K Windows Explorer Microsoft Corporation egui.exe 2480 2.292 K 8.788 K ESET GUI ESET iTunesHelper.exe 2560 4.728 K 11.544 K iTunesHelper Apple Inc. firefox.exe 3768 165.964 K 186.404 K Firefox Mozilla Corporation msnmsgr.exe 3604 32.544 K 55.956 K Windows Live Messenger Microsoft Corporation fm.exe 2652 630.512 K 629.296 K Football Manager 2010 10.3.0f104766 Sports Interactive uTorrent.exe 4052 10.988 K 16.780 K µTorrent BitTorrent, Inc. procexp.exe 2420 1.56 16.504 K 32.524 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com------------------------------------Process: uTorrent.exe Pid: 4052---------------------------------------------Name Description Company Name VersionADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.1.7600.16385C_1252.NLS CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.8530.16385COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7600.16385comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.1.7600.16385CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.1.7600.16385CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.1.7600.16385dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.1.7600.16385dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.1.7600.16385DnsApi.dll DNS Client API DLL Microsoft Corporation 6.1.7600.16385dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation 6.1.7600.16385FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.1.7600.16385fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.1.7600.16385GDI32.dll GDI Client DLL Microsoft Corporation 6.1.7600.16385IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.1.7600.16385Iphlpapi.dll IP Helper API Microsoft Corporation 6.1.7600.16385kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16481KERNELBASE.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385locale.nls LPK.dll Language Pack Microsoft Corporation 6.1.7600.16385mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 2.0.1.2MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.1.7600.16385msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.7600.16385mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.1.7600.16385npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.1.7600.16385NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.1.7600.16385ntdll.dll NT Layer DLL Microsoft Corporation 6.1.7600.16385ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.1.7600.16385oleaut32.dll Microsoft Corporation 6.1.7600.16385profapi.dll User Profile Basic API Microsoft Corporation 6.1.7600.16385PSAPI.DLL Process Status Helper Microsoft Corporation 6.1.7600.16385R000000000006.clb rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.1.7600.16385RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.1.7600.16385RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.1.7600.16385rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.1.7600.16385sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.1.7600.16385SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.1.7600.16532shfolder.dll Shell Folder Service Microsoft Corporation 6.1.7600.16385SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.1.7600.16385SortDefault.nls SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.1.7600.16385StaticCache.dat USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.1.7600.16385USERENV.dll Userenv Microsoft Corporation 6.1.7600.16385USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385uTorrent.exe µTorrent BitTorrent, Inc. 2.0.1.19248uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.1.7600.16385VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.1.7600.16385WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.1.7600.16385WLIDNSP.DLL Microsoft® Windows Live ID Namespace Provider Microsoft Corporation 6.500.3146.0WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.1.7600.16385wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.1.7600.16385wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.1.7600.16385 Link to comment Share on other sites More sharing options...
moogly Posted May 1, 2010 Report Share Posted May 1, 2010 You need to select utorrent.exe and enable DLL mode (ctrl+D) in Process Explorer. Edit your log please. Link to comment Share on other sites More sharing options...
n1k3 Posted May 1, 2010 Report Share Posted May 1, 2010 ok. i think i edited the above log as you asked Link to comment Share on other sites More sharing options...
artweb Posted May 1, 2010 Report Share Posted May 1, 2010 Hi, I got the same problem.OS: Windows 7 µTorrent version: latestHere is the Hijack and Utorrent reports:http://www.zshare.net/download/75585696fb2dfcb4/ - hhijackthis.loghttp://www.zshare.net/download/75585711f2666e2a/ - uTorrent.exe.txt Link to comment Share on other sites More sharing options...
moogly Posted May 1, 2010 Report Share Posted May 1, 2010 Post logs in your thread please. Link to comment Share on other sites More sharing options...
artweb Posted May 1, 2010 Report Share Posted May 1, 2010 sure...sorry.:Logfile of Trend Micro HijackThis v2.0.4Scan saved at 12:54:28, on 01/05/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\system32\taskhost.exeC:\Windows\Explorer.EXEC:\Windows\RtHDVCpl.exeC:\hp\support\hpsysdrv.exeC:\Program Files\SSC Service Utility\ssc_serv.exeC:\Windows\Samsung\PanelMgr\SSMMgr.exeC:\Program Files\WebMoney Agent\wmagent.exeC:\Program Files\DAEMON Tools Lite\DTLite.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Provide Support\Live Support Chat for Web Site\ProvideSupportConsole.exeC:\Windows\system32\wuauclt.exeC:\Program Files\Microsoft Office\Office12\OUTLOOK.EXEC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Download Master\dmaster.exeC:\Windows\system32\SearchFilterHost.exeC:\Users\Chief\Desktop\HiJackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://start.icq.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=74&bd=Presario&pf=desktopR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=EN_GB&c=74&bd=Presario&pf=desktopR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - - (no file)O1 - Hosts: ::1 localhostO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dllO2 - BHO: IE 4.x-6.x BHO for Download Master - {9961627E-4059-41B4-8E0E-A7D6B3854ADF} - C:\PROGRA~1\DOWNLO~1\dmiehlp.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO3 - Toolbar: Easy Photo Print - {9421DD08-935F-4701-A9CA-22DF90AC4EA6} - C:\Program Files\Epson Software\Easy Photo Print\EPTBL.dllO4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exeO4 - HKLM\..\Run: [hpsysdrv] c:\hp\support\hpsysdrv.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [sSC Service Utility] C:\Program Files\SSC Service Utility\ssc_serv.exe /sO4 - HKLM\..\Run: [samsung PanelMgr] C:\Windows\Samsung\PanelMgr\SSMMgr.exe /autorunO4 - HKLM\..\Run: [wmagent.exe] "C:\Program Files\WebMoney Agent\wmagent.exe"O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\DTLite.exe" -autorunO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O4 - HKCU\..\Run: [iCQ] "C:\Program Files\ICQ7.1\ICQ.exe" silent loginmode=4O4 - HKCU\..\Run: [ProvideSupportOperatorConsole] C:\PROGRA~1\PROVID~1\LIVESU~1\PROVID~1.EXEO4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [EPSON Stylus DX8400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\Windows\TEMP\E_SEEC1.tmp" /EF "HKCU" (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [EPSON Stylus DX8400 Series] C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICEE.EXE /FU "C:\Windows\TEMP\E_SEEC1.tmp" /EF "HKCU" (User 'Default user')O4 - Global Startup: NETGEAR WNDA3100 Smart Wizard.lnk = C:\Program Files\NETGEAR\WNDA3100\WNDA3100.exeO8 - Extra context menu item: &Анализатор боёв - C:\Windows\system32\serial.htmO8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Se&nd to OneNote - res:///105O8 - Extra context menu item: Закачать ВСЕ при помощи Download Master - C:\Program Files\Download Master\dmieall.htmO8 - Extra context menu item: Закачать при помощи Download Master - C:\Program Files\Download Master\dmie.htmO9 - Extra button: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exeO9 - Extra 'Tools' menuitem: ICQ7.1 - {71BFC818-0CED-42D6-9C87-5142918957EE} - C:\Program Files\ICQ7.1\ICQ.exeO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO16 - DPF: {463ED66E-431B-11D2-ADB0-0080C83DA4EB} (AcceptWM Class) - https://w3s.webmoney.ru/WMAcceptor.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO20 - AppInit_DLLs: C:\Windows\system32\vksaver.dllO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: EPSON V5 Service4(01) (EPSON_EB_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40ST7.EXEO23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\ProgramData\EPSON\EPW!3 SSRP\E_S40RP7.EXEO23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: Jumpstart Wifi Protected Setup (jswpsapi) - Atheros Communications, Inc. - C:\Program Files\NETGEAR\WNDA3100\jswpsapi.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - c:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exeO23 - Service: TomTomHOMEService - TomTom - C:\Program Files\TomTom HOME 2\TomTomHOMEService.exe--End of file - 6894 bytesProcess PID CPU Description Company NameSystem Idle Process 0 79.59 Interrupts n/a Hardware Interrupts DPCs n/a 2.27 Deferred Procedure Calls System 4 smss.exe 232 Windows Session Manager Microsoft Corporationcsrss.exe 372 Client Server Runtime Process Microsoft Corporationwininit.exe 436 Windows Start-Up Application Microsoft Corporation services.exe 488 Services and Controller app Microsoft Corporation svchost.exe 672 Host Process for Windows Services Microsoft Corporation svchost.exe 752 0.76 Host Process for Windows Services Microsoft Corporation svchost.exe 816 Host Process for Windows Services Microsoft Corporation audiodg.exe 3120 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 900 Host Process for Windows Services Microsoft Corporation dwm.exe 2252 2.27 Desktop Window Manager Microsoft Corporation WUDFHost.exe 2996 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation svchost.exe 932 Host Process for Windows Services Microsoft Corporation wuauclt.exe 4476 Windows Update Microsoft Corporation svchost.exe 1068 Host Process for Windows Services Microsoft Corporation svchost.exe 1248 Host Process for Windows Services Microsoft Corporation spoolsv.exe 1408 Spooler SubSystem App Microsoft Corporation svchost.exe 1436 Host Process for Windows Services Microsoft Corporation svchost.exe 1528 Host Process for Windows Services Microsoft Corporation E_S40ST7.EXE 1596 EPSON Status Monitor 3 SEIKO EPSON CORPORATION E_S40RP7.EXE 1640 EPSON Status Monitor 3 SEIKO EPSON CORPORATION svchost.exe 1668 Host Process for Windows Services Microsoft Corporation msftesql.exe 1736 PKM executable Microsoft Corporation sqlservr.exe 1764 SQL Server Windows NT Microsoft Corporation NBService.exe 1796 Nero BackItUp Nero AG SMSvcHost.exe 1872 SMSvcHost.exe Microsoft Corporation sqlwriter.exe 1996 SQL Server VSS Writer Microsoft Corporation svchost.exe 2032 Host Process for Windows Services Microsoft Corporation TomTomHOMEService.exe 380 Windows Service for TomTom HOME TomTom svchost.exe 428 Host Process for Windows Services Microsoft Corporation taskhost.exe 2264 Host Process for Windows Tasks Microsoft Corporation alg.exe 2580 Application Layer Gateway Service Microsoft Corporation svchost.exe 2884 Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 3712 Microsoft Windows Search Indexer Microsoft Corporation svchost.exe 3940 Host Process for Windows Services Microsoft Corporation wmpnetwk.exe 3784 Windows Media Player Network Sharing Service Microsoft Corporation svchost.exe 5688 Host Process for Windows Services Microsoft Corporation lsass.exe 512 Local Security Authority Process Microsoft Corporation lsm.exe 520 Local Session Manager Service Microsoft Corporationcsrss.exe 452 Client Server Runtime Process Microsoft Corporationwinlogon.exe 584 Windows Logon Application Microsoft Corporationexplorer.exe 2316 Windows Explorer Microsoft Corporation RtHDVCpl.exe 3160 HD Audio Control Panel Realtek Semiconductor hpsysdrv.exe 3172 hpsysdrv Hewlett-Packard Company ssc_serv.exe 3196 SSC Service Utility SSC Localization Group SSMMgr.exe 3212 wmagent.exe 3240 DTLite.exe 3284 DAEMON Tools Lite DT Soft Ltd uTorrent.exe 3348 µTorrent BitTorrent, Inc. ProvideSupportConsole.exe 3440 OUTLOOK.EXE 2504 Microsoft Office Outlook Microsoft Corporation firefox.exe 3552 Firefox Mozilla Corporation dmaster.exe 1156 Download Master WestByte WinRAR.exe 4440 WinRAR archiver Alexander Roshal procexp.exe 2900 16.68 Sysinternals Process Explorer Sysinternals - www.sysinternals.comProcess: uTorrent.exe Pid: 3348Name Description Company Name VersionADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.1.7600.16385apphelp.dll Application Compatibility Client Library Microsoft Corporation 6.1.7600.16481ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.5.2284.0C_1252.NLS CFGMGR32.dll Configuration Manager DLL Microsoft Corporation 6.1.7600.16385CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.8530.16385COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7600.16385comctl32.dll.mui User Experience Controls Library Microsoft Corporation 6.10.7600.16385comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.1.7600.16385credssp.dll Credential Delegation Security Package Microsoft Corporation 6.1.7600.16385CRYPT32.dll Crypto API32 Microsoft Corporation 6.1.7600.16385CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.1.7600.16385CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.1.7600.16385cscapi.dll Offline Files Win32 API Microsoft Corporation 6.1.7600.16385DEVOBJ.dll Device Information Set DLL Microsoft Corporation 6.1.7600.16385dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.1.7600.16385dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.1.7600.16385DnsApi.dll DNS Client API DLL Microsoft Corporation 6.1.7600.16385DUser.dll Windows DirectUser Engine Microsoft Corporation 6.1.7600.16385duser.dll.mui Windows DirectUser Engine Microsoft Corporation 6.1.7600.16385dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation 6.1.7600.16385EhStorShell.dll Windows Enhanced Storage Shell Extension DLL Microsoft Corporation 6.1.7600.16385FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.1.7600.16385fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.1.7600.16385GDI32.dll GDI Client DLL Microsoft Corporation 6.1.7600.16385GPAPI.dll Group Policy Client API Microsoft Corporation 6.1.7600.16385hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.1.7600.16385iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.0.7600.16385imageres.dll Windows Image Resource Microsoft Corporation 6.1.7600.16385IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.1.7600.16385Iphlpapi.dll IP Helper API Microsoft Corporation 6.1.7600.16385kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16481KERNELBASE.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385locale.nls LPK.dll Language Pack Microsoft Corporation 6.1.7600.16385mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.0.6.2MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.1.7600.16415MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.1.7600.16385msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.7600.16385mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.1.7600.16385msxml3.dll MSXML 3.0 SP11 Microsoft Corporation 8.110.7600.16385msxml3r.dll XML Resources Microsoft Corporation 8.110.7600.16385netshell.dll Network Connections Shell Microsoft Corporation 6.1.7600.16385netutils.dll Net Win32 API Helpers DLL Microsoft Corporation 6.1.7600.16385nlaapi.dll Network Location Awareness 2 Microsoft Corporation 6.1.7600.16385npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.1.7600.16385NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.1.7600.16385ntdll.dll NT Layer DLL Microsoft Corporation 6.1.7600.16385ntmarta.dll Windows NT MARTA provider Microsoft Corporation 6.1.7600.16385ntshrui.dll Shell extensions for sharing Microsoft Corporation 6.1.7600.16385ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.1.7600.16385oleaut32.dll Microsoft Corporation 6.1.7600.16385profapi.dll User Profile Basic API Microsoft Corporation 6.1.7600.16385PROPSYS.dll Microsoft Property System Microsoft Corporation 7.0.7600.16385R000000000016.clb rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.1.7600.16385RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.1.7600.16385RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.1.7600.16385rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.1.7600.16385sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.1.7600.16385SETUPAPI.dll Windows Setup API Microsoft Corporation 6.1.7600.16385SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.1.7600.16532shfolder.dll Shell Folder Service Microsoft Corporation 6.1.7600.16385SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.1.7600.16385slc.dll Software Licensing Client Dll Microsoft Corporation 6.1.7600.16385SortDefault.nls srvcli.dll Server Service Client DLL Microsoft Corporation 6.1.7600.16385SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.1.7600.16385SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.1.7600.16385StaticCache.dat SXS.DLL Fusion 2.5 Microsoft Corporation 6.1.7600.16385tiptsf.dll Tablet PC Input Panel Text Services Framework Microsoft Corporation 6.1.7600.16385upnp.dll UPnP Control Point API Microsoft Corporation 6.1.7600.16385urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 8.0.7600.16535USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.1.7600.16385USERENV.dll Userenv Microsoft Corporation 6.1.7600.16385USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385uTorrent.exe µTorrent BitTorrent, Inc. 2.0.1.19248uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.1.7600.16385VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.1.7600.16385vksaver.dll Music and video downloader for vkontakte.ru AudioVkontakte.Ru 2.2.1.0webio.dll Web Transfer Protocols API Microsoft Corporation 6.1.7600.16385WindowsCodecs.dll Microsoft Windows Codecs Library Microsoft Corporation 6.1.7600.16385WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.1.7600.16385WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.1.7600.16385wkscli.dll Workstation Service Client DLL Microsoft Corporation 6.1.7600.16385WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.1.7600.16385WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.1.7600.16385wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.1.7600.16385wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.1.7600.16385 Link to comment Share on other sites More sharing options...
moogly Posted May 1, 2010 Report Share Posted May 1, 2010 @n1k3Your logs look fine, no hostile DLL injected into µT.@artwebvksaver.dll Music and video downloader for vkontakte.ru AudioVkontakte.Ru 2.2.1.0What's its role? Anyway I doubt it's really the culprit...To both of you, I think you're experiencing the same issue reported in this long thread:http://forum.utorrent.com/viewtopic.php?id=71296So can you test this 2.0.1 version posted by Firon? And report if the issue persists.http://forum.utorrent.com/viewtopic.php?pid=479880#p479880 Link to comment Share on other sites More sharing options...
n1k3 Posted May 1, 2010 Report Share Posted May 1, 2010 if you think of something tell us. thanks anyway Link to comment Share on other sites More sharing options...
artweb Posted May 1, 2010 Report Share Posted May 1, 2010 2.0.1 version posted by Firon fixed my problem. thanks alot moogly Link to comment Share on other sites More sharing options...
Firon Posted May 3, 2010 Report Share Posted May 3, 2010 Good to know. This gives us a lot more insight as to where the bug in Windows lies. It's more than likely related to IPv6. Link to comment Share on other sites More sharing options...
ratonjd Posted May 7, 2010 Report Share Posted May 7, 2010 I'm having this same annoying issue, this is my hijack log:Logfile of Trend Micro HijackThis v2.0.4Scan saved at 11:39:00 AM, on 5/7/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Windows\system32\Dwm.exeC:\Windows\system32\taskhost.exeC:\Windows\Explorer.EXEC:\Windows\system32\taskeng.exeC:\Program Files\RegCure\RegCure.exeC:\Program Files\AVG\AVG9\avgtray.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Windows Live\Contacts\wlcomm.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Windows\system32\Macromed\Flash\FlashUtil10e.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Internet Explorer\iexplore.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Trend Micro\HiJackThis\HiJackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://m.www.yahoo.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO4 - HKLM\..\Run: [AVG9_TRAY] C:\PROGRA~1\AVG\AVG9\avgtray.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"O4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunO4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000O9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra button: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exeO9 - Extra 'Tools' menuitem: ICQ7 - {88EB38EF-4D2C-436D-ABD3-56B232674062} - C:\Program Files\ICQ7.0\ICQ.exeO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLLO16 - DPF: {87BE3784-6977-4E84-AA08-55A96B9CEAC5} (Bl_camera Control) - http://192.168.1.253:50000/bl_camera.cabO16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cabO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/3,0,0,5951/mcfscan.cabO20 - AppInit_DLLs: avgrsstx.dllO23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program Files\AVG\AVG9\avgwdsvc.exeO23 - Service: LexBce Server (LexBceS) - Lexmark International, Inc. - C:\Windows\System32\LEXBCES.EXEO23 - Service: lxbc_device - - C:\Windows\system32\lxbccoms.exeO23 - Service: TeamViewer 5 (TeamViewer5) - TeamViewer GmbH - C:\Program Files\TeamViewer\Version5\TeamViewer_Service.exe--End of file - 5196 bytes Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.