Jump to content

port forwarding woes


ryanrk

Recommended Posts

So here's my problem. Dell Laptop on WIFI and DLINK 4300 router. I can't seem to get the port forwarding to work. I got it to work with 2 other pc's.

Here's what i did.

Selected a port (12121 in this example) in Utorrent.

Opened that port on the DLINK 4300 router.

Disabled windows xp firewall.

The speedguide tells me that the port can't be routed.

If i open the cmd window in windows and do "telnet localhost 12121 i get a connection.

If i open another cmd window and do "telnet 192.168.0.180 12121 i get a connection (this is the ip of that pc on my lan).

If I open another cmd window and do "telnet <my internet ip> 12121 it won't connect.

If I look at the dlink logs everything seem ok. However if i disable the port forwarding on the router the logs start filling up with warning that it's refusing connections to port 12121. This makes me think the routing is working. So now i'm stumped.

There is nothing between the router and the Dell PC. So i'm thinking maybe there is something on her pc blocking it but the only thing i have running is Nod32.

Any suggestions?

Link to comment
Share on other sites

a) get HijackThis from trendsecure.com, run it, view the log, and post the contents here

B) get Process Explorer from sysinternals.com, run it, Ctrl+D (to show the lower DLL pane), select the µTorrent process from the list, Ctrl+S (and save the list somewhere you'll find easily -- like the Desktop), then post the contents of the saved process list in the .txt file here

Link to comment
Share on other sites

Okay so I can't seem to figure out how to take attach files here so I copy and pasted them below. I also before running these test added utorrent to the IMON exception list on NOD32. I was reading in other posts that NOD32 might caused issues but this didn't solve it.

Here's HiJackThis

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 10:39:15 AM, on 6/22/2008
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16674)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
C:\WINDOWS\System32\WLTRYSVC.EXE
C:\WINDOWS\System32\bcmwltry.exe
C:\WINDOWS\system32\spoolsv.exe
C:\WINDOWS\eHome\ehRecvr.exe
C:\WINDOWS\eHome\ehSched.exe
C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
C:\Program Files\Eset\nod32krn.exe
C:\WINDOWS\system32\svchost.exe
C:\Program Files\Viewpoint\Common\ViewpointService.exe
C:\Program Files\Canon\CAL\CALMAIN.exe
C:\WINDOWS\system32\dllhost.exe
C:\WINDOWS\system32\Ati2evxx.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\CheckPoint\SecuRemote\bin\SR_GUI.Exe
C:\WINDOWS\ehome\ehtray.exe
C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe
C:\WINDOWS\system32\WLTRAY.exe
C:\WINDOWS\stsystra.exe
C:\Program Files\Dell\QuickSet\quickset.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe
C:\Program Files\Real\RealPlayer\RealPlay.exe
C:\WINDOWS\eHome\ehmsas.exe
C:\WINDOWS\system32\dla\tfswctrl.exe
C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe
C:\WINDOWS\system32\rundll32.exe
C:\Program Files\Messenger\msmsgs.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Program Files\Steam\Steam.exe
C:\Program Files\Digital Line Detect\DLG.exe
C:\Program Files\ATI Technologies\ATI.ACE\cli.exe
C:\Program Files\Viewpoint\Viewpoint Manager\ViewMgr.exe
C:\Program Files\Adobe\Acrobat 7.0\Reader\AcroRd32.exe
C:\Program Files\uTorrent\utorrent.exe
C:\Program Files\ESET\nod32kui.exe
C:\PROGRA~1\MOZILL~1\FIREFOX.EXE
c:\program files\common files\installshield\updateservice\isuspm.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.msnbc.com/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)
O2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\system32\dla\tfswshx.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: Browser Address Error Redirector - {CA6319C0-31B7-401E-A518-A07C3DB8F777} - c:\Program Files\BAE\BAE.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"
O4 - HKLM\..\Run: [Broadcom Wireless Manager UI] C:\WINDOWS\system32\WLTRAY.exe
O4 - HKLM\..\Run: [SigmatelSysTrayApp] stsystra.exe
O4 - HKLM\..\Run: [Dell QuickSet] C:\Program Files\Dell\QuickSet\quickset.exe
O4 - HKLM\..\Run: [ShowLOMControl]
O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay
O4 - HKLM\..\Run: [DVDLauncher] "C:\Program Files\CyberLink\PowerDVD\DVDLauncher.exe"
O4 - HKLM\..\Run: [RealTray] C:\Program Files\Real\RealPlayer\RealPlay.exe SYSTEMBOOTHIDEPLAYER
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [dla] C:\WINDOWS\system32\dla\tfswctrl.exe
O4 - HKLM\..\Run: [ISUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startup
O4 - HKLM\..\Run: [ISUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -start
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
O4 - HKCU\..\Run: [MSMSGS] "C:\Program Files\Messenger\msmsgs.exe" /background
O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [Steam] "C:\Program Files\Steam\Steam.exe" -silent
O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
O4 - Global Startup: Digital Line Detect.lnk = ?
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~4\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dll
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe
O16 - DPF: {05D44720-58E3-49E6-BDF6-D00330E511D3} (StagingUI Object) - http://zone.msn.com/binFrameWork/v10/StagingUI.cab55579.cab
O16 - DPF: {3BB54395-5982-4788-8AF4-B5388FFDD0D8} (MSN Games – Buddy Invite) - http://zone.msn.com/BinFrameWork/v10/ZBuddy.cab55579.cab
O16 - DPF: {5736C456-EA94-4AAC-BB08-917ABDD035B3} (ZonePAChat Object) - http://zone.msn.com/binframework/v10/ZPAChat.cab55579.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/EN-US/a-UNO1/GAME_UNO1.cab
O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1145492472062
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cab
O16 - DPF: {A4110378-789B-455F-AE86-3A1BFC402853} (ZPA_SHVL Object) - http://zone.msn.com/bingame/zpagames/zpa_shvl.cab55579.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://cdn2.zone.msn.com/binFramework/v10/ZIntro.cab56649.cab
O16 - DPF: {DA2AA6CF-5C7A-4B71-BC3B-C771BB369937} (MSN Games – Game Communicator) - http://zone.msn.com/binframework/v10/StProxy.cab55579.cab
O16 - DPF: {DF780F87-FF2B-4DF8-92D0-73DB16A1543A} (PopCapLoader Object) - http://zone.msn.com/bingame/popcaploader_v10.cab
O16 - DPF: {E008A543-CEFB-4559-912F-C27C2B89F13B} (Domino Web Access 7 Control) - https://usseat05.notes.milliman.com/dwa7W.cab
O16 - DPF: {F6BF0D00-0B2A-4A75-BF7B-F385591623AF} (Solitaire Showdown Class) - http://messenger.zone.msn.com/binary/SolitaireShowdown.cab31267.cab
O18 - Filter hijack: text/html - (no CLSID) - (no file)
O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe
O23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: NICCONFIGSVC - Dell Inc. - C:\Program Files\Dell\NICCONFIGSVC\NICCONFIGSVC.exe
O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exe
O23 - Service: Check Point SecuRemote Service (SR_Service) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_Service.exe
O23 - Service: Check Point SecuRemote WatchDog (SR_WatchDog) - Check Point Software Technologies - C:\Program Files\CheckPoint\SecuRemote\bin\SR_WatchDog.exe
O23 - Service: Viewpoint Manager Service - Viewpoint Corporation - C:\Program Files\Viewpoint\Common\ViewpointService.exe
O23 - Service: Dell Wireless WLAN Tray Service (wltrysvc) - Unknown owner - C:\WINDOWS\System32\WLTRYSVC.EXE

--
End of file - 9886 bytes

This is the sysinternal log

Process    PID    CPU    Description    Company Name
System Idle Process 0 91.79
Interrupts n/a 1.49 Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4
smss.exe 1064 Windows NT Session Manager Microsoft Corporation
csrss.exe 1124 1.49 Client Server Runtime Process Microsoft Corporation
winlogon.exe 1152 Windows NT Logon Application Microsoft Corporation
services.exe 1196 0.75 Services and Controller app Microsoft Corporation
ati2evxx.exe 1388 ATI External Event Utility EXE Module ATI Technologies Inc.
svchost.exe 1404 Generic Host Process for Win32 Services Microsoft Corporation
wmiprvse.exe 2132 WMI Microsoft Corporation
ehmsas.exe 4084 Media Center Media Status Aggregator Service Microsoft Corporation
svchost.exe 1472 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1524 Generic Host Process for Win32 Services Microsoft Corporation
SR_Service.exe 1680 SecureClient Service Check Point Software Technologies
SR_Watchdog.exe 1692 Check Point Software Technologies
SR_GUI.exe 3684 SecureClient Application Check Point Software Technologies
svchost.exe 1812 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 1848 Generic Host Process for Win32 Services Microsoft Corporation
WLTRYSVC.EXE 2024
BCMWLTRY.EXE 2040 0.75 Dell Wireless WLAN Card Wireless Network Controller Dell Inc.
spoolsv.exe 196 Spooler SubSystem App Microsoft Corporation
svchost.exe 412 Generic Host Process for Win32 Services Microsoft Corporation
ehrecvr.exe 492 Media Center Receiver Service Microsoft Corporation
ehSched.exe 560 Media Center Scheduler Service Microsoft Corporation
NicConfigSvc.exe 628 Internal Network Card Power Management Service Dell Inc.
nod32krn.exe 544 NOD32 Kernel Service Eset
svchost.exe 784 Generic Host Process for Win32 Services Microsoft Corporation
svchost.exe 820 Generic Host Process for Win32 Services Microsoft Corporation
ViewpointService.exe 872 ViewMgr Viewpoint Corporation
ViewMgr.exe 1588 ViewMgr Viewpoint Corporation
mcrdsvc.exe 984 MCRD Device Service Microsoft Corporation
CALMAIN.exe 1544 Canon Camera Access Library 8 Canon Inc.
dllhost.exe 2360 COM Surrogate Microsoft Corporation
alg.exe 2512 Application Layer Gateway Service Microsoft Corporation
lsass.exe 1208 LSA Shell (Export Version) Microsoft Corporation
ati2evxx.exe 3412 ATI External Event Utility EXE Module ATI Technologies Inc.
explorer.exe 3504 Windows Explorer Microsoft Corporation
ehtray.exe 3832 Media Center Tray Applet Microsoft Corporation
jusched.exe 3896 Java(TM) 2 Platform Standard Edition binary Sun Microsystems, Inc.
WLTRAY.EXE 3908 0.75 Dell Wireless WLAN Card Wireless Network Tray Applet Dell Inc.
stsystra.exe 3936 Sigmatel Audio system tray application SigmaTel, Inc.
quickset.exe 3992 QuickSet Dell Inc
SynTPEnh.exe 4008 1.49 Synaptics TouchPad Enhancements Synaptics, Inc.
CLI.exe 4024 CLI Application (Command Line Interface) ATI Technologies Inc.
CLI.exe 1600 CLI Application (Command Line Interface) ATI Technologies Inc.
DVDLauncher.exe 4036 CyberLink PowerCinema Resident Program CyberLink Corp.
realplay.exe 4060 RealPlayer RealNetworks, Inc.
tfswctrl.exe 380 Drive Letter Access Component Sonic Solutions
issch.exe 960 InstallShield Update Service Scheduler InstallShield Software Corporation
ISUSPM.exe 10728 InstallShield Update Service Update Manager InstallShield Software Corporation
rundll32.exe 1108 Run a DLL as an App Microsoft Corporation
msmsgs.exe 1960 Windows Messenger Microsoft Corporation
ctfmon.exe 2240 CTF Loader Microsoft Corporation
Steam.exe 2152 Steam Valve Corporation
DLG.exe 2692 Digital Line Detection BVRP Software
utorrent.exe 11152 0.75 µTorrent BitTorrent, Inc.
nod32kui.exe 9200 NOD32 Control Center GUI Eset
iexplore.exe 7164 Internet Explorer Microsoft Corporation
procexp.exe 7612 0.75 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
AcroRd32.exe 2272 Adobe Reader 7.0 Adobe Systems Incorporated
firefox.exe 6404 Firefox Mozilla Corporation

Process: utorrent.exe Pid: 11152

Name Description Company Name Version
ACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.5512
adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.5512
ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.5512
appHelp.dll Application Compatibility Client Library Microsoft Corporation 5.01.2600.5512
ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0001
CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0700
COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.5512
comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.5512
COMRes.dll Microsoft Corporation 2001.12.4414.0700
credui.dll Credential Manager User Interface Microsoft Corporation 5.01.2600.5512
CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.5512
ctype.nls
dadkeyb.dll
DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.5512
dot3api.dll 802.3 Autoconfiguration API Microsoft Corporation 5.01.2600.5512
dot3dlg.dll 802.3 UI Helper Microsoft Corporation 5.01.2600.5512
eappcfg.dll Eap Peer Config Microsoft Corporation 5.01.2600.5512
eappprxy.dll Microsoft EAPHost Peer Client DLL Microsoft Corporation 5.01.2600.5512
GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.5512
hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.5512
ieframe.dll Internet Explorer Microsoft Corporation 7.00.6000.16674
ieframe.dll.mui Internet Explorer Microsoft Corporation 7.00.6000.16414
iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6000.16674
IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.5512
imon.dll NOD32 IMON - Internet scanning support Eset 2.70.0039.0000
Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.5512
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.5512
locale.nls
MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.5512
MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.5512
MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.01.2600.5512
msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.5512
MSVCP60.dll Microsoft (R) C++ Runtime Library Microsoft Corporation 6.02.3104.0000
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.5512
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.5512
NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.5512
netshell.dll Network Connections Shell Microsoft Corporation 5.01.2600.5512
ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.5512
ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.5512
oleaut32.dll Microsoft Corporation 5.01.2600.5512
OneX.DLL IEEE 802.1X supplicant library Microsoft Corporation 5.01.2600.5512
PSAPI.DLL Process Status Helper Microsoft Corporation 5.01.2600.5512
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.5512
RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.5512
rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.5512
SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.5512
Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.5512
SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.5512
SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.5512
shfolder.dll Shell Folder Service Microsoft Corporation 6.00.2900.5512
SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.5512
sortkey.nls
sorttbls.nls
unicode.nls
urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.00.6000.16674
USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.5512
utorrent.exe µTorrent BitTorrent, Inc. 1.08.0000.10431
UxTheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.5512
VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.5512
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.5512
WINSTA.dll Winstation Library Microsoft Corporation 5.01.2600.5512
WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.5512
WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.5512
WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.5512
wshbth.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.5512
wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.5512
WSOCK32.dll Windows Socket 32-Bit DLL Microsoft Corporation 5.01.2600.5512
WTSAPI32.dll Windows Terminal Server SDK APIs Microsoft Corporation 5.01.2600.5512
xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.01.2600.5512

Thanks for your help!

Link to comment
Share on other sites

I am having a problem with my port also, but my problem is this:

My port was forwarded for several months and then suddenly yesterday I get a red light at the bottom of the screen where my torrents are shown downloading. It says I am not connectable and that I need to open a port so that people can connect to me. So I checked to make sure everything was still forwarded and everything was. I am stumped. My info is: Internet by COMCAST. Router is Linksys Wireless-G, I use Windows XP.

I have run Hijack This and here are the results:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 12:44:29 AM, on 6/25/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Ahead\InCD\InCDsrv.exe

C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

C:\WINDOWS\system32\spoolsv.exe

C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\VIA\RAID\raid_tool.exe

C:\WINDOWS\SOUNDMAN.EXE

C:\PROGRA~1\AVG\AVG8\avgtray.exe

C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe

C:\Program Files\Ahead\InCD\InCD.exe

C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe

C:\Program Files\Google\Gmail Notifier\gnotify.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe

C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe

C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe

C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe

C:\Program Files\Pando Networks\Pando\Pando.exe

C:\Program Files\Desktop Calendar\Desktop Calendar.exe

C:\PROGRA~1\AVG\AVG8\avgrsx.exe

C:\PROGRA~1\AVG\AVG8\avgemc.exe

C:\Program Files\Windows Live\Messenger\usnsvc.exe

C:\Program Files\uTorrent\uTorrent.exe

C:\Program Files\Internet Explorer\IEXPLORE.EXE

C:\Program Files\Common Files\Microsoft Shared\Windows Live\WLLoginProxy.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://us.rd.yahoo.com/customize/ie/defaults/sb/msgr8/*http://www.yahoo.com/ext/search/search.html

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://us.rd.yahoo.com/customize/ie/defaults/sp/msgr8/*http://www.yahoo.com

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://us.rd.yahoo.com/customize/ie/defaults/su/msgr8/*http://www.yahoo.com

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page =

R3 - URLSearchHook: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll

O2 - BHO: CInterceptor Object - {38D3FE60-3D53-4F37-BB0E-C7A97A26A156} - C:\Program Files\Pando Networks\Pando\PandoIEPlugin.dll

O2 - BHO: AVG Safe Search - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files\AVG\AVG8\avgssie.dll

O2 - BHO: Yahoo! IE Services Button - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)

O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\2.1.1119.1736\swg.dll

O2 - BHO: Windows Live Toolbar Helper - {BDBD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: Yahoo! ¤u¨ã¦C - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~1\Yahoo!\Companion\Installs\cpn0\yt.dll

O3 - Toolbar: Windows Live Toolbar - {BDAD1DAD-C946-4A17-ADC1-64B5B4FF55D0} - C:\Program Files\Windows Live Toolbar\msntb.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll

O4 - HKLM\..\Run: [RaidTool] C:\Program Files\VIA\RAID\raid_tool.exe

O4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXE

O4 - HKLM\..\Run: [AVG8_TRAY] C:\PROGRA~1\AVG\AVG8\avgtray.exe

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_06\bin\jusched.exe"

O4 - HKLM\..\Run: [DiskeeperSystray] "C:\Program Files\Diskeeper Corporation\Diskeeper\DkIcon.exe"

O4 - HKLM\..\Run: [inCD] C:\Program Files\Ahead\InCD\InCD.exe

O4 - HKLM\..\Run: [WinPatrol] C:\Program Files\BillP Studios\WinPatrol\winpatrol.exe

O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe

O4 - HKLM\..\Run: [{0228e555-4f9c-4e35-a3ec-b109a192b4c2}] C:\Program Files\Google\Gmail Notifier\gnotify.exe

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exe

O4 - HKCU\..\Run: [FreeRAM XP] "C:\Program Files\YourWare Solutions\FreeRAM XP Pro\FreeRAM XP Pro.exe" -win

O4 - HKCU\..\Run: [Yahoo! Pager] "C:\PROGRA~1\Yahoo!\Messenger\YahooMessenger.exe" -quiet

O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background

O4 - HKCU\..\Run: [Pando] "C:\Program Files\Pando Networks\Pando\Pando.exe" /Minimized

O4 - HKCU\..\Run: [Desktop Calendar] C:\Program Files\Desktop Calendar\Desktop Calendar.exe

O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office10\OSA.EXE

O8 - Extra context menu item: &Windows Live Search - res://C:\Program Files\Windows Live Toolbar\msntb.dll/search.htm

O8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspx

O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\Microsoft Office\Office10\EXCEL.EXE/3000

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O9 - Extra button: Yahoo! Services - {5BAB4B5B-68BC-4B02-94D6-2FC0DE4A7897} - C:\Program Files\Yahoo!\Common\yiesrvc.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\Microsoft Office\OFFICE11\REFIEBAR.DLL

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://www.update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1212463313765

O18 - Protocol: linkscanner - {F274614C-63F8-47D5-A4D1-FBDDE494F8D1} - C:\Program Files\AVG\AVG8\avgpp.dll

O20 - AppInit_DLLs: avgrsstx.dll

O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe

O23 - Service: AVG8 E-mail Scanner (avg8emc) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgemc.exe

O23 - Service: AVG8 WatchDog (avg8wd) - AVG Technologies CZ, s.r.o. - C:\PROGRA~1\AVG\AVG8\avgwdsvc.exe

O23 - Service: Diskeeper - Diskeeper Corporation - C:\Program Files\Diskeeper Corporation\Diskeeper\DkService.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InCD Helper (InCDsrv) - Nero AG - C:\Program Files\Ahead\InCD\InCDsrv.exe

--

End of file - 8953 bytes

If anyone can help it would be greatly appreciated.

Thanks

sachlind

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...