Jump to content

Strange behavior since installing uTorrent:


srt6

Recommended Posts

I installed uTorrent about two weeks ago.

Everything ran well at first, then I started to get an occasional buzz from the speakers that disappeared when I clicked the mouse.

This went on for about a week, and then the keyboard started having intermittent problems. Now it is totally FUBAR, and the mouse is starting to degrade and when I open a browser it has a mind of its own.

I am guessing that this is a virus, but I have been running AVAST antivirus and Ad-Aware anti-spyware, and have never had any such problems before uTorrent.

Could this have anything to do with uTorrent? The torrents I accessed all came from mininova.

I am running Windows XP, and I am hoping not to have to wipe the hard drive clean and start over.

I did read the FAQ's, and will try the fix for AVAST when I get home, but it doesn't sound likely to help.

Thanks in advance,

Jeff

Link to comment
Share on other sites

Process Explorer:

Process PID CPU Description Company Name

System Idle Process 0

Interrupts n/a Hardware Interrupts

DPCs n/a Deferred Procedure Calls

System 4

smss.exe 672 Windows NT Session Manager Microsoft Corporation

csrss.exe 924 Client Server Runtime Process Microsoft Corporation

winlogon.exe 948 Windows NT Logon Application Microsoft Corporation

services.exe 992 0.78 Services and Controller app Microsoft Corporation

svchost.exe 1168 Generic Host Process for Win32 Services Microsoft Corporation

Playlist.exe 2236 Roxio AudioCentral Media Manager Playlist Roxio, Inc.

SZServer.exe 1216 STOPzilla Service iS3, Inc.

STOPzilla.exe 1748 STOPzilla Application iS3, Inc.

svchost.exe 1260 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1568 3.13 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1612 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1728 Generic Host Process for Win32 Services Microsoft Corporation

aswUpdSv.exe 220 avast! Antivirus updating service ALWIL Software

ashServ.exe 340 avast! antivirus service ALWIL Software

spoolsv.exe 928 Spooler SubSystem App Microsoft Corporation

ATKKBService.exe 1332 ASUS Keyboard Service ASUSTeK COMPUTER INC.

dvpapi.exe 1424 Command Software Systems, Inc.

GoogleUpdaterService.exe 1592 gusvc Google

McciCMService.exe 640 mcci+McciCMService Motive Communications, Inc.

MOVIEL~1.EXE 2348 Movielink Manager Core Movielink LLC

nvsvc32.exe 2380 NVIDIA Driver Helper Service, Version 83.91 NVIDIA Corporation

slserv.exe 2592 Smart Link

MsPMSPSv.exe 2776 WMDM PMSP Service Microsoft Corporation

ashMaiSv.exe 3312 avast! e-Mail Scanner Service ALWIL Software

ashWebSv.exe 3376 avast! Web Scanner ALWIL Software

alg.exe 1368 Application Layer Gateway Service Microsoft Corporation

svchost.exe 3468 Generic Host Process for Win32 Services Microsoft Corporation

lsass.exe 1004 LSA Shell (Export Version) Microsoft Corporation

WgaTray.exe 2488 Windows Genuine Advantage Notification Microsoft Corporation

explorer.exe 1708 Windows Explorer Microsoft Corporation

smax4pnp.exe 1840 SMax4PNP Analog Devices, Inc.

SMax4.exe 1884 Audio Control Panel Analog Devices, Inc.

rundll32.exe 1912 Run a DLL as an App Microsoft Corporation

DrgToDsc.exe 1980 Drag To Disc Application Roxio

RxMon.exe 1992 Roxio AudioCentral Media Manager Tray App Roxio, Inc.

ashDisp.exe 2008 avast! service GUI component ALWIL Software

Movielink User.exe 2012 Movielink Manager User App Movielink LLC

jusched.exe 2024 Java Platform SE binary Sun Microsystems, Inc.

realsched.exe 2040 RealNetworks Scheduler RealNetworks, Inc.

ctfmon.exe 204 CTF Loader Microsoft Corporation

GoogleToolbarNotifier.exe 1828 GoogleToolbarNotifier Google Inc.

VeohClient.exe 268 Veoh Client Veoh Networks

RtWLan.exe 1312 RtWLan (ASUS) Application ASUSTek Computer Inc.

boincmgr.exe 1372 BOINC Manager for Windows Space Sciences Laboratory

boinc.exe 2360 BOINC client Space Sciences Laboratory

wcg_dddt_autodock_6.05_windows_intelx86 3612 45.31 Created under grants from the National Institutes of Health National Institute of General Medical Sciences grant numbers P01 GM48870 and R01 GM069832. The Scripps Research Institute and IBM Corporation

wcg_hcc1_img_6.06_windows_intelx86 4016 49.22

GoogleUpdater.exe 1048 Google Updater Google

WinCinemaMgr.exe 1524 WinCinema Manager InterVideo Inc.

TDKLauncher.exe 2068 TDKInstaller/TDKLauncher MFC Application TDK

iexplore.exe 3156 Internet Explorer Microsoft Corporation

procexp.exe 5728 1.56 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

rundll32.exe 1968 Run a DLL as an App Microsoft Corporation

HiJack This:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 1:42:32 AM, on 7/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16674)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

C:\WINDOWS\System32\svchost.exe

C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

C:\Program Files\Alwil Software\Avast4\ashServ.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\Explorer.EXE

C:\Program Files\STOPzilla!\STOPzilla.exe

C:\Program Files\Analog Devices\Core\smax4pnp.exe

C:\Program Files\Analog Devices\SoundMAX\Smax4.exe

C:\WINDOWS\system32\RunDLL32.exe

C:\WINDOWS\system32\rundll32.exe

C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe

C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe

C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

C:\Program Files\Movielink\MovielinkManager\Movielink User.exe

C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe

C:\Program Files\Common Files\Real\Update_OB\realsched.exe

C:\WINDOWS\system32\ctfmon.exe

C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

C:\Program Files\Veoh Networks\Veoh\VeohClient.exe

C:\Program Files\ASUS WiFi-AP Solo\RtWLan.exe

C:\WINDOWS\ATKKBService.exe

C:\Program Files\BOINC\boincmgr.exe

C:\Program Files\Common Files\Command Software\dvpapi.exe

C:\Program Files\Google\Google Updater\GoogleUpdater.exe

C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

C:\Program Files\Common Files\Motive\McciCMService.exe

C:\Program Files\TDK\TDKLauncher\TDKLauncher.exe

C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\Playlist.exe

C:\PROGRA~1\MOVIEL~1\MOVIEL~1\MOVIEL~1.EXE

C:\WINDOWS\system32\nvsvc32.exe

C:\WINDOWS\system32\slserv.exe

C:\WINDOWS\system32\MsPMSPSv.exe

C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

C:\Program Files\BOINC\boinc.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\WgaTray.exe

C:\Program Files\BOINC\projects\www.worldcommunitygrid.org\wcg_dddt_autodock_6.05_windows_intelx86

C:\Program Files\BOINC\projects\www.worldcommunitygrid.org\wcg_hcc1_img_6.06_windows_intelx86

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://my.att.net

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)

O2 - BHO: SITEguard BHO - {1827766B-9F49-4854-8034-F6EE26FCB1EC} - C:\Program Files\STOPzilla!\SZSG.dll

O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar2.dll

O2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dll

O2 - BHO: STOPzilla Browser Helper Object - {E3215F20-3212-11D6-9F8B-00D0B743919D} - C:\Program Files\STOPzilla!\SZIEBHO.dll

O3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dll

O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar2.dll

O3 - Toolbar: STOPzilla - {98828DED-A591-462F-83BA-D2F62A68B8B8} - C:\Program Files\STOPzilla!\SZSG.dll

O4 - HKLM\..\Run: [soundMAXPnP] C:\Program Files\Analog Devices\Core\smax4pnp.exe

O4 - HKLM\..\Run: [soundMAX] "C:\Program Files\Analog Devices\SoundMAX\Smax4.exe" /tray

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [nwiz] nwiz.exe /install

O4 - HKLM\..\Run: [NvMediaCenter] RunDLL32.exe NvMCTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [RoxioEngineUtility] "C:\Program Files\Common Files\Roxio Shared\System\EngUtil.exe"

O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy CD Creator 6\DragToDisc\DrgToDsc.exe"

O4 - HKLM\..\Run: [RoxioAudioCentral] "C:\Program Files\Roxio\Easy CD Creator 6\AudioCentral\RxMon.exe"

O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe

O4 - HKLM\..\Run: [LoadMSvcmm] "C:\Program Files\Movielink\MovielinkManager\Movielink User.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osboot

O4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exe

O4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe

O4 - HKCU\..\Run: [Veoh] "C:\Program Files\Veoh Networks\Veoh\VeohClient.exe" /VeohHide

O4 - Startup: TDK Launcher.lnk = C:\Program Files\TDK\TDKLauncher\TDKLauncher.exe

O4 - Global Startup: ASUS WiFi-AP Solo.lnk = ?

O4 - Global Startup: BOINC Manager.lnk = C:\Program Files\BOINC\boincmgr.exe

O4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exe

O4 - Global Startup: InterVideo WinCinema Manager.lnk = C:\Program Files\InterVideo\Common\Bin\WinCinemaMgr.exe

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exe

O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\common files\is3\anti-spyware\is3lsp.dll

O16 - DPF: {0D41B8C5-2599-4893-8183-00195EC8D5F9} (asusTek_sysctrl Class) - http://support.asus.com/common/asusTek_sys_ctrl.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1161092669314

O16 - DPF: {67DABFBF-D0AB-41FA-9C46-CC0F21721616} (DivXBrowserPlugin Object) - http://download.divx.com/player/DivXBrowserPlugin.cab

O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe

O23 - Service: ATK Keyboard Service (ATKKeyboardService) - ASUSTeK COMPUTER INC. - C:\WINDOWS\ATKKBService.exe

O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe

O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe

O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe

O23 - Service: DvpApi (dvpapi) - Command Software Systems, Inc. - C:\Program Files\Common Files\Command Software\dvpapi.exe

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: McciCMService - Motive Communications, Inc. - C:\Program Files\Common Files\Motive\McciCMService.exe

O23 - Service: Movielink Core Service - Movielink LLC - C:\PROGRA~1\MOVIEL~1\MOVIEL~1\MOVIEL~1.EXE

O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exe

O23 - Service: SmartLinkService (SLService) - Smart Link - C:\WINDOWS\SYSTEM32\slserv.exe

O23 - Service: STOPzilla Service (szserver) - iS3, Inc. - C:\Program Files\Common Files\iS3\Anti-Spyware\SZServer.exe

--

End of file - 9391 bytes

Thanks for the help,

Jeff

P.S. - my home computer keyboard is now working, and I'm able to go online without spawning 20 instant pages. I did install StopZilla; perhaps that helped. I also reseated all boards, too.

Link to comment
Share on other sites

Are you sure about IS3/StopZilla?

Thing got better after I installed it - keyboard resumed functioning, and I can now use the internet from this computer. I did do adware & antivirus scans; found lots of adware, but no viruses.

Could I have a power supply problem? For a few months, about every 10th or 20th time I start my computer, I have to unplug it for a minute before it will boot up - if I don't it goes through a few seconds of start up, and then shuts off.

Thanks,

Jeff

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...