aggixx Posted July 31, 2008 Report Share Posted July 31, 2008 I am using uTorrent 1.8 RC.After leaving bittorrent open for a while its starts to take up more and more cpu power (Ive seen spikes up to 75% of my cpu). Once it starts to slow it down enough, it crashes when I try to exit (making it impossible to shutdown my computer normally). Please help, having my mouse lag around the screen is not fun. Link to comment Share on other sites More sharing options...
thelittlefire Posted July 31, 2008 Report Share Posted July 31, 2008 Follow the troubleshooting sticky, and start with a Process Explorer logfile... followed by HiJackThis. Also, not to be rude, are you sure you're seeing CPU spikes and not RAM usage increase? Link to comment Share on other sites More sharing options...
aggixx Posted July 31, 2008 Author Report Share Posted July 31, 2008 Correct, Cpu spikes, ram is consistent like usual.Ill edit this message with a logfile, but, how do I make the logfile? Link to comment Share on other sites More sharing options...
thelittlefire Posted July 31, 2008 Report Share Posted July 31, 2008 Apologies, it's not in Troubleshooting like I thought >< This is the sticky frequently mentioned http://forum.utorrent.com/viewtopic.php?id=15992Go to the bottom, read the last post about logfiles, follow the steps for those two relatively small programs, and copy-paste them into your post above/below Link to comment Share on other sites More sharing options...
aggixx Posted July 31, 2008 Author Report Share Posted July 31, 2008 Heres the Process Explorer Log, scroll down for hijackthisProcess PID CPU Description Company NameSystem Idle Process 0 72.45 Interrupts n/a 3.85 Hardware Interrupts DPCs n/a 13.10 Deferred Procedure Calls System 4 smss.exe 440 Windows Session Manager Microsoft Corporationcsrss.exe 516 Client Server Runtime Process Microsoft Corporationwininit.exe 568 Windows Start-Up Application Microsoft Corporation services.exe 612 Services and Controller app Microsoft Corporation svchost.exe 816 Host Process for Windows Services Microsoft Corporation unsecapp.exe 812 Sink to receive asynchronous callbacks for WMI client application Microsoft Corporation WmiPrvSE.exe 2548 WMI Provider Host Microsoft Corporation nvvsvc.exe 860 NVIDIA Driver Helper Service, Version 177.35 NVIDIA Corporation rundll32.exe 1372 Windows host process (Rundll32) Microsoft Corporation svchost.exe 888 Host Process for Windows Services Microsoft Corporation svchost.exe 928 Host Process for Windows Services Microsoft Corporation svchost.exe 980 Host Process for Windows Services Microsoft Corporation audiodg.exe 1188 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1012 0.77 Host Process for Windows Services Microsoft Corporation dwm.exe 1968 Desktop Window Manager Microsoft Corporation WUDFHost.exe 3848 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation svchost.exe 1032 Host Process for Windows Services Microsoft Corporation taskeng.exe 1596 Task Scheduler Engine Microsoft Corporation SansaDispatch.exe 480 Sansa Dispatcher SanDisk Corporation taskeng.exe 2228 Task Scheduler Engine Microsoft Corporation taskeng.exe 5992 Task Scheduler Engine Microsoft Corporation svchost.exe 1220 Host Process for Windows Services Microsoft Corporation SLsvc.exe 1268 Microsoft Software Licensing Service Microsoft Corporation svchost.exe 1300 Host Process for Windows Services Microsoft Corporation VistaSrv.exe 1468 WindowBlinds Service Stardock Corporation WBVista.exe 1492 svchost.exe 1588 Host Process for Windows Services Microsoft Corporation vsmon.exe 1672 3.85 TrueVector Service Check Point Software Technologies LTD spoolsv.exe 1932 Spooler SubSystem App Microsoft Corporation svchost.exe 1960 Host Process for Windows Services Microsoft Corporation NetworkLicenseServer.exe 2432 ABBYY network license server ABBYY (BIT Software) httpd.exe 2680 Apache HTTP Server Apache Software Foundation httpd.exe 2812 Apache HTTP Server Apache Software Foundation AppleMobileDeviceService.exe 2716 Apple Mobile Device Service Apple Inc. avgamsvr.exe 2728 AVG Alert Manager GRISOFT, s.r.o. avgupsvc.exe 2740 AVG Update Service GRISOFT, s.r.o. avgrssvc.exe 2780 AVG Resident Shield Service GRISOFT, s.r.o. avgrssvc.exe 2896 AVG Resident Shield Service GRISOFT, s.r.o. avgemc.exe 2872 AVG E-Mail Scanner GRISOFT, s.r.o. mDNSResponder.exe 2884 Bonjour Service Apple Inc. DynUpSvc.exe 2916 DynDNS® Updater Service Dynamic Network Services, Inc. iRebootd.exe 3348 iReboot Service svchost.exe 3460 Host Process for Windows Services Microsoft Corporation svchost.exe 3476 Host Process for Windows Services Microsoft Corporation TeamViewer_Host.exe 3540 TeamViewer Service TeamViewer GmbH svchost.exe 3568 Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 3588 Microsoft Windows Search Indexer Microsoft Corporation wmpnetwk.exe 3948 Windows Media Player Network Sharing Service Microsoft Corporation lsass.exe 624 Local Security Authority Process Microsoft Corporation lsm.exe 632 Local Session Manager Service Microsoft Corporationcsrss.exe 580 Client Server Runtime Process Microsoft Corporationwinlogon.exe 792 Windows Logon Application Microsoft Corporationexplorer.exe 2100 0.77 Windows Explorer Microsoft Corporation rundll32.exe 2188 Windows host process (Rundll32) Microsoft Corporation avgcc.exe 2220 AVG Control Center GRISOFT, s.r.o. uTorrent.exe 2260 1.54 µTorrent BitTorrent, Inc. wmpnscfg.exe 2268 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation firefox.exe 1712 Firefox Mozilla Corporation WinRAR.exe 2864 procexp.exe 4376 3.85 Sysinternals Process Explorer Sysinternals - www.sysinternals.com trillian.exe 5644 Trillian Cerulean StudiosProcess: uTorrent.exe Pid: 2260Name Description Company Name VersionADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6001.18000C_936.NLS CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6001.18000comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6001.18000DesktopControlPanel.dll This file is responsible for enhancing the "Desktop Background" control panel to be compatible with ".dream" files. Stardock 2.00.0000.0106dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6001.18000dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6001.18000DNSAPI.dll DNS Client API DLL Microsoft Corporation 6.00.6001.18000events.dll Trillian Event Control Cerulean Studios 3.01.0010.0000FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.00.6001.18000GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6001.18023IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6001.18000Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6001.18000kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000locale.nls locale.nls LPK.DLL Language Pack Microsoft Corporation 6.00.6001.18000mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.00.0004.0012MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6001.18000MSVCR71.dll Microsoft® C Runtime Library Microsoft Corporation 7.10.3052.0004msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6001.18000mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6001.18000napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.00.6001.18000NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6001.18000NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6001.18000ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6001.18000OLEACC.dll Active Accessibility Core Component Microsoft Corporation 4.02.5406.0000oleaccrc.dll Active Accessibility Resource DLL Microsoft Corporation 4.02.5406.0000oleaut32.dll Microsoft Corporation 6.00.6001.18000pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.00.6001.18000PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386R000000000009.clb rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.00.6000.16386RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6001.18051Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6001.18000SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6001.18062shfolder.dll Shell Folder Service Microsoft Corporation 6.00.6000.16386SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6001.18000USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6001.18000USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000uTorrent.exe µTorrent BitTorrent, Inc. 1.08.0000.11564uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6001.18000VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.00.6001.18000WINMM.dll MCI API DLL Microsoft Corporation 6.00.6001.18000WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6001.18000winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.00.6001.18000WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6001.18000wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.00.6001.18000wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6001.18000Hijackthis Log:Logfile of Trend Micro HijackThis v2.0.2Scan saved at 4:40:19 PM, on 7/31/2008Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v7.00 (7.00.6001.18000)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exeC:\Windows\Explorer.EXEC:\Windows\System32\rundll32.exeC:\Program Files\Grisoft\AVG7\avgcc.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Windows Media Player\wmpnscfg.exeC:\Windows\system32\wbem\unsecapp.exeC:\Program Files\Mozilla Firefox 3 Beta 5\firefox.exeC:\Program Files\Trillian\trillian.exeC:\Users\aggixx\Documents\Downloads\HiJackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: (no name) - {00A6FAF6-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLLO1 - Hosts: ::1 localhostO2 - BHO: MyWebSearch Search Assistant BHO - {00A6FAF1-072E-44cf-8957-5838F569A31D} - C:\Program Files\MyWebSearch\SrchAstt\1.bin\MWSSRCAS.DLLO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: mwsBar BHO - {07B18EA1-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLLO2 - BHO: Google Web Accelerator Helper - {69A87B7D-DE56-4136-9655-716BA50C19C7} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO3 - Toolbar: Veoh Browser Plug-in - {D0943516-5076-4020-A3B5-AEFAF26AB263} - C:\Program Files\Veoh Networks\Veoh\Plugins\reg\VeohToolbar.dllO3 - Toolbar: My Web Search - {07B18EA9-A523-4961-B6BB-170DE4475CCA} - C:\Program Files\MyWebSearch\bar\1.bin\MWSBAR.DLLO3 - Toolbar: Google Web Accelerator - {DB87BFA2-A2E3-451E-8E5A-C89982D87CBF} - C:\Program Files\Google\Web Accelerator\GoogleWebAccToolbar.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUPO4 - HKLM\..\Run: [My Web Search Bar Search Scope Monitor] "C:\PROGRA~1\MYWEBS~1\bar\1.bin\m3SrchMn.exe" /m=0O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKCU\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenterO4 - HKCU\..\Run: [Orb] "C:\Program Files\Orb Networks\Orb\bin\OrbTray.exe" /backgroundO4 - HKCU\..\Run: [TLH_PTFBPro] "C:\Program Files\Technology Lighthouse\PTFB Pro\PTFBStart.exe"O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [AVG7_Run] C:\PROGRA~1\Grisoft\AVG7\avgw.exe /RUNONCE (User 'Default user')O4 - Startup: Xfire.lnk = C:\Program Files\Xfire\xfire.exeO8 - Extra context menu item: &Search - http://edits.mywebsearch.com/toolbaredits/menusearch.jhtml?p=ZRfox000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\PROGRA~1\Java\JRE16~3.0_0\bin\ssv.dllO13 - Gopher Prefix: O16 - DPF: {39B0684F-D7BF-4743-B050-FDC3F48F7E3B} (CDownloadCtrl Object) - http://www.fileplanet.com/fpdlmgr/cabs/FPDC_2.3.6.108.cabO16 - DPF: {69EF49E5-FE46-4B92-B5FA-2193AB7A6B8A} (GameLauncher Control) - http://www.acclaim.com/cabs/acclaim_v4.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{7BAE0FFC-1A1D-4F69-996D-B304DA10084C}: NameServer = 204.60.203.179,206.141.193.55O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - Winlogon Notify: avgwlntf - C:\Windows\SYSTEM32\avgwlntf.dllO22 - SharedTaskScheduler: Stardock Vista ControlPanel Extension - {EC654325-1273-C2A9-2B7C-45D29BCE68FD} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DesktopControlPanel.dllO22 - SharedTaskScheduler: StardockDreamController - {EC654325-1273-C2A9-2B7C-45D29BCE68FF} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\DreamControl.dllO22 - SharedTaskScheduler: Deskscapes - {EC654325-1273-C2A9-2B7C-45D29BCE68FB} - C:\PROGRA~1\Stardock\OBJECT~1\DESKSC~1\deskscapes.dllO23 - Service: ABBYY FineReader 9.0 Licensing Service (ABBYY.Licensing.FineReader.Professional.9.0) - ABBYY (BIT Software) - C:\Program Files\ABBYY FineReader 9.0\NetworkLicenseServer.exeO23 - Service: Apache2.2 - Apache Software Foundation - C:\Program Files\Apache Software Foundation\Apache2.2\bin\httpd.exeO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG7 Resident Shield Service (AvgCoreSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgrssvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: DynDNS Updater - Dynamic Network Services, Inc. - C:\Program Files\DynDNS Updater\DynUpSvc.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: iReboot Background Service (iReboot) - Unknown owner - C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exeO23 - Service: My Web Search Service (MyWebSearchService) - MyWebSearch.com - C:\PROGRA~1\MYWEBS~1\bar\1.bin\mwssvc.exeO23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: SoundMovieServer - SoundMovieServer - C:\Windows\system32\snmvtsvc.exeO23 - Service: TeamViewer 3 (TeamViewer) - TeamViewer GmbH - C:\Program Files\TeamViewer3\TeamViewer_Host.exeO23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\Windows\System32\ZoneLabs\vsmon.exeO23 - Service: Stardock WindowBlinds (WindowBlinds) - Stardock Corporation - C:\Program Files\Stardock\Object Desktop\WindowBlinds\vistasrv.exe--End of file - 8117 bytes Link to comment Share on other sites More sharing options...
DreadWingKnight Posted July 31, 2008 Report Share Posted July 31, 2008 Stardock is known to cause problems.Trillian's event handler shouldn't really be injecting itself into the uT process.Those are my first two thoughts for culprits. Link to comment Share on other sites More sharing options...
aggixx Posted July 31, 2008 Author Report Share Posted July 31, 2008 Lol, I agree with that second part.I dont really use stardock so Ill uninstall that. Link to comment Share on other sites More sharing options...
thelittlefire Posted July 31, 2008 Report Share Posted July 31, 2008 hmm, well you see there stardock dreamscene DLL and trillian DLL injected (into utorrent.exe) ... could you see if the problem persists with those programs closed before opening uT?Also... TrueVector.. that's Zone Alarm, isn't it? Please don't use Zone Alarm :/ It doesn't play well at all with networking-intensive applications.After that... you'd need to get a .DMP file or check the call stack (with process explorer) while uT is frozen, see what else is in there. I'm thinking it's ZA, since it does scanning on packets, but I don't know what would cause an occasional spike unless you do some sort of once in a while operation like Advanced -> bt.scrape_stopped or have many RSS feeds which update at a set interval. Can you correlate the spikes to any actions from within uT like tracker scrapes, or anything I mentioned above? Link to comment Share on other sites More sharing options...
aggixx Posted July 31, 2008 Author Report Share Posted July 31, 2008 Actually, I had ZA at one point, but it annoyed me so I disabled. I never bothered to uninstall it, but I did now.Edit: Every application that access the internet just stopped working (except firefox apparently). Link to comment Share on other sites More sharing options...
thelittlefire Posted July 31, 2008 Report Share Posted July 31, 2008 ...you uninstalled mywebsearch didn't you? Either repair the "fixed" HJT entries, or reinstall it? Then uninstall it from the Control Panel Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.