Citsme Posted August 6, 2008 Report Share Posted August 6, 2008 Note: Ran Malwarebyte's Anti-Malware and do not have any of the programs or firewalls listed in the Computer Crash Discussion.I noticed when I first began using uTorrent, that I had a pop up triangle in the system tray stating that there was a disk error and to run a disk check. The disk check failed and after going back and forth, I was able to get that straightened out and ran a successful disk check, Anti-Malware Program, Anti-Spyware Program a Cleaner program and then I defragged the disk after deleting unused and unwanted programs.Should have been in good shape.Yesterday afternoon, while using uTorrent (and reading the user's manual) I got the Blue Screen of Death with the message: DRIVER_IRQL_NOT_LESS_OR_EQUAL. I restarted the computer and all seemed well.Last night, I opened uTorrent and cleared out a couple of completed torrents and added two new ones to download. Same blue screen appeared. Assistance is greatly appreciated. Can follow directions but still not close to mastering this topic!Thanks to all.Citsme Link to comment Share on other sites More sharing options...
DreadWingKnight Posted August 6, 2008 Report Share Posted August 6, 2008 is a .sys file mentioned in the bluescreen?Post a hijackthis log and process explorer process list with dll list for the uTorrent.exe process please. Link to comment Share on other sites More sharing options...
Citsme Posted August 6, 2008 Author Report Share Posted August 6, 2008 Nothing except the message I included. I do have hijackthis installed but have not had to use it yet. That *shouldn't* be a problem. However, "process explorer process list with dll list for the uTorrent.exe process," is new to me. Please give detailed instructions. I know it's hard working with the newbies but we are the ones that need you most!Thanks! Link to comment Share on other sites More sharing options...
DreadWingKnight Posted August 6, 2008 Report Share Posted August 6, 2008 http://forum.utorrent.com/viewtopic.php?id=29748we need both logs Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 Logfile of HijackThis v1.99.1Scan saved at 8:06:18 PM, on 8/6/2008Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16674)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\Windows Defender\MsMpEng.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware\aawservice.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\ehome\ehtray.exeC:\WINDOWS\system32\hkcmd.exeC:\WINDOWS\system32\igfxpers.exeC:\WINDOWS\System32\DLA\DLACTRLW.EXEC:\Program Files\Java\jre1.6.0_07\bin\jusched.exeC:\Program Files\ScreenPrint32 v3\ScreenPrint32.exeC:\Program Files\Microsoft IntelliType Pro\itype.exeC:\Program Files\HP\HP Software Update\HPWuSchd2.exeC:\Program Files\SiteAdvisor\6261\SiteAdv.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\McAfee.com\Agent\mcagent.exeC:\Program Files\Windows Defender\MSASCui.exeC:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exeC:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exeC:\WINDOWS\SM1BG.EXEC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exeC:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Program Files\Common Files\Ahead\Lib\NMBgMonitor.exeC:\Program Files\Google\Google Updater\GoogleUpdater.exeC:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeC:\PROGRA~1\Webshots\webshots.scrC:\WINDOWS\system32\spoolsv.exeC:\Program Files\HP\Digital Imaging\bin\hpqimzone.exeC:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WINDOWS\eHome\ehSched.exeC:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeC:\PROGRA~1\McAfee\MSC\mcmscsvc.exeC:\Program Files\HP\Digital Imaging\bin\hpqSTE08.exec:\program files\common files\mcafee\mna\mcnasvc.exec:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exeC:\Program Files\Common Files\Microsoft Shared\VS7DEBUG\MDM.EXEC:\Program Files\McAfee\MPF\MPFSrv.exeC:\WINDOWS\system32\HPZipm12.exeC:\Program Files\SiteAdvisor\6261\SAService.exeC:\WINDOWS\system32\svchost.exec:\WINDOWS\system32\ZuneBusEnum.exeC:\WINDOWS\system32\fxssvc.exeC:\Program Files\Canon\CAL\CALMAIN.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeC:\WINDOWS\eHome\ehmsas.exeC:\WINDOWS\system32\dllhost.exeC:\Program Files\Common Files\Ahead\Lib\NMIndexStoreSvr.exeC:\WINDOWS\system32\wuauclt.exeC:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exeC:\Program Files\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.nytimes.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Bar = http://red.clientapps.yahoo.com/customize/ie/defaults/sb/sbcydsl/*http://www.yahoo.com/search/ie.htmlR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157O2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll (file missing)O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dllO2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Program Files\Real\RealPlayer\rpbrowserrecordplugin.dllO2 - BHO: DriveLetterAccess - {5CA3D70E-1895-11CF-8E15-001234567890} - C:\WINDOWS\System32\DLA\DLASHX_W.DLLO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - C:\Program Files\McAfee\VirusScan\scriptsn.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\3.0.1225.9868\swg.dllO3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dllO3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dllO4 - HKLM\..\Run: [ehTray] C:\WINDOWS\ehome\ehtray.exeO4 - HKLM\..\Run: [igfxtray] C:\WINDOWS\system32\igfxtray.exeO4 - HKLM\..\Run: [igfxhkcmd] C:\WINDOWS\system32\hkcmd.exeO4 - HKLM\..\Run: [igfxpers] C:\WINDOWS\system32\igfxpers.exeO4 - HKLM\..\Run: [iSUSPM Startup] "c:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -startupO4 - HKLM\..\Run: [iSUSScheduler] "C:\Program Files\Common Files\InstallShield\UpdateService\issch.exe" -startO4 - HKLM\..\Run: [DLA] C:\WINDOWS\System32\DLA\DLACTRLW.EXEO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"O4 - HKLM\..\Run: [screenPrint32] C:\Program Files\ScreenPrint32 v3\ScreenPrint32.exe -startupO4 - HKLM\..\Run: [EPSON Stylus Photo 820 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_S0EIC1.EXE /P29 "EPSON Stylus Photo 820 Series" /O6 "USB001" /M "Stylus Photo 820"O4 - HKLM\..\Run: [itype] "C:\Program Files\Microsoft IntelliType Pro\itype.exe"O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\HP\HP Software Update\HPWuSchd2.exeO4 - HKLM\..\Run: [siteAdvisor] "C:\Program Files\SiteAdvisor\6261\SiteAdv.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [mcagent_exe] C:\Program Files\McAfee.com\Agent\mcagent.exe /runkeyO4 - HKLM\..\Run: [Windows Defender] "C:\Program Files\Windows Defender\MSASCui.exe" -hideO4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Ahead\Lib\NeroCheck.exeO4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero 7\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [RoxioDragToDisc] "C:\Program Files\Roxio\Easy Media Creator 7\Drag to Disc\DrgToDsc.exe"O4 - HKLM\..\Run: [sM1BG] C:\WINDOWS\SM1BG.EXEO4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -kO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [iSUSPM] "C:\Program Files\Common Files\InstallShield\UpdateService\isuspm.exe" -schedulerO4 - HKCU\..\Run: [swg] C:\Program Files\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeO4 - Startup: Webshots.lnk = C:\Program Files\Webshots\Launcher.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: Google Updater.lnk = C:\Program Files\Google\Google Updater\GoogleUpdater.exeO4 - Global Startup: HP Digital Imaging Monitor.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqtra08.exeO4 - Global Startup: HP Image Zone Fast Start.lnk = C:\Program Files\HP\Digital Imaging\bin\hpqthb08.exeO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLLO9 - Extra button: Real.com - {CD67F990-D8E9-11d2-98FE-00C0F0318AFE} - C:\WINDOWS\system32\Shdocvw.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO11 - Options group: [iNTERNATIONAL] International*O15 - Trusted Zone: http://*.mcafee.comO16 - DPF: {01113300-3E00-11D2-8470-0060089874ED} (Support.com Configuration Class) - http://supportcenter.rr.com/sdccommon/download/tgctlcm.cabO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?LinkID=39204O16 - DPF: {4ED9DDF0-7479-4BBE-9335-5A1EDB1D8A21} (McAfee.com Operating System Class) - http://download.mcafee.com/molbin/shared/mcinsctl/4,0,0,101/mcinsctl.cabO16 - DPF: {9600F64D-755F-11D4-A47F-0001023E6D5A} (Shutterfly Picture Upload Plugin) - http://web1.shutterfly.com/downloads/Uploader.cabO16 - DPF: {D2349304-8F9E-4A54-ACF6-0F6104B44209} (SketchCtl.Pic1) - http://auditor.cuyahogacounty.us/repi/sketch/Sketch.ocxO16 - DPF: {EF791A6B-FC12-4C68-99EF-FB9E207A39E6} (McFreeScan Class) - http://download.mcafee.com/molbin/iss-loc/mcfscan/2,2,0,5297/mcfscan.cabO16 - DPF: {FFFFFFFF-CACE-BABE-BABE-00AA0055595A} - http://www.trueswitch.com/sbc/TrueInstallSBC.exeO18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Program Files\SiteAdvisor\6261\SiteAdv.dllO20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.dllO20 - Winlogon Notify: dimsntfy - %SystemRoot%\System32\dimsntfy.dll (file missing)O20 - Winlogon Notify: igfxcui - C:\WINDOWS\SYSTEM32\igfxdev.dllO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dllO23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exeO23 - Service: Adobe Active File Monitor V5 (AdobeActiveFileMonitor5.0) - Unknown owner - C:\Program Files\Adobe\Photoshop Elements 5.0\PhotoshopElementsFileAgent.exeO23 - Service: Canon Camera Access Library 8 (CCALib8) - Canon Inc. - C:\Program Files\Canon\CAL\CALMAIN.exeO23 - Service: DSBrokerService - Unknown owner - C:\Program Files\DellSupport\brkrsvc.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: McAfee Services (mcmscsvc) - McAfee, Inc. - C:\PROGRA~1\McAfee\MSC\mcmscsvc.exeO23 - Service: McAfee Network Agent (McNASvc) - McAfee, Inc. - c:\program files\common files\mcafee\mna\mcnasvc.exeO23 - Service: McAfee Scanner (McODS) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcods.exeO23 - Service: McAfee Proxy Service (McProxy) - McAfee, Inc. - c:\PROGRA~1\COMMON~1\mcafee\mcproxy\mcproxy.exeO23 - Service: McAfee Real-time Scanner (McShield) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcshield.exeO23 - Service: McAfee SystemGuards (McSysmon) - McAfee, Inc. - C:\PROGRA~1\McAfee\VIRUSS~1\mcsysmon.exeO23 - Service: McAfee Personal Firewall Service (MpfService) - McAfee, Inc. - C:\Program Files\McAfee\MPF\MPFSrv.exeO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: Intel NCS NetService (NetSvc) - Intel® Corporation - C:\Program Files\Intel\PROSetWired\NCS\Sync\NetSvc.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: Pml Driver HPZ12 - HP - C:\WINDOWS\system32\HPZipm12.exeO23 - Service: ServiceLayer - Nokia. - C:\Program Files\PC Connectivity Solution\ServiceLayer.exeO23 - Service: SiteAdvisor Service - Unknown owner - C:\Program Files\SiteAdvisor\6261\SAService.exeThen there are two copies of the next program log. I'll post Procexp.txt first and then uTorrent.exe.txt Process PID CPU Description Company NameSystem Idle Process 0 97.73 Interrupts n/a Hardware Interrupts DPCs n/a 0.76 Deferred Procedure Calls System 4 smss.exe 616 Windows NT Session Manager Microsoft Corporation csrss.exe 664 Client Server Runtime Process Microsoft Corporation winlogon.exe 688 Windows NT Logon Application Microsoft Corporation services.exe 732 0.76 Services and Controller app Microsoft Corporation svchost.exe 976 Generic Host Process for Win32 Services Microsoft Corporation ehmsas.exe 2792 Media Center Media Status Aggregator Service Microsoft Corporation NMIndexStoreSvr.exe 396 Nero Home Nero AG svchost.exe 1052 Generic Host Process for Win32 Services Microsoft Corporation MsMpEng.exe 1148 Service Executable Microsoft Corporation svchost.exe 1188 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1256 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1384 Generic Host Process for Win32 Services Microsoft Corporation aawservice.exe 1532 Ad-Aware Service Lavasoft spoolsv.exe 652 Spooler SubSystem App Microsoft Corporation PhotoshopElementsFileAgent.exe 1348 ehrecvr.exe 1248 Media Center Receiver Service Microsoft Corporation ehSched.exe 1448 Media Center Scheduler Service Microsoft Corporation GoogleUpdaterService.exe 1540 gusvc Google mcmscsvc.exe 876 McAfee Services McAfee, Inc. McNASvc.exe 2276 McAfee Network Agent McAfee, Inc. McProxy.exe 2368 McAfee Proxy Service Module McAfee, Inc. Mcshield.exe 2440 On-Access Scanner service McAfee, Inc. MDM.EXE 2516 Machine Debug Manager Microsoft Corporation MpfSrv.exe 2556 McAfee Personal Firewall Service McAfee, Inc. HPZipm12.exe 2652 PML Driver HP SAService.exe 2808 SiteAdvisor McAfee, Inc. svchost.exe 2904 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 2996 Generic Host Process for Win32 Services Microsoft Corporation ZuneBusEnum.exe 3188 Zune Bus Enumerator Service Microsoft Corporation fxssvc.exe 3324 Fax Service Microsoft Corporation mcrdsvc.exe 3364 MCRD Device Service Microsoft Corporation CALMAIN.exe 3616 Canon Camera Access Library 8 Canon Inc. NMIndexingService.exe 224 Nero Home Nero AG dllhost.exe 3244 COM Surrogate Microsoft Corporation alg.exe 3860 Application Layer Gateway Service Microsoft Corporation mcsysmon.exe 3704 McAfee SystemGuards Service McAfee, Inc. lsass.exe 744 LSA Shell (Export Version) Microsoft Corporationexplorer.exe 1692 Windows Explorer Microsoft Corporation ehtray.exe 1800 Media Center Tray Applet Microsoft Corporation hkcmd.exe 1816 hkcmd Module Intel Corporation igfxpers.exe 1824 persistence Module Intel Corporation DLACTRLW.EXE 1868 Drive Letter Access Component Sonic Solutions jusched.exe 1884 Java Platform SE binary Sun Microsystems, Inc. ScreenPrint32.exe 1892 Main Executable Provtech Limited itype.exe 1916 IType.exe Microsoft Corporation hpwuSchd2.exe 1928 hpwuSchd Application Hewlett-Packard SiteAdv.exe 1948 SiteAdvisor McAfee, Inc. realsched.exe 1956 RealNetworks Scheduler RealNetworks, Inc. mcagent.exe 1964 McAfee Integrated Security Platform McAfee, Inc. MSASCui.exe 1972 Windows Defender User Interface Microsoft Corporation NBKeyScan.exe 1988 Nero BackItUp Nero AG DrgToDsc.exe 2000 Drag To Disc Application Sonic Solutions SM1bg.exe 2008 Cypress USB Mass Storage Driver Background Application Cypress Semiconductor ctfmon.exe 2036 CTF Loader Microsoft Corporation ISUSPM.exe 128 Macrovision Software Manager Macrovision Corporation GoogleToolbarNotifier.exe 188 GoogleToolbarNotifier Google Inc. NMBgMonitor.exe 204 Nero Home Nero AG GoogleUpdater.exe 232 Google Updater Google hpqtra08.exe 252 HP Digital Imaging Monitor Hewlett-Packard Co. hpqste08.exe 2228 HP CUE Status Hewlett-Packard Co. iexplore.exe 2788 Internet Explorer Microsoft Corporation procexp.exe 2360 0.76 Sysinternals Process Explorer Sysinternals - www.sysinternals.comWebshots.scr 404 Webshots Photo Manager Webshots.comhpqimzone.exe 1212 Hewlett-Packard Co.uTorrent.exe.txtProcess PID CPU Description Company NameSystem Idle Process 0 68.18 Interrupts n/a 0.75 Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 2.27 smss.exe 616 Windows NT Session Manager Microsoft Corporation csrss.exe 664 Client Server Runtime Process Microsoft Corporation winlogon.exe 688 Windows NT Logon Application Microsoft Corporation services.exe 732 1.52 Services and Controller app Microsoft Corporation svchost.exe 976 Generic Host Process for Win32 Services Microsoft Corporation ehmsas.exe 2792 Media Center Media Status Aggregator Service Microsoft Corporation NMIndexStoreSvr.exe 396 Nero Home Nero AG svchost.exe 1052 Generic Host Process for Win32 Services Microsoft Corporation MsMpEng.exe 1148 Service Executable Microsoft Corporation svchost.exe 1188 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1256 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1384 Generic Host Process for Win32 Services Microsoft Corporation aawservice.exe 1532 Ad-Aware Service Lavasoft spoolsv.exe 652 Spooler SubSystem App Microsoft Corporation PhotoshopElementsFileAgent.exe 1348 ehrecvr.exe 1248 Media Center Receiver Service Microsoft Corporation ehSched.exe 1448 Media Center Scheduler Service Microsoft Corporation GoogleUpdaterService.exe 1540 gusvc Google mcmscsvc.exe 876 McAfee Services McAfee, Inc. McNASvc.exe 2276 McAfee Network Agent McAfee, Inc. McProxy.exe 2368 McAfee Proxy Service Module McAfee, Inc. Mcshield.exe 2440 0.76 On-Access Scanner service McAfee, Inc. MDM.EXE 2516 Machine Debug Manager Microsoft Corporation MpfSrv.exe 2556 McAfee Personal Firewall Service McAfee, Inc. HPZipm12.exe 2652 PML Driver HP SAService.exe 2808 SiteAdvisor McAfee, Inc. svchost.exe 2904 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 2996 Generic Host Process for Win32 Services Microsoft Corporation ZuneBusEnum.exe 3188 Zune Bus Enumerator Service Microsoft Corporation fxssvc.exe 3324 Fax Service Microsoft Corporation mcrdsvc.exe 3364 MCRD Device Service Microsoft Corporation CALMAIN.exe 3616 Canon Camera Access Library 8 Canon Inc. NMIndexingService.exe 224 Nero Home Nero AG dllhost.exe 3244 COM Surrogate Microsoft Corporation alg.exe 3860 Application Layer Gateway Service Microsoft Corporation mcsysmon.exe 3704 McAfee SystemGuards Service McAfee, Inc. lsass.exe 744 LSA Shell (Export Version) Microsoft Corporationexplorer.exe 1692 Windows Explorer Microsoft Corporation ehtray.exe 1800 Media Center Tray Applet Microsoft Corporation hkcmd.exe 1816 hkcmd Module Intel Corporation igfxpers.exe 1824 persistence Module Intel Corporation DLACTRLW.EXE 1868 Drive Letter Access Component Sonic Solutions jusched.exe 1884 Java Platform SE binary Sun Microsystems, Inc. ScreenPrint32.exe 1892 Main Executable Provtech Limited itype.exe 1916 IType.exe Microsoft Corporation hpwuSchd2.exe 1928 hpwuSchd Application Hewlett-Packard SiteAdv.exe 1948 SiteAdvisor McAfee, Inc. realsched.exe 1956 RealNetworks Scheduler RealNetworks, Inc. mcagent.exe 1964 McAfee Integrated Security Platform McAfee, Inc. MSASCui.exe 1972 Windows Defender User Interface Microsoft Corporation NBKeyScan.exe 1988 Nero BackItUp Nero AG DrgToDsc.exe 2000 Drag To Disc Application Sonic Solutions SM1bg.exe 2008 Cypress USB Mass Storage Driver Background Application Cypress Semiconductor ctfmon.exe 2036 CTF Loader Microsoft Corporation ISUSPM.exe 128 Macrovision Software Manager Macrovision Corporation GoogleToolbarNotifier.exe 188 GoogleToolbarNotifier Google Inc. NMBgMonitor.exe 204 Nero Home Nero AG GoogleUpdater.exe 232 Google Updater Google hpqtra08.exe 252 HP Digital Imaging Monitor Hewlett-Packard Co. hpqste08.exe 2228 HP CUE Status Hewlett-Packard Co. iexplore.exe 2788 Internet Explorer Microsoft Corporation uTorrent.exe 2108 22.73 procexp.exe 2548 1.52 Sysinternals Process Explorer Sysinternals - www.sysinternals.comWebshots.scr 404 Webshots Photo Manager Webshots.comhpqimzone.exe 1212 Hewlett-Packard Co.Process: uTorrent.exe Pid: 2108Name Description Company Name VersionACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.5512adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.5512ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.5512ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0001CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0700COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.5512comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.5512COMRes.dll Microsoft Corporation 2001.12.4414.0700ctype.nls DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.5625GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.5512hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.5512IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.5512Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.5512kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.5512locale.nls MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.5512MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.01.2600.5512msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.5512msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.5512mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.5625NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.5512ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.5512ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.5512oleaut32.dll Microsoft Corporation 5.01.2600.5512rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.5512RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.5512rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.5512saHook.dll SiteAdvisor McAfee, Inc. 2.06.0000.6261SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.5512Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.5512SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.5512SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.5512SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.5512sortkey.nls sorttbls.nls unicode.nls USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.5512uTorrent.exe uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.5512VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.5512winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.5512WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.5512WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.5512WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.5512wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.5512 Link to comment Share on other sites More sharing options...
Switeck Posted August 7, 2008 Report Share Posted August 7, 2008 I didn't look very hard, so there's bound to be other issues I missed...but...File indexers and uTorrent seriously don't get along:O23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 I really appreciate your help; I can't imagine how you decipher all of that information. What do you suggest I do to resolve the conflict? Would it be asking too much for you to review the logs when you have more time in case there is something else? I want to avoid the Blue Screen at all costs but this is something I know nothing about and really need your assistance.I appreciate what you've done so far. Thanks so much.CitsmeEdit: My internet connection is EXTREMELY SLOW - sometimes pages won't load at all when uTorrent is running. I am trying to understand the proper settings - one problem at a time!UPDATE: "RECOVERY FROM SERIOUS ERROR" MESSAGE - Problem with a device driver. No new hardware installed. Installed lots of software to go along with uTorrent and file conversion and burning, etc.Nero Indexing Service keeps track of media files on the disk and is not needed. Was checking the start up folder (msconfig) and unchecked a couple of programs not needed at startup. Restarted computer and moments later got the latest error message. The other suggestion was to do a regedit but I'm not up for that at the moment!Advice? A way to disable it permanently?Thanks. Link to comment Share on other sites More sharing options...
Switeck Posted August 7, 2008 Report Share Posted August 7, 2008 Simple trick I do is look at everything NOT Microsoft. That eliminates over 50% of everything listed.What's your internet connection speeds down AND up?What settings are you trying to use in uTorrent, as shown by Speed Guide (CTRL+G)?(just what "xx/###k" upload speed setting you chose is good enough.)There's gotta be something in Nero you can check to disable or remove its indexer.HijackThis! can remove entries on the same list that shows them. Check them, then click "Fix checked" at bottom. Fix checked = delete entry from registry/startup list...but does NOT delete files from your hard drive as far as I know. This is generally the last resort, as various programs can and often do reinstall their auto-loading-on-bootup stuff every time they get run. It's best to use the program's disable features than trying to force it with HijackThis! Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 Disable automatic rebooting for BSODs and write down the entire message. Make sure that Windows is configured to make a minidump as well. Then install the debugging tools for Windows and open the minidump in windbg and see what it thinks is the faulty device driver.http://www.microsoft.com/whdc/DevTools/Debugging/default.mspx Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 Hello and thank you both for your help. Switeck, I have tested my internet connection speeds through Speakeasy (3 times) and the speeds are consistantly in the same range which is: DL 5739 Kbps and UL 492 Kbps. This is close to what I got when I set up uTorrent using dslreports included with the program. I set the connection type to 512k which was the closest number. Upload limit is 47 Kb/s and encryption is enabled.I searched the Nero website and didn't come up with any way to disable that (feature?) Google didn't help either. Firon, I would love to follow your instructions but as you might have guessed, they are over my head. Seriously. Would you be kind enough to supply more detail? In the meantime, I will google the disable automatic rebooting for BSODs to see if I can figure out how to do that.Thank you both for your time AND PATIENCE! Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 Well, just start with the settings in the control panel. System -> ADvanced -> Startup and Recovery.Set write debugging info to small dump and disable automatically restart. Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 Hi Firon,I was able to google the Disable Automatic Booting process and followed the instructions to find that it was already disabled and it was already set for a minidump. The entire message on that BSOD was what I originally reported:DRIVER_IRQL_NOT_LESS_OR_EQUALTwo programs have been mentioned as possible culprits (both recently installed BTW) Roxio Easy Media Creator and Nero 7 Premium.I have downloaded and installed the debugging tools and the only thing I haven't figured out yet is how to open the minidump in windbg. I haven't found where the minidump is located to open it. Would you please explain?***BTW: I do have the reports the system generates when there is an error. Many thanks.***Using the SEARCH function, I found a file minidump in the Windows file on the C: drive. Safe to assume this is what I need? Using the search function - what a thought! I am giving myself a headache now. Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 Just uh, RAR/ZIP the latest dump file created in %SystemRoot%\Minidump (that's where they're saved to by default) and upload it to mediafire.com. I'll examine it for you.And yes, you paste that path name exactly as it is into explorer, % and all. Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 I appreciate the offer - now if I can figure out how to do that!Actually for a extreme novice in the art of debugging and most of the processes that go on here, I haven't done too bad, so far at least!My first error in the debugging process was that I didn't have the proper symbols. Research time. Ok. Found out what to do and somehow figured out how to do it. The result: (Can't cut and paste or figure out how to save output!)Symbol search path is: SRV*c:\Web Symbols*http://msdl.microsoft.com/download/symbolsLoading Kernel SymbolsLoading User SymbolsUnable to load image Sacm2A.sys Win 32 error 0n2***WARNING: Unable to verify timestamp for Sacm2A.sys***ERROR: Module load completed but symbols could not be loaded for Sacm2A.sysHOW DO I FIX THIS PROBLEM WITH Scam2A.sys?In another area of this output:DRIVER_IRQL_NOT_LESS_OR_EQUAL (d1)An attempt was made to access a pageable (or completely invalid) address at an interrupt request level (IRQL) that is too high. This is usually caused by drivers using improper addresses.If kernel debugger is available get stack backtrace.Arguments:Arg1:00000006, memory referencedArg2:00000002, IRQLArg3:00000000, value 0 = read operation 1 = write operationArg4:f72cb508, address which referenced memoryPLEASE TELL ME HOW TO SAVE THE OUTPUT TO A FILE I CAN COPY, CUT AND PASTE. I really don't know if the information I am giving you is anything you need!!!Over my head and sinking fast . . . but laughing on the way down!Edit: The only minidump file I could find is:C:\Windows\Minidump\Mini080608.01.dmp 88kbIs this the one I need or is there another one and step by step how do I get there?Sorry. If I knew all of this, I wouldn't need to be here! I really appreciate the help.Thanks. Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 Select all the text (Ctrl+A), then copy it with Ctrl+C. Paste it onto codepad.org. Link to comment Share on other sites More sharing options...
DreadWingKnight Posted August 7, 2008 Report Share Posted August 7, 2008 Just based on the file, I'd say you have a USB modem and it's being overloaded. Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 Firon - for me, the easiest things are the hardest! The Ctrl+A and Ctrl+C and codepad.org are lifesavers!Hope it works.http://codepad.org/w7GKRdf6DWK - I am currently using a cable modem; I was previously connected by a dsl modem.Edit:Don't know if this information applies - In Device Manager, I have two Network Adapters and the first one has a red X over it which I understand means it is disabled.That is the: Intel ® Pro/100 VE Network ConnectionThe other is: Scientific-Atlanta WebSTAR 2000 Series Cable ModemThanks everyone - definitely time for a short break! Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 Yup, DWKnight is correct. Sacm2A.sys is the culprit. You can't use USB for internet. it's very unreliable. Switch to ethernet, or buy an internal PCI wireless card. Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 So my broadband connection set up by the cable company is not sufficient? I've never had a problem with the internet connection before unless of course the company was down!The modem is listed as:Conexant D850 56K V.9X ModemOk, I know I am losing my mind but I ***thought*** I was already connected with an ethernet cable. Like a phone cord but thicker? How do I verify if I have ethernet ability and it is set up correctly?Sorry, guys. Cherie Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 You're connecting to your cable modem using USB. You cannot use USB. Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 My apologies to all - I hear a big GROAN coming and possibly a few choice words. I do the more than the basic fixes for friends and family that some people don't know how to do - I've actually replaced every physical item in my ex's computer except the motherboard so I'm not brain dead, exactly! I was working on a friend's laptop and the connection was weak so I connected it to my modem using my ethernet cable. I got rid of the cockroach infestation, added anti-virus and malware programs, an anti-spyware program, updated the operating system and defragged.Worked on it a couple of days and gave it back. Apparently, I did not reconnect my ethernet cable and didn't notice because my computer was still working as usual. Duh.I've plugged it back in and now I need your help making sure its set up and functioning correctly and getting rid of that USB connection that I was not aware of. The computer is connected to a phone/fax machine and two printers as an FYI. I used to have it set up so that the phone rang through the computer (very helpful when the music is way up) but I don't remember how I did that - it was accidental. I attempted to rerun the debugging tool but I am assuming that the minidump file needs to be updated to get a clear picture and I do not know how to do that.Would you be kind enough to help me get this back in order? I promise to print out this thread and file it in a notebook of help I have received so that if I screw up again, I'll have a reference.You are all great! Let the groaning begin! Link to comment Share on other sites More sharing options...
Firon Posted August 7, 2008 Report Share Posted August 7, 2008 The Conexant is not your modem. The Scientific Atlanta, which should be some box sitting near your computer hooked up to the cable is the modem. Link to comment Share on other sites More sharing options...
Citsme Posted August 7, 2008 Author Report Share Posted August 7, 2008 I'm sorry - that is the information I found in Device Manager under modems. Will you be able to continue helping me get this set up correctly ie. get rid of the USB connection?I know I have frustrated all of you (and myself, too.) I just want to get back to using uTorrent and continuing the fun I was having. I do apologize for all the confusion. I do know which one the modem is I just wanted to let you know what was listed under Device Manager - Modems. Cherie*** When I am running utorrent, my regular internet connection is extremely slow - if it works at all. I printed the utorrent set up directions and followed them exactly. I'm not sure what else to do.Thanks.### As you already realized, you were 100% right. I was connected to the internet unknowingly by USB and Ethernet until I fixed my friends computer and forgot to replug the Ethernet cable. I called the cable company and told them the story and that the network adapter had a red X and they said to call the manufacturer and have it replaced! I decided to make sure it was enabled - it wasn't - I enabled it and rebooted the modem and the computer and am running solely on the Ethernet connection. Thank you for all of your assistance. It is very much appreciated.I did kill the Nero Indexing Service also so that shouldn't interfere. Now I will start uTorrent back up and see how it goes. Again, thank you. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.