Jump to content

uTorrent 1.8/1.8.1 Beta Freeze on Windows Vista SP1


teohhanhui

Recommended Posts

Just for a bit of context...

a) get HijackThis from trendsecure.com, run it, view the log, and post the contents here

B) get Process Explorer from sysinternals.com, run it, Ctrl+D (to show the lower DLL pane), select the µTorrent process from the list, Ctrl+S (and save the list somewhere you'll find easily -- like the Desktop), then post the contents of the saved process list in the .txt file here

Link to comment
Share on other sites

Well, I don't see anything suspicious, but here is the HJT log:

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 11:07:13 PM, on 8/23/2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe
C:\Windows\vVX3000.exe
C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe
C:\Program Files\ClamWin\bin\ClamTray.exe
C:\Program Files\Windows Sidebar\sidebar.exe
C:\Program Files\Windows Live\Messenger\msnmsgr.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Windows Live\Contacts\wlcomm.exe
C:\Program Files\Mozilla Firefox\firefox.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Users\Narumi Ayumu\Desktop\hjt\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: IEVkbdBHO - {59273AB4-E7D3-40F9-A1A8-6FA9CCA1862C} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\ievkbd.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe"
O4 - HKLM\..\Run: [LifeCam] "C:\Program Files\Microsoft LifeCam\LifeExp.exe"
O4 - HKLM\..\Run: [VX3000] C:\Windows\vVX3000.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"
O4 - HKLM\..\Run: [ClamWin] "C:\Program Files\ClamWin\bin\ClamTray.exe" --logon
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /background
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_07\bin\ssv.dll
O9 - Extra button: Web traffic protection statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\SCIEPlgn.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O13 - Gopher Prefix:
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd.dll,C:\PROGRA~1\KASPER~1\KASPER~1\mzvkbd3.dll
O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll
O23 - Service: Ati External Event Utility - ATI Technologies Inc. - C:\Windows\system32\Ati2evxx.exe
O23 - Service: Kaspersky Anti-Virus (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 2009\avp.exe

--
End of file - 5173 bytes

And here is the Process Explorer DLL list for utorrent.exe:

Process    PID    CPU    Description    Company Name
System Idle Process 0 91.68
Interrupts n/a Hardware Interrupts
DPCs n/a Deferred Procedure Calls
System 4 1.53
smss.exe 460 Windows Session Manager Microsoft Corporation
csrss.exe 536 Client Server Runtime Process Microsoft Corporation
csrss.exe 596 0.76 Client Server Runtime Process Microsoft Corporation
wininit.exe 604 Windows Start-Up Application Microsoft Corporation
services.exe 640 Services and Controller app Microsoft Corporation
svchost.exe 868 Host Process for Windows Services Microsoft Corporation
wlcomm.exe 4072 Windows Live Messenger Contacts Server Microsoft Corp.
WmiPrvSE.exe 3592 WMI Provider Host Microsoft Corporation
svchost.exe 928 Host Process for Windows Services Microsoft Corporation
svchost.exe 964 Host Process for Windows Services Microsoft Corporation
Ati2evxx.exe 1056 ATI External Event Utility EXE Module ATI Technologies Inc.
Ati2evxx.exe 1492 ATI External Event Utility EXE Module ATI Technologies Inc.
svchost.exe 1096 Host Process for Windows Services Microsoft Corporation
audiodg.exe 1252 Windows Audio Device Graph Isolation Microsoft Corporation
svchost.exe 1160 Host Process for Windows Services Microsoft Corporation
dwm.exe 2860 1.53 Desktop Window Manager Microsoft Corporation
svchost.exe 1180 Host Process for Windows Services Microsoft Corporation
taskeng.exe 2192 Task Scheduler Engine Microsoft Corporation
taskeng.exe 2908 Task Scheduler Engine Microsoft Corporation
taskeng.exe 4516 Task Scheduler Engine Microsoft Corporation
mcupdate.exe 5204 6.12 Windows Media Center Store Update Manager Microsoft Corporation
SLsvc.exe 1300 Microsoft Software Licensing Service Microsoft Corporation
svchost.exe 1364 Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1676 Spooler SubSystem App Microsoft Corporation
svchost.exe 1708 Host Process for Windows Services Microsoft Corporation
avp.exe 296 Kaspersky Anti-Virus Kaspersky Lab
svchost.exe 344 Host Process for Windows Services Microsoft Corporation
MSCamS32.exe 480 MsCamSvc.exe Microsoft Corporation
svchost.exe 512 Host Process for Windows Services Microsoft Corporation
svchost.exe 540 Host Process for Windows Services Microsoft Corporation
svchost.exe 1288 Host Process for Windows Services Microsoft Corporation
SearchIndexer.exe 1512 Microsoft Windows Search Indexer Microsoft Corporation
SearchProtocolHost.exe 1064 Microsoft Windows Search Protocol Host Microsoft Corporation
SearchFilterHost.exe 5120 Microsoft Windows Search Filter Host Microsoft Corporation
wmpnetwk.exe 3396 Windows Media Player Network Sharing Service Microsoft Corporation
usnsvc.exe 2652 Messenger Sharing USN Journal Reader Service Microsoft Corporation
lsass.exe 656 Local Security Authority Process Microsoft Corporation
lsm.exe 664 Local Session Manager Service Microsoft Corporation
winlogon.exe 784 Windows Logon Application Microsoft Corporation
explorer.exe 2900 Windows Explorer Microsoft Corporation
MSASCui.exe 3188 Windows Defender User Interface Microsoft Corporation
avp.exe 3196 Kaspersky Anti-Virus Kaspersky Lab
vVX3000.exe 3220 Microsoft LifeCam Device Application Microsoft Corporation
jusched.exe 3232 Java(TM) Platform SE binary Sun Microsystems, Inc.
ClamTray.exe 3240 ClamWin Antivirus alch
sidebar.exe 3264 Windows Sidebar Microsoft Corporation
msnmsgr.exe 3272 0.77 Windows Live Messenger Microsoft Corporation
wmpnscfg.exe 3296 Windows Media Player Network Sharing Service Configuration Application Microsoft Corporation
firefox.exe 1360 3.06 Firefox Mozilla Corporation
utorrent.exe 2668 µTorrent BitTorrent, Inc.
procexp.exe 4100 8.42 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

Process: utorrent.exe Pid: 2668

Name Description Company Name Version
ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6001.18000
ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000
CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000
COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6001.18000
comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6001.18000
dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6001.18000
dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6001.18000
DnsApi.dll DNS Client API DLL Microsoft Corporation 6.00.6001.18000
GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6001.18023
GPAPI.dll Group Policy Client API Microsoft Corporation 6.00.6001.18000
hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.00.6001.18000
iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6001.18000
IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6001.18000
Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6001.18000
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000
locale.nls
locale.nls
LPK.DLL Language Pack Microsoft Corporation 6.00.6001.18000
MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6001.18000
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6001.18000
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6001.18000
msxml3.dll MSXML 3.0 SP10 Microsoft Corporation 8.100.1043.0000
msxml3r.dll XML Resources Microsoft Corporation 8.20.8730.0001
mzvkbd.dll Mozilla 2 Virtual Keyboard Kaspersky Lab 8.00.0000.0454
mzvkbd3.dll Mozilla 3 Virtual Keyboard Kaspersky Lab 8.00.0000.0454
napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.00.6001.18000
netshell.dll Network Connections Shell Microsoft Corporation 6.00.6001.18000
NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6001.18000
npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.00.6000.16386
NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6001.18000
ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000
ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6001.18000
oleaut32.dll Microsoft Corporation 6.00.6001.18000
pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.00.6001.18000
PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.00.6000.16386
RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6001.18051
rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.00.6001.18000
Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6001.18000
SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6001.18062
shfolder.dll Shell Folder Service Microsoft Corporation 6.00.6000.16386
SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6001.18000
slc.dll Software Licensing Client Dll Microsoft Corporation 6.00.6001.18000
SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.00.6000.16386
SXS.DLL Fusion 2.5 Microsoft Corporation 6.00.6001.18000
upnp.dll UPnP Control Point API Microsoft Corporation 6.00.6001.18000
urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.00.6001.18099
USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6001.18000
USERENV.dll Userenv Microsoft Corporation 6.00.6001.18000
USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000
utorrent.exe µTorrent BitTorrent, Inc. 1.08.0001.11903
uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6001.18000
WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.00.6001.18000
WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6001.18000
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386
WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.00.6001.18000
WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6001.18000
wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.00.6001.18000
wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6001.18000

Link to comment
Share on other sites

I have this exact same problem after I departed from XP x64 to Vista Ultimate x64 SP1.

At some point during checking of a file the checking stops and the program continues running for a while, until it stops responding. At that point, there's no way to log off or reboot the system without a hard shutdown (8 sec powerbutton)

Logs pasted below:

HJT

Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 20:33:55, on 24-8-2008
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
E:\Fraps\fraps.exe
C:\Windows\mdm.exe
E:\DAEMON Tools Lite\daemon.exe
C:\Program Files (x86)\Areca Technology Corp\Http Proxy Server Service\ArcHttpSrvGUI.exe
E:\Buzof\Buzof.exe
E:\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe
C:\Windows\SysWOW64\CTXFIHLP.EXE
E:\Trillian\trillian.exe
E:\DU Meter\DUMeter.exe
c:\temp\Creative_Audio_Engine_Cleanup.0001
C:\Windows\SysWOW64\CTXFISPI.EXE
E:\Xfire\xfire.exe
E:\mIRC\mirc.exe
E:\mIRC\UPP\mirc_upp.exe
E:\Utorrent\utorrent.exe
e:\Winamp\winampa.exe
E:\Winamp\winamp.exe
E:\Mozilla Firefox\firefox.exe
E:\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O1 - Hosts: ::1 localhost
O4 - HKLM\..\Run: [StartCCC] "E:\ATI\ATI.ACE\Core-Static\CLIStart.exe" MSRun
O4 - HKLM\..\Run: [VolPanel] "e:\Auzen X-Fi Prelude 7.1\Volume Panel\VolPanlu.exe" /r
O4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXE
O4 - HKLM\..\Run: [UpdReg] C:\Windows\UpdReg.EXE
O4 - HKLM\..\Run: [DU Meter] E:\DU Meter\DUMeter.exe
O4 - HKLM\..\Run: [WinampAgent] e:\Winamp\winampa.exe
O4 - HKCU\..\Run: [mdm] C:\Windows\mdm.exe
O4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\DAEMON Tools Lite\daemon.exe" -autorun
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')
O4 - Startup: ArcHttpSrvGUI.lnk = C:\Program Files (x86)\Areca Technology Corp\Http Proxy Server Service\ArcHttpSrvGUI.exe
O4 - Startup: Buzof.lnk = E:\Buzof\Buzof.exe
O4 - Startup: Trillian.lnk = E:\Trillian\trillian.exe
O4 - Startup: Xfire.lnk = E:\Xfire\xfire.exe
O4 - Global Startup: Fraps.lnk = E:\Fraps\fraps.exe
O13 - Gopher Prefix:
O16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cab
O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab
O16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15105/CTPID.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{D63356FE-D3AC-429B-9275-8490A1D57A71}: NameServer = 10.10.10.1
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Areca HTTP Proxy Server (ArcHttpProxyServer) - Unknown owner - C:\Program Files (x86)\Areca Technology Corp\Http Proxy Server Service\ArcHttpSrv.exe
O23 - Service: Ati External Event Utility - Unknown owner - C:\Windows\system32\Ati2evxx.exe (file missing)
O23 - Service: Creative ALchemy AL1 Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\AL1Licensing.exe
O23 - Service: Creative Audio Engine Licensing Service - Creative Labs - C:\Program Files (x86)\Common Files\Creative Labs Shared\Service\CTAELicensing.exe
O23 - Service: Creative Audio Service (CTAudSvcService) - Creative Technology Ltd - C:\Program Files (x86)\Creative\Shared Files\CTAudSvc.exe
O23 - Service: @dfsrres.dll,-101 (DFSR) - Unknown owner - C:\Windows\system32\DFSR.exe (file missing)
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - c:\Program Files (x86)\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 6637 bytes

PE

Process    PID    CPU    Description    Company Name
System Idle Process 0 96.07
csrss.exe 540 Client Server Runtime Process Microsoft Corporation
wininit.exe 600 Windows Start-Up Application Microsoft Corporation
csrss.exe 620 Client Server Runtime Process Microsoft Corporation
winlogon.exe 1160 Windows Logon Application Microsoft Corporation
explorer.exe 1244 0.36 Windows Explorer Microsoft Corporation
mdm.exe 716
daemon.exe 2020 DAEMON Tools Lite DT Soft Ltd
ArcHttpSrvGUI.exe 2068
Buzof.exe 2096 Annoying windows eliminator Basta Computing
trillian.exe 2128 Trillian Cerulean Studios
xfire.exe 2272 Xfire Xfire Inc.
mirc.exe 720 mIRC mIRC Co. Ltd.
mirc_upp.exe 2352 mIRC mIRC Co. Ltd.
utorrent.exe 608 µTorrent BitTorrent, Inc.
winamp.exe 2044 Winamp Nullsoft
firefox.exe 2084 Firefox Mozilla Corporation
explorer.exe 1136 Windows Explorer Microsoft Corporation
procexp.exe 1124 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
procexp64.exe 3548 2.51 Sysinternals Process Explorer Sysinternals - www.sysinternals.com
MOM.exe 2088 Catalyst Control Center: Monitoring program Advanced Micro Devices Inc.
CCC.exe 2380 Catalyst Control Centre: Host application ATI Technologies Inc.
VolPanlu.exe 2104 VolPanlu.exe Creative Technology Ltd
Creative_Audio_Engine_Cleanup.0001 2184 Cleanup Macrovision Europe Ltd.
CTXFIHLP.EXE 2116 CTXfiHlp MFC Application Creative Technology Ltd
DUMeter.exe 2160 DU Meter Hagel Technologies
winampa.exe 3404
notepad.exe 3192 Notepad Microsoft Corporation

Process: utorrent.exe Pid: 608

Name Description Company Name Version
ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6001.18000
C_936.NLS
CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000
COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6001.18000
comctl32.dll.mui User Experience Controls Library Microsoft Corporation 6.10.6001.18000
comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6001.18000
dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6001.18000
dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6001.18000
DNSAPI.dll DNS Client API DLL Microsoft Corporation 6.00.6001.18000
DUser.dll Windows DirectUser Engine Microsoft Corporation 6.00.6001.18000
duser.dll.mui Windows DirectUser Engine Microsoft Corporation 6.00.6000.16386
events.dll Trillian Event Control Cerulean Studios 3.01.0009.0000
FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.00.6001.18000
FRAPS.DLL Fraps Beepa P/L 2.09.0004.7037
GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6001.18023
IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6001.18000
Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6001.18000
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000
kernel32.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000
locale.nls
locale.nls
LPK.DLL Language Pack Microsoft Corporation 6.00.6001.18000
MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6001.18000
msctf.dll.mui MSCTF Server DLL Microsoft Corporation 6.00.6000.16386
MSIMG32.dll GDIEXT Client DLL Microsoft Corporation 6.00.6000.16386
MSVCR71.dll Microsoft® C Runtime Library Microsoft Corporation 7.10.3052.0004
msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6001.18000
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6001.18000
napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.00.6001.18000
NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6001.18000
npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.00.6000.16386
NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6001.18000
ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000
ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000
ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6001.18000
OLEACC.dll Active Accessibility Core Component Microsoft Corporation 4.02.5406.0000
oleaccrc.dll Active Accessibility Resource DLL Microsoft Corporation 4.02.5406.0000
OLEAUT32.dll Microsoft Corporation 6.00.6001.18000
pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.00.6001.18000
PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.00.6000.16386
RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6001.18051
rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.00.6001.18000
Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6001.18000
SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6001.18062
shfolder.dll Shell Folder Service Microsoft Corporation 6.00.6000.16386
SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6001.18000
USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6001.18000
USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000
utorrent.exe µTorrent BitTorrent, Inc. 1.08.0000.11813
UxTheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6001.18000
VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.00.6001.18000
WINMM.dll MCI API DLL Microsoft Corporation 6.00.6001.18000
WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6001.18000
winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386
WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.00.6001.18000
wow64.dll Win32 Emulation on NT64 Microsoft Corporation 6.00.6001.18000
wow64cpu.dll AMD64 Wow64 CPU Microsoft Corporation 6.00.6001.18000
wow64win.dll Wow64 Console and Win32 API Logging Microsoft Corporation 6.00.6001.18000
WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6001.18000
wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.00.6001.18000
wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6001.18000
WSOCK32.dll Windows Socket 32-Bit DLL Microsoft Corporation 6.00.6001.18000
xfire_toucan_33659.dll Xfire Toucan DLL Xfire Inc. 0.00.0000.0000

Link to comment
Share on other sites

At first glance I don't see anything fishy that you guys have in common.

@Haiya-Dragon:

You could try turning off Trillian, Xfire and fraps to exclude them as possible trouble causers.

Does it happen with all torrents or just one torrent?

@teohhanhui:

In the other thread you seemed to think it was caused by a certain torrent? If so, why did you think that? Did the freeze only occur with that torrent?

Link to comment
Share on other sites

I noticed after a few tries that the problem always occurred with one torrent file. After I removed it (.torrent + data) and redownloaded the .torrent file, the problem was gone.

Not per se a 'fixed' issue, but it works like it should now.

I think the problem has to be found in the sparse allocating, which was on before I changed to Vista. On Vista it's off for some reason, probably the default for that specific option.

Link to comment
Share on other sites

Yes, it only occurred with a particular torrent file. I don't think it has anything to do with sparse files (I always use pre-allocation).

Re-adding torrent file, even generating a new settings.dat didn't help. I fixed the problem by moving the downloaded file to another partition and back. Weird, huh? :P

Link to comment
Share on other sites

The save path was "H:\Torrents\" where H: had more than 190GB free space.

I saw svchost.exe reading the download file at very high rate and Windows unable to shut down even without running uTorrent. That was what led me to think the file is the cause of all these. My download progress was more before this happened. It seems like corruption occurred near the first pieces of the file.

Link to comment
Share on other sites

I have the exact same problem, on a different thread. To the teeth it is the same problem. while its checking a specific torrents files, the machine slows down, until it stops responding. Manual restart is required. Same thing happened using Vuze (formally AZ) Would someone else try that same torrent they were having problems with on a different client? Test purposes only.

Link to comment
Share on other sites

  • 5 months later...

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...