lasse12345 Posted August 26, 2008 Report Share Posted August 26, 2008 Since I upgraded to utorrent 1.8 I had lot's of problems with portforwarding.Is that a know issue?I also tried 1.8.1 beta build 11903 but still see the same problem.UPDATE: Just tried 1.7.7 and _still_ see the same problem! (must be a configuration issue on my PC)I get a yellow triangle telling me that the inbound connections is not open.I selected another port to try something and it was working fine for a while.I am using Windows Vista SP1.I ran hijackthisLogfile of HijackThis v1.99.1Scan saved at 6:55:38 AM, on 8/27/2008Platform: Unknown Windows (WinNT 6.00.1905 SP1)MSIE: Internet Explorer v7.00 (7.00.6001.18000)Running processes:D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeD:\Windows\system32\taskeng.exeD:\Windows\system32\Dwm.exeD:\Windows\Explorer.EXED:\Program Files\Windows Defender\MSASCui.exeD:\Program Files\McAfee\VirusScan Enterprise\shstat.exeD:\Program Files\McAfee\Common Framework\UdaterUI.exeD:\Java\jre1.6.0_06\bin\jusched.exeG:\Program Files\TortoiseSVN\bin\TSVNCache.exeC:\Program Files\itunes\iTunesHelper.exeD:\Windows\System32\CtHelper.exeD:\Windows\System32\rundll32.exeD:\Windows\System32\rundll32.exeD:\Program Files\Windows Media Player\wmpnscfg.exeD:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exeD:\Program Files\McAfee\Common Framework\McTray.exeD:\Program Files\Logitech\QuickCam\Quickcam.exeG:\Program Files\Skype\Phone\Skype.exeD:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exeD:\Program Files\Password Safe\pwsafe.exeG:\Program Files\Yahoo!\Widgets\YahooWidgets.exeD:\Program Files\Internet Explorer\ieuser.exeG:\Program Files\Skype\Plugin Manager\skypePM.exeD:\Program Files\Common Files\Logishrd\LQCVFX\COCIManager.exeD:\Windows\system32\conime.exeD:\Program Files\Microsoft Office\Office12\EXCEL.EXED:\Program Files\Windows NT\Accessories\WORDPAD.EXEG:\Program Files\Yahoo!\Widgets\YahooWidgets.exeD:\Program Files\Wolfram Research\Mathematica\6.0\SystemFiles\FrontEnd\Binaries\Windows\Mathematica.exeD:\Program Files\Wolfram Research\Mathematica\6.0\MathKernel.exeD:\Program Files\Wolfram Research\Mathematica\6.0\SystemFiles\Java\Windows\bin\javaw.exeD:\Windows\explorer.exeD:\Windows\system32\taskmgr.exeD:\Program Files\VMware\VMware Workstation\vmware-tray.exeD:\Program Files\Internet Explorer\iexplore.exeD:\Program Files\Mozilla Firefox\firefox.exeD:\Program Files\Adobe\Reader 8.0\Reader\AcroRd32.exeD:\Program Files\Internet Explorer\iexplore.exeD:\Program Files\Windows Media Player\wmplayer.exeD:\Program Files\uTorrent\uTorrent.exeD:\Windows\system32\Macromed\Flash\FlashUtil9e.exeD:\Users\las\Downloads\hijackthis_sfx.exeC:\Program Files\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.yahoo.comR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.yahoo.comR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - D:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - G:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO2 - BHO: Google Update Helper - {25D596E9-BD03-4D4A-8310-5DF3B31E8D26} - D:\Program Files\Google\Update\1.2.121.17\GoopdateBho.dllO2 - BHO: Flashget Catch Url Class - {2F364306-AA45-47B5-9F9D-39A8B94E7EF7} - D:\PROGRA~1\FlashGet\jccatch.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - D:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - D:\Program Files\Java\jre1.6.0_07\bin\ssv.dllO2 - BHO: scriptproxy - {7DB2D5A0-7241-4E79-B68D-6309F01C5231} - D:\Program Files\McAfee\VirusScan Enterprise\Scriptcl.dllO2 - BHO: Google Gears Helper - {E0FEFE40-FBF9-42AE-BA58-794CA7E3FB53} - D:\Program Files\Google\Google Gears\Internet Explorer\0.4.15.0\gears.dllO2 - BHO: gFlash Class - {F156768E-81EF-470C-9057-481BA8380DBA} - D:\Program Files\FlashGet\getflash.dllO3 - Toolbar: FlashGet - {E0E899AB-F487-11D5-8D29-0050BA6940E3} - D:\Program Files\FlashGet\fgiebar.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [shStatEXE] "D:\Program Files\McAfee\VirusScan Enterprise\SHSTAT.EXE" /STANDALONEO4 - HKLM\..\Run: [McAfeeUpdaterUI] "D:\Program Files\McAfee\Common Framework\UdaterUI.exe" /StartedFromRunKeyO4 - HKLM\..\Run: [sunJavaUpdateSched] "D:\Program Files\Java\jre1.6.0_07\bin\jusched.exe"O4 - HKLM\..\Run: [QGetIEMenuExt] g:\Program Files\QNAP\QGet\QGetIEMenuExt.exe /standardO4 - HKLM\..\Run: [MSConfig] "D:\Windows\system32\Msconfig.exe" /autoO4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [QuickTime Task] "G:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\itunes\iTunesHelper.exe"O4 - HKLM\..\Run: [CTHelper] CTHELPER.EXEO4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXEO4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE D:\Windows\system32\nvsvc.dll,nvsvcStartO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\Windows\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\Windows\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [LogitechCommunicationsManager] "D:\Program Files\Common Files\LogiShrd\LComMgr\Communications_Helper.exe"O4 - HKLM\..\Run: [LogitechQuickCamRibbon] "D:\Program Files\Logitech\QuickCam\Quickcam.exe" /hideO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "D:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [incrediBuild Agent Monitor] D:\Program Files\Xoreax\IncrediBuild\BuildTrayIcon.exeO4 - HKLM\..\Run: [vmware-tray] "D:\Program Files\VMware\VMware Workstation\vmware-tray.exe"O4 - HKLM\..\Run: [VMware hqtray] "D:\Program Files\VMware\VMware Workstation\hqtray.exe"O4 - HKCU\..\Run: [skype] "G:\Program Files\Skype\Phone\Skype.exe" /nosplash /minimizedO4 - HKCU\..\Run: [indxStoreSvr_{79662E04-7C6C-4d9f-84C7-88D8A56B10AA}] "D:\Program Files\Common Files\Nero\Lib\NMIndexStoreSvr.exe" ASO-616B5711-6DAE-4795-A05F-39A1E5104020O4 - Startup: Password Safe.lnk = D:\Program Files\Password Safe\pwsafe.exeO4 - Startup: Yahoo! Widgets.lnk = G:\Program Files\Yahoo!\Widgets\YahooWidgets.exeO8 - Extra context menu item: &Download All with FlashGet - D:\Program Files\FlashGet\jc_all.htmO8 - Extra context menu item: &Download with FlashGet - D:\Program Files\FlashGet\jc_link.htmO8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - D:\PROGRA~1\Java\JRE16~4.0_0\bin\ssv.dllO9 - Extra button: (no name) - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.4.15.0\gears.dllO9 - Extra 'Tools' menuitem: &Gears Settings - {09C04DA7-5B76-4EBC-BBEE-B25EAC5965F5} - D:\Program Files\Google\Google Gears\Internet Explorer\0.4.15.0\gears.dllO9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: S&end to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - D:\PROGRA~1\MICROS~2\Office12\ONBttnIE.dllO9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - G:\Program Files\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLLO9 - Extra button: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exeO9 - Extra 'Tools' menuitem: FlashGet - {D6E814A0-E0C5-11d4-8D29-0050BA6940E3} - D:\PROGRA~1\FlashGet\flashget.exeO10 - Unknown file in Winsock LSP: d:\windows\system32\nlaapi.dllO10 - Unknown file in Winsock LSP: d:\windows\system32\napinsp.dllO10 - Unknown file in Winsock LSP: d:\program files\bonjour\mdnsnsp.dllO11 - Options group: [iNTERNATIONAL] International*O13 - Gopher Prefix: O16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - D:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {B015B944-7316-49AE-AC84-ACCA9379EA32} (IPCamPlugIn Control) - http://85.80.219.91/IPCamPluginMJPEG.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - D:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dllO18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - D:\Program Files\Common Files\Microsoft Shared\Help\hxds.dllO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - D:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - D:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLLO23 - Service: Apple Mobile Device - Apple, Inc. - D:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: B's Recorder GOLD Library General Service (bgsvcgen) - B.H.A Corporation - D:\Windows\system32\bgsvcgen.exeO23 - Service: Bonjour Service - Apple Inc. - D:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: Google Update Service (gupdate1c8d07ca8a9a041) (gupdate1c8d07ca8a9a041) - Unknown owner - D:\Program Files\Google\Update\GoogleUpdate.exe" /svc (file missing)O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - D:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: IncrediBuild Agent (IncrediBuild_Agent) - Xoreax Software Ltd. - D:\Program Files\Xoreax\IncrediBuild\BuildService.exeO23 - Service: IncrediBuild Coordinator (IncrediBuild_Coordinator) - Xoreax Software Ltd. - D:\Program Files\Xoreax\IncrediBuild\CoordService.exeO23 - Service: iPod Service - Apple Inc. - D:\Program Files\iPod\bin\iPodService.exeO23 - Service: LVCOMSer - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVCOMSER\LVComSer.exeO23 - Service: Process Monitor (LVPrcSrv) - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\LVMVFM\LVPrcSrv.exeO23 - Service: LVSrvLauncher - Logitech Inc. - D:\Program Files\Common Files\LogiShrd\SrvLnch\SrvLnch.exeO23 - Service: MokaFive Authorization Service (m5authd) - moka5, Inc. - D:\Program Files\moka5\Engine\bin\m5authd.exeO23 - Service: McAfee Framework Service (McAfeeFramework) - Unknown owner - D:\Program Files\McAfee\Common Framework\FrameworkService.exe" /ServiceStart (file missing)O23 - Service: McAfee McShield (McShield) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\Mcshield.exeO23 - Service: McAfee Task Manager (McTaskManager) - McAfee, Inc. - D:\Program Files\McAfee\VirusScan Enterprise\VsTskMgr.exeO23 - Service: SQL Server (SQLEXPRESS) (MSSQL$SQLEXPRESS) - Unknown owner - d:\Program Files\Microsoft SQL Server\MSSQL.1\MSSQL\Binn\sqlservr.exe" -sSQLEXPRESS (file missing)O23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - D:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - D:\Windows\system32\IoctlSvc.exeO23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)O23 - Service: VMware Agent Service (ufad-ws60) - Unknown owner - D:\Program Files\VMware\VMware Workstation\vmware-ufad.exe" -d "D:\Program Files\VMware\VMware Workstation\\" -s ufad-p2v.xml (file missing)O23 - Service: VMware Authorization Service (VMAuthdService) - VMware, Inc. - D:\Program Files\VMware\VMware Workstation\vmware-authd.exeO23 - Service: VMware DHCP Service (VMnetDHCP) - VMware, Inc. - D:\Windows\system32\vmnetdhcp.exeO23 - Service: VMware Virtual Mount Manager Extended (vmount2) - VMware, Inc. - D:\Program Files\Common Files\VMware\VMware Virtual Image Editing\vmount2.exeO23 - Service: VMware NAT Service - VMware, Inc. - D:\Windows\system32\vmnat.exeO23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)lasse Link to comment Share on other sites More sharing options...
Firon Posted August 27, 2008 Report Share Posted August 27, 2008 Try uninstalling McAfee. Link to comment Share on other sites More sharing options...
lasse12345 Posted August 27, 2008 Author Report Share Posted August 27, 2008 Thanks I tried that and found out my router was pointing to the wrong local IP address!Installed visusscan and it still works..THANKSlasse Link to comment Share on other sites More sharing options...
Switeck Posted August 27, 2008 Report Share Posted August 27, 2008 These may cause problems later on:O10 - Unknown file in Winsock LSP: d:\windows\system32\nlaapi.dllO10 - Unknown file in Winsock LSP: d:\windows\system32\napinsp.dllO10 - Unknown file in Winsock LSP: d:\program files\bonjour\mdnsnsp.dllAnything buried that deep on a system tends to cause a mess when it's uninstalled.And the 1st and 2nd ones may be viruses/trojans for all I know atm. Link to comment Share on other sites More sharing options...
Firon Posted August 28, 2008 Report Share Posted August 28, 2008 those 2 files are Vista DLLs, and the last is bonjour, which causes no harm. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.