Jump to content

Add,delete and resume problems with utorrent 1.8


Mentaray

Recommended Posts

Whenever I exit utorrent nothing that I did during that session is saved. Upon restarting utorrent nothing that I added, deleted or downloaded shows up in the list. It basically goes back to it's previous state listing only those older torrents. This has only started since I 'upgraded' to utorrent 1.8.

I'm using XP Professional. When trying to change permissions of my %APPDATA%\uTorrent folder it doesn't allow me to apply this change to all of the subfolders/ files because 'Access is denied' to all of the DAT files (dht, resume, and settings).

If I apply the changes to only the 'utorrent' folder the resume.DAT file shows that it's NOT read only but upon rebooting everything returns to 'read only'.

Link to comment
Share on other sites

a) get HijackThis from trendsecure.com, run it, view the log, and post the contents here

B) get Process Explorer from sysinternals.com, run it, Ctrl+D (to show the lower DLL pane), select the µTorrent process from the list, Ctrl+S (and save the list somewhere you'll find easily -- like the Desktop), then post the contents of the saved process list in the .txt file here

If you're using a software firewall, does it include some functionality to block applications from performing certain actions on the computer (not just internet-related activity)?

Link to comment
Share on other sites

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 1:40:31 PM, on 9/1/2008

Platform: Windows XP SP2 (WinNT 5.01.2600)

MSIE: Internet Explorer v7.00 (7.00.6000.16640)

Boot mode: Normal

Running processes:

C:\WINDOWS\System32\smss.exe

C:\WINDOWS\system32\csrss.exe

C:\WINDOWS\system32\winlogon.exe

C:\WINDOWS\system32\services.exe

C:\WINDOWS\system32\lsass.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\System32\svchost.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\Sygate\SPF\smc.exe

C:\WINDOWS\system32\svchost.exe

C:\WINDOWS\system32\spoolsv.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

C:\Program Files\Comodo\CBOClean\BOCORE.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

C:\WINDOWS\System32\SnoopFreeSvc.exe

C:\WINDOWS\system32\svchost.exe

C:\Program Files\ThreatFire\TFService.exe

C:\WINDOWS\System32\alg.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

C:\WINDOWS\system32\Ati2evxx.exe

C:\WINDOWS\Explorer.EXE

C:\WINDOWS\system32\wscntfy.exe

C:\WINDOWS\AGRSMMSG.exe

C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe

C:\WINDOWS\SnoopFreeUI.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\Microsoft IntelliPoint\point32.exe

C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe

C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe

C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe

C:\PROGRA~1\Comodo\CBOClean\BOC426.exe

C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe

C:\Program Files\ThreatFire\TFTray.exe

C:\Program Files\R-Wipe&Clean\rwiped.exe

C:\Program Files\Microsoft ActiveSync\wcescomm.exe

C:\PROGRA~1\MI3AA1~1\rapimgr.exe

C:\Program Files\APC\APC PowerChute Personal Edition\apcsystray.exe

C:\Program Files\ATI Technologies\ATI.ACE\cli.exe

C:\Program Files\Opera\Opera.exe

C:\Documents and Settings\sssssss\Desktop\utorrent.exe

C:\Program Files\Trend Micro\HijackThis\HijackThis.exe

C:\WINDOWS\system32\wbem\wmiprvse.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.cnn.com/

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Window Title = Microsoft Internet Explorer provided by Comcast

O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O4 - HKLM\..\Run: [AGRSMMSG] AGRSMMSG.exe

O4 - HKLM\..\Run: [smcService] C:\PROGRA~1\Sygate\SPF\smc.exe -startgui

O4 - HKLM\..\Run: [WinPatrol] C:\PROGRA~1\BILLPS~1\WINPAT~1\winpatrol.exe

O4 - HKLM\..\Run: [snoopFreeUI] SnoopFreeUI.exe

O4 - HKLM\..\Run: [ATICCC] "C:\Program Files\ATI Technologies\ATI.ACE\cli.exe" runtime -Delay

O4 - HKLM\..\Run: [intelliPoint] "C:\Program Files\Microsoft IntelliPoint\point32.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.5.0_10\bin\jusched.exe"

O4 - HKLM\..\Run: [KernelFaultCheck] %systemroot%\system32\dumprep 0 -k

O4 - HKLM\..\Run: [sSBkgdUpdate] "C:\Program Files\Common Files\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot

O4 - HKLM\..\Run: [OpwareSE4] "C:\Program Files\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"

O4 - HKLM\..\Run: [sansaDispatch] C:\Program Files\SanDisk\Sansa Updater\SansaDispatch.exe

O4 - HKLM\..\Run: [bOC-426] C:\PROGRA~1\Comodo\CBOClean\BOC426.exe

O4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitservice

O4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exe

O4 - HKCU\..\Run: [RWipeD] C:\Program Files\R-Wipe&Clean\rwiped.exe

O4 - HKCU\..\Run: [H/PC Connection Agent] "C:\Program Files\Microsoft ActiveSync\wcescomm.exe"

O4 - HKUS\S-1-5-18\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [Picasa Media Detector] C:\Program Files\Picasa2\PicasaMediaDetector.exe (User 'Default user')

O4 - Global Startup: APC UPS Status.lnk = ?

O4 - Global Startup: Microsoft Office.lnk = C:\Program Files\Microsoft Office\Office\OSA9.EXE

O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.5.0_10\bin\ssv.dll

O9 - Extra button: Create Mobile Favorite - {2EAF5BB1-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra 'Tools' menuitem: Create Mobile Favorite... - {2EAF5BB2-070F-11D3-9307-00C04FAE2D4F} - C:\PROGRA~1\MI3AA1~1\INetRepl.dll

O9 - Extra button: (no name) - SolidConverterPDF - (no file) (HKCU)

O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab

O16 - DPF: {406B5949-7190-4245-91A9-30A17DE16AD0} (Snapfish Activia) - http://photo.walgreens.com/WalgreensActivia.cab

O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w2/pr02/resources/MSNPUpld.cab

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1194720225968

O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1194720206953

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {FFB3A759-98B1-446F-BDA9-909C6EB18CC7} (PCPitstop Exam) - http://utilities.pcpitstop.com/Optimize2/pcpitstop2.dll

O20 - AppInit_DLLs: C:\WINDOWS\system32\wmfhotfix.dll

O23 - Service: APC UPS Service - American Power Conversion Corporation - C:\Program Files\APC\APC PowerChute Personal Edition\mainserv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: ATI Smart - Unknown owner - C:\WINDOWS\system32\ati2sgag.exe

O23 - Service: BOCore - COMODO - C:\Program Files\Comodo\CBOClean\BOCORE.exe

O23 - Service: Eset HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exe

O23 - Service: Eset Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exe

O23 - Service: FLEXnet Licensing Service - Unknown owner - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe (file missing)

O23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: Sygate Personal Firewall (SmcService) - Sygate Technologies, Inc. - C:\Program Files\Sygate\SPF\smc.exe

O23 - Service: Snoop Free Service (SnoopFreeSvc) - Unknown owner - C:\WINDOWS\System32\SnoopFreeSvc.exe

O23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exe

--

End of file - 7775 bytes

PROCESS EXPLORER

Process PID CPU Description Company Name

System Idle Process 0 87.69

Interrupts n/a Hardware Interrupts

DPCs n/a Deferred Procedure Calls

System 4

smss.exe 584 Windows NT Session Manager Microsoft Corporation

csrss.exe 656 Client Server Runtime Process Microsoft Corporation

winlogon.exe 684 Windows NT Logon Application Microsoft Corporation

services.exe 728 Services and Controller app Microsoft Corporation

ati2evxx.exe 896 ATI External Event Utility EXE Module ATI Technologies Inc.

svchost.exe 908 Generic Host Process for Win32 Services Microsoft Corporation

wmiprvse.exe 1192 WMI Microsoft Corporation

rapimgr.exe 2668 ActiveSync RAPI Manager Microsoft Corporation

svchost.exe 988 Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1080 Generic Host Process for Win32 Services Microsoft Corporation

wscntfy.exe 1944 Windows Security Center Notification App Microsoft Corporation

svchost.exe 1120 Generic Host Process for Win32 Services Microsoft Corporation

Smc.exe 1276 Sygate Agent Firewall Sygate Technologies, Inc.

svchost.exe 1316 Generic Host Process for Win32 Services Microsoft Corporation

spoolsv.exe 1568 Spooler SubSystem App Microsoft Corporation

svchost.exe 1684 Generic Host Process for Win32 Services Microsoft Corporation

mainserv.exe 1716 Battery backup management service American Power Conversion Corporation

BOCore.exe 1764 COMODO BOClean - Anti-Malware COMODO

ekrn.exe 1788 Eset Service ESET

SnoopFreeSvc.exe 1864

svchost.exe 1912 Generic Host Process for Win32 Services Microsoft Corporation

TFService.exe 1984 PC Tools ThreatFire Service PC Tools

alg.exe 600 Application Layer Gateway Service Microsoft Corporation

lsass.exe 740 LSA Shell (Export Version) Microsoft Corporation

ati2evxx.exe 976 ATI External Event Utility EXE Module ATI Technologies Inc.

explorer.exe 1888 1.54 Windows Explorer Microsoft Corporation

AGRSMMSG.exe 2092 SoftModem Messaging Applet Agere Systems

WinPatrol.exe 2116 4.62 WinPatrol System Monitor BillP Studios

SnoopFreeUI.exe 2128 SnoopFree Privacy Shield (User Interface) SnoopFree Software

CLI.exe 2156 CLI Application (Command Line Interface) ATI Technologies Inc.

CLI.exe 2344 CLI Application (Command Line Interface) ATI Technologies Inc.

point32.exe 2180 Point32.exe Microsoft Corporation

jusched.exe 2196 Java 2 Platform Standard Edition binary Sun Microsystems, Inc.

OpWareSE4.exe 2236 OCR Aware ScanSoft, Inc.

SansaDispatch.exe 2248 Sansa Dispatcher SanDisk Corporation

BOC426.EXE 2288 COMODO BOClean - Anti-Malware COMODO

egui.exe 2300 1.54 Eset GUI ESET

TFTray.exe 2328 PC Tools ThreatFire Tray App PC Tools

rwiped.exe 2368

wcescomm.exe 2388 ActiveSync Connection Manager Microsoft Corporation

opera.exe 3116 Opera Internet Browser Opera Software

utorrent.exe 2176 µTorrent BitTorrent, Inc.

procexp.exe 4016 4.62 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

apcsystray.exe 3476 PowerChute system tray power icon American Power Conversion Corporation

Process: utorrent.exe Pid: 2176

Name Description Company Name Version

ACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.2180

adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.2180

ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180

ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000

COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982

comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.2180

ctype.nls

DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.3316

GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3316

hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.2180

IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180

Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2912

kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.3119

locale.nls

MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180

msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180

mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.2180

NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2976

ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180

ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726

OLEAUT32.dll Microsoft Corporation 5.01.2600.3266

OpHookSE4.dll OCR Aware Hook (32-bit) ScanSoft, Inc. 15.00.0000.0000

PATROLPRO.DLL WinPatrol Helper DLL BillP Studios 1.02.0000.0000

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938

RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173

rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180

SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180

Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180

SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.2180

SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.3241

shfolder.dll Shell Folder Service Microsoft Corporation 6.00.2900.2180

SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.3086

SnoopFreeDll.dll

sortkey.nls

sorttbls.nls

SSSensor.dll ScreenSaver Sensor Sygate Technologies, Inc. 5.05.0000.0005

TFWAH.dll PC Tools ThreatFire PC Tools 3.08.0004.0024

unicode.nls

USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.3099

utorrent.exe µTorrent BitTorrent, Inc. 1.08.0000.11813

uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180

WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180

wmfhotfix.dll

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180

WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180

wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180

As far as the software firewall question: I'm using Sygate 5.8. I believe it only affects applications and their activities.

Link to comment
Share on other sites

Scansoft, SnoopFree, Sygate, and ThreatFire all injected into uTorrent. Do any of those muck with programs' settings or "profiles" to "remember where you were" or somesuch...

Common instructions include "temporarily uninstall software, try to reproduce problem... when problem goes away verify problem reoccurs with program last uninstalled" :/

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...