Kyoujin Posted September 15, 2008 Report Posted September 15, 2008 Recently, uTorrent has begun to crash on me...frequently. Usually within a minute or two after launching the program and seemingly at first, without rhyme or reason. This afternoon, however, I noticed a pattern. Firefox3 was running each time uTorrent crashed during the past 24 hours. So I tested my findings and found them to be true. uTorrent crashes when Firefox3 is running.I am not sure if this is a result of a recent Firefox update as I have not had Firefox all that long. No more than a week I don't think... (I had been using Opera but I needed the security of the Firefox plug-ins, no-script and flashblock, given the current issues with iFrames and Flash.) I can't say for certain one way or the other if uTorrent worked with Firefox3 at first. I simply do not remember.Below the problem signature I have linked a .rar containing three crash dumps.Problem signature: Problem Event Name: APPCRASH Application Name: uTorrent.exe Application Version: 1.8.0.11813 Application Timestamp: 48a2610d Fault Module Name: hnetcfg.dll_unloaded Fault Module Version: 0.0.0.0 Fault Module Timestamp: 4791a6c2 Exception Code: c0000005 Exception Offset: 745dc7fa OS Version: 6.0.6001.2.1.0.256.1 Locale ID: 1033 Additional Information 1: 40d4 Additional Information 2: 4062ad41ec8067256aa4c5e2b56d3c79 Additional Information 3: 40d4 Additional Information 4: 4062ad41ec8067256aa4c5e2b56d3c79kyoujin_crashdumps.rar - 0.08MB**I have thoroughly scanned for malware using Avast! and Spybot. If this is the result of malware, it is not yet detectable by either program.
Firon Posted September 15, 2008 Report Posted September 15, 2008 Please post a HijackThis log and Process Explorer DLL list for utorrent's process.
Kyoujin Posted September 16, 2008 Author Report Posted September 16, 2008 Here is the information you requested.Hijack ThisLogfile of Trend Micro HijackThis v2.0.2Scan saved at 8:41:43 PM, on 9/15/2008Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v7.00 (7.00.6001.18000)Boot mode: NormalRunning processes:E:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exeE:\Program Files (x86)\DAEMON Tools Lite\daemon.exeE:\Program Files\Alwil Software\Avast4\ashDisp.exeC:\Windows\SysWOW64\CTHELPER.EXEC:\Windows\SysWOW64\CTXFIHLP.EXEC:\Windows\SysWOW64\CTXFISPI.EXEE:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exeC:\Program Files (x86)\uTorrent\uTorrent.exeE:\Program Files (x86)\Opera\opera.exeE:\Program Files (x86)\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = F2 - REG:system.ini: UserInit=userinit.exeO1 - Hosts: ::1 localhostO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - e:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - E:\Program Files (x86)\Java\jre1.6.0_07\bin\ssv.dllO4 - HKLM\..\Run: [avast!] e:\PROGRA~2\ALWILS~1\Avast4\ashDisp.exeO4 - HKLM\..\Run: [AsioThk32Reg] REGSVR32.EXE /S CTASIO.DLLO4 - HKLM\..\Run: [CTHelper] CTHELPER.EXEO4 - HKLM\..\Run: [CTxfiHlp] CTXFIHLP.EXEO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Program Files (x86)\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [SunJavaUpdateSched] "E:\Program Files (x86)\Java\jre1.6.0_07\bin\jusched.exe"O4 - HKCU\..\Run: [SpybotSD TeaTimer] e:\Program Files (x86)\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeO4 - HKCU\..\Run: [DAEMON Tools Lite] "E:\Program Files (x86)\DAEMON Tools Lite\daemon.exe" -autorunO4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [DevconDefaultDB] C:\Windows\system32\READREG /SILENT /FAIL=1 (User 'Default user')O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - E:\PROGRA~1\Java\JRE16~1.0_0\bin\ssv.dllO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - e:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search && Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - e:\Program Files (x86)\Spybot - Search & Destroy\SDHelper.dllO13 - Gopher Prefix: O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - e:\Program Files\Alwil Software\Avast4\aswUpdSv.exeO23 - Service: avast! Antivirus - ALWIL Software - e:\Program Files\Alwil Software\Avast4\ashServ.exeO23 - Service: avast! Mail Scanner - ALWIL Software - e:\Program Files\Alwil Software\Avast4\ashMaiSv.exeO23 - Service: avast! Web Scanner - ALWIL Software - e:\Program Files\Alwil Software\Avast4\ashWebSv.exeO23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)O23 - Service: SBSD Security Center Service (SBSDWSCService) - Safer Networking Ltd. - e:\Program Files (x86)\Spybot - Search & Destroy\SDWinSec.exeO23 - Service: @%SystemRoot%\system32\SLsvc.exe,-101 (slsvc) - Unknown owner - C:\Windows\system32\SLsvc.exe (file missing)O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)--End of file - 6743 bytesProcess ExplorerProcess PID CPU Description Company NameSystem Idle Process 0 97.68 Interrupts n/a Hardware Interrupts DPCs n/a 1.55 Deferred Procedure Calls System 4 smss.exe 416 Windows Session Manager Microsoft Corporationcsrss.exe 484 Client Server Runtime Process Microsoft Corporationwininit.exe 528 Windows Start-Up Application Microsoft Corporation services.exe 584 Services and Controller app Microsoft Corporation svchost.exe 744 Host Process for Windows Services Microsoft Corporation ehmsas.exe 2624 Media Center Media Status Aggregator Service Microsoft Corporation CTXFISPI.EXE 12 SPI (Creative X-Fi Module) Creative Technology Ltd nvvsvc.exe 828 NVIDIA Driver Helper Service, Version 175.16 NVIDIA Corporation rundll32.exe 1056 Windows host process (Rundll32) Microsoft Corporation svchost.exe 856 Host Process for Windows Services Microsoft Corporation svchost.exe 960 Host Process for Windows Services Microsoft Corporation audiodg.exe 456 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 988 Host Process for Windows Services Microsoft Corporation dwm.exe 2824 Desktop Window Manager Microsoft Corporation svchost.exe 1000 Host Process for Windows Services Microsoft Corporation taskeng.exe 2592 Task Scheduler Engine Microsoft Corporation taskeng.exe 2848 Task Scheduler Engine Microsoft Corporation taskeng.exe 3452 Task Scheduler Engine Microsoft Corporation SLsvc.exe 604 Microsoft Software Licensing Service Microsoft Corporation svchost.exe 1044 Host Process for Windows Services Microsoft Corporation svchost.exe 1216 Host Process for Windows Services Microsoft Corporation aswUpdSv.exe 1344 avast! Antivirus updating service ALWIL Software ashServ.exe 1372 avast! antivirus service ALWIL Software spoolsv.exe 1612 Spooler SubSystem App Microsoft Corporation svchost.exe 1640 Host Process for Windows Services Microsoft Corporation svchost.exe 1936 Host Process for Windows Services Microsoft Corporation svchost.exe 2000 Host Process for Windows Services Microsoft Corporation svchost.exe 1336 Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 1712 Microsoft Windows Search Indexer Microsoft Corporation SDWinSec.exe 2084 Spybot-S&D Security Center integration Safer Networking Ltd. ashMaiSv.exe 2236 avast! e-Mail Scanner Service ALWIL Software ashWebSv.exe 2276 avast! Web Scanner ALWIL Software lsass.exe 600 Local Security Authority Process Microsoft Corporation lsm.exe 608 Local Session Manager Service Microsoft Corporationcsrss.exe 548 Client Server Runtime Process Microsoft Corporationwinlogon.exe 776 Windows Logon Application Microsoft Corporationexplorer.exe 2924 Windows Explorer Microsoft Corporation rundll32.exe 740 Windows host process (Rundll32) Microsoft Corporation TeaTimer.exe 2212 System settings protector Safer Networking Limited ehtray.exe 2148 Media Center Tray Applet Microsoft Corporation daemon.exe 1872 DAEMON Tools Lite DT Soft Ltd uTorrent.exe 2036 µTorrent BitTorrent, Inc. opera.exe 1852 Opera Internet Browser Opera Software procexp.exe 1924 Sysinternals Process Explorer Sysinternals - www.sysinternals.com procexp64.exe 3592 1.55 Sysinternals Process Explorer Sysinternals - www.sysinternals.comashDisp.exe 700 avast! service GUI component ALWIL SoftwareCTHELPER.EXE 488 CtHelper Application Creative Technology LtdCTXFIHLP.EXE 1464 CTXfiHlp MFC Application Creative Technology Ltdjusched.exe 2760 Java(TM) Platform SE binary Sun Microsystems, Inc.HijackThis.exe 3848 HijackThis Trend Micro Inc. notepad.exe 4020 Notepad Microsoft CorporationProcess: uTorrent.exe Pid: 2036Name Description Company Name VersionADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.00.6001.18000CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.6001.18000comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.6001.18000dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.00.6001.18000dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.00.6001.18000DNSAPI.dll DNS Client API DLL Microsoft Corporation 6.00.6001.18000GDI32.dll GDI Client DLL Microsoft Corporation 6.00.6001.18023GPAPI.dll Group Policy Client API Microsoft Corporation 6.00.6001.18000iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6001.18000IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.00.6001.18000Iphlpapi.dll IP Helper API Microsoft Corporation 6.00.6001.18000kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000kernel32.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.00.6001.18000locale.nls locale.nls LPK.DLL Language Pack Microsoft Corporation 6.00.6001.18000MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.00.6001.18000msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.6001.18000mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.00.6001.18000napinsp.dll E-mail Naming Shim Provider Microsoft Corporation 6.00.6001.18000NETAPI32.dll Net Win32 API DLL Microsoft Corporation 6.00.6001.18000netshell.dll Network Connections Shell Microsoft Corporation 6.00.6001.18000NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.00.6001.18000NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.00.6001.18000ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000ntdll.dll NT Layer DLL Microsoft Corporation 6.00.6001.18000ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.00.6001.18000oleaut32.dll Microsoft Corporation 6.00.6001.18000pnrpnsp.dll PNRP Name Space Provider Microsoft Corporation 6.00.6001.18000PSAPI.DLL Process Status Helper Microsoft Corporation 6.00.6000.16386rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.00.6000.16386RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.00.6001.18051rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.00.6001.18000Secur32.dll Security Support Provider Interface Microsoft Corporation 6.00.6001.18000SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.6001.18062shfolder.dll Shell Folder Service Microsoft Corporation 6.00.6000.16386SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.6001.18000slc.dll Software Licensing Client Dll Microsoft Corporation 6.00.6001.18000SXS.DLL Fusion 2.5 Microsoft Corporation 6.00.6001.18000urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.00.6001.18099USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.00.6001.18000USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000uTorrent.exe µTorrent BitTorrent, Inc. 1.08.0000.11813uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.6001.18000WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.00.6001.18000winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.00.6000.16386WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.00.6001.18000wow64.dll Win32 Emulation on NT64 Microsoft Corporation 6.00.6001.18000wow64cpu.dll AMD64 Wow64 CPU Microsoft Corporation 6.00.6001.18000wow64win.dll Wow64 Console and Win32 API Logging Microsoft Corporation 6.00.6001.18000WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.00.6001.18000wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.00.6001.18000wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.00.6001.18000
Ultima Posted September 16, 2008 Report Posted September 16, 2008 Hrm. Have you tried disabling avast!'s P2P guard and/or adding µTorrent to any exclusions/exceptions list it may have?
Kyoujin Posted September 16, 2008 Author Report Posted September 16, 2008 No I haven't. But I've had Avast! on this machine since I built it...and given that this problem was not occuring when I first started using uTorrent, I doubt that the issue is related to Avast!. After checking Avast!'s P2P Shield settings I found that uTorrent downloads weren't being scanned at all by P2P Shield. (Good thing like to manually scan downloads.) This would seem to confirm that P2P Shield is not the cause of the problem.
Firon Posted September 16, 2008 Report Posted September 16, 2008 Well, AV apps do constantly update themselves, and they tend to be a bit more problematic on 64bit OSes... Tried disabling Avast's Web and Email scanners too? That being said, you may just be running into the crash bug in Vista we've seen for a while now (that we unfortunately haven't been able to figure out).
Recommended Posts
Archived
This topic is now archived and is closed to further replies.