clarizard Posted December 8, 2008 Report Share Posted December 8, 2008 Ok, something has just happened. I tried to resolve by starting over from the beginning and uninstalling and reinstalling 1.8.1 and it is now telling me: The file 'C:\Documents and Settings\user\Application Data\uTorrent\settings.dat' is in use by another process and can't be opened and The file 'C:\Documents and Settings\user\Application Data\uTorrent\resume.dat' is in use by another process and can't be opened.Nothing else is running at the moment so can't figure it out.Any suggestions? Link to comment Share on other sites More sharing options...
moogly Posted December 8, 2008 Report Share Posted December 8, 2008 Did you check if utorrent.exe is already running in your process manager ?If yes, kill all utorrent.exe and restart uT. Link to comment Share on other sites More sharing options...
clarizard Posted December 8, 2008 Author Report Share Posted December 8, 2008 Yep, checked it already. It is not already running. It really has me baffled. I uninstalled the google toolbar as i heard that could be the problem but the problem remains. Is there any other programs or processes that could cause this? Link to comment Share on other sites More sharing options...
moogly Posted December 8, 2008 Report Share Posted December 8, 2008 Post an HijackThis log: http://forum.utorrent.com/viewtopic.php?id=29748 Link to comment Share on other sites More sharing options...
clarizard Posted December 8, 2008 Author Report Share Posted December 8, 2008 Logfile of Trend Micro HijackThis v2.0.2Scan saved at 2:48:23 PM, on 12/8/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\csrss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXEC:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeC:\Program Files\Eset\nod32krn.exeC:\WINDOWS\system32\IoctlSvc.exeC:\Program Files\Common Files\Protexis\License Service\PsiService_2.exeC:\WINDOWS\system32\svchost.exeC:\Program Files\ThreatFire\TFService.exeC:\WINDOWS\System32\alg.exeC:\WINDOWS\Explorer.EXEC:\WINDOWS\system32\VTTimer.exeC:\Program Files\Eset\nod32kui.exeC:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exeC:\Program Files\Java\jre1.6.0_05\bin\jusched.exeC:\Program Files\ThreatFire\TFTray.exeC:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exeC:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exeC:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exeC:\Program Files\DAEMON Tools Lite\daemon.exeC:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKE.EXEC:\WINDOWS\System32\svchost.exeC:\Program Files\VIA\RAID\raid_tool.exeC:\WINDOWS\system32\wuauclt.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Program Files\Java\jre1.6.0_05\bin\jucheck.exeC:\Documents and Settings\user\Desktop\utorrent.exeC:\Documents and Settings\user\Desktop\HiJackThis.exeC:\WINDOWS\system32\wbem\wmiprvse.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www2.iesearch.com/R1 - HKCU\Software\Microsoft\Internet Explorer\SearchURL,(Default) = http://g.msn.co.uk/0SEENGB/SAOS01?FORM=TOOLBRR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page = R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: (no name) - {02478D38-C3F9-4efb-9B51-7695ECA05670} - (no file)O2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: EpsonToolBandKicker Class - {E99421FB-68DD-40F0-B4AC-B7027CAE2F1A} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dllO3 - Toolbar: EPSON Web-To-Page - {EE5D279F-081B-4404-994D-C6B60AAEBA6D} - C:\Program Files\EPSON\EPSON Web-To-Page\EPSON Web-To-Page.dllO4 - HKLM\..\Run: [VTTimer] VTTimer.exeO4 - HKLM\..\Run: [VTTrayp] VTtrayp.exeO4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICEO4 - HKLM\..\Run: [Adobe Photo Downloader] "C:\Program Files\Adobe\Photoshop Album Starter Edition\3.2\Apps\apdproxy.exe"O4 - HKLM\..\Run: [NBKeyScan] "C:\Program Files\Nero\Nero8\Nero BackItUp\NBKeyScan.exe"O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre1.6.0_05\bin\jusched.exe"O4 - HKLM\..\Run: [NeroFilterCheck] C:\Program Files\Common Files\Nero\Lib\NeroCheck.exeO4 - HKLM\..\Run: [ThreatFire] C:\Program Files\ThreatFire\TFTray.exeO4 - HKLM\..\Run: [Corel Photo Downloader] "C:\Program Files\Common Files\Corel\Corel PhotoDownloader\Corel Photo Downloader.exe" -startupO4 - HKLM\..\Run: [Corel File Shell Monitor] C:\Program Files\Corel\Corel Paint Shop Pro Photo X2\CorelIOMonitor.exeO4 - HKCU\..\Run: [AnyDVD] C:\Program Files\SlySoft\AnyDVD\AnyDVDtray.exeO4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program Files\DAEMON Tools Lite\daemon.exe" -autorunO4 - HKCU\..\Run: [spybotSD TeaTimer] C:\Program Files\Spybot - Search & Destroy\TeaTimer.exeO4 - HKCU\..\Run: [EPSON Stylus Photo R285 Series] C:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICKE.EXE /FU "C:\DOCUME~1\user\LOCALS~1\Temp\E_S11BB.tmp" /EF "HKCU"O4 - HKCU\..\Run: [µTorrent] "C:\Documents and Settings\user\Desktop\utorrent.exe"O4 - HKCU\..\Run: [uTorrent] "C:\Documents and Settings\user\Desktop\utorrent.exe"O4 - HKUS\S-1-5-18\..\RunOnce: [RunNarrator] Narrator.exe (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\RunOnce: [RunNarrator] Narrator.exe (User 'Default user')O4 - Startup: Adobe Gamma.lnk = C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exeO4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program Files\Adobe\Acrobat 7.0\Reader\reader_sl.exeO4 - Global Startup: VIA RAID TOOL.lnk = C:\Program Files\VIA\RAID\raid_tool.exeO8 - Extra context menu item: Add to Windows &Live Favorites - http://favorites.live.com/quickadd.aspxO9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exeO9 - Extra button: Ladbrokes Poker - {C2A80015-C447-4dc4-82DD-AED83D6ED57E} - C:\Microgaming\Poker\ladbrokesMPP\MPPoker.exeO9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dllO9 - Extra button: The News of the World Poker - {F3DFA494-B04A-4d83-82FD-61A67235E03D} - C:\Microgaming\Poker\notwMPP\MPPoker.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra button: Doyles Room - {00000000-0000-0000-0000-000000000000} - C:\MicroGaming\Poker\DoylesRoomMPP\MPPoker.exe (HKCU)O10 - Unknown file in Winsock LSP: c:\windows\system32\nwprovau.dllO16 - DPF: {30528230-99f7-4bb4-88d8-fa1d4f56a2ab} (Installation Support) - C:\Program Files\Yahoo!\Common\Yinsthelper.dllO16 - DPF: {7B297BFD-85E4-4092-B2AF-16A91B2EA103} (WScanCtl Class) - http://www.ca.com/us/securityadvisor/virusinfo/webscan.cabO16 - DPF: {BB21F850-63F4-4EC9-BF9D-565BD30C9AE9} (a-squared Scanner) - http://ax.emsisoft.com/asquared.cabO16 - DPF: {D8089245-3211-40F6-819B-9E5E92CD61A2} - O17 - HKLM\System\CCS\Services\Tcpip\..\{8FE6B0AF-6E49-4946-8E06-5A8D4A3DEF54}: NameServer = 192.168.1.1O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: EPSON V3 Service4(01) (EPSON_PM_RPCV4_01) - SEIKO EPSON CORPORATION - C:\Documents and Settings\All Users\Application Data\EPSON\EPW!3 SSRP\E_S40RP7.EXEO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program Files\Eset\nod32krn.exeO23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\WINDOWS\system32\IoctlSvc.exeO23 - Service: Protexis Licensing V2 (PSI_SVC_2) - Protexis Inc. - C:\Program Files\Common Files\Protexis\License Service\PsiService_2.exeO23 - Service: ThreatFire - PC Tools - C:\Program Files\ThreatFire\TFService.exeO24 - Desktop Component 0: Privacy Protection - (no file)--End of file - 8093 bytesProcess PID CPU Description Company NameSystem Idle Process 0 97.76 Interrupts n/a Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 smss.exe 716 Windows NT Session Manager Microsoft Corporation csrss.exe 776 Client Server Runtime Process Microsoft Corporation winlogon.exe 800 Windows NT Logon Application Microsoft Corporation services.exe 844 0.75 Services and Controller app Microsoft Corporation svchost.exe 1028 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1096 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1220 Generic Host Process for Win32 Services Microsoft Corporation wuauclt.exe 2096 Windows Update Automatic Updates Microsoft Corporation svchost.exe 1420 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1508 Generic Host Process for Win32 Services Microsoft Corporation spoolsv.exe 1768 Spooler SubSystem App Microsoft Corporation mDNSResponder.exe 1988 Bonjour Service Apple Inc. E_S40RP7.EXE 2028 EPSON Status Monitor 3 SEIKO EPSON CORPORATION NBService.exe 348 Nero BackItUp Nero AG nod32krn.exe 700 NOD32 Kernel Service Eset IoctlSvc.exe 744 PLFlash DeviceIoControl Service Prolific Technology Inc. PsiService_2.exe 780 PsiService PsiService Protexis Inc. svchost.exe 1256 Generic Host Process for Win32 Services Microsoft Corporation TFService.exe 1388 PC Tools ThreatFire Service PC Tools alg.exe 508 Application Layer Gateway Service Microsoft Corporation svchost.exe 652 Generic Host Process for Win32 Services Microsoft Corporation lsass.exe 856 LSA Shell (Export Version) Microsoft Corporationexplorer.exe 1456 Windows Explorer Microsoft Corporation VTTimer.exe 2804 S3 Graphics, Inc. nod32kui.exe 2996 NOD32 Control Center GUI Eset apdproxy.exe 3080 Adobe Photoshop Album Starter Edition 3.2 component Adobe Systems Incorporated jusched.exe 3316 Java Platform SE binary Sun Microsystems, Inc. jucheck.exe 3864 Java Update Checker Sun Microsystems, Inc. TFTray.exe 3476 PC Tools ThreatFire Tray App PC Tools Corel Photo Downloader.exe 3504 Corel Photo Downloader Corel, Inc. CorelIOMonitor.exe 3532 Corel File Shell Monitor Corel, Inc. AnyDVDtray.exe 3652 AnyDVD Application SlySoft, Inc. daemon.exe 3736 DAEMON Tools main application DT Soft Ltd E_FATICKE.EXE 3800 EPSON Status Monitor 3 SEIKO EPSON CORPORATION raid_tool.exe 756 VIA RAID Tool VIA Technologies firefox.exe 3152 Firefox Mozilla Corporation utorrent.exe 2588 0.75 µTorrent BitTorrent, Inc. HiJackThis.exe 576 HijackThis Trend Micro Inc. NOTEPAD.EXE 2888 Notepad Microsoft Corporation procexp.exe 2140 0.75 Sysinternals Process Explorer Sysinternals - www.sysinternals.comProcess: utorrent.exe Pid: 2588Name Description Company Name VersionACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.2180adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.2180ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180ADvdDiscHlp1.dll ADvdDisc Dynamic Link Library SlySoft, Inc. 1.00.0000.0003appHelp.dll Application Compatibility Client Library Microsoft Corporation 5.01.2600.2180ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000browseui.dll Shell Browser UI Library Microsoft Corporation 6.00.2900.3429CFGMGR32.dll Configuration Manager Forwarder DLL Microsoft Corporation 5.01.2600.2180CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0308COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.2180COMRes.dll Microsoft Corporation 2001.12.4414.0258credui.dll Credential Manager User Interface Microsoft Corporation 5.01.2600.2180CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.2180CRYPTUI.dll Microsoft Trust UI Provider Microsoft Corporation 5.131.2600.2180CSCDLL.dll Offline Network Agent Microsoft Corporation 5.01.2600.2180cscui.dll Client Side Caching UI Microsoft Corporation 5.01.2600.2180ctype.nls davclnt.dll Web DAV Client DLL Microsoft Corporation 5.01.2600.2180DnsApi.dll DNS Client API DLL Microsoft Corporation 5.01.2600.3394drprov.dll Microsoft Terminal Server Network Provider Microsoft Corporation 5.01.2600.2180GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3316hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.2180IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 5.01.2600.2180imon.dll NOD32 IMON - Internet scanning support Eset 2.51.0008.0000index.dat index.dat index.dat Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2912kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.3119LINKINFO.dll Windows Volume Tracking Microsoft Corporation 5.01.2600.2751locale.nls mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.00.0005.0011MPR.dll Multiple Provider Router DLL Microsoft Corporation 5.01.2600.2180MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.2180MSGINA.dll Windows NT Logon GINA DLL Microsoft Corporation 5.01.2600.2180msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.3394netapi32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.3462NETRAP.dll Net Remote Admin Protocol DLL Microsoft Corporation 5.01.2600.2180NETSHELL.dll Network Connections Shell Microsoft Corporation 5.01.2600.2180NETUI0.dll NT LM UI Common Code - GUI Classes Microsoft Corporation 5.01.2600.2180NETUI1.dll NT LM UI Common Code - Networking classes Microsoft Corporation 5.01.2600.2180ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180ntlanman.dll Microsoft® Lan Manager Microsoft Corporation 5.01.2600.2180NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 5.01.2600.2180ntshrui.dll Shell extensions for sharing Microsoft Corporation 5.01.2600.2180ODBC32.dll Microsoft Data Access - ODBC Driver Manager Microsoft Corporation 3.525.1117.0000odbcint.dll Microsoft Data Access - ODBC Resources Microsoft Corporation 3.525.1117.0000ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726OLEAUT32.dll Microsoft Corporation 5.01.2600.3266PortableDeviceApi.dll Windows Portable Device API Components Microsoft Corporation 5.02.5721.5145rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 5.01.2600.2161rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.2180shdocvw.dll Shell Doc Object and Control Library Microsoft Corporation 6.00.2900.3429SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.3241shfolder.dll Shell Folder Service Microsoft Corporation 6.00.2900.2180SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.3429sortkey.nls sorttbls.nls sti.dll Still Image Devices client DLL Microsoft Corporation 5.01.2600.2180SXS.DLL Fusion 2.5 Microsoft Corporation 5.01.2600.3019TFWAH.dll PC Tools ThreatFire PC Tools 4.08.0011.0017unicode.nls USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.3099USERENV.dll Userenv Microsoft Corporation 5.01.2600.2180utorrent.exe µTorrent BitTorrent, Inc. 1.08.0001.12639uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180WININET.dll Internet Extensions for Win32 Microsoft Corporation 6.00.2900.3429WINSTA.dll Winstation Library Microsoft Corporation 5.01.2600.2180WINTRUST.dll Microsoft Trust Verification APIs Microsoft Corporation 5.131.2600.2180WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180wship6.dll IPv6 Helper DLL Microsoft Corporation 5.01.2600.2180wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180WSOCK32.dll Windows Socket 32-Bit DLL Microsoft Corporation 5.01.2600.2180xpsp2res.dll Service Pack 2 Messages Microsoft Corporation 5.01.2600.2180 Link to comment Share on other sites More sharing options...
moogly Posted December 8, 2008 Report Share Posted December 8, 2008 TFWAH.dll PC Tools ThreatFire PC Tools 4.08.0011.0017Frequent source of pbm with uT, search on the board, it's already reported. Link to comment Share on other sites More sharing options...
clarizard Posted December 8, 2008 Author Report Share Posted December 8, 2008 Thank you very much for your help. Just uninstalled the offender and it is running fine again. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.