Jump to content

uTorrent freezing computer


nivyan

Recommended Posts

got a hijacklog:

Logfile of HijackThis v1.99.1

Scan saved at 23:06:53, on 01-04-2009

Platform: Unknown Windows (WinNT 6.00.1905 SP1)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\rundll32.exe

C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\Rainlendar2\Rainlendar2.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\spool\drivers\w32x86\3\E_FATICDE.EXE

C:\Program Files\Steam\Steam.exe

C:\Program Files\DNA\btdna.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\MSI\DualCoreCenter\DualCoreCenter.exe

C:\Program Files\BitDefender\BitDefender 2009\seccenter.exe

C:\Windows\system32\wuauclt.exe

C:\Program Files\Java\jre6\bin\jucheck.exe

C:\Windows\system32\WgaTray.exe

C:\Users\Nivyan\Desktop\CohUpdater.exe

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Program Files\Windows Live\Messenger\msnmsgr.exe

C:\Program Files\Windows Live\Contacts\wlcomm.exe

C:\Users\Nivyan\Downloads\utorrent(4).exe

C:\Windows\system32\SearchFilterHost.exe

F:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O3 - Toolbar: BitDefender Toolbar - {381FFDE8-2394-4f90-B10D-FC6124A40F8C} - C:\Program Files\BitDefender\BitDefender 2009\IEToolbar.dll

O4 - HKLM\..\Run: [NvCplDaemon] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\Windows\KHALMNPR.EXE"

O4 - HKLM\..\Run: [bDAgent] "C:\Program Files\BitDefender\BitDefender 2009\bdagent.exe"

O4 - HKLM\..\Run: [bitDefender Antiphishing Helper] "C:\Program Files\BitDefender\BitDefender 2009\IEShow.exe"

O4 - HKLM\..\Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKCU\..\Run: [sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun

O4 - HKCU\..\Run: [Rainlendar2] "C:\Program Files\Rainlendar2\Rainlendar2.exe"

O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"

O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] "C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" /FU "C:\Windows\TEMP\E_S495F.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKCU\..\Run: [bitTorrent DNA] "C:\Program Files\DNA\btdna.exe"

O4 - Global Startup: DualCoreCenter.lnk = C:\Program Files\MSI\DualCoreCenter\StartUpDualCoreCenter.exe

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000

O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{46B3B4AD-332E-422E-8FE2-62EF44F2FA3D}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~3\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~3\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: BitDefender Arrakis Server (Arrakis3) - BitDefender S.R.L. http://www.bitdefender.com - C:\Program Files\Common Files\BitDefender\BitDefender Arrakis Server\bin\Arrakis3.exe

O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

O23 - Service: BitDefender Desktop Update Service (LIVESRV) - Unknown owner - C:\Program Files\Common Files\BitDefender\BitDefender Update Service\livesrv.exe" /service (file missing)

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: BitDefender Virus Shield (VSSERV) - Unknown owner - C:\Program Files\BitDefender\BitDefender 2009\vsserv.exe" /service (file missing)

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

if anyone can decode this for me i'd be very pleased :>

it freezes randomly, sometimes after 2 mins, sometimes after a few hours.

Link to comment
Share on other sites

added Process Explorer

Process PID CPU Description Company Name

System Idle Process 0 95.37

Interrupts n/a Hardware Interrupts

DPCs n/a 0.77 Deferred Procedure Calls

System 4

smss.exe 524 Windows Session Manager Microsoft Corporation

csrss.exe 596 Klient/server-kørselsproces Microsoft Corporation

wininit.exe 656 Windows-startprogram Microsoft Corporation

services.exe 700 Tjenester og controllerprogrammer Microsoft Corporation

svchost.exe 900 Værtsproces for Windows Tjenester Microsoft Corporation

WmiPrvSE.exe 376 WMI Provider Host Microsoft Corporation

WmiPrvSE.exe 4292 0.39 WMI Provider Host Microsoft Corporation

nvvsvc.exe 948 NVIDIA Driver Helper Service, Version 182.08 NVIDIA Corporation

rundll32.exe 516 Windows værtsproces (Rundll32) Microsoft Corporation

svchost.exe 976 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 1160 Værtsproces for Windows Tjenester Microsoft Corporation

audiodg.exe 1332 Windows Audio Device Graph Isolation Microsoft Corporation

svchost.exe 1192 Værtsproces for Windows Tjenester Microsoft Corporation

dwm.exe 896 0.39 Styring af skrivebordsvindue Microsoft Corporation

svchost.exe 1204 Værtsproces for Windows Tjenester Microsoft Corporation

taskeng.exe 268 Programmet Opgavestyring Microsoft Corporation

taskeng.exe 1440 Programmet Opgavestyring Microsoft Corporation

wuauclt.exe 4220 Windows Update Automatic Updates Microsoft Corporation

svchost.exe 1364 Værtsproces for Windows Tjenester Microsoft Corporation

SLsvc.exe 1404 Tjenesten Microsoft Software Licensing Microsoft Corporation

svchost.exe 1468 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 1592 Værtsproces for Windows Tjenester Microsoft Corporation

spoolsv.exe 1804 Spooler SubSystem App Microsoft Corporation

svchost.exe 1828 Værtsproces for Windows Tjenester Microsoft Corporation

AppleMobileDeviceService.exe 2444 Apple Mobile Device Service Apple Inc.

mDNSResponder.exe 2476 Bonjour Service Apple Inc.

mdm.exe 2532 Machine Debug Manager Microsoft Corporation

svchost.exe 2696 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 2720 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 2804 Værtsproces for Windows Tjenester Microsoft Corporation

SearchIndexer.exe 2848 Microsoft Windows Search Indeksering Microsoft Corporation

SearchProtocolHost.exe 2944 Microsoft Windows Search Protocol Host Microsoft Corporation

SearchFilterHost.exe 696 Microsoft Windows Search Filter Host Microsoft Corporation

wmpnetwk.exe 3792 Windows Media Player Network Sharing Service Microsoft Corporation

iPodService.exe 884 iPodService Module Apple Inc.

SteamService.exe 420 Steam Client Service Valve Corporation

TrustedInstaller.exe 788 Installationsprogram til Windows-moduler Microsoft Corporation

msiexec.exe 1340 Windows® Installer Microsoft Corporation

VSSVC.exe 5796 Tjenesten Microsoft® Volume Snapshots Microsoft Corporation

svchost.exe 2812 Værtsproces for Windows Tjenester Microsoft Corporation

lsass.exe 712 LSA-proces (Local Security Authority) Microsoft Corporation

lsm.exe 724 Tjenesten Lokal sessionsstyring Microsoft Corporation

csrss.exe 668 Klient/server-kørselsproces Microsoft Corporation

winlogon.exe 1016 Windows-logonprogram Microsoft Corporation

explorer.exe 2056 Windows Stifinder Microsoft Corporation

rundll32.exe 3052 Windows værtsproces (Rundll32) Microsoft Corporation

RtHDVCpl.exe 3204 HD Audio Control Panel Realtek Semiconductor

jusched.exe 3272 Java Platform SE binary Sun Microsystems, Inc.

jucheck.exe 5612 Java Update Checker Sun Microsystems, Inc.

iTunesHelper.exe 3512 iTunesHelper Module Apple Inc.

GrooveMonitor.exe 3540 GrooveMonitor Utility Microsoft Corporation

Rainlendar2.exe 3616 Rainlendar2

wmpnscfg.exe 3688 Konfigurationsprogram til Windows Media Player Network Sharing Service Microsoft Corporation

E_FATICDE.EXE 3744 EPSON Status Monitor 3 SEIKO EPSON CORPORATION

Steam.exe 3776 Steam Valve Corporation

btdna.exe 3800 DNA BitTorrent, Inc.

SetPoint.exe 3916 Logitech SetPoint Event Manager (UNICODE) Logitech, Inc.

KHALMNPR.exe 4028 Logitech KHAL Main Process Logitech, Inc.

firefox.exe 4964 Firefox Mozilla Corporation

utorrent(5).exe 3384 1.93 µTorrent BitTorrent, Inc.

explorer.exe 3188 Windows Stifinder Microsoft Corporation

DualCoreCenter.exe 3592 0.39 CoreCellCenter MFC Application

WGATray.exe 5008 Windows Genuine Advantage Notifications Microsoft Corporation

procexp.exe 3480 1.16 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

Process: utorrent(5).exe Pid: 3384

Name Description Company Name Version

ADVAPI32.dll Avanceret Windows 32 Base-API Microsoft Corporation 6.0.6001.18000

ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.5.2284.0

CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000

COMCTL32.dll Objektbibliotek til brugeroplevelsen Microsoft Corporation 6.10.6001.18000

comctl32.dll.mui Objektbibliotek til brugeroplevelsen Microsoft Corporation 6.10.6000.16386

comdlg32.dll DLL-fil med fælles dialogbokse Microsoft Corporation 6.0.6001.18000

comsvcs.dll COM+ Services Microsoft Corporation 2001.12.6931.18000

dhcpcsvc.DLL Tjenesten DHCP Client Microsoft Corporation 6.0.6001.18000

dhcpcsvc6.DLL DHCPv6-klient Microsoft Corporation 6.0.6001.18000

DnsApi.dll API DLL til DNS-klient Microsoft Corporation 6.0.6001.18000

DUser.dll Windows DirectUser Engine Microsoft Corporation 6.0.6001.18000

duser.dll.mui Windows DirectUser Engine Microsoft Corporation 6.0.6000.16386

FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.0.6001.18000

GameHook.dll Logitech Gaming Hook (UNICODE) Logitech, Inc. 4.60.122.0

GDI32.dll GDI Client DLL Microsoft Corporation 6.0.6001.18159

IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.0.6001.18000

Iphlpapi.dll IP Helper API Microsoft Corporation 6.0.6001.18000

kernel32.dll Klient-DLL til Windows NT BASE API Microsoft Corporation 6.0.6001.18000

kernel32.dll.mui Klient-DLL til Windows NT BASE API Microsoft Corporation 6.0.6001.18000

lgscroll.dll Logitech Scroll Enabler (UNICODE) Logitech, Inc. 4.60.122.0

locale.nls

locale.nls

LPK.DLL Language Pack Microsoft Corporation 6.0.6001.18000

mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.0.6.2

MSCTF.dll DLL-fil til MSCTF-server Microsoft Corporation 6.0.6001.18000

msctf.dll.mui DLL-fil til MSCTF-server Microsoft Corporation 6.0.6000.16386

MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.0.50727.3053

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.6001.18000

mswsock.dll Microsoft Windows Sockets 2.0-tjenesteudbyder Microsoft Corporation 6.0.6001.18000

napinsp.dll Shim-provider til e-mail-navngivning Microsoft Corporation 6.0.6001.18000

NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.0.6001.18000

npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.0.6000.16386

NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.0.6001.18000

ntdll.dll DLL til NT-lag Microsoft Corporation 6.0.6001.18000

NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 6.0.6001.18000

ole32.dll Microsoft OLE til Windows Microsoft Corporation 6.0.6001.18000

oleaut32.dll Microsoft Corporation 6.0.6001.18000

pnrpnsp.dll Provider til navneområde for PNRP Microsoft Corporation 6.0.6001.18000

PSAPI.DLL Process Status Helper Microsoft Corporation 6.0.6000.16386

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.0.6000.16386

RPCRT4.dll Kørsel af RPC (Remote Procedure Call) Microsoft Corporation 6.0.6001.18051

rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.0.6001.18000

SAMLIB.dll SAM Library DLL Microsoft Corporation 6.0.6001.18000

Secur32.dll Security Support Provider Interface Microsoft Corporation 6.0.6001.18000

SHELL32.dll Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows Microsoft Corporation 6.0.6001.18167

shfolder.dll Shell Folder Service Microsoft Corporation 6.0.6000.16386

SHLWAPI.dll Shells letvægts-programmappe Microsoft Corporation 6.0.6001.18000

SXS.DLL Fusion 2.5 Microsoft Corporation 6.0.6001.18000

USER32.dll Klient-DLL til Windows USER API til flere brugere Microsoft Corporation 6.0.6001.18000

USERENV.dll Userenv Microsoft Corporation 6.0.6001.18000

USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000

utorrent.exe µTorrent BitTorrent, Inc. 1.8.2.14458

uxtheme.dll Microsoft UxTheme-bibliotek Microsoft Corporation 6.0.6001.18000

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.0.6001.18000

WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.0.6001.18000

winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.0.6000.16386

WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.0.6001.18000

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.0.6001.18000

wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.0.6001.18000

wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.0.6001.18000

i uninstalled Bitdefender, waiting to see what happens :)

EDIT: Still frezees with BitDefender removed :(

Link to comment
Share on other sites

Im sure of it, since it ONLY occours when utorrent is downloading. Never had it happen when ANY other program has been running.

It happens at very different times- Which is why it's hard to explain the circumstances. Because it's so random! Sometimes I'm watching a movie and suddenly everything freezes- Sometimes i just let the computer stand there with utorrent on and it freezes- etc etc. but NEVER when utorrent isn't running.

Link to comment
Share on other sites

Your PE log seems to be fine. What's the result without Bitdefender.

Anyway:

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

I think the problem is here. Did you try to repair your TCP/IP Winsock?

http://www.mydigitallife.info/2007/06/18/repair-and-reset-windows-vista-tcpip-winsock-catalog-corruption/

Link to comment
Share on other sites

Thanks for that- But the problem still arises :/

Tried to let it download last night- Only to let it have frozen a few hours before.

Any other ideas??

New Hijacklog, without BitDefender:

Logfile of Trend Micro HijackThis v2.0.2

Scan saved at 07:20:16, on 03-04-2009

Platform: Windows Vista SP1 (WinNT 6.00.1905)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Boot mode: Normal

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Windows\System32\rundll32.exe

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Program Files\iTunes\iTunesHelper.exe

C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe

C:\Program Files\Rainlendar2\Rainlendar2.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\spool\drivers\w32x86\3\E_FATICDE.EXE

C:\Program Files\Steam\Steam.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Windows\system32\wuauclt.exe

C:\Program Files\Java\jre6\bin\jucheck.exe

C:\Program Files\WinRAR\WinRAR.exe

C:\Users\Nivyan\AppData\Local\Temp\Rar$EX00.156\HijackThis.exe

C:\Users\Nivyan\Downloads\utorrent.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [NvCplDaemon] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] "C:\Windows\system32\RUNDLL32.EXE" C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\Windows\KHALMNPR.EXE"

O4 - HKLM\..\Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottime

O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"

O4 - HKLM\..\Run: [GrooveMonitor] "C:\Program Files\Microsoft Office\Office12\GrooveMonitor.exe"

O4 - HKCU\..\Run: [sidebar] "C:\Program Files\Windows Sidebar\sidebar.exe" /autoRun

O4 - HKCU\..\Run: [Rainlendar2] "C:\Program Files\Rainlendar2\Rainlendar2.exe"

O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"

O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] "C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" /FU "C:\Windows\TEMP\E_S495F.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [steam] "C:\Program Files\Steam\Steam.exe" -silent

O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOKAL TJENESTE')

O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETVÆRKSTJENESTE')

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000

O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL

O13 - Gopher Prefix:

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{46B3B4AD-332E-422E-8FE2-62EF44F2FA3D}: NameServer = 208.67.222.222,208.67.220.220

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dll

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

--

End of file - 6443 bytes

New ProcessExplorer:

Process PID CPU Description Company Name

System Idle Process 0 92.19

Interrupts n/a 0.39 Hardware Interrupts

DPCs n/a 1.56 Deferred Procedure Calls

System 4

smss.exe 524 Windows Session Manager Microsoft Corporation

csrss.exe 596 Klient/server-kørselsproces Microsoft Corporation

wininit.exe 656 Windows-startprogram Microsoft Corporation

services.exe 700 Tjenester og controllerprogrammer Microsoft Corporation

svchost.exe 884 Værtsproces for Windows Tjenester Microsoft Corporation

WmiPrvSE.exe 3028 WMI Provider Host Microsoft Corporation

WmiPrvSE.exe 3492 WMI Provider Host Microsoft Corporation

nvvsvc.exe 932 NVIDIA Driver Helper Service, Version 182.08 NVIDIA Corporation

rundll32.exe 2024 Windows værtsproces (Rundll32) Microsoft Corporation

svchost.exe 996 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 1036 Værtsproces for Windows Tjenester Microsoft Corporation

audiodg.exe 1180 Windows Audio Device Graph Isolation Microsoft Corporation

svchost.exe 1084 5.47 Værtsproces for Windows Tjenester Microsoft Corporation

dwm.exe 972 0.39 Styring af skrivebordsvindue Microsoft Corporation

svchost.exe 1100 Værtsproces for Windows Tjenester Microsoft Corporation

taskeng.exe 1876 Programmet Opgavestyring Microsoft Corporation

taskeng.exe 1396 Programmet Opgavestyring Microsoft Corporation

svchost.exe 1204 Værtsproces for Windows Tjenester Microsoft Corporation

SLsvc.exe 1244 Tjenesten Microsoft Software Licensing Microsoft Corporation

svchost.exe 1324 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 1416 Værtsproces for Windows Tjenester Microsoft Corporation

spoolsv.exe 1624 Spooler SubSystem App Microsoft Corporation

svchost.exe 1648 Værtsproces for Windows Tjenester Microsoft Corporation

AppleMobileDeviceService.exe 2200 Apple Mobile Device Service Apple Inc.

mDNSResponder.exe 2224 Bonjour Service Apple Inc.

mdm.exe 2268 Machine Debug Manager Microsoft Corporation

svchost.exe 2380 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 2480 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 2560 Værtsproces for Windows Tjenester Microsoft Corporation

SearchIndexer.exe 2616 Microsoft Windows Search Indeksering Microsoft Corporation

SearchProtocolHost.exe 2220 0.39 Microsoft Windows Search Protocol Host Microsoft Corporation

SearchFilterHost.exe 1312 Microsoft Windows Search Filter Host Microsoft Corporation

wmpnetwk.exe 3368 Windows Media Player Network Sharing Service Microsoft Corporation

iPodService.exe 3816 iPodService Module Apple Inc.

SteamService.exe 3888 Steam Client Service Valve Corporation

TrustedInstaller.exe 3208 Installationsprogram til Windows-moduler Microsoft Corporation

VSSVC.exe 1492 Tjenesten Microsoft® Volume Snapshots Microsoft Corporation

svchost.exe 3736 Værtsproces for Windows Tjenester Microsoft Corporation

lsass.exe 712 LSA-proces (Local Security Authority) Microsoft Corporation

lsm.exe 724 Tjenesten Lokal sessionsstyring Microsoft Corporation

csrss.exe 668 0.39 Klient/server-kørselsproces Microsoft Corporation

winlogon.exe 956 Windows-logonprogram Microsoft Corporation

explorer.exe 1656 Windows Stifinder Microsoft Corporation

rundll32.exe 2776 Windows værtsproces (Rundll32) Microsoft Corporation

RtHDVCpl.exe 2824 HD Audio Control Panel Realtek Semiconductor

jusched.exe 2860 Java Platform SE binary Sun Microsystems, Inc.

iTunesHelper.exe 3020 iTunesHelper Module Apple Inc.

GrooveMonitor.exe 3076 GrooveMonitor Utility Microsoft Corporation

Rainlendar2.exe 3160 Rainlendar2

wmpnscfg.exe 3188 Konfigurationsprogram til Windows Media Player Network Sharing Service Microsoft Corporation

E_FATICDE.EXE 3224 EPSON Status Monitor 3 SEIKO EPSON CORPORATION

Steam.exe 3292 Steam Valve Corporation

SetPoint.exe 3308 Logitech SetPoint Event Manager (UNICODE) Logitech, Inc.

KHALMNPR.exe 3584 Logitech KHAL Main Process Logitech, Inc.

firefox.exe 3468 Firefox Mozilla Corporation

WinRAR.exe 3360 WinRAR archiver Alexander Roshal

procexp.exe 1708 1.17 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

WinRAR.exe 1936 WinRAR archiver Alexander Roshal

HijackThis.exe 1988 HijackThis Trend Micro Inc.

notepad.exe 1856 Notesblok Microsoft Corporation

utorrent.exe 2156 5.47 µTorrent BitTorrent, Inc.

Process: utorrent.exe Pid: 2156

Name Description Company Name Version

ADVAPI32.dll Avanceret Windows 32 Base-API Microsoft Corporation 6.0.6001.18000

apphelp.dll Klient-dll til programkompatibilitet Microsoft Corporation 6.0.6001.18000

ATL80.DLL ATL Module for Windows (Unicode) Microsoft Corporation 8.0.50727.762

browseui.dll Dll-fil til Shell Browser-brugergrænsefladen Microsoft Corporation 6.0.6001.18000

CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000

COMCTL32.dll Objektbibliotek til brugeroplevelsen Microsoft Corporation 6.10.6001.18000

comdlg32.dll DLL-fil med fælles dialogbokse Microsoft Corporation 6.0.6001.18000

CRYPT32.dll Crypto API32 Microsoft Corporation 6.0.6001.18000

CSCAPI.dll Offline Files Win32 API Microsoft Corporation 6.0.6001.18000

CSCDLL.dll Offline Files Temporary Shim Microsoft Corporation 6.0.6001.18000

cscui.dll Client Side Caching UI Microsoft Corporation 6.0.6001.18000

dhcpcsvc.DLL Tjenesten DHCP Client Microsoft Corporation 6.0.6001.18000

dhcpcsvc6.DLL DHCPv6-klient Microsoft Corporation 6.0.6001.18000

DnsApi.dll API DLL til DNS-klient Microsoft Corporation 6.0.6001.18000

DUser.dll Internet Explorer UI Engine Microsoft Corporation 6.0.6001.18000

FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.0.6001.18000

GameHook.dll Logitech Gaming Hook (UNICODE) Logitech, Inc. 4.60.122.0

GDI32.dll GDI Client DLL Microsoft Corporation 6.0.6001.18159

GrooveNew.DLL GrooveNew Module Microsoft Corporation 12.0.6211.1000

GrooveShellExtensions.dll GrooveShellExtensions Module Microsoft Corporation 12.0.6211.1000

GrooveUtil.DLL GrooveUtil Module Microsoft Corporation 12.0.6211.1000

iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.0.6001.18203

IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.0.6001.18000

Iphlpapi.dll IP Helper API Microsoft Corporation 6.0.6001.18000

kernel32.dll Klient-DLL til Windows NT BASE API Microsoft Corporation 6.0.6001.18000

lgscroll.dll Logitech Scroll Enabler (UNICODE) Logitech, Inc. 4.60.122.0

locale.nls

locale.nls

LPK.DLL Language Pack Microsoft Corporation 6.0.6001.18000

mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.0.6.2

MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.0.6000.16386

MSCTF.dll DLL-fil til MSCTF-server Microsoft Corporation 6.0.6001.18000

MSImg32.dll GDIEXT Client DLL Microsoft Corporation 6.0.6000.16386

MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.0.50727.3053

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.6001.18000

mswsock.dll Microsoft Windows Sockets 2.0-tjenesteudbyder Microsoft Corporation 6.0.6001.18000

napinsp.dll Shim-provider til e-mail-navngivning Microsoft Corporation 6.0.6001.18000

NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.0.6001.18000

Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.0.6000.16386

npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.0.6000.16386

NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.0.6001.18000

ntdll.dll DLL til NT-lag Microsoft Corporation 6.0.6001.18000

NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 6.0.6001.18000

ole32.dll Microsoft OLE til Windows Microsoft Corporation 6.0.6001.18000

oleaut32.dll Microsoft Corporation 6.0.6001.18000

pnrpnsp.dll Provider til navneområde for PNRP Microsoft Corporation 6.0.6001.18000

PROPSYS.dll Microsoft Egenskabssystem Microsoft Corporation 7.0.6001.16503

PSAPI.DLL Process Status Helper Microsoft Corporation 6.0.6000.16386

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.0.6000.16386

RPCRT4.dll Kørsel af RPC (Remote Procedure Call) Microsoft Corporation 6.0.6001.18051

rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.0.6001.18000

SAMLIB.dll SAM Library DLL Microsoft Corporation 6.0.6001.18000

Secur32.dll Security Support Provider Interface Microsoft Corporation 6.0.6001.18000

SHELL32.dll Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows Microsoft Corporation 6.0.6001.18167

shfolder.dll Shell Folder Service Microsoft Corporation 6.0.6000.16386

SHLWAPI.dll Shells letvægts-programmappe Microsoft Corporation 6.0.6001.18000

USER32.dll Klient-DLL til Windows USER API til flere brugere Microsoft Corporation 6.0.6001.18000

user32.dll.mui Klient-DLL til Windows USER API til flere brugere Microsoft Corporation 6.0.6001.18000

USERENV.dll Userenv Microsoft Corporation 6.0.6001.18000

USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000

utorrent.exe µTorrent BitTorrent, Inc. 1.8.2.14458

uxtheme.dll Microsoft UxTheme-bibliotek Microsoft Corporation 6.0.6001.18000

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.0.6001.18000

WindowsCodecs.dll Microsoft Windows Codecs Library Microsoft Corporation 6.0.6001.18131

WININET.dll Internetudvidelser til Win32 Microsoft Corporation 7.0.6001.18203

WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.0.6001.18000

winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.0.6000.16386

WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.0.6001.18000

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.0.6001.18000

wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.0.6001.18000

wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.0.6001.18000

Link to comment
Share on other sites

Just a question about that:

GameHook.dll Logitech Gaming Hook (UNICODE) Logitech, Inc. 4.60.122.0

Logitech products are NOT known to be the source of freezing anyway I never see this one.

Is it just a process to manage the display of desktop etc?

Are you running wireless? If yes did you try to update your wifi adapter drivers?

Link to comment
Share on other sites

I'm sort of new at forums, so excuse me if I step out of line here.

I seem to be having the same problem.

I'm not sure if it is uTorrent, or if its part of Explorer, because whenever uTorrent bloats and crashes, explorer goes with it, along with a few other programs.

I have decent Anti: spyware, malware, virus, and spybot protection on my computer, and up until recently, I've never had a problem. I run my checks and full system scans fairly frequently.

I am now using uT v1.9 where before I was using v1.8.2, and it would begin to download, then crash immediately, and if not, within 15 minutes.

After installing v1.9, I've been getting about one hour, maybe two, and then it returns to bloating, freezing, and locking my system.

Like I said, it might not be uT. it may be explorer or some other problem, but explorer goes with it, usually.

At least in my experience so far.

if you want my HJT-log, I'll gladly compare notes with you. just wondering if this helps.

I'm going to try to fix my LSP's and see if that helps.

Edit- My LSP's are in proper working order, and my firewall doesn't affect anything in a negative fashion.

Link to comment
Share on other sites

As I was experiencing this same issue, one of the things I ended up doing, and as of yet, it has worked, was updating my nVidia drivers to the most current. I happen to be using a GeForce8800 GTS..

So, try updating your nVidia drivers. http://www.nvidia.com/Download/index.aspx?lang=en-us

After I did that, all my problems went away.

Everything is running smooth again, and perhaps that may be your problem too.

Give it a go! and good luck! :)

It is suggested that you try that in the initial troubleshooting stickies.. And I recalled that many days later after much hair pulling...

Link to comment
Share on other sites

longshot ideas:

Stuff like this suggests a 'gutted' operating system that's had files ripped out of it that it still NEEDS to run properly:

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

uTorrent doesn't have this:

C:\Program Files\DNA\btdna.exe

...But BitTorrent does.

Search indexers can cause uTorrent all kinds of havoc...though not normally freezing up the whole computer:

SearchIndexer.exe 2848 Microsoft Windows Search Indeksering Microsoft Corporation

SearchProtocolHost.exe 2944 Microsoft Windows Search Protocol Host Microsoft Corporation

SearchFilterHost.exe 696 Microsoft Windows Search Filter Host Microsoft Corporation

Why this is so hard? Because even networking drivers are often extremely buggy:

http://blogs.technet.com/markrussinovich/archive/2008/12/30/3174871.aspx

Link to comment
Share on other sites

uninstalled btdna.exe, and uninstalled and fixed many different things- So i'll post new logs - perhaps something different comes foruth :)

Hijacklog:

Logfile of HijackThis v1.99.1

Scan saved at 18:52:55, on 13/04/2009

Platform: Unknown Windows (WinNT 6.00.1905 SP1)

MSIE: Internet Explorer v7.00 (7.00.6001.18000)

Running processes:

C:\Windows\system32\Dwm.exe

C:\Windows\system32\taskeng.exe

C:\Windows\Explorer.EXE

C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe

C:\Program Files\Java\jre6\bin\jusched.exe

C:\Windows\System32\rundll32.exe

C:\Program Files\Rainlendar2\Rainlendar2.exe

C:\Program Files\Windows Media Player\wmpnscfg.exe

C:\Windows\System32\spool\drivers\w32x86\3\E_FATICDE.EXE

C:\Program Files\BullGuard Ltd\BullGuard\BullGuard.exe

C:\Program Files\Logitech\SetPoint\SetPoint.exe

C:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXE

C:\Program Files\Mozilla Firefox\firefox.exe

C:\Windows\system32\wuauclt.exe

C:\Users\Nivyan\Desktop\utorrent.exe

C:\Windows\system32\SearchFilterHost.exe

F:\HijackThis\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =

R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =

R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local

R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =

O1 - Hosts: ::1 localhost

O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program Files\Microsoft Office\Office12\GrooveShellExtensions.dll

O2 - BHO: Java Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll

O2 - BHO: Hjælp til tilmelding til Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

O2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll

O4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] "C:\Windows\KHALMNPR.EXE"

O4 - HKLM\..\Run: [RtHDVCpl] "C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe"

O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"

O4 - HKLM\..\Run: [bullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe" -boot

O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup

O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit

O4 - HKCU\..\Run: [Rainlendar2] "C:\Program Files\Rainlendar2\Rainlendar2.exe"

O4 - HKCU\..\Run: [WMPNSCFG] "C:\Program Files\Windows Media Player\WMPNSCFG.exe"

O4 - HKCU\..\Run: [EPSON Stylus DX7400 Series] "C:\Windows\system32\spool\DRIVERS\W32X86\3\E_FATICDE.EXE" /FU "C:\Windows\TEMP\E_S495F.tmp" /EF "HKCU"

O4 - HKCU\..\Run: [bullGuard] "C:\Program Files\BullGuard Ltd\BullGuard\bullguard.exe"

O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exe

O8 - Extra context menu item: E&ksporter til Microsoft Excel - res://C:\PROGRA~1\MICROS~4\Office12\EXCEL.EXE/3000

O9 - Extra button: Blog det - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra 'Tools' menuitem: &Blog det i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dll

O9 - Extra button: Send til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

O9 - Extra 'Tools' menuitem: S&end til OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~4\Office12\ONBttnIE.dll

O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\Office12\REFIEBAR.DLL

O10 - Unknown file in Winsock LSP: c:\windows\system32\nlaapi.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\napinsp.dll

O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O10 - Unknown file in Winsock LSP: c:\windows\system32\bglsp.dll

O11 - Options group: [iNTERNATIONAL] International*

O13 - Gopher Prefix:

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program Files\Microsoft Office\Office12\GrooveSystemServices.dll

O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~3\MESSEN~1\MSGRAP~1.DLL

O18 - Protocol: ms-help - {314111C7-A502-11D2-BBCA-00C04F8EC294} - C:\Program Files\Common Files\Microsoft Shared\Help\hxds.dll

O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\WINDOW~3\MESSEN~1\MSGRAP~1.DLL

O18 - Filter hijack: text/xml - {807563E5-5146-11D5-A672-00B0D022E945} - C:\PROGRA~1\COMMON~1\MICROS~1\OFFICE12\MSOXMLMF.DLL

O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exe

O23 - Service: BullGuard LiveUpdate (BgLiveSvc) - BullGuard Ltd. - C:\Program Files\BullGuard Ltd\BullGuard\BullGuardUpdate.exe

O23 - Service: Bonjour-tjeneste (Bonjour Service) - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe

O23 - Service: @%SystemRoot%\ehome\ehstart.dll,-101 (ehstart) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @gpapi.dll,-112 (gpsvc) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: iPod-tjeneste (iPod Service) - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe

O23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exe

O23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exe

O23 - Service: @%SystemRoot%\system32\qwave.dll,-1 (QWAVE) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: @%SystemRoot%\system32\seclogon.dll,-7001 (seclogon) - Unknown owner - %windir%\system32\svchost.exe (file missing)

O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe

O23 - Service: @%ProgramFiles%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - %ProgramFiles%\Windows Media Player\wmpnetwk.exe (file missing)

Process Explorer:

Process PID CPU Description Company Name

System Idle Process 0 100.00

Interrupts n/a Hardware Interrupts

DPCs n/a Deferred Procedure Calls

System 4

smss.exe 528 Windows Session Manager Microsoft Corporation

csrss.exe 596 Klient/server-kørselsproces Microsoft Corporation

wininit.exe 656 Windows-startprogram Microsoft Corporation

services.exe 700 Tjenester og controllerprogrammer Microsoft Corporation

svchost.exe 876 Værtsproces for Windows Tjenester Microsoft Corporation

nvvsvc.exe 936 NVIDIA Driver Helper Service, Version 182.50 NVIDIA Corporation

rundll32.exe 132 Windows værtsproces (Rundll32) Microsoft Corporation

svchost.exe 1000 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 1084 Værtsproces for Windows Tjenester Microsoft Corporation

audiodg.exe 1196 Windows Audio Device Graph Isolation Microsoft Corporation

svchost.exe 1108 Værtsproces for Windows Tjenester Microsoft Corporation

dwm.exe 1328 Styring af skrivebordsvindue Microsoft Corporation

svchost.exe 1120 Værtsproces for Windows Tjenester Microsoft Corporation

taskeng.exe 1900 Programmet Opgavestyring Microsoft Corporation

taskeng.exe 1436 Programmet Opgavestyring Microsoft Corporation

wuauclt.exe 2352 Windows Update Automatic Updates Microsoft Corporation

svchost.exe 1224 Værtsproces for Windows Tjenester Microsoft Corporation

SLsvc.exe 1264 Tjenesten Microsoft Software Licensing Microsoft Corporation

svchost.exe 1336 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 1428 Værtsproces for Windows Tjenester Microsoft Corporation

spoolsv.exe 1656 Spooler SubSystem App Microsoft Corporation

svchost.exe 1684 Værtsproces for Windows Tjenester Microsoft Corporation

AppleMobileDeviceService.exe 2876 Apple Mobile Device Service Apple Inc.

BullGuardUpdate.exe 2892 BullGuard LiveUpdate Service BullGuard Ltd.

svchost.exe 2936 Værtsproces for Windows Tjenester Microsoft Corporation

mDNSResponder.exe 2952 Bonjour Service Apple Inc.

mdm.exe 3000 Machine Debug Manager Microsoft Corporation

svchost.exe 3092 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 3196 Værtsproces for Windows Tjenester Microsoft Corporation

svchost.exe 3244 Værtsproces for Windows Tjenester Microsoft Corporation

SearchIndexer.exe 3296 Microsoft Windows Search Indeksering Microsoft Corporation

SearchProtocolHost.exe 3620 Microsoft Windows Search Protocol Host Microsoft Corporation

wmpnetwk.exe 3724 Windows Media Player Network Sharing Service Microsoft Corporation

lsass.exe 712 LSA-proces (Local Security Authority) Microsoft Corporation

lsm.exe 724 Tjenesten Lokal sessionsstyring Microsoft Corporation

csrss.exe 668 Klient/server-kørselsproces Microsoft Corporation

winlogon.exe 960 Windows-logonprogram Microsoft Corporation

explorer.exe 1316 Windows Stifinder Microsoft Corporation

RtHDVCpl.exe 2268 HD Audio Control Panel Realtek Semiconductor

jusched.exe 2276 Java Platform SE binary Sun Microsystems, Inc.

rundll32.exe 2424 Windows værtsproces (Rundll32) Microsoft Corporation

Rainlendar2.exe 2456 Rainlendar2

wmpnscfg.exe 2496 Konfigurationsprogram til Windows Media Player Network Sharing Service Microsoft Corporation

E_FATICDE.EXE 2528 EPSON Status Monitor 3 SEIKO EPSON CORPORATION

BullGuard.exe 2556 BullGuard BullGuard Ltd.

SetPoint.exe 2564 Logitech SetPoint Event Manager (UNICODE) Logitech, Inc.

KHALMNPR.exe 2640 Logitech KHAL Main Process Logitech, Inc.

firefox.exe 2244 Firefox Mozilla Corporation

utorrent.exe 2780 µTorrent BitTorrent, Inc.

WinRAR.exe 3624 WinRAR archiver Alexander Roshal

procexp.exe 2152 Sysinternals Process Explorer Sysinternals - www.sysinternals.com

Process: utorrent.exe Pid: 2780

Name Description Company Name Version

ADVAPI32.dll Avanceret Windows 32 Base-API Microsoft Corporation 6.0.6001.18000

apphelp.dll Klient-dll til programkompatibilitet Microsoft Corporation 6.0.6001.18000

ATL80.DLL ATL Module for Windows (Unicode) Microsoft Corporation 8.0.50727.762

bglsp.dll BGLsp BullGuard Ltd. 8.5.0.2

browseui.dll Dll-fil til Shell Browser-brugergrænsefladen Microsoft Corporation 6.0.6001.18000

CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.6931.18000

COMCTL32.dll Objektbibliotek til brugeroplevelsen Microsoft Corporation 6.10.6001.18000

comdlg32.dll DLL-fil med fælles dialogbokse Microsoft Corporation 6.0.6001.18000

CRYPT32.dll Crypto API32 Microsoft Corporation 6.0.6001.18000

CSCAPI.dll Offline Files Win32 API Microsoft Corporation 6.0.6001.18000

CSCDLL.dll Offline Files Temporary Shim Microsoft Corporation 6.0.6001.18000

cscui.dll Client Side Caching UI Microsoft Corporation 6.0.6001.18000

dhcpcsvc.DLL Tjenesten DHCP Client Microsoft Corporation 6.0.6001.18000

dhcpcsvc6.DLL DHCPv6-klient Microsoft Corporation 6.0.6001.18000

DnsApi.dll API DLL til DNS-klient Microsoft Corporation 6.0.6001.18000

DUser.dll Internet Explorer UI Engine Microsoft Corporation 6.0.6001.18000

FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.0.6001.18000

GameHook.dll Logitech Gaming Hook (UNICODE) Logitech, Inc. 4.60.122.0

GDI32.dll GDI Client DLL Microsoft Corporation 6.0.6001.18159

GrooveNew.DLL GrooveNew Module Microsoft Corporation 12.0.6211.1000

GrooveShellExtensions.dll GrooveShellExtensions Module Microsoft Corporation 12.0.6211.1000

GrooveUtil.DLL GrooveUtil Module Microsoft Corporation 12.0.6211.1000

iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.0.6001.18203

IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.0.6001.18000

Iphlpapi.dll IP Helper API Microsoft Corporation 6.0.6001.18000

kernel32.dll Klient-DLL til Windows NT BASE API Microsoft Corporation 6.0.6001.18000

lgscroll.dll Logitech Scroll Enabler (UNICODE) Logitech, Inc. 4.60.122.0

locale.nls

locale.nls

LPK.DLL Language Pack Microsoft Corporation 6.0.6001.18000

mdnsNSP.dll Bonjour Namespace Provider Apple Inc. 1.0.6.2

MFC80U.DLL MFCDLL Shared Library - Retail Version Microsoft Corporation 8.0.50727.762

MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.0.6000.16386

MSCTF.dll DLL-fil til MSCTF-server Microsoft Corporation 6.0.6001.18000

MSImg32.dll GDIEXT Client DLL Microsoft Corporation 6.0.6000.16386

MSVCP80.dll Microsoft® C++ Runtime Library Microsoft Corporation 8.0.50727.3053

MSVCR80.dll Microsoft® C Runtime Library Microsoft Corporation 8.0.50727.3053

msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.6001.18000

mswsock.dll Microsoft Windows Sockets 2.0-tjenesteudbyder Microsoft Corporation 6.0.6001.18000

napinsp.dll Shim-provider til e-mail-navngivning Microsoft Corporation 6.0.6001.18000

NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.0.6001.18000

Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.0.6000.16386

npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.0.6000.16386

NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.0.6001.18000

ntdll.dll DLL til NT-lag Microsoft Corporation 6.0.6001.18000

NTMARTA.DLL Windows NT MARTA provider Microsoft Corporation 6.0.6001.18000

ole32.dll Microsoft OLE til Windows Microsoft Corporation 6.0.6001.18000

oleaut32.dll Microsoft Corporation 6.0.6001.18000

PluginHook.dll SpamFilter Outlook Express Plugin BullGuard Ltd. 8.5.0.2

PluginHookRes.dll PluginHookRes Bullguard Software 7.0.0.0

pnrpnsp.dll Provider til navneområde for PNRP Microsoft Corporation 6.0.6001.18000

PROPSYS.dll Microsoft Egenskabssystem Microsoft Corporation 7.0.6001.16503

PSAPI.DLL Process Status Helper Microsoft Corporation 6.0.6000.16386

rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.0.6000.16386

RPCRT4.dll Kørsel af RPC (Remote Procedure Call) Microsoft Corporation 6.0.6001.18051

rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.0.6001.18000

SAMLIB.dll SAM Library DLL Microsoft Corporation 6.0.6001.18000

Secur32.dll Security Support Provider Interface Microsoft Corporation 6.0.6001.18000

SHELL32.dll Dll-fil med fælles dialogbokse til brugergrænsefladen i Windows Microsoft Corporation 6.0.6001.18167

shfolder.dll Shell Folder Service Microsoft Corporation 6.0.6000.16386

SHLWAPI.dll Shells letvægts-programmappe Microsoft Corporation 6.0.6001.18000

USER32.dll Klient-DLL til Windows USER API til flere brugere Microsoft Corporation 6.0.6001.18000

user32.dll.mui Klient-DLL til Windows USER API til flere brugere Microsoft Corporation 6.0.6001.18000

USERENV.dll Userenv Microsoft Corporation 6.0.6001.18000

USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.6001.18000

utorrent.exe µTorrent BitTorrent, Inc. 1.8.2.14458

uxtheme.dll Microsoft UxTheme-bibliotek Microsoft Corporation 6.0.6001.18000

VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.0.6001.18000

WindowsCodecs.dll Microsoft Windows Codecs Library Microsoft Corporation 6.0.6001.18131

WININET.dll Internetudvidelser til Win32 Microsoft Corporation 7.0.6001.18203

WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.0.6001.18000

winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.0.6000.16386

WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.0.6001.18000

WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.0.6001.18000

wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.0.6001.18000

wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.0.6001.18000

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...