vovel92 Posted June 18, 2009 Report Share Posted June 18, 2009 So i have a problem with utorrent. it's crash. when i start it, it's begin use memory more and more. For example, when i start it the memory was about 4 MB, but after 1 minute it use 200MB, and then it crash. I uninstal it and install the new late version, but it happens again. OS is Vista. Threre are about 4 torrents that I seed. Here are some screensWhen I start utorrent first time, I see this when open from tray Link to comment Share on other sites More sharing options...
DreadWingKnight Posted June 18, 2009 Report Share Posted June 18, 2009 Post a hijackthis log please. Link to comment Share on other sites More sharing options...
vovel92 Posted June 18, 2009 Author Report Share Posted June 18, 2009 Logfile of Trend Micro HijackThis v2.0.2Scan saved at 19:19:18, on 18.06.2009Platform: Windows Vista SP1 (WinNT 6.00.1905)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Windows\system32\Dwm.exeC:\Fraps\fraps.exeC:\Windows\Explorer.EXEC:\Program Files\Windows Defender\MSASCui.exeC:\Windows\RtHDVCpl.exeC:\Program Files\Stream.AntiVirus\Common\FSM32.EXEC:\Program Files\WebMoney Agent\wmagent.exeC:\Windows\System32\rundll32.exeC:\Program Files\Unlocker\UnlockerAssistant.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Program Files\Windows Media Player\wmpnscfg.exeC:\Program Files\DAEMON Tools Pro\DTProAgent.exeC:\Windows\ehome\ehtray.exeC:\Program Files\Logitech\SetPoint\SetPoint.exeC:\Windows\ehome\ehmsas.exeC:\Program Files\BeholdTV\BeholdTV.exeC:\Program Files\Common Files\Logishrd\KHAL2\KHALMNPR.EXEC:\Program Files\Stream.AntiVirus\FSGUI\fsguidll.exeC:\Windows\System32\mobsync.exeC:\Program Files\Opera\opera.exeC:\Program Files\Miranda IM\miranda32.exeC:\Games\Valve\Steam\Steam.exeC:\Program Files\Adobe\Adobe After Effects CS4\Support Files\AfterFX.exeC:\Program Files\Common Files\Adobe\dynamiclink\processcoordinationserver.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeC:\Program Files\uTorrent\uTorrent.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.APEHA.ruR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Users\EL\AppData\Local\Temp\Rar$EX00.940\tools\bitcometbho.dllO4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hideO4 - HKLM\..\Run: [Kernel and Hardware Abstraction Layer] KHALMNPR.EXEO4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exeO4 - HKLM\..\Run: [F-Secure Manager] "C:\Program Files\Stream.AntiVirus\Common\FSM32.EXE" /splashO4 - HKLM\..\Run: [F-Secure TNB] "C:\Program Files\Stream.AntiVirus\FSGUI\TNBUtil.exe" /CHECKALL /WAITFORSWO4 - HKLM\..\Run: [RivaTunerStartupDaemon] "C:\Program Files\RivaTuner v2.20\RivaTunerWrapper.exe" /SO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [wmagent.exe] "C:\Program Files\WebMoney Agent\wmagent.exe"O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe"O4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunO4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKCU\..\Run: [DAEMON Tools Pro Agent] "C:\Program Files\DAEMON Tools Pro\DTProAgent.exe"O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeO4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'NETWORK SERVICE')O4 - Startup: Behold TV.lnk = C:\Program Files\BeholdTV\BeholdTV.exeO4 - Global Startup: DSLMON.lnk = ?O4 - Global Startup: Logitech SetPoint.lnk = C:\Program Files\Logitech\SetPoint\SetPoint.exeO8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Users\EL\AppData\Local\Temp\Rar$EX00.940\BitComet.exe/AddLink.htmO8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Users\EL\AppData\Local\Temp\Rar$EX00.940\BitComet.exe/AddVideo.htmO8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Users\EL\AppData\Local\Temp\Rar$EX00.940\BitComet.exe/AddAllLink.htmO8 - Extra context menu item: &Экспорт в Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office12\EXCEL.EXE/3000O9 - Extra button: (no name) - {8DAE90AD-4583-4977-9DD4-4360F7A45C74} - (no file)O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\Office12\REFIEBAR.DLLO9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Users\EL\AppData\Local\Temp\Rar$EX00.940\tools\bitcometbho.dll/206 (file missing)O9 - Extra button: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exeO9 - Extra 'Tools' menuitem: ICQ6 - {E59EB121-F339-4851-A3BA-FE49C35617C2} - C:\Program Files\ICQ6.5\ICQ.exeO13 - Gopher Prefix: O16 - DPF: {463ED66E-431B-11D2-ADB0-0080C83DA4EB} (AcceptWM Class) - https://w3s.webmoney.ru/WMAcceptor.dllO16 - DPF: {D0C0F75C-683A-4390-A791-1ACFD5599AB8} (Oberon Flash Game Host) - http://icq.oberon-media.com/Gameshell/GameHost/1.0/OberonGameHost.cabO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{7CC99919-6AF4-4C97-8F90-34619095C044}: NameServer = 195.34.32.116 212.188.4.10O22 - SharedTaskScheduler: Windows DreamScene - {E31004D1-A431-41B8-826F-E902F9D95C81} - C:\Windows\System32\DreamScene.dllO23 - Service: @dfsrres.dll,-101 (DFSR) - Корпорация Майкрософт - C:\Windows\system32\DFSR.exeO23 - Service: FSGKHS (F-Secure Gatekeeper Handler Starter) - F-Secure Corporation - C:\Program Files\Stream.AntiVirus\Anti-Virus\fsgk32st.exeO23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: F-Secure Automatic Update Agent (FSAUA) - F-Secure Corporation - C:\Program Files\Stream.AntiVirus\FSAUA\program\fsaua.exeO23 - Service: F-Secure Anti-Virus Firewall Daemon (FSDFWD) - F-Secure Corporation - C:\Program Files\Stream.AntiVirus\FWES\Program\fsdfwd.exeO23 - Service: FSMA - F-Secure Corporation - C:\Program Files\Stream.AntiVirus\Common\FSMA32.EXEO23 - Service: F-Secure ORSP Client (FSORSPClient) - F-Secure Corporation - C:\Program Files\Stream.AntiVirus\ORSP Client\fsorsp.exeO23 - Service: Hamachi Service (HamachiService) - LogMeIn Inc. - C:\Program Files\Hamachi\hamachi.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: Logitech Bluetooth Service (LBTServ) - Logitech, Inc. - C:\Program Files\Common Files\Logishrd\Bluetooth\LBTServ.exeO23 - Service: Nero BackItUp Scheduler 3 - Nero AG - C:\Program Files\Nero\Nero8\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Nero\Lib\NMIndexingService.exeO23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exeO23 - Service: PLFlash DeviceIoControl Service - Prolific Technology Inc. - C:\Windows\system32\IoctlSvc.exeO23 - Service: PnkBstrA - Unknown owner - C:\Windows\system32\PnkBstrA.exeO23 - Service: Steam Client Service - Valve Corporation - C:\Program Files\Common Files\Steam\SteamService.exe--End of file - 8088 bytes Link to comment Share on other sites More sharing options...
moogly Posted June 18, 2009 Report Share Posted June 18, 2009 Maybe a module of F-Secure is the culprit.Can you add Process Explorer log when uT is running please.Don't forget to select utorrent.exe and enable DLL mode (ctrl+d).Guide: http://forum.utorrent.com/viewtopic.php?id=29748 Link to comment Share on other sites More sharing options...
vovel92 Posted June 18, 2009 Author Report Share Posted June 18, 2009 I think, I solve a problem... F-Secure is the module of my anti-virus program. I turned off all options of it and the utorrent use less of memory. When it's seeding it use 4 MB, when downloading it use 20-35 MB. Is it normal?Here a log of Process Explorer with a running uTorrentProcess PID CPU Description Company NameSystem Idle Process 0 87.78 Interrupts n/a 0.77 Hardware Interrupts DPCs n/a 4.62 Deferred Procedure Calls System 4 smss.exe 496 Windows Session Manager Microsoft Corporationcsrss.exe 568 Процесс исполнения клиент-сервер Microsoft Corporationwininit.exe 620 Автозагрузка приложений Windows Microsoft Corporation services.exe 664 Приложение служб и контроллеров Microsoft Corporation svchost.exe 880 Хост-процесс для служб Windows Microsoft Corporation mobsync.exe 2668 Microsoft Sync Center Microsoft Corporation processcoordinationserver.exe 2920 processcoordinationserver Adobe Systems Incorporated nvvsvc.exe 924 NVIDIA Driver Helper Service, Version 182.50 NVIDIA Corporation rundll32.exe 1612 Хост-процесс Windows (Rundll32) Microsoft Corporation svchost.exe 952 Хост-процесс для служб Windows Microsoft Corporation svchost.exe 996 Хост-процесс для служб Windows Microsoft Corporation svchost.exe 1136 Хост-процесс для служб Windows Microsoft Corporation audiodg.exe 1260 Изоляция графиков аудиоустройств Windows Microsoft Corporation svchost.exe 1164 Хост-процесс для служб Windows Microsoft Corporation dwm.exe 1020 0.77 Диспетчер рабочего стола Microsoft Corporation svchost.exe 1200 Хост-процесс для служб Windows Microsoft Corporation taskeng.exe 812 Обработчик планировщика заданий Microsoft Corporation fraps.exe 1712 Fraps Beepa P/L taskeng.exe 5232 Обработчик планировщика заданий Microsoft Corporation svchost.exe 1288 Хост-процесс для служб Windows Microsoft Corporation SLsvc.exe 1336 Служба лицензирования программного обеспечения Майкрософт Microsoft Corporation svchost.exe 1368 Хост-процесс для служб Windows Microsoft Corporation svchost.exe 1628 Хост-процесс для служб Windows Microsoft Corporation spoolsv.exe 1824 Диспетчер очереди печати Microsoft Corporation svchost.exe 1848 Хост-процесс для служб Windows Microsoft Corporation svchost.exe 2660 Хост-процесс для служб Windows Microsoft Corporation fsgk32st.exe 2684 F-Secure Anti-Virus Scanning Service F-Secure Corporation fsgk32.exe 2708 Gatekeeper Handler II F-Secure Corporation fssm32.exe 3440 F-Secure Scanner Manager F-Secure Corporation FSMA32.EXE 2716 F-Secure Management Agent F-Secure Corporation FSMB32.EXE 2908 F-Secure Message Broker F-Secure Corporation FCH32.EXE 3316 F-Secure Configuration Handler F-Secure Corporation fsqh.exe 3416 F-Secure Quarantine Handler F-Secure Corporation FAMEH32.EXE 3500 F-Secure Alert and Management Extension Handler F-Secure Corporation fsav32.exe 4424 FSAV Handler F-Secure Corporation NBService.exe 2980 Nero BackItUp Nero AG IoctlSvc.exe 3040 PLFlash DeviceIoControl Service Prolific Technology Inc. PnkBstrA.exe 3060 svchost.exe 3072 Хост-процесс для служб Windows Microsoft Corporation svchost.exe 3096 Хост-процесс для служб Windows Microsoft Corporation svchost.exe 3140 Хост-процесс для служб Windows Microsoft Corporation SearchIndexer.exe 3172 Индексатор службы Microsoft Windows Search Microsoft Corporation wmpnetwk.exe 2280 Служба общих сетевых ресурсов проигрывателя Windows Media Microsoft Corporation ehsched.exe 2364 Служба планировщика Windows Media Center Microsoft Corporation fsaua.exe 2156 F-Secure Automatic Update Agent F-Secure Corporation fsorsp.exe 1072 F-Secure ORSP Service F-Secure Corporation fsdfwd.exe 2880 F-Secure Internet Shield daemon F-Secure Corporation alg.exe 904 Служба шлюза уровня приложения Microsoft Corporation ehrecvr.exe 5160 Служба ресивера Windows Media Center Microsoft Corporation SteamService.exe 5356 Steam Client Service Valve Corporation FNPLicensingService.exe 5696 Activation Licensing Service Acresso Software Inc. lsass.exe 680 Процесс локального администратора безопасности Microsoft Corporation lsm.exe 688 Служба диспетчера локальных сеансов Microsoft Corporationcsrss.exe 632 Процесс исполнения клиент-сервер Microsoft Corporationwinlogon.exe 768 Программа входа в систему Windows Microsoft Corporation taskmgr.exe 9584 Диспетчер задач Windows Microsoft Corporationexplorer.exe 1768 Проводник Microsoft Corporation MSASCui.exe 1400 Windows Defender User Interface Microsoft Corporation RtHDVCpl.exe 2056 HD Audio Control Panel Realtek Semiconductor FSM32.EXE 2064 F-Secure Settings and Statistics F-Secure Corporation fsguidll.exe 3716 F-Secure GUI component F-Secure Corporation wmagent.exe 2288 rundll32.exe 2304 Хост-процесс Windows (Rundll32) Microsoft Corporation UnlockerAssistant.exe 2320 sidebar.exe 2472 1.54 Боковая панель Windows Microsoft Corporation wmpnscfg.exe 2488 Приложение конфигурации службы общих сетевых ресурсов проигрывателя Windows Media Microsoft Corporation DTProAgent.exe 2500 DAEMON Tools Pro Tray Application DT Soft Ltd. SetPoint.exe 2548 Logitech SetPoint Event Manager (UNICODE) Logitech, Inc. KHALMNPR.exe 3676 Logitech KHAL Main Process Logitech, Inc. BeholdTV.exe 2828 Behold TV Beholder opera.exe 5044 Opera Internet Browser Opera Software miranda32.exe 4220 Miranda IM Steam.exe 2368 Steam Valve Corporation AfterFX.exe 3212 Adobe After Effects CS4 Adobe Systems Incorporated procexp.exe 9324 3.85 Sysinternals Process Explorer Sysinternals - www.sysinternals.com uTorrent.exe 4712 0.77 µTorrent BitTorrent, Inc.fsus.exe 2208 F-Secure Automatic Update Agent - Run Upstreamer F-Secure CorporationHijackThis.exe 4908 HijackThis Trend Micro Inc. notepad.exe 2948 Блокнот Microsoft Corporationfsavaui.exe 9768 Advanced User Interface F-Secure CorporationProcess: uTorrent.exe Pid: 4712Name Path SizeADVAPI32.dll C:\Windows\system32\ADVAPI32.dll 0xC6000C_1252.NLS C:\Windows\System32\C_1252.NLS 0x11000CLBCatQ.DLL C:\Windows\system32\CLBCatQ.DLL 0x84000COMCTL32.dll C:\Windows\WinSxS\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.6001.18000_none_5cdbaa5a083979cc\COMCTL32.dll 0x19E000comdlg32.dll C:\Windows\system32\comdlg32.dll 0x73000dhcpcsvc.DLL C:\Windows\system32\dhcpcsvc.DLL 0x35000dhcpcsvc6.DLL C:\Windows\system32\dhcpcsvc6.DLL 0x21000DnsApi.dll C:\Windows\system32\DnsApi.dll 0x2C000FirewallAPI.dll C:\Windows\system32\FirewallAPI.dll 0x66000FRAPS.DLL C:\Fraps\FRAPS.DLL 0x34000fsgkiapi.dll c:\program files\stream.antivirus\scanner-interface\fsgkiapi.dll 0x17000fslsp.dll C:\Program Files\Stream.AntiVirus\FSPS\program\fslsp.dll 0x30000GDI32.dll C:\Windows\system32\GDI32.dll 0x4B000IMM32.DLL C:\Windows\system32\IMM32.DLL 0x1E000Iphlpapi.dll C:\Windows\system32\Iphlpapi.dll 0x19000kernel32.dll C:\Windows\system32\kernel32.dll 0xDB000lgscroll.dll C:\Program Files\Logitech\SetPoint\lgscroll.dll 0xE000locale.nls C:\Windows\System32\locale.nls 0x37F000locale.nls C:\Windows\System32\locale.nls 0x37F000LPK.DLL C:\Windows\system32\LPK.DLL 0x9000MSCTF.dll C:\Windows\system32\MSCTF.dll 0xC8000MSVCR80.dll C:\Windows\WinSxS\x86_microsoft.vc80.crt_1fc8b3b9a1e18e3b_8.0.50727.3053_none_d08d7bba442a9b36\MSVCR80.dll 0x9B000msvcrt.dll C:\Windows\system32\msvcrt.dll 0xAA000mswsock.dll C:\Windows\system32\mswsock.dll 0x3B000napinsp.dll C:\Windows\system32\napinsp.dll 0xF000NLAapi.dll C:\Windows\system32\NLAapi.dll 0xF000npmproxy.dll C:\Windows\System32\npmproxy.dll 0x8000NSI.dll C:\Windows\system32\NSI.dll 0x6000ntdll.dll C:\Windows\system32\ntdll.dll 0x127000NTMARTA.DLL C:\Windows\system32\NTMARTA.DLL 0x21000ole32.dll C:\Windows\system32\ole32.dll 0x144000oleaut32.dll C:\Windows\system32\oleaut32.dll 0x8D000pnrpnsp.dll C:\Windows\system32\pnrpnsp.dll 0x12000PSAPI.DLL C:\Windows\system32\PSAPI.DLL 0x7000rasadhlp.dll C:\Windows\system32\rasadhlp.dll 0x6000RPCRT4.dll C:\Windows\system32\RPCRT4.dll 0xC2000rsaenh.dll C:\Windows\system32\rsaenh.dll 0x3B000SAMLIB.dll C:\Windows\system32\SAMLIB.dll 0x11000Secur32.dll C:\Windows\system32\Secur32.dll 0x14000SETUPAPI.dll C:\Windows\system32\SETUPAPI.dll 0x18A000SHELL32.dll C:\Windows\system32\SHELL32.dll 0xB10000shfolder.dll C:\Windows\system32\shfolder.dll 0x5000SHLWAPI.dll C:\Windows\system32\SHLWAPI.dll 0x58000UnlockerHook.dll C:\Program Files\Unlocker\UnlockerHook.dll 0x4000USER32.dll C:\Windows\system32\USER32.dll 0x9D000USERENV.dll C:\Windows\system32\USERENV.dll 0x1E000USP10.dll C:\Windows\system32\USP10.dll 0x7D000uTorrent.exe C:\Program Files\uTorrent\uTorrent.exe 0xB4000uxtheme.dll C:\Windows\system32\uxtheme.dll 0x3F000VERSION.dll C:\Windows\system32\VERSION.dll 0x8000WINNSI.DLL C:\Windows\system32\WINNSI.DLL 0x7000winrnr.dll C:\Windows\System32\winrnr.dll 0x8000WLDAP32.dll C:\Windows\system32\WLDAP32.dll 0x4A000WS2_32.dll C:\Windows\system32\WS2_32.dll 0x2D000wshbth.dll C:\Windows\system32\wshbth.dll 0xC000wship6.dll C:\Windows\System32\wship6.dll 0x5000wshtcpip.dll C:\Windows\System32\wshtcpip.dll 0x5000 Link to comment Share on other sites More sharing options...
moogly Posted June 18, 2009 Report Share Posted June 18, 2009 fsgkiapi.dll fslsp.dll That sounds like the residential protection of F-Secure uses a lot of memory. Maybe try to exclude the uT download folder from F-secure scanning. Link to comment Share on other sites More sharing options...
vovel92 Posted June 18, 2009 Author Report Share Posted June 18, 2009 Ok, thanks a lot! Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.