Inferno.o Posted October 4, 2009 Report Share Posted October 4, 2009 Hey guys,Lately, uTorrent 1.8.4 has started to freeze my entire system upon downloading. Scanned computer for viruses, adware, spyware. Nothing. Cleaned registry and old compressed files. Defragged as well. Any help is appreciated. Thanks.Logfile of Trend Micro HijackThis v2.0.2Scan saved at 9:54:49 PM, on 10/3/2009Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\nvsvc32.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\spoolsv.exeC:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exeC:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exeC:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeC:\WINDOWS\Explorer.EXEC:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exeC:\WINDOWS\system32\oodag.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\wuauclt.exeC:\WINDOWS\system32\RUNDLL32.EXEC:\Program Files\ESET\ESET NOD32 Antivirus\egui.exeC:\WINDOWS\RTHDCPL.EXEC:\Program Files\Rainlendar2\Rainlendar2.exeC:\WINDOWS\system32\ctfmon.exeC:\Program Files\Lavalys\EVEREST Ultimate Edition\everest.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\AIM6\aim6.exeC:\Program Files\AIM6\aolsoftware.exeC:\Program Files\Windows Live\Messenger\usnsvc.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.gmail.com/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localO2 - BHO: SnagIt Toolbar Loader - {00C6482D-C502-44C8-8409-FCE54AD9C208} - C:\Program Files\TechSmith\SnagIt 9\SnagItBHO.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO3 - Toolbar: SnagIt - {8FF5E183-ABDE-46EB-B09E-D2AAB95CABE3} - C:\Program Files\TechSmith\SnagIt 9\SnagItIEAddin.dllO3 - Toolbar: (no name) - {DE9C389F-3316-41A7-809B-AA305ED9D922} - (no file)O4 - HKLM\..\Run: [MSPY2002] C:\WINDOWS\system32\IME\PINTLGNT\ImScInst.exe /SYNCO4 - HKLM\..\Run: [PHIME2002ASync] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /SYNCO4 - HKLM\..\Run: [PHIME2002A] C:\WINDOWS\system32\IME\TINTLGNT\TINTSETP.EXE /IMENameO4 - HKLM\..\Run: [nwiz] C:\Program Files\NVIDIA Corporation\nView\nwiz.exe /installO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitserviceO4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXEO4 - HKCU\..\Run: [Rainlendar2] C:\Program Files\Rainlendar2\Rainlendar2.exeO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [EVEREST AutoStart] C:\Program Files\Lavalys\EVEREST Ultimate Edition\everest.exeO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [Aim6] "C:\Program Files\AIM6\aim6.exe" /d locale=en-US ee://aol/imAppO4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_05\bin\ssv.dllO9 - Extra button: PokerStars - {3AD14F0C-ED16-4e43-B6D8-661B03F6A1EF} - C:\Program Files\PokerStars\PokerStarsUpdate.exeO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program Files\Messenger\msmsgs.exeO16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: ANIWZCSd Service (ANIWZCSdService) - Wireless Service - C:\Program Files\ANI\ANIWZCS2 Service\ANIWZCSdS.exeO23 - Service: Apple Mobile Device - Apple, Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exeO23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exeO23 - Service: GEST Service for program management. (GEST Service) - Unknown owner - C:\Program Files\GIGABYTE\GEST\GSvr.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: MBAMService - Malwarebytes Corporation - C:\Program Files\Malwarebytes' Anti-Malware\mbamservice.exeO23 - Service: Nero BackItUp Scheduler 4.0 - Nero AG - C:\Program Files\Common Files\Nero\Nero BackItUp 4\NBService.exeO23 - Service: NMIndexingService - Unknown owner - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exe (file missing)O23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: O&O Defrag - O&O Software GmbH - C:\WINDOWS\system32\oodag.exe--End of file - 6671 bytes Link to comment Share on other sites More sharing options...
GTHK Posted October 4, 2009 Report Share Posted October 4, 2009 You may want to look into this: http://spywarefiles.prevx.com/RRCFDI24268863/RAINLENDAR2.EXE.html Link to comment Share on other sites More sharing options...
Inferno.o Posted October 5, 2009 Author Report Share Posted October 5, 2009 Thanks for the suggestion GTHK. I've downloaded and ran the prog and scanned my comp. No malware was found.Any other suggestions? Thanks. Link to comment Share on other sites More sharing options...
GTHK Posted October 5, 2009 Report Share Posted October 5, 2009 What prog, the Prevx CSI? Do you know what that Rainlender2 is? Also, Service Pack 3 is recommended, it usually has a noticeable increase on a computers performance. Are you running two AV's at once? That's usually a bad idea. Link to comment Share on other sites More sharing options...
Inferno.o Posted October 5, 2009 Author Report Share Posted October 5, 2009 Yes, the Prevx. The Rainlendar program is a calendar application where I use to store important dates, and to-do lists. I will give SP3 a shot. As for two AV's, are you referring to NOD and Malwarebytes? Link to comment Share on other sites More sharing options...
GTHK Posted October 5, 2009 Report Share Posted October 5, 2009 Yeah. I know MBAM's active component is paid for and optional, not sure if you can tell from just PE/HJT which is which though. Link to comment Share on other sites More sharing options...
Inferno.o Posted October 5, 2009 Author Report Share Posted October 5, 2009 The thing is, the freezing has been occuring prior to me installing MBAM. Any other suggestions up your sleeve GTHK, or any other member out there? Thanks. Link to comment Share on other sites More sharing options...
GTHK Posted October 5, 2009 Report Share Posted October 5, 2009 Hmmmmmm, define/describe freeze. Got SP3? A Process Explorer with DLL list? And finally update all the drivers you can, 'specially networking. Link to comment Share on other sites More sharing options...
Inferno.o Posted October 5, 2009 Author Report Share Posted October 5, 2009 Freeze would occur when uTorrent is loaded and is leeching/seeding. In a matter of minutes, system would lock up, Ctrl+Alt+Del will not work. Nums Lock, Caps Lock frozen, only a hard reboot will solve the problem.I have since updated BIOS, mobo drivers, graphics drivers, any critical windows updates (with the exception of SP3)As for networking, you mean drivers for my router? My D-Link AirPlus ExtremeG DWL-G132 has since been discontinued, but I have updated the last available driver provided by the company site.This system I built last year. Link to comment Share on other sites More sharing options...
GTHK Posted October 5, 2009 Report Share Posted October 5, 2009 Hm, it's not uncommon for hardware issues to be exacerbated by µTorrent. Network cards for example tend to cause BSOD's when the drivers suck, and appear/become more frequent when being taxed. Do you happen to have any files in C:\Windows\Minidump ?Networking drivers as in the NIC drivers for the computer. You could also try conservative settings:http://www.utorrent.com/setup_guide.phphttp://forum.utorrent.com/viewtopic.php?id=15992https://forum.utorrent.com/viewtopic.php?id=58404 Link to comment Share on other sites More sharing options...
Inferno.o Posted October 5, 2009 Author Report Share Posted October 5, 2009 I'm updating to SP3 as we speak. There is one file in the Minidump folder that was created 2 days ago on 10/3. As for networking drivers, how do I know what I have and where do I go to find the drivers? Thanks. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.