aseoi Posted February 25, 2010 Report Share Posted February 25, 2010 Like many others uTorrent 2.0 is hogging all my CPU time and I can't see why! It seems to happen randomly sometimes but I recall that it once happened as soon as I tried to access the WebUI. I disabled WebUI but it still happens randomly. I haven't even downloaded anything for a couple of weeks.The problems started with 2.0 and won't go away even in build 18296.HijackThis:Logfile of Trend Micro HijackThis v2.0.3 (BETA)Scan saved at 23:49:36, on 2010-02-25Platform: Windows XP SP3 (WinNT 5.01.2600)MSIE: Internet Explorer v8.00 (8.00.6001.18702)Boot mode: NormalRunning processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\WINDOWS\system32\svchost.exeC:\Program\AVG\AVG9\avgchsvx.exeC:\Program\AVG\AVG9\avgrsx.exeC:\Program\AVG\AVG9\avgcsrvx.exeC:\WINDOWS\system32\spoolsv.exeC:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeC:\Program\AVG\AVG9\avgwdsvc.exeC:\Program\Bonjour\mDNSResponder.exeC:\Program\FileZilla Server\FileZilla Server.exeC:\Program\Java\jre6\bin\jqs.exeC:\WINDOWS\Explorer.EXEC:\Program\Microsoft LifeCam\MSCamS32.exeC:\Program\CDBurnerXP\NMSAccessU.exeC:\WINDOWS\system32\nvsvc32.exeC:\Program\Microsoft\Search Enhancement Pack\SeaPort\SeaPort.exeC:\WINDOWS\system32\svchost.exeC:\Program\Microsoft Office\Office12\GrooveMonitor.exeC:\Program\Messenger\msmsgs.exeC:\WINDOWS\system32\ctfmon.exeC:\Program\DAEMON Tools Lite\daemon.exeC:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exeC:\Documents and Settings\Sven\Lokala inställningar\Application Data\Google\Update\1.2.183.17\GoogleCrashHandler.exeC:\Program\Samurize\Client.exeC:\Program\SpeedFan\speedfan.exeC:\Program\iPod\bin\iPodService.exeC:\WINDOWS\system32\wscntfy.exeC:\Program\Windows Live\Messenger\msnmsgr.exeC:\Program\Windows Live\Contacts\wlcomm.exeC:\Program\Spotify\spotify.exeC:\Program\uTorrent\uTorrent.exeC:\Documents and Settings\Sven\Lokala inställningar\Application Data\Google\Chrome\Application\chrome.exeC:\Documents and Settings\Sven\Lokala inställningar\Application Data\Google\Chrome\Application\chrome.exeC:\WINDOWS\system32\msiexec.exeC:\Program\TrendMicro\HiJackThis\HiJackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = LänkarO2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program\AVG\AVG9\avgssie.dll (file missing)O2 - BHO: Search Helper - {6EBF7485-159F-4bff-A14F-B9E3AAC4465B} - C:\Program\Microsoft\Search Enhancement Pack\Search Helper\SEPsearchhelperie.dllO2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\Program\Microsoft Office\Office12\GrooveShellExtensions.dllO2 - BHO: Windows Live inloggningshjälpen - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program\Delade filer\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - C:\Program\Google\Google Toolbar\GoogleToolbar_32.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program\Google\GoogleToolbarNotifier\5.5.4723.1820\swg.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program\Java\jre6\bin\jp2ssv.dllO2 - BHO: Windows Live Toolbar Helper - {E15A8DC0-8516-42A1-81EA-DC94EC1ACF10} - C:\Program\Windows Live\Toolbar\wltcore.dllO2 - BHO: FlashFXP Helper for Internet Explorer - {E5A1691B-D188-4419-AD02-90002030B8EE} - C:\Program\FlashFXP\IEFlash.dllO2 - BHO: JQSIEStartDetectorImpl - {E7E6F031-17CE-4C07-BC86-EABFE594F69C} - C:\Program\Java\jre6\lib\deploy\jqs\ie\jqs_plugin.dllO3 - Toolbar: &Windows Live Toolbar - {21FA44EF-376D-4D53-9B0F-8A89D3229068} - C:\Program\Windows Live\Toolbar\wltcore.dllO3 - Toolbar: Google Toolbar - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - C:\Program\Google\Google Toolbar\GoogleToolbar_32.dllO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\WINDOWS\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [VX6000] C:\WINDOWS\vVX6000.exeO4 - HKLM\..\Run: [soundMAXPnP] C:\Program\Analog Devices\Core\smax4pnp.exeO4 - HKLM\..\Run: [soundMAX] "C:\Program\Analog Devices\SoundMAX\Smax4.exe" /trayO4 - HKLM\..\Run: [QuickTime Task] "C:\Program\QuickTime\qttask.exe" -atboottimeO4 - HKLM\..\Run: [nwiz] nwiz.exe /installO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [LifeCam] "C:\Program\Microsoft LifeCam\LifeExp.exe"O4 - HKLM\..\Run: [High Definition Audio Property Page Shortcut] HDAShCut.exeO4 - HKLM\..\Run: [FileZilla Server Interface] "C:\Program\FileZilla Server\FileZilla Server Interface.exe"O4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [iTunesHelper] "C:\Program\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [AVG9_TRAY] C:\Program\AVG\AVG9\avgtray.exeO4 - HKLM\..\Run: [GrooveMonitor] "C:\Program\Microsoft Office\Office12\GrooveMonitor.exe"O4 - HKCU\..\Run: [µTorrent] "C:\Program\uTorrent\utorrent.exe"O4 - HKCU\..\Run: [MSMSGS] "C:\Program\Messenger\msmsgs.exe" /backgroundO4 - HKCU\..\Run: [Google Update] "C:\Documents and Settings\Sven\Lokala inställningar\Application Data\Google\Update\GoogleUpdate.exe" /cO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\Program\DAEMON Tools Lite\daemon.exe" -autorunO4 - HKCU\..\Run: [swg] "C:\Program\Google\GoogleToolbarNotifier\GoogleToolbarNotifier.exe"O4 - HKCU\..\RunOnce: [FlashPlayerUpdate] C:\WINDOWS\system32\Macromed\Flash\NPSWF32_FlashUtil.exe -pO4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'LOKAL TJÄNST')O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')O4 - Startup: Client Default.lnk = C:\Program\Samurize\Client.exeO4 - Startup: SpeedFan.lnk = C:\Program\SpeedFan\speedfan.exeO8 - Extra context menu item: &Search - ?p=ZNxmk570YYSEO8 - Extra context menu item: E&xportera till Microsoft Excel - res://C:\Program\MICROS~2\Office12\EXCEL.EXE/3000O8 - Extra context menu item: Google Sidewiki... - res://C:\Program\Google\Google Toolbar\Component\GoogleToolbarDynamic_mui_en_96D6FF0C6D236BF8.dll/cmsidewiki.htmlO9 - Extra button: Blogga detta - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra 'Tools' menuitem: &Blogga detta i Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra button: Skicka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~2\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: Ski&cka till OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program\MICROS~2\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\Program\MICROS~2\Office12\REFIEBAR.DLLO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exeO9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exeO9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Program\Messenger\msmsgs.exeO16 - DPF: {001EE746-A1F9-460E-80AD-269E088D6A01} (Infotl Control) - http://site.ebrary.com.ezproxy.ub.gu.se/lib/gubselibrary/support/plugins/ebraryRdr.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1264979270984O16 - DPF: {6E32070A-766D-4EE6-879C-DC1FA91D2FC3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1188509150875O18 - Protocol: grooveLocalGWS - {88FED34C-F0CA-4636-A375-3CB6248B04CD} - C:\Program\Microsoft Office\Office12\GrooveSystemServices.dllO20 - Winlogon Notify: avgrsstarter - avgrsstx.dll (file missing)O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dllO22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dllO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program\Delade filer\Apple\Mobile Device Support\bin\AppleMobileDeviceService.exeO23 - Service: AVG Free WatchDog (avg9wd) - AVG Technologies CZ, s.r.o. - C:\Program\AVG\AVG9\avgwdsvc.exeO23 - Service: Bonjour-tjänst (Bonjour Service) - Apple Inc. - C:\Program\Bonjour\mDNSResponder.exeO23 - Service: FileZilla Server FTP server (FileZilla Server) - FileZilla Project - C:\Program\FileZilla Server\FileZilla Server.exeO23 - Service: Tjänsten Google Update (gupdate) (gupdate) - Google Inc. - C:\Program\Google\Update\GoogleUpdate.exeO23 - Service: Google Software Updater (gusvc) - Google - C:\Program\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program\Delade filer\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: iPod Service - Apple Inc. - C:\Program\iPod\bin\iPodService.exeO23 - Service: Java Quick Starter (JavaQuickStarterService) - Sun Microsystems, Inc. - C:\Program\Java\jre6\bin\jqs.exeO23 - Service: NMSAccessU - Unknown owner - C:\Program\CDBurnerXP\NMSAccessU.exeO23 - Service: NVIDIA Display Driver Service (NVSvc) - NVIDIA Corporation - C:\WINDOWS\system32\nvsvc32.exeO23 - Service: ServiceLayer - Nokia. - C:\Program\PC Connectivity Solution\ServiceLayer.exe--End of file - 10444 bytesProcess explorer:Process PID CPU Description Company NameSystem Idle Process 0 95.31 Interrupts n/a Hardware Interrupts DPCs n/a 1.56 Deferred Procedure Calls System 4 1.56 smss.exe 528 Sessionshanteraren i Windows NT Microsoft Corporation csrss.exe 592 Client Server Runtime Process Microsoft Corporation winlogon.exe 616 Inloggningsprogram för Windows NT Microsoft Corporation services.exe 660 Tjänst- och styrenhetsprogram Microsoft Corporation svchost.exe 840 Generic Host Process for Win32 Services Microsoft Corporation wlcomm.exe 3696 Windows Live Communications Platform Microsoft Corporation wmiprvse.exe 2268 WMI Microsoft Corporation svchost.exe 888 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 956 Generic Host Process for Win32 Services Microsoft Corporation wscntfy.exe 1024 Windows Security Center Notification App Microsoft Corporation svchost.exe 992 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1172 Generic Host Process for Win32 Services Microsoft Corporation svchost.exe 1272 Generic Host Process for Win32 Services Microsoft Corporation spoolsv.exe 1520 Spooler SubSystem App Microsoft Corporation svchost.exe 1604 Generic Host Process for Win32 Services Microsoft Corporation AppleMobileDeviceService.exe 1644 Apple Mobile Device Service Apple Inc. avgwdsvc.exe 1656 AVG Watchdog Service AVG Technologies CZ, s.r.o. mDNSResponder.exe 1692 Bonjour Service Apple Inc. FileZilla server.exe 1816 FileZilla Server FileZilla Project jqs.exe 220 Java Quick Starter Service Sun Microsystems, Inc. MSCamS32.exe 484 MsCamSvc.exe Microsoft Corporation NMSAccessU.exe 400 nvsvc32.exe 588 NVIDIA Driver Helper Service, Version 81.85 NVIDIA Corporation SeaPort.exe 980 Microsoft SeaPort Search Enhancement Broker Microsoft Corporation svchost.exe 1244 Generic Host Process for Win32 Services Microsoft Corporation wdfmgr.exe 1472 Windows User Mode Driver Manager Microsoft Corporation alg.exe 3144 Application Layer Gateway Service Microsoft Corporation iPodService.exe 3444 iPodService Module Apple Inc. msiexec.exe 636 Windows® installer Microsoft Corporation lsass.exe 672 LSA Shell (Export Version) Microsoft Corporation avgchsvx.exe 1048 AVG Cache Server AVG Technologies CZ, s.r.o. avgrsx.exe 1056 AVG Resident Shield Service AVG Technologies CZ, s.r.o. avgcsrvx.exe 1264 AVG Scanning Core Module - Server Part AVG Technologies CZ, s.r.o.explorer.exe 312 Utforskaren Microsoft Corporation GrooveMonitor.exe 2324 GrooveMonitor Utility Microsoft Corporation msmsgs.exe 2400 Windows Messenger Microsoft Corporation ctfmon.exe 2460 CTF Loader Microsoft Corporation daemon.exe 2528 DAEMON Tools Lite DT Soft Ltd GoogleToolbarNotifier.exe 2548 GoogleToolbarNotifier Google Inc. Client.exe 2772 Samurize.com speedfan.exe 2892 Almico Software (www.almico.com) msnmsgr.exe 1764 Windows Live Messenger Microsoft Corporation spotify.exe 2888 Spotify Spotify ABGoogleCrashHandler.exe 2584 Google Installer Google Inc.utorrent.exe 2768 µTorrent BitTorrent, Inc. chrome.exe 336 Google Chrome Google Inc. chrome.exe 556 Google Chrome Google Inc. WinRAR.exe 1232 WinRAR archiver Alexander Roshal procexp.exe 1700 1.56 Sysinternals Process Explorer Sysinternals - www.sysinternals.com Link to comment Share on other sites More sharing options...
Firon Posted February 25, 2010 Report Share Posted February 25, 2010 Turn off the 'alternate port' function in the webui and restart. Link to comment Share on other sites More sharing options...
aseoi Posted February 25, 2010 Author Report Share Posted February 25, 2010 Thank you, that did the trick.For anyone else having this problem: I had turned off the WebUI but the alternate port checkbox was still checked. So I turned on WebUI, unchecked the alternate port checkbox, turned off WebUI, shut down uTorrent and then started it again. Then I enabled WebUI again, with the alternate port as well and now everything is dandy.So what's the cause of this anyways? Link to comment Share on other sites More sharing options...
GTHK Posted February 25, 2010 Report Share Posted February 25, 2010 Bad bug Link to comment Share on other sites More sharing options...
aseoi Posted February 27, 2010 Author Report Share Posted February 27, 2010 Actually I noticed the problem was back today. The CPU usage was sky rocketing again and I hadn't even tried to access the WebUI. I'll try turning off the alternate port and see what happens. Link to comment Share on other sites More sharing options...
rafi Posted February 27, 2010 Report Share Posted February 27, 2010 try see if setting gui.transparent_graph_legend to false helps Link to comment Share on other sites More sharing options...
Switeck Posted February 28, 2010 Report Share Posted February 28, 2010 We never did see your Process Explorer DLL list, like the troubleshooting guide asks. If a hostile DLL is deep-linking into utorrent.exe, that could easily cause high cpu use. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.