future_freezer Posted August 14, 2010 Report Posted August 14, 2010 HelloI have problem with uTorrent version 2.0.3 on my Windows 7 professional. I use utorrent for some time, but the problem appeared only a few days. When I run the program, after a few minutes the application hangs and it is suspended. It does not help re-install uTorrent or reboot the system. does not help also disables antivirus (I use Panda). When i kill the uTorrent process i still see it on task manager - and i can't disable it.Please help in solving this problem
moogly Posted August 14, 2010 Report Posted August 14, 2010 Run µT and post logs (Hijackthis and Process Explorer).Guide: http://forum.utorrent.com/viewtopic.php?id=29748
future_freezer Posted August 14, 2010 Author Report Posted August 14, 2010 Logfile of Trend Micro HijackThis v2.0.4Scan saved at 20:40:13, on 2010-08-14Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Program Files\uTorrent\uTorrent.exeC:\Windows\system32\Dwm.exeC:\Windows\system32\taskhost.exeC:\Windows\Explorer.EXEC:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exeC:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exeC:\Program Files\Windows Sidebar\sidebar.exeC:\Users\freezer\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\freezer\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\freezer\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\freezer\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\uTorrent\uTorrent.exeC:\Users\freezer\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\Trend Micro\HiJackThis\HiJackThis.exeR0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.onet.pl/R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 5.0\Reader\ActiveX\AcroIEHelper.ocxO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: IEPluginBHO - {F5CC7F02-6F4E-4462-B5B1-394A57FD3E0D} - C:\Users\freezer\AppData\Roaming\Nowe Gadu-Gadu\_userdata\ggbho.1.dllO4 - HKLM\..\Run: [JMB36X IDE Setup] C:\Windows\RaidTool\xInsIDE.exeO4 - HKLM\..\Run: [PSUNMain] "C:\Program Files\Panda Security\Panda Cloud Antivirus\PSUNMain.exe" /TraybarO4 - HKLM\..\Run: [RtHDVCpl] C:\Program Files\Realtek\Audio\HDA\RtHDVCpl.exe -sO4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunO4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA LOKALNA')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'USŁUGA SIECIOWA')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'USŁUGA SIECIOWA')O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\Windows\system32\GPhotos.scr/200O8 - Extra context menu item: E&ksportuj do programu Microsoft Excel - res://C:\PROGRA~1\MICROS~1\Office12\EXCEL.EXE/3000O9 - Extra button: Wyślij do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dllO9 - Extra 'Tools' menuitem: Wyślij &do programu OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\PROGRA~1\MICROS~1\Office12\ONBttnIE.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~1\Office12\REFIEBAR.DLLO12 - Plugin for .spop: C:\Program Files\Internet Explorer\Plugins\NPDocBox.dllO16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cabO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Firebird Server - MAGIX Instance (FirebirdServerMAGIXInstance) - MAGIX® - C:\Program Files\MAGIX\Common\Database\bin\fbserver.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1050\Intel 32\IDriverT.exeO23 - Service: Panda Cloud Antivirus Service (NanoServiceMain) - Panda Security, S.L. - C:\Program Files\Panda Security\Panda Cloud Antivirus\PSANHost.exeO23 - Service: NMSAccessU - Unknown owner - C:\Program Files\CDBurnerXP\NMSAccessU.exeO23 - Service: NVIDIA Display Driver Service (nvsvc) - NVIDIA Corporation - C:\Windows\system32\nvvsvc.exeO23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe--End of file - 5035 bytes
future_freezer Posted August 14, 2010 Author Report Posted August 14, 2010 Process PID CPU Private Bytes Working Set Description Company NameDPCs n/a 0 K 0 K Deferred Procedure Calls Interrupts n/a 0 K 0 K Hardware Interrupts System Idle Process 0 96.23 0 K 24 K System 4 52 K 2 868 K smss.exe 384 260 K 812 K NMSAccessU.exe 1704 588 K 2 156 K nvvsvc.exe 856 984 K 3 756 K NVIDIA Driver Helper Service, Version 258.96 NVIDIA Corporationsvchost.exe 1812 1 076 K 4 220 K Proces hosta dla usług systemu Windows Microsoft Corporationwininit.exe 584 1 152 K 3 728 K csrss.exe 516 1 284 K 3 172 K alg.exe 2200 1 296 K 4 172 K Usługa bramy warstwy aplikacji Microsoft Corporationsvchost.exe 1452 1 492 K 4 972 K Proces hosta dla usług systemu Windows Microsoft Corporationlsm.exe 696 1 516 K 3 328 K csrss.exe 2080 1 540 K 7 220 K csrss.exe 576 1 696 K 6 344 K winlogon.exe 4024 1 796 K 5 012 K nvSCPAPISvr.exe 1764 1 896 K 4 788 K Stereo Vision Control Panel API Server NVIDIA Corporationtaskhost.exe 1748 2 544 K 6 276 K Proces hosta dla zadań systemu Windows Microsoft Corporationsvchost.exe 792 2 824 K 6 840 K Proces hosta dla usług systemu Windows Microsoft Corporationsvchost.exe 896 2 824 K 5 688 K Proces hosta dla usług systemu Windows Microsoft Corporationlsass.exe 688 3 460 K 8 676 K Local Security Authority Process Microsoft Corporationnvvsvc.exe 1212 3 560 K 7 948 K svchost.exe 1020 3 780 K 9 508 K Proces hosta dla usług systemu Windows Microsoft Corporationsvchost.exe 1848 4 188 K 7 208 K Proces hosta dla usług systemu Windows Microsoft Corporationservices.exe 680 4 684 K 7 568 K HiJackThis.exe 1904 4 700 K 13 532 K svchost.exe 1184 5 168 K 8 508 K Proces hosta dla usług systemu Windows Microsoft CorporationPSUNMain.exe 2984 6 048 K 2 148 K Panda Cloud Antivirus Panda Security, S.L.RtHDVCpl.exe 3024 7 472 K 8 340 K Menedżer Realtek HD Audio Realtek Semiconductorsvchost.exe 1400 11 308 K 12 516 K Proces hosta dla usług systemu Windows Microsoft Corporationprocexp.exe 3528 3.88 13 900 K 31 724 K Sysinternals Process Explorer Sysinternals - www.sysinternals.comsvchost.exe 988 14 652 K 14 324 K Proces hosta dla usług systemu Windows Microsoft Corporationchrome.exe 2464 14 740 K 22 824 K Google Chrome Google Inc.svchost.exe 1044 15 620 K 28 616 K Proces hosta dla usług systemu Windows Microsoft Corporationsvchost.exe 1284 16 376 K 19 584 K Proces hosta dla usług systemu Windows Microsoft CorporationuTorrent.exe 3180 19 028 K 26 308 K uTorrent.exe 1864 19 456 K 28 108 K dwm.exe 1448 23 124 K 23 024 K Menedżer okien pulpitu Microsoft Corporationexplorer.exe 2448 30 432 K 45 676 K Eksplorator Windows Microsoft Corporationchrome.exe 2780 30 632 K 46 320 K Google Chrome Google Inc.sidebar.exe 2600 33 092 K 26 668 K Gadżety pulpitu systemu Windows Microsoft Corporationgg.exe 2116 44 324 K 33 112 K Gadu-Gadu - program główny Gadu-Gadu S.A.PSANHost.exe 1644 44 348 K 19 600 K Application Host Service Panda Security, S.L.svchost.exe 3660 66 380 K 24 876 K Proces hosta dla usług systemu Windows Microsoft Corporation
paintball9 Posted August 14, 2010 Report Posted August 14, 2010 Try disabling panda antivirusAlso you've got 2 instances of utorrent running. close them both and try again.
future_freezer Posted August 14, 2010 Author Report Posted August 14, 2010 i can't close both of utorrent instances there is - acces denied msg when i try kill one of them
moogly Posted August 14, 2010 Report Posted August 14, 2010 In PE, you need to select utorrent.exe and enable DLL mode (ctrl+D).Edit PE log please.
regietron Posted August 14, 2010 Report Posted August 14, 2010 help!!when i play back an uncompleted movie torrent download. what i see is an existing movie on my system or a movie i had previously deleted. is this normal or will the actual movie show upon completion of the download
future_freezer Posted August 14, 2010 Author Report Posted August 14, 2010 Process: uTorrent.exe Pid: 3180Name Description Company Name VersionAcGenral.DLL Windows Compatibility DLL Microsoft Corporation 6.1.7600.16385AcLayers.dll Windows Compatibility DLL Microsoft Corporation 6.1.7600.16385AcXtrnal.DLL Windows Compatibility DLL Microsoft Corporation 6.1.7600.16385ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.1.7600.16385apphelp.dll Biblioteka klienta zgodności aplikacji Microsoft Corporation 6.1.7600.16481C_1252.NLS CFGMGR32.dll Configuration Manager DLL Microsoft Corporation 6.1.7600.16385CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.8530.16385COMCTL32.dll Biblioteka formantów czynności użytkownika Microsoft Corporation 6.10.7600.16385comdlg32.dll Plik DLL wspólnych okien dialogowych Microsoft Corporation 6.1.7600.16385CRYPT32.dll Crypto API32 Microsoft Corporation 6.1.7600.16385CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.1.7600.16385CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.1.7600.16385DEVOBJ.dll Device Information Set DLL Microsoft Corporation 6.1.7600.16385dhcpcsvc.DLL Usługa klienta DHCP Microsoft Corporation 6.1.7600.16385dhcpcsvc6.DLL Klient DHCPv6 Microsoft Corporation 6.1.7600.16385DnsApi.dll Biblioteka DLL interfejsu API klienta usługi DNS Microsoft Corporation 6.1.7600.16385dwmapi.dll Interfejs API menedżera okien Microsoft Desktop Window Manager Microsoft Corporation 6.1.7600.16385FirewallAPI.dll Interfejs API Zapory systemu Windows Microsoft Corporation 6.1.7600.16385fwpuclnt.dll Interfejs API trybu użytkownika funkcji FWP/IPSec Microsoft Corporation 6.1.7600.16385GDI32.dll GDI Client DLL Microsoft Corporation 6.1.7600.16385iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.0.7600.16385IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.1.7600.16385index.dat index.dat index.dat Iphlpapi.dll IP Helper API Microsoft Corporation 6.1.7600.16385kernel32.dll Biblioteka DLL klienta Windows NT BASE API Microsoft Corporation 6.1.7600.16481KERNELBASE.dll Biblioteka DLL klienta Windows NT BASE API Microsoft Corporation 6.1.7600.16385KernelBase.dll.mui Biblioteka DLL klienta Windows NT BASE API Microsoft Corporation 6.1.7600.16385locale.nls LPK.dll Language Pack Microsoft Corporation 6.1.7600.16385MPR.dll Multiple Provider Router DLL Microsoft Corporation 6.1.7600.16385MSACM32.dll Filtr audio ACM Microsoft Microsoft Corporation 6.1.7600.16385MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.1.7600.16415MSCTF.dll Biblioteka DLL serwera MSCTF Microsoft Corporation 6.1.7600.16385msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.7600.16385mswsock.dll Microsoft Windows Sockets 2.0 Dostawca usługi Microsoft Corporation 6.1.7600.16385napinsp.dll Dostawca podkładek nazewnictwa poczty e-mail Microsoft Corporation 6.1.7600.16385NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.1.7600.16385Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.1.7600.16385npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.1.7600.16385NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.1.7600.16385ntdll.dll Biblioteka NT Layer DLL Microsoft Corporation 6.1.7600.16559ntmarta.dll Windows NT - dostawca MARTA Microsoft Corporation 6.1.7600.16385ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.1.7600.16385OLEAUT32.dll Microsoft Corporation 6.1.7600.16385pnrpnsp.dll Dostawca obszaru nazw PNRP Microsoft Corporation 6.1.7600.16385profapi.dll User Profile Basic API Microsoft Corporation 6.1.7600.16385rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.1.7600.16385RASAPI32.dll Remote Access API Microsoft Corporation 6.1.7600.16385rasman.dll Remote Access Connection Manager Microsoft Corporation 6.1.7600.16385RPCRT4.dll Czas wykonania zdalnego wywoływania procedury Microsoft Corporation 6.1.7600.16385RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.1.7600.16385rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.1.7600.16385rtutils.dll Routing Utilities Microsoft Corporation 6.1.7600.16617samcli.dll Security Accounts Manager Client DLL Microsoft Corporation 6.1.7600.16385sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.1.7600.16385sensapi.dll SENS Connectivity API DLL Microsoft Corporation 6.1.7600.16385SETUPAPI.dll Interfejs API Instalatora systemu Windows Microsoft Corporation 6.1.7600.16385sfc.dll Windows File Protection Microsoft Corporation 6.1.7600.16385sfc_os.DLL Windows File Protection Microsoft Corporation 6.1.7600.16385SHELL32.dll Wspólna biblioteka DLL Powłoki systemu Windows Microsoft Corporation 6.1.7600.16644shfolder.dll Shell Folder Service Microsoft Corporation 6.1.7600.16385SHLWAPI.dll Biblioteka dodatkowych narzędzi powłoki Microsoft Corporation 6.1.7600.16385SHUNIMPL.DLL Windows Shell Obsolete APIs Microsoft Corporation 6.1.7600.16385SortDefault.nls SortServer2003Compat.dll Sort Version Server 2003 Microsoft Corporation 6.1.7600.16385SortServer2003Compat.nls SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.1.7600.16385StaticCache.dat urlmon.dll Rozszerzenia OLE32 dla Win32 Microsoft Corporation 8.0.7600.16625USER32.dll Współużytkowana biblioteka DLL klienta Windows USER API Microsoft Corporation 6.1.7600.16385USERENV.dll Userenv Microsoft Corporation 6.1.7600.16385USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385uTorrent.exe µTorrent BitTorrent, Inc. 2.0.3.20664UxTheme.dll Biblioteka Microsoft UxTheme Microsoft Corporation 6.1.7600.16385VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.1.7600.16385wininet.dll Rozszerzenia internetowe Win32 Microsoft Corporation 8.0.7600.16625WINMM.dll MCI API DLL Microsoft Corporation 6.1.7600.16385WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.1.7600.16385winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 6.1.7600.16385WINSPOOL.DRV Windows Spooler Driver Microsoft Corporation 6.1.7600.16385WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.1.7600.16385WS2_32.dll Biblioteka DLL 32-bitowej wersji usługi Windows Socket 2.0 Microsoft Corporation 6.1.7600.16385wship6.dll Biblioteka DLL pomocy usługi Winsock2 (TL/IPv6) Microsoft Corporation 6.1.7600.16385wshtcpip.dll Biblioteka DLL pomocy usługi Winsock2 (TL/IPv4) Microsoft Corporation 6.1.7600.16385
moogly Posted August 14, 2010 Report Posted August 14, 2010 Nothing nasty seems to be injected into µT...Did you try to run µT with Panda AV uninstalled? (you can run MSE temporarily)And do you know what did you install/update these last days before the issue?
future_freezer Posted August 14, 2010 Author Report Posted August 14, 2010 I uinstall Panda then instal avg and now i will try how it works.
paintball9 Posted August 15, 2010 Report Posted August 15, 2010 if you install avg right after it may just recreate the problem, try without an av first, and then you can install one and configure the proper rules for it if that fixed it.
future_freezer Posted August 15, 2010 Author Report Posted August 15, 2010 OK I uninstalled Panda and installed AVG the problem is solved now uTorrent works
moogly Posted August 15, 2010 Report Posted August 15, 2010 Yep, Panda is known here to cause some issues with µT.Maybe Panda has some settings to exclude utorrent.exe and not block p2p traffic (disabling IP Flood Detection e.g. or something like that).
Recommended Posts
Archived
This topic is now archived and is closed to further replies.