mystery666 Posted August 18, 2010 Report Share Posted August 18, 2010 I'm getting this error quite a bit. Several times per day. Its running on a system connected to my tv, so its only for downloading and XBMC, nothing else. I just ran malwarebytes and nothing was found. Logfile of Trend Micro HijackThis v2.0.4Scan saved at 1:10:52 PM, on 8/18/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16385)Boot mode: NormalRunning processes:C:\Windows\system32\taskeng.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\PeerBlock\peerblock.exeC:\Windows\system32\taskhost.exeC:\Windows\system32\rdpclip.exeC:\Windows\Explorer.EXEC:\Windows\SOUNDMAN.EXEC:\Program Files\TightVNC\tvnserver.exeC:\Windows\System32\rundll32.exeC:\Program Files\Java\jre6\bin\javaw.exeC:\Program Files\No-IP\DUC20.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\uTorrent\uTorrent.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Users\Marcus\AppData\Local\Google\Chrome\Application\chrome.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Malwarebytes' Anti-Malware\mbam.exeC:\Windows\system32\SearchFilterHost.exeC:\Program Files\Trend Micro\HiJackThis\HiJackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = about:blankR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderUame = O1 - Hosts: 85.17.80.246 tracker.openbittorrent.com # TORRENT REDIRECTO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO4 - HKLM\..\Run: [soundMan] SOUNDMAN.EXEO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [tvncontrol] "C:\Program Files\TightVNC\tvnserver.exe" -controlservice -slaveO4 - HKLM\..\Run: [startupDelayer] "C:\Program Files\r2 Studios\Startup Delayer\Startup Launcher GUI.exe"O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStartO4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartupO4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInitO4 - HKLM\..\Run: [Malwarebytes Anti-Malware (reboot)] "C:\Program Files\Malwarebytes' Anti-Malware\mbam.exe" /runcleanupscriptO4 - HKLM\..\RunOnce: [Malwarebytes' Anti-Malware] C:\Program Files\Malwarebytes' Anti-Malware\mbamgui.exe /install /silentO4 - HKCU\..\Run: [Google Update] "C:\Users\Marcus\AppData\Local\Google\Update\GoogleUpdate.exe" /cO4 - HKUS\S-1-5-19\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O4 - S-1-5-21-3587081964-1397126182-1305224119-1003 Startup: XBMC - Shortcut.lnk = C:\Program Files\XBMC\XBMC.exe (User 'XBMC')O4 - S-1-5-21-3587081964-1397126182-1305224119-1003 User Startup: XBMC - Shortcut.lnk = C:\Program Files\XBMC\XBMC.exe (User 'XBMC')O16 - DPF: {1E54D648-B804-468d-BC78-4AFFED8E262F} (System Requirements Lab) - http://www.nvidia.com/content/DriverDownload/srl/3.0.0.4/srl_bin/sysreqlab_nvd.cabO23 - Service: NBService - Nero AG - C:\Program Files\Nero\Nero 7\Nero BackItUp\NBService.exeO23 - Service: NMIndexingService - Nero AG - C:\Program Files\Common Files\Ahead\Lib\NMIndexingService.exeO23 - Service: NoIPDUCService - Vitalwerks LLC - C:\Program Files\No-IP\DUC20.exeO23 - Service: Realtek8185 - Realtek - C:\Program Files\REALTEK\RTL8185 Wireless LAN Utility\RtlService.exeO23 - Service: TightVNC Server (tvnserver) - GlavSoft LLC. - C:\Program Files\TightVNC\tvnserver.exe--End of file - 5014 bytesProcess PID CPU Description Company Name SessionSystem Idle Process 0 65.95 Interrupts n/a Hardware Interrupts 0 DPCs n/a 0.62 Deferred Procedure Calls 0 System 4 1.23 0 smss.exe 256 Windows Session Manager Microsoft Corporation 0csrss.exe 348 Client Server Runtime Process Microsoft Corporation 0wininit.exe 404 Windows Start-Up Application Microsoft Corporation 0 services.exe 464 Services and Controller app Microsoft Corporation 0 svchost.exe 632 Host Process for Windows Services Microsoft Corporation 0 dllhost.exe 2348 COM Surrogate Microsoft Corporation 0 svchost.exe 708 Host Process for Windows Services Microsoft Corporation 0 svchost.exe 808 Host Process for Windows Services Microsoft Corporation 0 svchost.exe 852 Host Process for Windows Services Microsoft Corporation 0 svchost.exe 880 Host Process for Windows Services Microsoft Corporation 0 taskeng.exe 1584 Task Scheduler Engine Microsoft Corporation 0 uTorrent.exe 1684 µTorrent BitTorrent, Inc. 0 peerblock.exe 1700 PeerBlock PeerBlock, LLC 0 svchost.exe 1028 Host Process for Windows Services Microsoft Corporation 0 svchost.exe 1176 Host Process for Windows Services Microsoft Corporation 0 rdpclip.exe 1280 RDP Clip Monitor Microsoft Corporation 2 spoolsv.exe 1428 Spooler SubSystem App Microsoft Corporation 0 svchost.exe 1480 Host Process for Windows Services Microsoft Corporation 0 taskhost.exe 1848 Host Process for Windows Tasks Microsoft Corporation 1 DUC20.exe 1916 No-IP.com DUC Vitalwerks LLC 0 RtlService.exe 112 RtlService MFC Application Realtek 0 RtWLan.exe 400 RtWLan ( For Vista / Win7) Application(External Registrar) Realtek Semiconductor Corp. 1 svchost.exe 592 Host Process for Windows Services Microsoft Corporation 0 tvnserver.exe 476 TightVNC Server for Windows GlavSoft LLC. 0 svchost.exe 2176 Host Process for Windows Services Microsoft Corporation 0 SearchIndexer.exe 2328 Microsoft Windows Search Indexer Microsoft Corporation 0 SearchProtocolHost.exe 2672 Microsoft Windows Search Protocol Host Microsoft Corporation 0 SearchFilterHost.exe 3184 Microsoft Windows Search Filter Host Microsoft Corporation 0 svchost.exe 2924 Host Process for Windows Services Microsoft Corporation 0 svchost.exe 3096 Host Process for Windows Services Microsoft Corporation 0 wmpnetwk.exe 3364 Windows Media Player Network Sharing Service Microsoft Corporation 0 svchost.exe 3836 Host Process for Windows Services Microsoft Corporation 0 taskhost.exe 436 Host Process for Windows Tasks Microsoft Corporation 2 lsass.exe 480 Local Security Authority Process Microsoft Corporation 0 lsm.exe 488 Local Session Manager Service Microsoft Corporation 0csrss.exe 412 Client Server Runtime Process Microsoft Corporation 1winlogon.exe 516 Windows Logon Application Microsoft Corporation 1SOUNDMAN.EXE 1576 Realtek Sound Manager Realtek Semiconductor Corp. 1jusched.exe 1624 Java Platform SE binary Sun Microsystems, Inc. 1tvnserver.exe 1644 TightVNC Server for Windows GlavSoft LLC. 1XBMC.exe 1816 XBMC Team XBMC 1rundll32.exe 1836 Windows host process (Rundll32) Microsoft Corporation 1csrss.exe 1924 Client Server Runtime Process Microsoft Corporation 2winlogon.exe 1152 Windows Logon Application Microsoft Corporation 2explorer.exe 892 Windows Explorer Microsoft Corporation 2 SOUNDMAN.EXE 4008 Realtek Sound Manager Realtek Semiconductor Corp. 2 tvnserver.exe 4000 TightVNC Server for Windows GlavSoft LLC. 2 chrome.exe 3304 Google Chrome Google Inc. 2 chrome.exe 4012 Google Chrome Google Inc. 2 chrome.exe 3928 Google Chrome Google Inc. 2 uTorrent.exe 2828 0.76 µTorrent BitTorrent, Inc. 2 chrome.exe 3004 3.03 Google Chrome Google Inc. 2 chrome.exe 2860 0.76 Google Chrome Google Inc. 2 chrome.exe 2040 Google Chrome Google Inc. 2 chrome.exe 3784 Google Chrome Google Inc. 2 chrome.exe 264 Google Chrome Google Inc. 2 chrome.exe 3680 Google Chrome Google Inc. 2 uTorrent.exe 3148 µTorrent BitTorrent, Inc. 2 chrome.exe 728 Google Chrome Google Inc. 2 WinRAR.exe 1796 WinRAR archiver Alexander Roshal 2 procexp.exe 2848 7.58 Sysinternals Process Explorer Sysinternals - www.sysinternals.com 2 HiJackThis.exe 2508 HijackThis Trend Micro Inc. 2 notepad.exe 2616 Notepad Microsoft Corporation 2rundll32.exe 3072 Windows host process (Rundll32) Microsoft Corporation 2javaw.exe 2744 Java Platform SE binary Sun Microsystems, Inc. 2DUC20.exe 2796 No-IP.com DUC Vitalwerks LLC 2explorer.exe 2256 Windows Explorer Microsoft Corporation 1mbam.exe 3832 Malwarebytes' Anti-Malware Malwarebytes Corporation 2MpCmdRun.exe 1956 Microsoft Malware Protection Command Line Utility Microsoft Corporation 0Process: uTorrent.exe Pid: 1684Name Description Company Name VersionADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.1.7600.16385AUTHZ.dll Authorization Framework Microsoft Corporation 6.1.7600.16385CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.8530.16385COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7600.16385comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.1.7600.16385CRYPT32.dll Crypto API32 Microsoft Corporation 6.1.7600.16385CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.1.7600.16385CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.1.7600.16385dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.1.7600.16385dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.1.7600.16385DnsApi.dll DNS Client API DLL Microsoft Corporation 6.1.7600.16385FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.1.7600.16385fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.1.7600.16385GDI32.dll GDI Client DLL Microsoft Corporation 6.1.7600.16385iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.0.7600.16385IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.1.7600.16385index.dat index.dat index.dat Iphlpapi.dll IP Helper API Microsoft Corporation 6.1.7600.16385kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16481KERNELBASE.dll Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation 6.1.7600.16385locale.nls LPK.dll Language Pack Microsoft Corporation 6.1.7600.16385MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.1.7600.16415MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.1.7600.16385msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.0.7600.16385mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.1.7600.16385NLAapi.dll Network Location Awareness 2 Microsoft Corporation 6.1.7600.16385Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.1.7600.16385npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.1.7600.16385NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.1.7600.16385ntdll.dll NT Layer DLL Microsoft Corporation 6.1.7600.16385ntmarta.dll Windows NT MARTA provider Microsoft Corporation 6.1.7600.16385ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.1.7600.16385oleaut32.dll Microsoft Corporation 6.1.7600.16385peerdist.dll BranchCache Client Library Microsoft Corporation 6.1.7600.16385profapi.dll User Profile Basic API Microsoft Corporation 6.1.7600.16385rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.1.7600.16385RASAPI32.dll Remote Access API Microsoft Corporation 6.1.7600.16385rasman.dll Remote Access Connection Manager Microsoft Corporation 6.1.7600.16385RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.1.7600.16385RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.1.7600.16385rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.1.7600.16385rtutils.dll Routing Utilities Microsoft Corporation 6.1.7600.16385sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation 6.1.7600.16385sensapi.dll SENS Connectivity API DLL Microsoft Corporation 6.1.7600.16385SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.1.7600.16532shfolder.dll Shell Folder Service Microsoft Corporation 6.1.7600.16385SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.1.7600.16385SortDefault.nls SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.1.7600.16385StaticCache.dat urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 8.0.7600.16535urlmon.dll.mui OLE32 Extensions for Win32 Microsoft Corporation 8.0.7600.16385USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.1.7600.16385USERENV.dll Userenv Microsoft Corporation 6.1.7600.16385USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7600.16385uTorrent.exe µTorrent BitTorrent, Inc. 2.0.3.20664UxTheme.dll Microsoft UxTheme Library Microsoft Corporation 6.1.7600.16385VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.1.7600.16385wininet.dll Internet Extensions for Win32 Microsoft Corporation 8.0.7600.16535wininet.dll.mui Internet Extensions for Win32 Microsoft Corporation 8.0.7600.16385WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.1.7600.16385WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.1.7600.16385WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.1.7600.16385wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.1.7600.16385wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.1.7600.16385 Link to comment Share on other sites More sharing options...
moogly Posted August 18, 2010 Report Share Posted August 18, 2010 Did you try with PeerBlock uninstalled? Link to comment Share on other sites More sharing options...
mystery666 Posted August 20, 2010 Author Report Share Posted August 20, 2010 Uninstalled peerblock yesterday, rebooted twice since, got same error again today. Link to comment Share on other sites More sharing options...
paintball9 Posted August 20, 2010 Report Share Posted August 20, 2010 Try disabling/uninstalling VNC Link to comment Share on other sites More sharing options...
DreadWingKnight Posted August 20, 2010 Report Share Posted August 20, 2010 It's probably the windows 7 ipv6 bug again. Link to comment Share on other sites More sharing options...
mystery666 Posted August 20, 2010 Author Report Share Posted August 20, 2010 I'm looking at the IPV6 link in your signature. Will that kill my remote desktop access? Link to comment Share on other sites More sharing options...
DreadWingKnight Posted August 20, 2010 Report Share Posted August 20, 2010 only if you use ipv6 to connect to it. Link to comment Share on other sites More sharing options...
mystery666 Posted August 22, 2010 Author Report Share Posted August 22, 2010 I followed the IPV6 link in paintball9's signature, I added the key and set it to 0x11. Still having problems. Link to comment Share on other sites More sharing options...
paintball9 Posted August 22, 2010 Report Share Posted August 22, 2010 Did you restart? Link to comment Share on other sites More sharing options...
mystery666 Posted August 23, 2010 Author Report Share Posted August 23, 2010 I did, several times. Link to comment Share on other sites More sharing options...
Firon Posted August 23, 2010 Report Share Posted August 23, 2010 What is net.ipv6_disable set to? Link to comment Share on other sites More sharing options...
mystery666 Posted August 23, 2010 Author Report Share Posted August 23, 2010 I don't have a net.ipv6_disable, i do however have a net.disable_ipv6, and it's set to true. Link to comment Share on other sites More sharing options...
paintball9 Posted August 23, 2010 Report Share Posted August 23, 2010 What version of utorrent are you running. Some previous beta versions had that functionality broken. Try updating. Link to comment Share on other sites More sharing options...
mystery666 Posted August 24, 2010 Author Report Share Posted August 24, 2010 presently running 2.0.3 build 20664, will update now. I'll let you know if problems continue. Link to comment Share on other sites More sharing options...
mystery666 Posted August 24, 2010 Author Report Share Posted August 24, 2010 it seems i'm running the most recent version already. Link to comment Share on other sites More sharing options...
mystery666 Posted August 30, 2010 Author Report Share Posted August 30, 2010 any other ideas? Link to comment Share on other sites More sharing options...
moogly Posted August 30, 2010 Report Share Posted August 30, 2010 C:\Program Files\No-IP\DUC20.exeAre you using No-IP when µT is running? Can you make a test without No-IP running. Link to comment Share on other sites More sharing options...
Firon Posted August 30, 2010 Report Share Posted August 30, 2010 The No-IP DUC has nothing to do with it. Trust me. Do you have unkillable utorrent.exe in your Task Manager? Link to comment Share on other sites More sharing options...
mystery666 Posted August 31, 2010 Author Report Share Posted August 31, 2010 unkillable?as in not being able to close it in task manager? I haven't had that problem yet. Link to comment Share on other sites More sharing options...
paintball9 Posted August 31, 2010 Report Share Posted August 31, 2010 What are you running in java? Link to comment Share on other sites More sharing options...
mystery666 Posted August 31, 2010 Author Report Share Posted August 31, 2010 Torrent Episode Downloader Link to comment Share on other sites More sharing options...
Firon Posted August 31, 2010 Report Share Posted August 31, 2010 Is there another utorrent.exe running in the Processes list of task manager? Link to comment Share on other sites More sharing options...
paintball9 Posted August 31, 2010 Report Share Posted August 31, 2010 Try closing it, there may be a bug in their software that's causing it, (I'm assuming it integrates with uTorrent somehow) Link to comment Share on other sites More sharing options...
mystery666 Posted August 31, 2010 Author Report Share Posted August 31, 2010 it downloads torrents and opens them in their default program (utorrent). My understanding is that it doesn't actually integrate with utorrent, just opens them the same way when we double click a torrent.I'll try closing it. Link to comment Share on other sites More sharing options...
aelthric Posted September 7, 2010 Report Share Posted September 7, 2010 I have a similar problem with Utorrent 2.0.4 (Build 21586)...It seems that after closing Utorrent in the conventional way (Using the "Close" Widgets) it remains resident in the process list in Windows Task Manager requiring it to be ended manually in the process list before you can start a new instance...Running Windows XP Pro SP3 Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.