Ahmadov Posted December 1, 2010 Report Share Posted December 1, 2010 I have seen this problem reported before, but couldnt find a solution that solved it for me.As soon as utorrent starts downloading, it freezes and becomes unresponsive . It continues running (doesn't crash), but is not responding for most of the time. I have latest version 2.2 installed on Windows 7. NOD32 is version 4.2 and web access protection is disabled on it. below are the logs and any help would be appreciated.ThanksHijack this log---------------------------------Logfile of Trend Micro HijackThis v2.0.4Scan saved at 11:09:54 AM, on 12/1/2010Platform: Windows 7 (WinNT 6.00.3504)MSIE: Internet Explorer v8.00 (8.00.7600.16671)Boot mode: NormalRunning processes:C:\Windows\system32\rdpclip.exeC:\Windows\system32\Dwm.exeC:\Windows\system32\taskhost.exeC:\Windows\Explorer.EXEC:\Program Files\ESET\ESET NOD32 Antivirus\egui.exeC:\Program Files\Microsoft Office Communicator\communicator.exeC:\Program Files\iTunes\iTunesHelper.exeC:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exeC:\Program Files\Razer\Mamba\RazerTray.exeC:\Program Files\Common Files\Java\Java Update\jusched.exeC:\Program Files\Adobe\Acrobat 9.0\Acrobat\acrotray.exeC:\Program Files\Mediafour\MacDrive 8\MacDrive.exeC:\Program Files\WizMouse\WizMouse.exeC:\Program Files\USB Safely Remove\USBSafelyRemove.exeC:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exeC:\Program Files\Microsoft Firewall Client 2004\FwcMgmt.exeC:\Windows\System32\mobsync.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Program Files\Windows Live\Contacts\wlcomm.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Users\ahmadi\Downloads\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,AutoConfigURL = http://xxxx:8080/array.dll?Get.Routing.ScriptR1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyServer = xxxx:8080R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = R3 - URLSearchHook: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dllO2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dllO2 - BHO: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dllO2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~1\MICROS~3\Office14\GROOVEEX.DLLO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Adobe PDF Conversion Toolbar Helper - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dllO2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~1\MICROS~3\Office14\URLREDIR.DLLO2 - BHO: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dllO2 - BHO: Java Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO2 - BHO: SmartSelect - {F4971EE7-DAA0-4053-9964-665D8EE6A077} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dllO3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dllO3 - Toolbar: uTorrentBar Toolbar - {bf7380fa-e3b4-4db2-af3e-9d8783a45bfc} - C:\Program Files\uTorrentBar\tbuTor.dllO3 - Toolbar: Conduit Engine - {30F9B915-B755-4826-820B-08FBA6BD249D} - C:\Program Files\ConduitEngine\ConduitEngine.dllO4 - HKLM\..\Run: [egui] "C:\Program Files\ESET\ESET NOD32 Antivirus\egui.exe" /hide /waitserviceO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 9.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files\Common Files\Adobe\ARM\1.0\AdobeARM.exe"O4 - HKLM\..\Run: [Communicator] "C:\Program Files\Microsoft Office Communicator\communicator.exe" /fromrunkeyO4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files\iTunes\iTunesHelper.exe"O4 - HKLM\..\Run: [VirtualCloneDrive] "C:\Program Files\Elaborate Bytes\VirtualCloneDrive\VCDDaemon.exe" /sO4 - HKLM\..\Run: [bCSSync] "C:\Program Files\Microsoft Office\Office14\BCSSync.exe" /DelayServicesO4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "C:\Program Files\Common Files\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"O4 - HKLM\..\Run: [switchBoard] C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exeO4 - HKLM\..\Run: [AdobeCS5ServiceManager] "C:\Program Files\Common Files\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbyloginO4 - HKLM\..\Run: [Razer Mamba Driver] C:\Program Files\Razer\Mamba\RazerTray.exeO4 - HKLM\..\Run: [sunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"O4 - HKLM\..\Run: [Adobe Acrobat Speed Launcher] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrobat_sl.exe"O4 - HKLM\..\Run: [Acrobat Assistant 8.0] "C:\Program Files\Adobe\Acrobat 9.0\Acrobat\Acrotray.exe"O4 - HKLM\..\Run: [MacDrive 8 application] "C:\Program Files\Mediafour\MacDrive 8\MacDrive.exe"O4 - HKLM\..\Run: [Getting started with MacDrive 8] "C:\Program Files\Mediafour\MacDrive 8\MDGetStarted.exe" /autoO4 - HKCU\..\Run: [COMMUNICATOR] "C:\Program Files\Microsoft Office Communicator\Communicator.exe" /silentRetrials /backgroundO4 - HKCU\..\Run: [msnmsgr] "C:\Program Files\Windows Live\Messenger\msnmsgr.exe" /backgroundO4 - HKCU\..\Run: [sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRunO4 - HKCU\..\Run: [Azureus] C:\Program Files\Vuze\Azureus.exeO4 - HKCU\..\Run: [smallWindows] "D:\Freeware\SmallWindows.exe"O4 - HKCU\..\Run: [WizMouse] "C:\Program Files\WizMouse\WizMouse.exe"O4 - HKCU\..\Run: [uSB Safely Remove] C:\Program Files\USB Safely Remove\USBSafelyRemove.exe /startupO4 - HKCU\..\Run: [LightScribe Control Panel] C:\Program Files\Common Files\LightScribe\LightScribeControlPanel.exe -hiddenO4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"O4 - Startup: MagicFormation.exeO4 - Global Startup: Microsoft Firewall Client Management.lnk = ?O4 - Global Startup: Microsoft Outlook 2010.lnk = ?O8 - Extra context menu item: Append Link Target to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppendSelLinks.htmlO8 - Extra context menu item: Append to Existing PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIEAppend.htmlO8 - Extra context menu item: Convert Link Target to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECaptureSelLinks.htmlO8 - Extra context menu item: Convert to Adobe PDF - res://C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEFavClient.dll/AcroIECapture.htmlO8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\Office14\EXCEL.EXE/3000O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~1\MICROS~3\Office14\ONBttnIE.dll/105O9 - Extra button: ???C? ??? OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dllO9 - Extra 'Tools' menuitem: ??&?C? ??? OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files\Microsoft Office\Office14\ONBttnIE.dllO9 - Extra button: ??C?UCE OneNote C??&?EE?E - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dllO9 - Extra 'Tools' menuitem: ??C?UCE OneNote C??&?EE?E - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files\Microsoft Office\Office14\ONBttnIELinkedNotes.dllO17 - HKLM\System\CCS\Services\Tcpip\Parameters: Domain = xxx.xxx.xxxO17 - HKLM\System\CS1\Services\Tcpip\Parameters: Domain = xxx.xxx.xxxO17 - HKLM\System\CS2\Services\Tcpip\Parameters: Domain = xxx.xxx.xxxO18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLLO20 - AppInit_DLLs: acaptuser32.dllO23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exeO23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: ESET HTTP Server (EhttpSrv) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\EHttpSrv.exeO23 - Service: ESET Service (ekrn) - ESET - C:\Program Files\ESET\ESET NOD32 Antivirus\ekrn.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exeO23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exeO23 - Service: MacDrive 8 service (MacDrive8Service) - Mediafour Corporation - C:\Program Files\Mediafour\MacDrive 8\MacDrive8Service.exeO23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files\Common Files\Adobe\SwitchBoard\SwitchBoard.exeO23 - Service: USB Safely Remove Assistant (USBSafelyRemoveService) - Unknown owner - C:\Program Files\USB Safely Remove\USBSRService.exe--End of file - 10042 bytesProcess ExplorerProcess PID CPU Private Bytes Working Set Description Company NameSystem Idle Process 0 96.24 0 K 24 K Interrupts n/a 0 K 0 K Hardware Interrupts DPCs n/a 0 K 0 K Deferred Procedure Calls System 4 0.39 52 K 5,840 K smss.exe 296 344 K 896 K csrss.exe 460 3,180 K 4,796 K wininit.exe 516 1,348 K 4,112 K services.exe 616 5,916 K 10,772 K svchost.exe 748 4,436 K 8,600 K Host Process for Windows Services Microsoft Corporation mobsync.exe 6736 2,248 K 8,516 K Microsoft Sync Center Microsoft Corporation dllhost.exe 5216 48,984 K 52,500 K WmiPrvSE.exe 2412 7,744 K 12,648 K wlcomm.exe 5116 23,532 K 28,524 K Windows Live Communications Platform Microsoft Corporation svchost.exe 824 5,684 K 10,332 K Host Process for Windows Services Microsoft Corporation svchost.exe 924 19,724 K 19,560 K Host Process for Windows Services Microsoft Corporation svchost.exe 964 70,572 K 74,724 K Host Process for Windows Services Microsoft Corporation dwm.exe 6276 1,744 K 5,856 K Desktop Window Manager Microsoft Corporation svchost.exe 1004 77,032 K 86,884 K Host Process for Windows Services Microsoft Corporation svchost.exe 1184 10,716 K 18,272 K Host Process for Windows Services Microsoft Corporation svchost.exe 1380 26,184 K 26,744 K Host Process for Windows Services Microsoft Corporation rdpclip.exe 3460 1,796 K 5,488 K RDP Clip Monitor Microsoft Corporation spoolsv.exe 1524 7,304 K 12,384 K Spooler SubSystem App Microsoft Corporation svchost.exe 1564 10,492 K 11,480 K Host Process for Windows Services Microsoft Corporation AppleMobileDeviceService.exe 1676 1,584 K 4,532 K Apple Mobile Device Service Apple Inc. mDNSResponder.exe 1760 2,616 K 5,840 K Bonjour Service Apple Inc. ekrn.exe 1876 64,244 K 70,764 K ESET Service ESET FwcAgent.exe 1908 2,688 K 5,716 K Microsoft Firewall Client Agent Microsoft ® Corporation svchost.exe 2220 1,940 K 5,128 K Host Process for Windows Services Microsoft Corporation svchost.exe 3160 2,356 K 6,160 K Host Process for Windows Services Microsoft Corporation SearchIndexer.exe 3876 51,972 K 49,872 K Microsoft Windows Search Indexer Microsoft Corporation SearchProtocolHost.exe 3228 1,620 K 4,628 K Microsoft Windows Search Protocol Host Microsoft Corporation SearchFilterHost.exe 3420 1,148 K 3,764 K iPodService.exe 2696 2,296 K 5,872 K iPodService Module (32-bit) Apple Inc. OSPPSVC.EXE 4484 2,740 K 9,424 K LSSrvc.exe 2300 1,164 K 3,688 K LightScribe Service Hewlett-Packard Company MacDrive8Service.exe 356 1,992 K 6,260 K MacDrive service Mediafour Corporation svchost.exe 5204 4,676 K 9,932 K Host Process for Windows Services Microsoft Corporation USBSRService.exe 5272 1,476 K 4,152 K svchost.exe 4136 948 K 2,924 K Host Process for Windows Services Microsoft Corporation taskhost.exe 5892 8,212 K 9,832 K Host Process for Windows Tasks Microsoft Corporation taskhost.exe 3984 7,224 K 12,288 K lsass.exe 636 6,460 K 13,652 K Local Security Authority Process Microsoft Corporation lsm.exe 644 3,116 K 6,236 K rundll32.exe 2336 2,760 K 7,572 K csrss.exe 5328 5,484 K 5,088 K winlogon.exe 3924 1,780 K 4,824 K LogonUI.exe 5644 12,276 K 15,536 K csrss.exe 2828 1,788 K 6,024 K winlogon.exe 6480 2,324 K 5,984 K explorer.exe 8064 42,508 K 68,772 K Windows Explorer Microsoft Corporation egui.exe 5852 6,900 K 16,148 K ESET GUI ESET communicator.exe 4584 21,276 K 5,516 K Microsoft Office Communicator 2007 Microsoft Corporation iTunesHelper.exe 4868 5,524 K 13,008 K iTunesHelper Apple Inc. VCDDaemon.exe 8172 1,240 K 4,468 K Virtual CloneDrive Daemon Elaborate Bytes AG RazerTray.exe 7208 10,712 K 15,236 K Razer Mamba Configuration Utility Razer USA Ltd jusched.exe 6444 1,108 K 3,964 K Java Update Scheduler Sun Microsystems, Inc. acrotray.exe 720 1,064 K 4,152 K AcroTray Adobe Systems Inc. MacDrive.exe 4900 3,404 K 11,020 K MacDrive application Mediafour Corporation WizMouse.exe 4264 4,620 K 9,552 K WizMouse Antibody Software USBSafelyRemove.exe 708 14,692 K 20,288 K USB and SATA Device Manager LightScribeControlPanel.exe 8116 4,768 K 10,580 K Hewlett-Packard Company FwcMgmt.exe 6384 2,060 K 7,136 K Microsoft Firewall Client Management Microsoft ® Corporation uTorrent.exe 6296 9,372 K 18,556 K µTorrent BitTorrent, Inc. msnmsgr.exe 4408 33,360 K 6,256 K Windows Live Messenger Microsoft Corporation firefox.exe 3708 116,256 K 139,624 K Firefox Mozilla Corporation WinRAR.exe 4060 10,468 K 15,920 K WinRAR archiver Alexander Roshal procexp.exe 7060 2.32 19,932 K 32,548 K Sysinternals Process Explorer Sysinternals - www.sysinternals.commmc.exe 1260 72,292 K 9,440 K Link to comment Share on other sites More sharing options...
DreadWingKnight Posted December 1, 2010 Report Share Posted December 1, 2010 http://www.prevx.com/filenames/X1729919132580804192-X1/AVGRSSTX.DLL.html Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.