Utorrent stop working


I run Utorrent program. after 3 hours, the program stuck. the modem works fine, the internet still connected but i can't run explorer as well.

the only solution is to do restart.

If i'm not running Utorrent, everything is o.k.

I wonder what could it be?

I'm using windows xp sp3

I7 chip

4GB for memory

avira antivirus

zonealarm-basic firewall

Thank u in advance

Might it be a virus? or trojan? or browser hijack?

i think it's not zonealarm because even before i install the program Utorrent crashes.

Could my internet provider may cause this problem because i'm using all of my speed?

its very annoying.

i'll be glad if someone who had this problem and solved it can help me with this issue.


Logfile of Trend Micro HijackThis v2.0.4

Scan saved at 15:27:51, on 15/01/2011

Platform: Windows XP SP3 (WinNT 5.01.2600)

MSIE: Internet Explorer v8.00 (8.00.6001.18702)

Boot mode: Normal

Running processes:






C:\Program Files\Avira\AntiVir Desktop\avguard.exe

C:\Program Files\Avira\AntiVir Desktop\avshadow.exe

C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe











C:\Program Files\Avira\AntiVir Desktop\sched.exe


C:\Program Files\Common Files\Microsoft Shared\VS7Debug\mdm.exe

C:\Program Files\NetLimiter 3\nlsvc.exe

C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe



C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe

C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\MOM.exe

C:\Program Files\Avira\AntiVir Desktop\avgnt.exe


C:\Program Files\NetLimiter 3\NLClientApp.exe

C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\ccc.exe

C:\Program Files\Internet Explorer\iexplore.exe

C:\Program Files\Internet Explorer\iexplore.exe



C:\Program Files\Internet Explorer\iexplore.exe


C:\Program Files\hijack\Trend Micro\HiJackThis\HiJackThis.exe


R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896

R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896

R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157

O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll

O2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_06\bin\ssv.dll

O2 - BHO: Babylon IE plugin - {9CFACCB6-2F3F-4177-94EA-0D2B72D384C1} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll

O3 - Toolbar: StylerToolBar - {D2F8F919-690B-4EA2-9FA7-A203D1E04F75} - C:\Program Files\Styler\TB\StylerTB.dll


O4 - HKLM\..\Run: [JMB36X IDE Setup] "C:\WINDOWS\RaidTool\xInsIDE.exe"

O4 - HKLM\..\Run: [36X Raid Configurer] "C:\WINDOWS\system32\xRaidSetup.exe" boot

O4 - HKLM\..\Run: [NUSB3MON] "C:\Program Files\NEC Electronics\USB 3.0 Host Controller Driver\Application\nusb3mon.exe"

O4 - HKLM\..\Run: [startCCC] "C:\Program Files\ATI Technologies\ATI.ACE\Core-Static\CLIStart.exe" MSRun

O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe"

O4 - HKLM\..\Run: [KernelFaultCheck] "%systemroot%\system32\dumprep" 0 -k

O4 - HKLM\..\Run: [NetLimiter] "C:\Program Files\NetLimiter\NetLimiter.exe" /s

O4 - HKLM\..\Run: [avgnt] "C:\Program Files\Avira\AntiVir Desktop\avgnt.exe" /min

O4 - HKLM\..\Run: [babylon Client] "C:\Program Files\Babylon\Babylon-Pro\Babylon.exe" -AutoStart

O4 - HKLM\..\Run: [iObit Security 360] "C:\Program Files\IObit\IObit Security 360\IS360tray.exe" /autostart

O4 - HKLM\..\Run: [spySweeper] "C:\Program Files\Webroot\WebrootSecurity\SpySweeperUI.exe" /startintray

O4 - HKCU\..\Run: [CTFMON.EXE] "C:\WINDOWS\system32\ctfmon.exe"

O4 - HKCU\..\Run: [NetLimiter] "C:\Program Files\NetLimiter 3\NLClientApp.exe" /tray

O4 - HKCU\..\Run: [uTorrent] "C:\Program Files\uTorrent\uTorrent.exe"


O4 - HKUS\S-1-5-20\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'NETWORK SERVICE')

O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')

O4 - HKUS\S-1-5-18\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'SYSTEM')

O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')

O4 - HKUS\.DEFAULT\..\RunOnce: [nltide_3] rundll32 advpack.dll,LaunchINFSectionEx nLite.inf,C,,4,N (User 'Default user')

O8 - Extra context menu item: &יצא ל- Microsoft Excel - res://C:\PROGRA~1\MICROS~2\Office10\EXCEL.EXE/3000

O8 - Extra context menu item: Translate this web page with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/ActionTU.htm

O8 - Extra context menu item: Translate with Babylon - res://C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll/Action.htm

O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll

O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe

O9 - Extra button: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll

O9 - Extra 'Tools' menuitem: Translate this web page with Babylon - {F72841F0-4EF1-4df5-BCE5-B3AC8ACF5478} - C:\Program Files\Babylon\Babylon-Pro\Utils\BabylonIEPI.dll

O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1291746378937

O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab

O16 - DPF: {D27CDB6E-AE6D-11CF-96B8-444553540000} (Shockwave Flash Object) - http://fpdownload2.macromedia.com/get/shockwave/cabs/flash/swflash.cab

O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} (get_atlcom Class) - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab

O17 - HKLM\System\CCS\Services\Tcpip\..\{BB399357-1E20-4379-A799-74E22658E495}: NameServer =

O20 - Winlogon Notify: !SASWinLogon - C:\Program Files\SUPERAntiSpyware\SASWINLO.DLL

O22 - SharedTaskScheduler: Browseui preloader - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll

O22 - SharedTaskScheduler: Component Categories cache daemon - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll

O23 - Service: Avira AntiVir Scheduler (AntiVirSchedulerService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\sched.exe

O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - C:\Program Files\Avira\AntiVir Desktop\avguard.exe

O23 - Service: AppleChargerSrv - Unknown owner - C:\WINDOWS\system32\AppleChargerSrv.exe

O23 - Service: Ati HotKey Poller - ATI Technologies Inc. - C:\WINDOWS\system32\Ati2evxx.exe

O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe

O23 - Service: IS360service - IObit - C:\Program Files\IObit\IObit Security 360\IS360srv.exe

O23 - Service: NetLimiter 3 Service (nlsvc) - Locktime Software - C:\Program Files\NetLimiter 3\nlsvc.exe

O23 - Service: TrueVector Internet Monitor (vsmon) - Check Point Software Technologies LTD - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

O23 - Service: Webroot Spy Sweeper Engine (WebrootSpySweeperService) - Webroot Software, Inc. (www.webroot.com) - C:\Program Files\Webroot\WebrootSecurity\SpySweeper.exe

O23 - Service: Webroot Client Service (WRConsumerService) - Webroot Software, Inc. - C:\Program Files\Webroot\WebrootSecurity\WRConsumerService.exe


End of file - 8597 bytes

process explorer

Process PID CPU Private Bytes Working Set Description Company Name

System Idle Process 0 99.41 K 28 K

Interrupts n/a K K Hardware Interrupts

DPCs n/a 0.39 K K Deferred Procedure Calls

System 4 K 240 K

smss.exe 948 172 K 416 K Windows NT Session Manager Microsoft Corporation

csrss.exe 1056 0.20 1,904 K 4,312 K Client Server Runtime Process Microsoft Corporation

winlogon.exe 1088 5,980 K 4,000 K Windows NT Logon Application Microsoft Corporation

services.exe 1132 1,940 K 5,272 K Services and Controller app Microsoft Corporation

avguard.exe 1308 87,084 K 21,952 K Antivirus On-Access Service Avira GmbH

avshadow.exe 1412 1,364 K 4,676 K AntiVir shadow copy service Avira GmbH

WRConsumerService.exe 1588 13,460 K 15,732 K WRConsumerService Webroot Software, Inc.

ati2evxx.exe 1620 2,028 K 3,472 K ATI External Event Utility EXE Module ATI Technologies Inc.

svchost.exe 1640 3,292 K 5,556 K Generic Host Process for Win32 Services Microsoft Corporation

wmiprvse.exe 2424 2,552 K 5,100 K WMI Microsoft Corporation

svchost.exe 1716 2,032 K 4,876 K Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1840 15,396 K 26,544 K Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 1996 1,708 K 4,324 K Generic Host Process for Win32 Services Microsoft Corporation

svchost.exe 200 1,708 K 4,148 K Generic Host Process for Win32 Services Microsoft Corporation

vsmon.exe 492 22,052 K 25,568 K TrueVector Service Check Point Software Technologies LTD

spoolsv.exe 1904 3,220 K 4,844 K Spooler SubSystem App Microsoft Corporation

sched.exe 1948 4,796 K 884 K Antivirus Scheduler Avira GmbH

svchost.exe 164 1,460 K 3,988 K Generic Host Process for Win32 Services Microsoft Corporation

mdm.exe 692 1,152 K 3,632 K Machine Debug Manager Microsoft Corporation

nlsvc.exe 1024 3,656 K 7,408 K NetLimiter 3 Service Locktime Software

SpySweeper.exe 1368 14,320 K 10,252 K Spy Sweeper Engine Webroot Software, Inc. (www.webroot.com)

alg.exe 3020 1,300 K 3,804 K Application Layer Gateway Service Microsoft Corporation

dllhost.exe 2596 3,100 K 8,344 K COM Surrogate Microsoft Corporation

msdtc.exe 772 2,012 K 5,244 K MS DTC console program Microsoft Corporation

msiexec.exe 3980 2,736 K 6,424 K Windows® installer Microsoft Corporation

lsass.exe 1144 4,140 K 1,436 K LSA Shell (Export Version) Microsoft Corporation

ati2evxx.exe 292 2,496 K 4,756 K ATI External Event Utility EXE Module ATI Technologies Inc.

explorer.exe 712 32,300 K 41,760 K Windows Explorer Microsoft Corporation

RTHDCPL.EXE 3652 20,980 K 24,332 K Realtek HD Audio Control Panel Realtek Semiconductor Corp.

nusb3mon.exe 3784 2,172 K 3,456 K USB 3.0 Monitor NEC Electronics Corporation

zlclient.exe 3864 14,132 K 3,780 K ZoneAlarm Client Check Point Software Technologies LTD

avgnt.exe 3912 9,828 K 2,756 K Antivirus System Tray Tool Avira GmbH

ctfmon.exe 1788 1,216 K 4,452 K CTF Loader Microsoft Corporation

NLClientApp.exe 1796 14,148 K 22,528 K NetLimiter 3 Client Locktime Software

iexplore.exe 3780 12,532 K 5,552 K Internet Explorer Microsoft Corporation

HiJackThis.exe 2212 5,600 K 3,372 K HijackThis Trend Micro Inc.

procexp.exe 1400 12,644 K 18,700 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com

MOM.exe 3888 51,152 K 7,624 K Catalyst Control Center: Monitoring program Advanced Micro Devices Inc.

CCC.exe 740 63,220 K 11,080 K Catalyst Control Centre: Host application ATI Technologies Inc.

- and another thing, some of the files (that i'm downloading) are being stopped, not by me.

