Jump to content

System PID 4 downloads a LOT of data when uTorrent runs


Cutie Squiggoth

Recommended Posts

Since about a month ago my internet usage has climbed dramatically. I tracked it down to a System process, PID 4, downloading a lot of data when uTorrent runs. This didn't used to happen, so I'm assuming it's a problem with the newer versions. It happens with the latest beta.

Without uTorrent running PID 4 downloads maybe 4kb/s, when I start uTorrent this rapidly climbs to over 40kb/s, and slowly decays after I quit uTorrent.

This is killing uTorrent for me, I can't keep it running as that's over 1GB/day often near 2GB/day, and I have caps on my usage (damn OZ and it's internet caps)

As my usage never used to show this I assume it's a problem introduced in the newer releases, can this please be fixed so I can use uTorrent again.

How do I link files instead of dumping them in code blocks?

This is my System.txt file:

Process    PID    CPU    Private Bytes    Working Set    Description    Company Name
System Idle Process 0 95.10 0 K 24 K
Interrupts n/a 0 K 0 K Hardware Interrupts
DPCs n/a 0 K 0 K Deferred Procedure Calls
System 4 120 K 3,412 K
smss.exe 280 536 K 1,196 K
csrss.exe 376 3,816 K 5,536 K
wininit.exe 436 1,704 K 4,548 K
services.exe 540 6,008 K 12,104 K
svchost.exe 684 5,008 K 10,228 K Host Process for Windows Services Microsoft Corporation
dllhost.exe 4692 2,836 K 7,344 K
nvvsvc.exe 748 2,896 K 7,828 K NVIDIA Driver Helper Service, Version 266.58 NVIDIA Corporation
NvXDSync.exe 1108 7,300 K 17,104 K
nvvsvc.exe 1120 5,444 K 13,156 K
svchost.exe 788 4,664 K 8,668 K Host Process for Windows Services Microsoft Corporation
MsMpEng.exe 876 164,600 K 89,996 K Antimalware Service Executable Microsoft Corporation
svchost.exe 936 21,280 K 24,508 K Host Process for Windows Services Microsoft Corporation
audiodg.exe 4488 15,800 K 15,760 K
svchost.exe 976 158,520 K 166,684 K Host Process for Windows Services Microsoft Corporation
dwm.exe 2656 0.77 29,284 K 44,072 K Desktop Window Manager Microsoft Corporation
WUDFHost.exe 4484 2,248 K 6,368 K
svchost.exe 1008 33,404 K 51,200 K Host Process for Windows Services Microsoft Corporation
taskeng.exe 2444 4,440 K 7,292 K Task Scheduler Engine Microsoft Corporation
svchost.exe 488 11,188 K 18,264 K Host Process for Windows Services Microsoft Corporation
svchost.exe 388 32,700 K 36,692 K Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1364 7,488 K 13,512 K Spooler SubSystem App Microsoft Corporation
svchost.exe 1404 0.39 13,368 K 17,292 K Host Process for Windows Services Microsoft Corporation
taskhost.exe 1572 5,632 K 9,456 K Host Process for Windows Tasks Microsoft Corporation
AppleMobileDeviceService.exe 1680 2,352 K 7,428 K MobileDeviceService Apple Inc.
mDNSResponder.exe 1800 1,952 K 5,592 K Bonjour Service Apple Inc.
svchost.exe 1880 9,416 K 18,108 K Host Process for Windows Services Microsoft Corporation
snmp.exe 2000 4,152 K 8,576 K SNMP Service Microsoft Corporation
nvSCPAPISvr.exe 1300 2,440 K 5,576 K Stereo Vision Control Panel API Server NVIDIA Corporation
svchost.exe 1696 2,252 K 5,872 K Host Process for Windows Services Microsoft Corporation
WLIDSVC.EXE 1864 4,632 K 12,452 K
WLIDSVCM.EXE 2880 1,436 K 3,412 K
NisSrv.exe 2300 8,572 K 3,536 K Microsoft Network Inspection System Microsoft Corporation
svchost.exe 2392 2,556 K 6,232 K Host Process for Windows Services Microsoft Corporation
SearchIndexer.exe 2540 50,136 K 37,404 K Microsoft Windows Search Indexer Microsoft Corporation
SearchProtocolHost.exe 3408 3,756 K 8,756 K
wmpnetwk.exe 3416 14,952 K 11,864 K Windows Media Player Network Sharing Service Microsoft Corporation
iPodService.exe 3824 3,400 K 7,736 K iPodService Module (64-bit) Apple Inc.
svchost.exe 4084 11,764 K 15,652 K Host Process for Windows Services Microsoft Corporation
SteamService.exe 4944 5,472 K 9,352 K Steam Client Service (buildbot_winslave01_steam_rel_client_win32@winslave01) Valve Corporation
svchost.exe 4772 1,260 K 2,904 K Host Process for Windows Services Microsoft Corporation
lsass.exe 548 5,368 K 12,532 K Local Security Authority Process Microsoft Corporation
lsm.exe 556 2,688 K 4,448 K
csrss.exe 464 11,140 K 17,960 K
winlogon.exe 528 3,064 K 8,028 K
explorer.exe 2684 0.39 38,600 K 61,084 K Windows Explorer Microsoft Corporation
msseces.exe 2988 8,408 K 15,420 K Microsoft Security Client User Interface Microsoft Corporation
Steam.exe 3016 94,020 K 77,860 K Steam Valve Corporation
AirVideoServer.exe 2828 41,676 K 36,612 K
Xfire.exe 3268 50,976 K 4,140 K Xfire Xfire Inc.
xfire64.exe 4600 4,540 K 10,812 K
perfmon.exe 3976 0.77 40,484 K 54,188 K
GPU-Z.0.5.1.exe 1176 1.16 47,068 K 15,944 K
chrome.exe 4776 96,252 K 121,604 K Google Chrome Google Inc.
chrome.exe 784 20,632 K 30,276 K Google Chrome Google Inc.
chrome.exe 2448 10,296 K 16,888 K Google Chrome Google Inc.
chrome.exe 3648 51,012 K 61,632 K Google Chrome Google Inc.
chrome.exe 4528 17,760 K 28,200 K Google Chrome Google Inc.
chrome.exe 4908 36,076 K 46,508 K Google Chrome Google Inc.
chrome.exe 4180 21,344 K 31,676 K Google Chrome Google Inc.
chrome.exe 2204 26,408 K 35,624 K Google Chrome Google Inc.
chrome.exe 884 21,372 K 30,836 K Google Chrome Google Inc.
chrome.exe 4680 5,928 K 10,848 K Google Chrome Google Inc.
chrome.exe 2668 18,316 K 28,052 K Google Chrome Google Inc.
chrome.exe 3320 33,344 K 42,608 K Google Chrome Google Inc.
rundll32.exe 4120 5,880 K 7,020 K Windows host process (Rundll32) Microsoft Corporation
chrome.exe 2556 24,592 K 28,292 K Google Chrome Google Inc.
chrome.exe 3640 35,856 K 20,608 K Google Chrome Google Inc.
chrome.exe 288 1.16 47,724 K 58,688 K Google Chrome Google Inc.
chrome.exe 1636 6,292 K 8,976 K Google Chrome Google Inc.
chrome.exe 4552 71,232 K 83,072 K Google Chrome Google Inc.
7zFM.exe 3776 7,080 K 14,196 K 7-Zip File Manager Igor Pavlov
procexp.exe 2028 2,124 K 6,772 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
procexp64.exe 4164 0.39 29,368 K 47,164 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
pidgin.exe 2908 24,844 K 37,356 K Pidgin The Pidgin developer community
Skype.exe 4456 116,992 K 109,280 K Skype Skype Technologies S.A.
skypePM.exe 4612 20,108 K 27,372 K Skype Extras Manager Skype Technologies
GoogleCrashHandler.exe 3064 1,792 K 1,400 K Google Installer Google Inc.
jusched.exe 3128 1,268 K 4,368 K Java(TM) Update Scheduler Sun Microsystems, Inc.
iTunesHelper.exe 3192 8,164 K 14,248 K iTunesHelper Apple Inc.
uTorrent.exe 3956 0.39 16,252 K 22,284 K µTorrent BitTorrent, Inc.

This is my hijackthis.log:

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 8:01:59 PM, on 3/02/2011
Platform: Windows 7 (WinNT 6.00.3504)
MSIE: Internet Explorer v8.00 (8.00.7600.16700)
Boot mode: Normal

Running processes:
C:\Program Files (x86)\Steam\Steam.exe
C:\Users\michelle\AppData\Local\Google\Update\1.2.183.39\GoogleCrashHandler.exe
C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe
C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe
C:\Program Files (x86)\iTunes\iTunesHelper.exe
C:\Program Files (x86)\Xfire\Xfire.exe
C:\Users\michelle\Downloads\GPU-Z.0.5.1.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Windows\SysWOW64\rundll32.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Pidgin\pidgin.exe
C:\Program Files (x86)\Skype\Phone\Skype.exe
C:\Program Files (x86)\Skype\Plugin Manager\skypePM.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Users\michelle\AppData\Local\Temp\7zO2826.tmp\procexp.exe
C:\Program Files (x86)\uTorrent\uTorrent.exe
C:\Users\michelle\AppData\Local\Google\Chrome\Application\chrome.exe
C:\Program Files (x86)\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: WormRadar.com IESiteBlocker.NavFilter - {3CA2F312-6F6E-4B53-A66E-4E65E497C8C0} - C:\Program Files (x86)\AVG\AVG9\avgssie.dll (file missing)
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre6\bin\jp2ssv.dll
O4 - HKLM\..\Run: [amd_dc_opt] C:\Program Files (x86)\AMD\Dual-Core Optimizer\amd_dc_opt.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files (x86)\Common Files\Java\Java Update\jusched.exe"
O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files (x86)\QuickTime\QTTask.exe" -atboottime
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files (x86)\Adobe\Reader 10.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [iTunesHelper] "C:\Program Files (x86)\iTunes\iTunesHelper.exe"
O4 - HKLM\..\RunOnce: [AvgUninstallURL] cmd.exe /c start http://www.avg.com/ww.special-uninstallation-feedback-app?lic=OQBBAFYARgBSAEUARQAtAFYATgBKADMAMgAtAEcAMwBMAEEAQQAtAEEANAA4ADkAUgAtADkAVQBKAEsARgAtAEUASwBLADMAWAA"&"inst=NwA3AC0ANAAyADIANgA4ADkAMwAzADQALQBGAFAAOQArADMALQBUAEIAOQArADIALQBGAEwAKwA5AC0ARgA5AE0AKwAxAC0ARgA5AE0ANwBCACsANQA"&"prod=90"&"ver=9.0.872
O4 - HKCU\..\Run: [Google Update] "C:\Users\michelle\AppData\Local\Google\Update\GoogleUpdate.exe" /c
O4 - HKCU\..\Run: [Steam] "c:\program files (x86)\steam\steam.exe" -silent
O4 - HKCU\..\Run: [AirVideoServer] C:\Program Files (x86)\AirVideoServer\AirVideoServer.exe
O4 - HKCU\..\Run: [uTorrent] "C:\Program Files (x86)\uTorrent\uTorrent.exe"
O4 - HKCU\..\Run: [Skype] "C:\Program Files (x86)\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - Startup: Folding@home-gpu.lnk = ?
O4 - Startup: Xfire.lnk = C:\Program Files (x86)\Xfire\Xfire.exe
O8 - Extra context menu item: Download All by ASUS Download - C:\Program Files (x86)\ASUS\WL-500W Wireless Router Utilities\ASDownloadAll.htm
O8 - Extra context menu item: Download using ASUS Download - C:\Program Files (x86)\ASUS\WL-500W Wireless Router Utilities\ASDownload.htm
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O17 - HKLM\System\CCS\Services\Tcpip\..\{C120B88A-7065-4C4D-BDD3-065A58FE23FB}: NameServer = 10.0.6.1,203.17.154.34
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~2\COMMON~1\Skype\SKYPE4~1.DLL
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files (x86)\Bonjour\mDNSResponder.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 9862 bytes

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...