Jump to content

Excessive CPU usage on a single core


Didonko

Recommended Posts

Allrighty, I've been using uTorrent for quite some time, but two days ago it started to act weird. It started to use excessive amounts of CPU resources only on one of the cores.

System specs

LAPTOP Toshiba Satellite l750-1RE

OS: Windows 7 Home Premium 64 bit Service Pack 1

OS Version: 6.1.7601 (Win7 RTM)

CPU Type : Mobile QuadCore Intel Core i7-2670QM, 2800 MHz (28 x 100) with HyperThread Specs

uTorrent version: Irrelevant, all versions showed the same issue

uTorrent versions tried: 3.1.2, 3.1.3, 3.2, 3.2.1 (beta), 2.2.1

Antivirus program: Avast

Problem description:

Up until three days ago, I used to download torrents of all sizes (ranging 200MB to 40+ gigs - complete seasons in one torrent) and had no problems at all - if it was not for the network usage, utorrent was hardly noticeable (besides the occasional usage of 400+MBs of RAM).

However, since two days ago I am experiencing excessive CPU usage, system hanging due to uTorrent active torrents, crashes of uTorrent. Below I'll attach screenshots of the situation (one is with different wallpaper, had to change to basic theme, fixed it afterwards) - uTorrent with active torrents, without active torrents, not run at all.

I am using Avast as my antivirus software. Disabling the P2P shield, Network shield, and unchecking the "Scan files upon writing" did NOT improve the situation.

Today, I had my PC shut downed. After start up it behaved normally, until ~12GB were downloaded at max speed (2.2MB/s) then it started acting up again. Monitoring HDD activity (Windows gadgets) there was nothing out of the ordinary.

Windows firewall was turned on. After turning it off, it did not have any effect.

What I'm observing is the CPU usage goes up progressively as the download speed goes up. Upon start of a torrent, it goes up to ~40% constant usage with peaks, going up and above 1MB/s (8Mb/s) it peaks to the 90-100% usage and refuses to go higher.

Changing max global connections available at any range from 200 to 800 and even 1200; and max connections per torrent from 10 to 50 to 200 did not have the slightest effect.

I am also setting the affinity of the process of utorrent to any other core but with no effect as well.

Here I will list the things that have changed between 3 days ago (when I had no problems) and the period with problems:

1. Changed internet connection to cable from wifi

a) Since the purchase of the laptop, this is the first time the PC connects via cable

2. Changed partitions to which data is written onto

a) I ran out of free space on partition "D" which is used as data storage

B) I started downloading files onto partition "C", which is the system partition (partition with OS and all programs there are on my system)

3. Added a lot of torrents simultaneously

a) from usually 1-3 torrents, I added 30 torrents on one day. (All of them but two are magnet links)

I will post links to logs and pictures first. The actual logs and pics will be below the links

1. Hijackthis log

2. Process Explorer + dlls

3. Screenshots

NOTE to screenshots: In "Normal activity" Core 1 is green. In all the others is red. I changed it so it is better observed over the blue-ish RAM background color.

1. Normal activity.png file.html

2. 100% CPU big monitoring.png file.html

3. CPU with torrents.png file.html

4. CPU with stopped torrents.png file.html

5. Cache settings.png file.html

Hope all of this helps, in case you need more information, I am more than welcome to provide it.

Hijackthis log

 Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 22:42:30, on 9.7.2012
Platform: Windows 7 SP1 (WinNT 6.00.3505)
MSIE: Internet Explorer v9.00 (9.00.8112.16421)
Boot mode: Normal

Running processes:
C:\ProgramsInstalled\Skype\Phone\Skype.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtMng.exe
C:\ProgramsInstalled\Avast\AvastUI.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\NDSTray.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosA2dp.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHid.exe
C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtHsp.exe
C:\ProgramsInstalled\DAEMON Tools Lite\DTShellHlp.exe
C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSwMgr.exe
C:\Program Files (x86)\Internet Explorer\IELowutil.exe
C:\ProgramsInstalled\AIDA64\aida64.exe
D:\Installation files\HijackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Local Page = C:\Windows\SysWOW64\blank.htm
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
R3 - URLSearchHook: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
F2 - REG:system.ini: UserInit=userinit.exe
O2 - BHO: &Yahoo! Toolbar Helper - {02478D38-C3F9-4efb-9B51-7695ECA05670} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - C:\Program Files (x86)\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: Groove GFS Browser Helper - {72853161-30C5-4D22-B7F9-0BBC1D38A37E} - C:\PROGRA~2\MICROS~1\Office14\GROOVEEX.DLL
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files (x86)\Java\jre7\bin\ssv.dll
O2 - BHO: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\ProgramsInstalled\Avast\aswWebRepIE.dll
O2 - BHO: Windows Live ID Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files (x86)\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: McAfee SiteAdvisor BHO - {B164E929-A1B6-4A06-B104-2CD0E90A88FF} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O2 - BHO: URLRedirectionBHO - {B4F3A835-0E21-4959-BA22-42B3008E02FF} - C:\PROGRA~2\MICROS~1\Office14\URLREDIR.DLL
O2 - BHO: Ask Toolbar BHO - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files (x86)\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: McAfee SiteAdvisor Toolbar - {0EBBBE48-BAD4-4B4C-8E5A-516ABECAE064} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O3 - Toolbar: KMPlayer Toolbar - {D4027C7F-154A-4066-A1AD-4243D8127440} - C:\Program Files (x86)\Ask.com\GenericAskToolbar.dll
O3 - Toolbar: avast! WebRep - {8E5E2654-AD2D-48bf-AC2D-D17F00898D06} - C:\ProgramsInstalled\Avast\aswWebRepIE.dll
O3 - Toolbar: Yahoo! Toolbar - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\PROGRA~2\Yahoo!\Companion\Installs\cpn0\yt.dll
O4 - HKLM\..\Run: [Adobe ARM] "C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [NBAgent] "c:\Program Files (x86)\Nero\Nero 10\Nero BackItUp\NBAgent.exe" /WinStart
O4 - HKLM\..\Run: [TSleepSrv] %ProgramFiles(x86)%\TOSHIBA\TOSHIBA Sleep Utility\TSleepSrv.exe
O4 - HKLM\..\Run: [ToshibaServiceStation] "C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\ToshibaServiceStation.exe" /hide:60
O4 - HKLM\..\Run: [SwitchBoard] C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [avast] "C:\ProgramsInstalled\Avast\avastUI.exe" /nogui
O4 - HKLM\..\Run: [MobileBroadband] C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\MobileBroadband.exe /silent
O4 - HKCU\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\TOPI.exe /STARTUP
O4 - HKCU\..\Run: [DAEMON Tools Lite] "C:\ProgramsInstalled\DAEMON Tools Lite\DTLite.exe" -autorun
O4 - HKCU\..\Run: [Sidebar] C:\Program Files\Windows Sidebar\sidebar.exe /autoRun
O4 - HKCU\..\Run: [Skype] "C:\ProgramsInstalled\Skype\Phone\Skype.exe" /nosplash /minimized
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')
O4 - HKUS\S-1-5-18\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [TOPI.EXE] C:\Program Files (x86)\TOSHIBA\TOSHIBA Online Product Information\topi.exe /STARTUP (User 'Default user')
O4 - .DEFAULT User Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe (User 'Default user')
O4 - Startup: TRDCReminder.lnk = C:\Program Files (x86)\TOSHIBA\TRDCReminder\TRDCReminder.exe
O4 - Global Startup: Bluetooth Manager.lnk = ?
O4 - Global Startup: Toshiba Places Icon Utility.lnk = C:\Program Files\TOSHIBA\TOSHIBA Places Icon Utility\TosDIMonitor.exe
O8 - Extra context menu item: Add to TOSHIBA Bulletin Board - res://C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll/1000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~2\MICROS~1\Office14\EXCEL.EXE/3000
O8 - Extra context menu item: Se&nd to OneNote - res://C:\PROGRA~2\MICROS~1\Office14\ONBttnIE.dll/105
O9 - Extra button: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1004 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files (x86)\Windows Live\Writer\WindowsLiveWriterShortcuts.dll,-1003 - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files (x86)\Windows Live\Writer\WriterBrowserExtension.dll
O9 - Extra button: Send to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra 'Tools' menuitem: Se&nd to OneNote - {2670000A-7350-4f3c-8081-5663EE0C6C49} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIE.dll
O9 - Extra button: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra 'Tools' menuitem: OneNote Lin&ked Notes - {789FE86F-6FC4-46A1-9849-EDE0DB0C95CA} - C:\Program Files (x86)\Microsoft Office\Office14\ONBttnIELinkedNotes.dll
O9 - Extra button: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-229 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
O9 - Extra 'Tools' menuitem: @C:\Program Files\TOSHIBA\BulletinBoard\TosNcUi.dll,-228 - {97F922BD-8563-4184-87EE-8C4ACA438823} - C:\Program Files\TOSHIBA\BulletinBoard\TosBBCom.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O10 - Unknown file in Winsock LSP: c:\program files (x86)\common files\microsoft shared\windows live\wlidnsp.dll
O11 - Options group: [ACCELERATED_GRAPHICS] Accelerated graphics
O15 - Trusted Zone: *.clonewarsadventures.com
O15 - Trusted Zone: *.freerealms.com
O15 - Trusted Zone: *.soe.com
O15 - Trusted Zone: *.sony.com
O18 - Protocol: dssrequest - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: sacore - {5513F07E-936B-4E52-9B00-067394E91CC5} - c:\PROGRA~2\mcafee\SITEAD~1\mcieplg.dll
O18 - Protocol: wlpg - {E43EF6CD-A37A-4A9B-9E6F-83F89B8E6324} - C:\Program Files (x86)\Windows Live\Photo Gallery\AlbumDownloadProtocolHandler.dll
O18 - Filter hijack: text/xml - {807573E5-5146-11D5-A672-00B0D022E945} - C:\Program Files (x86)\Common Files\Microsoft Shared\OFFICE14\MSOXMLMF.DLL
O23 - Service: Adobe Acrobat Update Service (AdobeARMservice) - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
O23 - Service: Adobe Flash Player Update Service (AdobeFlashPlayerUpdateSvc) - Adobe Systems Incorporated - C:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exe
O23 - Service: @%SystemRoot%\system32\Alg.exe,-112 (ALG) - Unknown owner - C:\Windows\System32\alg.exe (file missing)
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Program Files (x86)\Common Files\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: ASP.NET State Service (aspnet_state) - Unknown owner - C:\Windows\Microsoft.NET\Framework\v2.0.50727\aspnet_state.exe (file missing)
O23 - Service: avast! Antivirus - AVAST Software - C:\ProgramsInstalled\Avast\AvastSvc.exe
O23 - Service: avast! Firewall - AVAST Software - C:\ProgramsInstalled\Avast\afwServ.exe
O23 - Service: Bonjour Service - Apple Inc. - C:\Program Files\Bonjour\mDNSResponder.exe
O23 - Service: ConfigFree WiMAX Service (cfWiMAXService) - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFIWmxSvcs64.exe
O23 - Service: ConfigFree Service - TOSHIBA CORPORATION - C:\Program Files (x86)\TOSHIBA\ConfigFree\CFSvcs.exe
O23 - Service: @%SystemRoot%\system32\efssvc.dll,-100 (EFS) - Unknown owner - C:\Windows\System32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\fxsresm.dll,-118 (Fax) - Unknown owner - C:\Windows\system32\fxssvc.exe (file missing)
O23 - Service: FLEXlm License Manager - Unknown owner - C:\ProgramsInstalled\Rational\common\lmgrd.exe
O23 - Service: GamesAppService - WildTangent, Inc. - C:\Program Files (x86)\WildTangent Games\App\GamesAppService.exe
O23 - Service: Google Update Service (gupdate) (gupdate) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: Google Update Service (gupdatem) (gupdatem) - Google Inc. - C:\Program Files (x86)\Google\Update\GoogleUpdate.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files (x86)\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exe
O23 - Service: iPod Service - Apple Inc. - C:\Program Files\iPod\bin\iPodService.exe
O23 - Service: @keyiso.dll,-100 (KeyIso) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: Intel(R) Management and Security Application Local Management Service (LMS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\LMS\LMS.exe
O23 - Service: McAfee SiteAdvisor Service - McAfee, Inc. - c:\PROGRA~2\mcafee\SITEAD~1\McSACore.exe
O23 - Service: @comres.dll,-2797 (MSDTC) - Unknown owner - C:\Windows\System32\msdtc.exe (file missing)
O23 - Service: @c:\Program Files (x86)\Nero\Update\NASvc.exe,-200 (NAUpdate) - Nero AG - c:\Program Files (x86)\Nero\Update\NASvc.exe
O23 - Service: @%SystemRoot%\System32\netlogon.dll,-102 (Netlogon) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: NVIDIA Display Driver Service (nvsvc) - Unknown owner - C:\Windows\system32\nvvsvc.exe (file missing)
O23 - Service: PandoraService (PanService) - Pandora.TV - C:\Program Files (x86)\PANDORA.TV\PanService\PandoraService.exe
O23 - Service: @%systemroot%\system32\psbase.dll,-300 (ProtectedStorage) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%systemroot%\system32\Locator.exe,-2 (RpcLocator) - Unknown owner - C:\Windows\system32\locator.exe (file missing)
O23 - Service: @%SystemRoot%\system32\samsrv.dll,-1 (SamSs) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: SiSoftware Deployment Agent Service (SandraAgentSrv) - SiSoftware - C:\ProgramsInstalled\Sandra\RpcAgentSrv.exe
O23 - Service: @%SystemRoot%\system32\snmptrap.exe,-3 (SNMPTRAP) - Unknown owner - C:\Windows\System32\snmptrap.exe (file missing)
O23 - Service: @%systemroot%\system32\spoolsv.exe,-1 (Spooler) - Unknown owner - C:\Windows\System32\spoolsv.exe (file missing)
O23 - Service: @%SystemRoot%\system32\sppsvc.exe,-101 (sppsvc) - Unknown owner - C:\Windows\system32\sppsvc.exe (file missing)
O23 - Service: Steam Client Service - Valve Corporation - C:\Program Files (x86)\Common Files\Steam\SteamService.exe
O23 - Service: NVIDIA Stereoscopic 3D Driver Service (Stereo Service) - NVIDIA Corporation - C:\Program Files (x86)\NVIDIA Corporation\3D Vision\nvSCPAPISvr.exe
O23 - Service: SwitchBoard - Adobe Systems Incorporated - C:\Program Files (x86)\Common Files\Adobe\SwitchBoard\SwitchBoard.exe
O23 - Service: Notebook Performance Tuning Service (TEMPRO) (TemproMonitoringService) - Toshiba Europe GmbH - C:\Program Files (x86)\Toshiba TEMPRO\TemproSvc.exe
O23 - Service: TMachInfo - TOSHIBA Corporation - C:\Program Files (x86)\TOSHIBA\TOSHIBA Service Station\TMachInfo.exe
O23 - Service: TOSHIBA Optical Disc Drive Service (TODDSrv) - Unknown owner - C:\Windows\system32\TODDSrv.exe (file missing)
O23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\Power Saver\TosCoSrv.exe
O23 - Service: TOSHIBA Bluetooth Service - TOSHIBA CORPORATION - C:\Program Files (x86)\Toshiba\Bluetooth Toshiba Stack\TosBtSrv.exe
O23 - Service: TOSHIBA eco Utility Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TECO\TecoService.exe
O23 - Service: TOSHIBA HDD SSD Alert Service - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TOSHIBA HDD SSD Alert\TosSmartSrv.exe
O23 - Service: TPCH Service (TPCHSrv) - TOSHIBA Corporation - C:\Program Files\TOSHIBA\TPHM\TPCHSrv.exe
O23 - Service: @%SystemRoot%\system32\ui0detect.exe,-101 (UI0Detect) - Unknown owner - C:\Windows\system32\UI0Detect.exe (file missing)
O23 - Service: Intel(R) Management and Security Application User Notification Service (UNS) - Intel Corporation - C:\Program Files (x86)\Intel\Intel(R) Management Engine Components\UNS\UNS.exe
O23 - Service: @%SystemRoot%\system32\vaultsvc.dll,-1003 (VaultSvc) - Unknown owner - C:\Windows\system32\lsass.exe (file missing)
O23 - Service: @%SystemRoot%\system32\vds.exe,-100 (vds) - Unknown owner - C:\Windows\System32\vds.exe (file missing)
O23 - Service: Oneoaaoa Vodafone Mobile Broadband (VmbService) - Vodafone - C:\Program Files (x86)\Vodafone\Vodafone Mobile Broadband\Bin\VmbService.exe
O23 - Service: @%systemroot%\system32\vssvc.exe,-102 (VSS) - Unknown owner - C:\Windows\system32\vssvc.exe (file missing)
O23 - Service: @%SystemRoot%\system32\Wat\WatUX.exe,-601 (WatAdminSvc) - Unknown owner - C:\Windows\system32\Wat\WatAdminSvc.exe (file missing)
O23 - Service: @%systemroot%\system32\wbengine.exe,-104 (wbengine) - Unknown owner - C:\Windows\system32\wbengine.exe (file missing)
O23 - Service: @%Systemroot%\system32\wbem\wmiapsrv.exe,-110 (wmiApSrv) - Unknown owner - C:\Windows\system32\wbem\WmiApSrv.exe (file missing)
O23 - Service: @%PROGRAMFILES%\Windows Media Player\wmpnetwk.exe,-101 (WMPNetworkSvc) - Unknown owner - C:\Program Files (x86)\Windows Media Player\wmpnetwk.exe (file missing)

--
End of file - 15994 bytes

Process Explorer + dlls


Process PID CPU Private Bytes Working Set Description Company Name
System Idle Process 0 72.67 0 K 24 K
System 4 6.37 112 K 324 K
uTorrent.exe 5196 6.16 78,072 K 81,312 K µTorrent BitTorrent, Inc.
Interrupts n/a 5.90 0 K 0 K Hardware Interrupts and DPCs
sidebar.exe 5024 1.87 133,108 K 196,540 K Windows Desktop Gadgets Microsoft Corporation
procexp64.exe 2116 1.43 34,096 K 57,164 K Sysinternals Process Explorer Sysinternals - www.sysinternals.com
audiodg.exe 3856 0.95 18,208 K 19,184 K Windows Audio Device Graph Isolation Microsoft Corporation
plugin-container.exe 6080 0.66 292,816 K 273,024 K Plugin Container for Waterfox Mozilla Corporation
SynTPEnh.exe 4288 0.56 13,024 K 20,240 K Synaptics TouchPad Enhancements Synaptics Incorporated
firefox.exe 5504 0.53 781,408 K 862,696 K Waterfox Mozilla Corporation
Skype.exe 5048 0.46 100,276 K 116,280 K Skype Skype Technologies S.A.
perfmon.exe 3480 0.39 45,344 K 57,452 K Resource and Performance Monitor Microsoft Corporation
dwm.exe 4016 0.34 100,532 K 114,704 K Desktop Window Manager Microsoft Corporation
AvastSvc.exe 1472 0.27 51,588 K 91,576 K avast! Service AVAST Software
svchost.exe 1056 0.26 33,760 K 49,088 K Host Process for Windows Services Microsoft Corporation
Core Temp.exe 632 0.17 5,724 K 2,104 K CPU temperature and system information utility
WmiPrvSE.exe 6380 0.17 7,684 K 11,944 K WMI Provider Host Microsoft Corporation
PandoraService.exe 2480 0.15 17,476 K 14,112 K Pandora.TV service file Pandora.TV
aida64.exe 7408 0.14 35,356 K 44,904 K AIDA64 Extreme Edition FinalWire Ltd.
csrss.exe 680 0.13 4,936 K 9,820 K Client Server Runtime Process Microsoft Corporation
explorer.exe 4036 0.11 89,160 K 114,916 K Windows Explorer Microsoft Corporation
svchost.exe 920 0.08 160,712 K 165,008 K Host Process for Windows Services Microsoft Corporation
taskmgr.exe 7632 0.06 5,976 K 15,476 K Windows Task Manager Microsoft Corporation
LMS.exe 6996 0.03 3,328 K 5,728 K Local Manageability Service Intel Corporation
WmiPrvSE.exe 3364 0.02 22,124 K 27,832 K WMI Provider Host Microsoft Corporation
WmiPrvSE.exe 3396 0.02 12,264 K 18,272 K WMI Provider Host Microsoft Corporation
svchost.exe 352 0.01 7,168 K 11,224 K Host Process for Windows Services Microsoft Corporation
AppleMobileDeviceService.exe 2212 0.01 3,632 K 9,864 K MobileDeviceService Apple Inc.
AvastUI.exe 2192 0.01 21,428 K 7,828 K avast! Antivirus AVAST Software
svchost.exe 1196 0.01 14,440 K 22,580 K Host Process for Windows Services Microsoft Corporation
svchost.exe 904 0.01 6,400 K 12,080 K Host Process for Windows Services Microsoft Corporation
svchost.exe 512 0.01 28,004 K 31,448 K Host Process for Windows Services Microsoft Corporation
NDSTray.exe 5168 < 0.01 9,928 K 1,708 K ConfigFree Task Tray Menu TOSHIBA CORPORATION
lsass.exe 748 < 0.01 7,464 K 14,936 K Local Security Authority Process Microsoft Corporation
svchost.exe 5316 < 0.01 11,696 K 80,256 K Host Process for Windows Services Microsoft Corporation
afwServ.exe 1688 < 0.01 15,852 K 20,508 K avast! firewall service AVAST Software
TOPI.exe 4492 < 0.01 53,572 K 48,480 K TOSHIBA Online Product Information TOSHIBA
mcsacore.exe 2452 < 0.01 21,648 K 5,512 K SiteAdvisor McAfee, Inc.
TosBtMng.exe 1168 < 0.01 9,336 K 14,412 K Bluetooth Manager TOSHIBA CORPORATION.
taskhost.exe 3344 < 0.01 9,892 K 12,800 K Host Process for Windows Tasks Microsoft Corporation
TemproTray.exe 4164 < 0.01 43,924 K 41,624 K Toshiba TEMPRO Toshiba Europe GmbH
VmbService.exe 3260 < 0.01 20,192 K 22,768 K VmbService Vodafone
WLIDSVC.EXE 2396 < 0.01 9,148 K 18,640 K Microsoft® Windows Live ID Service Microsoft Corp.
TMachInfo.exe 6504 < 0.01 37,308 K 37,428 K TSS TMachInfo Service TOSHIBA Corporation
TosReelTimeMonitor.exe 4192 < 0.01 28,992 K 31,560 K Monitor of TOSHIBA ReelTime TOSHIBA Corporation
csrss.exe 564 < 0.01 2,972 K 5,416 K Client Server Runtime Process Microsoft Corporation
svchost.exe 1296 < 0.01 30,240 K 35,628 K Host Process for Windows Services Microsoft Corporation
svchost.exe 5872 < 0.01 14,492 K 18,268 K Host Process for Windows Services Microsoft Corporation
SearchIndexer.exe 5108 < 0.01 47,888 K 38,700 K Microsoft Windows Search Indexer Microsoft Corporation
DTShellHlp.exe 6068 < 0.01 6,100 K 20,792 K DAEMON Tools Shell Extensions Helper DT Soft Ltd
mspaint.exe 7560 < 0.01 57,224 K 78,340 K Paint Microsoft Corporation
wmpnetwk.exe 3276 < 0.01 13,500 K 12,412 K Windows Media Player Network Sharing Service Microsoft Corporation
nvvsvc.exe 1464 < 0.01 6,972 K 14,380 K NVIDIA Driver Helper Service, Version 301.42 NVIDIA Corporation
TemproSvc.exe 2660 < 0.01 33,812 K 26,548 K Toshiba TEMPRO Toshiba Europe GmbH
notepad.exe 4872 < 0.01 4,192 K 10,036 K Notepad Microsoft Corporation
TosBtSrv.exe 1408 < 0.01 4,124 K 7,936 K TOSHIBA Bluetooth Service TOSHIBA CORPORATION
svchost.exe 7112 < 0.01 66,960 K 29,720 K Host Process for Windows Services Microsoft Corporation
TODDSrv.exe 2888 < 0.01 3,292 K 6,152 K TDCSrv Application TOSHIBA Corporation
TosCoSrv.exe 2168 < 0.01 5,232 K 7,976 K TOSHIBA Power Saver TOSHIBA Corporation
WLIDSVCM.EXE 3128 3,040 K 5,220 K Microsoft® Windows Live ID Service Monitor Microsoft Corp.
wlanext.exe 1524 2,888 K 6,296 K Windows Wireless LAN 802.11 Extensibility Framework Microsoft Corporation
winlogon.exe 808 4,264 K 8,740 K Windows Logon Application Microsoft Corporation
wininit.exe 664 2,224 K 5,220 K Windows Start-Up Application Microsoft Corporation
UNS.exe 2708 3,916 K 8,280 K User Notification Service Intel Corporation
TPwrMain.exe 4216 9,544 K 15,144 K TOSHIBA Power Saver TOSHIBA Corporation
TPCHWMsg.exe 3340 5,380 K 9,456 K TOSHIBA PC Health Monitor TOSHIBA Corporation
TPCHSrv.exe 4536 10,564 K 11,972 K TOSHIBA PC Health Monitor TOSHIBA Corporation
TosSmartSrv.exe 5152 4,480 K 9,968 K TosSmartSrv.exe TOSHIBA Corporation
TosSENotify.exe 6876 6,624 K 12,852 K TosSENotify.exe.mui TOSHIBA Corporation
TosNcCore.exe 4172 5,804 K 12,680 K Message Center TOSHIBA Corporation
ToshibaServiceStation.exe 4776 46,648 K 69,844 K TOSHIBA Service Station TOSHIBA Corporation
TosDIMonitor.exe 4460 75,476 K 67,036 K Toshiba Places Icon Utility Toshiba
TosBtHSP.exe 6140 5,220 K 9,268 K TosBtHSP TOSHIBA CORPORATION.
TosBtHid.exe 5384 3,632 K 8,632 K TosBtHid TOSHIBA CORPORATION.
TosA2dp.exe 5988 6,936 K 11,840 K TosA2DP TOSHIBA CORPORATION.
TecoService.exe 3192 5,044 K 9,700 K TOSHIBA eco Utility Service TOSHIBA Corporation
Teco.exe 4300 5,600 K 10,744 K TOSHIBA eco Utility TOSHIBA Corporation
TCrdMain.exe 4248 22,484 K 36,428 K TOSHIBA Flash Cards Main Module TOSHIBA Corporation
taskeng.exe 504 4,152 K 9,068 K Task Scheduler Engine Microsoft Corporation
taskeng.exe 4068 3,996 K 8,776 K Task Scheduler Engine Microsoft Corporation
SynTPHelper.exe 4824 3,328 K 6,008 K Synaptics Pointing Device Helper Synaptics Incorporated
svchost.exe 1876 13,756 K 15,968 K Host Process for Windows Services Microsoft Corporation
svchost.exe 3772 3,432 K 7,428 K Host Process for Windows Services Microsoft Corporation
svchost.exe 2616 2,728 K 7,404 K Host Process for Windows Services Microsoft Corporation
spoolsv.exe 1848 10,504 K 16,440 K Spooler SubSystem App Microsoft Corporation
smss.exe 428 752 K 1,440 K Windows Session Manager Microsoft Corporation
services.exe 728 6,672 K 11,416 K Services and Controller app Microsoft Corporation
rundll32.exe 2524 2,508 K 6,560 K Windows host process (Rundll32) Microsoft Corporation
rundll32.exe 2512 2,492 K 6,068 K Windows host process (Rundll32) Microsoft Corporation
rundll32.exe 2504 1,448 K 3,044 K Windows host process (Rundll32) Microsoft Corporation
nvxdsync.exe 1424 9,724 K 20,132 K NVIDIA User Experience Driver Component NVIDIA Corporation
nvvsvc.exe 984 3,636 K 8,508 K NVIDIA Driver Helper Service, Version 301.42 NVIDIA Corporation
nvSCPAPISvr.exe 1008 2,840 K 6,072 K Stereo Vision Control Panel API Server NVIDIA Corporation
NASvc.exe 7024 2,768 K 7,160 K NeroUpdate Nero AG
mscorsvw.exe 2224 8,344 K 11,192 K .NET Runtime Optimization Service Microsoft Corporation
mscorsvw.exe 6568 4,948 K 6,628 K .NET Runtime Optimization Service Microsoft Corporation
mDNSResponder.exe 2260 2,924 K 6,400 K Bonjour Service Apple Inc.
lsm.exe 756 3,472 K 5,148 K Local Session Manager Service Microsoft Corporation
ielowutil.exe 7428 2,156 K 540 K Internet Low-Mic Utility Tool Microsoft Corporation
dllhost.exe 6300 4,364 K 9,444 K COM Surrogate Microsoft Corporation
conhost.exe 1536 1,480 K 3,172 K Console Window Host Microsoft Corporation
CFSwMgr.exe 6276 4,504 K 560 K ConfigFree Switch Manager Process TOSHIBA CORPORATION
CFSvcs.exe 6880 2,564 K 3,424 K ConfigFree Service Process TOSHIBA CORPORATION
CFIWmxSvcs64.exe 6800 2,992 K 5,336 K ConfigFree Service Process TOSHIBA CORPORATION
armsvc.exe 2104 1,348 K 4,020 K Adobe Acrobat Update Service Adobe Systems Incorporated

Process: uTorrent.exe Pid: 5196

Name Description Company Name Path
advapi32.dll Advanced Windows 32 Base API Microsoft Corporation C:\Windows\SysWOW64\advapi32.dll
apisetschema.dll ApiSet Schema DLL Microsoft Corporation C:\Windows\System32\apisetschema.dll
bcrypt.dll Windows Cryptographic Primitives Library (Wow64) Microsoft Corporation C:\Windows\SysWOW64\bcrypt.dll
bcryptprimitives.dll Windows Cryptographic Primitives Library Microsoft Corporation C:\Windows\SysWOW64\bcryptprimitives.dll
C_1252.NLS C:\Windows\System32\C_1252.NLS
cfgmgr32.dll Configuration Manager DLL Microsoft Corporation C:\Windows\SysWOW64\cfgmgr32.dll
clbcatq.dll COM+ Configuration Catalog Microsoft Corporation C:\Windows\SysWOW64\clbcatq.dll
comctl32.dll User Experience Controls Library Microsoft Corporation C:\Windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.17514_none_41e6975e2bd6f2b2\comctl32.dll
comdlg32.dll Common Dialogs DLL Microsoft Corporation C:\Windows\SysWOW64\comdlg32.dll
crypt32.dll Crypto API32 Microsoft Corporation C:\Windows\SysWOW64\crypt32.dll
cryptbase.dll Base cryptographic API DLL Microsoft Corporation C:\Windows\SysWOW64\cryptbase.dll
cryptsp.dll Cryptographic Service Provider API Microsoft Corporation C:\Windows\SysWOW64\cryptsp.dll
devobj.dll Device Information Set DLL Microsoft Corporation C:\Windows\SysWOW64\devobj.dll
dhcpcsvc.dll DHCP Client Service Microsoft Corporation C:\Windows\SysWOW64\dhcpcsvc.dll
dhcpcsvc6.dll DHCPv6 Client Microsoft Corporation C:\Windows\SysWOW64\dhcpcsvc6.dll
dnsapi.dll DNS Client API DLL Microsoft Corporation C:\Windows\SysWOW64\dnsapi.dll
dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation C:\Windows\SysWOW64\dwmapi.dll
FirewallAPI.dll Windows Firewall API Microsoft Corporation C:\Windows\SysWOW64\FirewallAPI.dll
FWPUCLNT.DLL FWP/IPsec User-Mode API Microsoft Corporation C:\Windows\SysWOW64\FWPUCLNT.DLL
gdi32.dll GDI Client DLL Microsoft Corporation C:\Windows\SysWOW64\gdi32.dll
IconCodecService.dll Converts a PNG part of the icon to a legacy bmp icon Microsoft Corporation C:\Windows\SysWOW64\IconCodecService.dll
iertutil.dll Run time utility for Internet Explorer Microsoft Corporation C:\Windows\SysWOW64\iertutil.dll
imm32.dll Multi-User Windows IMM32 API Client DLL Microsoft Corporation C:\Windows\SysWOW64\imm32.dll
index.dat C:\Users\Didonko\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\index.dat
index.dat C:\Users\Didonko\AppData\Roaming\Microsoft\Windows\Cookies\index.dat
index.dat C:\Users\Didonko\AppData\Local\Microsoft\Windows\History\History.IE5\index.dat
IPHLPAPI.DLL IP Helper API Microsoft Corporation C:\Windows\SysWOW64\IPHLPAPI.DLL
kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation C:\Windows\SysWOW64\kernel32.dll
KernelBase.dll Windows NT BASE API Client DLL Microsoft Corporation C:\Windows\SysWOW64\KernelBase.dll
KernelBase.dll.mui Windows NT BASE API Client DLL Microsoft Corporation C:\Windows\SysWOW64\en-US\KernelBase.dll.mui
locale.nls C:\Windows\System32\locale.nls
lpk.dll Language Pack Microsoft Corporation C:\Windows\SysWOW64\lpk.dll
mdnsNSP.dll Bonjour Namespace Provider Apple Inc. C:\Program Files (x86)\Bonjour\mdnsNSP.dll
msasn1.dll ASN.1 Runtime APIs Microsoft Corporation C:\Windows\SysWOW64\msasn1.dll
msctf.dll MSCTF Server DLL Microsoft Corporation C:\Windows\SysWOW64\msctf.dll
msctf.dll.mui MSCTF Server DLL Microsoft Corporation C:\Windows\SysWOW64\en-US\msctf.dll.mui
msimg32.dll GDIEXT Client DLL Microsoft Corporation C:\Windows\SysWOW64\msimg32.dll
msvcrt.dll Windows NT CRT DLL Microsoft Corporation C:\Windows\SysWOW64\msvcrt.dll
mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation C:\Windows\SysWOW64\mswsock.dll
ncrypt.dll Windows cryptographic library Microsoft Corporation C:\Windows\SysWOW64\ncrypt.dll
normaliz.dll Unicode Normalization DLL Microsoft Corporation C:\Windows\SysWOW64\normaliz.dll
npmproxy.dll Network List Manager Proxy Microsoft Corporation C:\Windows\SysWOW64\npmproxy.dll
nsi.dll NSI User-mode interface DLL Microsoft Corporation C:\Windows\SysWOW64\nsi.dll
ntdll.dll NT Layer DLL Microsoft Corporation C:\Windows\System32\ntdll.dll
ntdll.dll NT Layer DLL Microsoft Corporation C:\Windows\SysWOW64\ntdll.dll
ole32.dll Microsoft OLE for Windows Microsoft Corporation C:\Windows\SysWOW64\ole32.dll
oleaut32.dll Microsoft Corporation C:\Windows\SysWOW64\oleaut32.dll
profapi.dll User Profile Basic API Microsoft Corporation C:\Windows\SysWOW64\profapi.dll
psapi.dll Process Status Helper Microsoft Corporation C:\Windows\SysWOW64\psapi.dll
R000000000009.clb C:\Windows\Registration\R000000000009.clb
rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation C:\Windows\SysWOW64\rasadhlp.dll
rpcrt4.dll Remote Procedure Call Runtime Microsoft Corporation C:\Windows\SysWOW64\rpcrt4.dll
RpcRtRemote.dll Remote RPC Extension Microsoft Corporation C:\Windows\SysWOW64\RpcRtRemote.dll
rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation C:\Windows\SysWOW64\rsaenh.dll
sahook.dll SiteAdvisor McAfee, Inc. C:\Program Files (x86)\McAfee\SiteAdvisor\sahook.dll
sechost.dll Host for SCM/SDDL/LSA Lookup APIs Microsoft Corporation C:\Windows\SysWOW64\sechost.dll
secur32.dll Security Support Provider Interface Microsoft Corporation C:\Windows\SysWOW64\secur32.dll
setupapi.dll Windows Setup API Microsoft Corporation C:\Windows\SysWOW64\setupapi.dll
shell32.dll Windows Shell Common Dll Microsoft Corporation C:\Windows\SysWOW64\shell32.dll
shlwapi.dll Shell Light-weight Utility Library Microsoft Corporation C:\Windows\SysWOW64\shlwapi.dll
snxhk.dll avast! snxhk AVAST Software C:\ProgramsInstalled\Avast\snxhk.dll
SortDefault.nls C:\Windows\Globalization\Sorting\SortDefault.nls
sspicli.dll Security Support Provider Interface Microsoft Corporation C:\Windows\SysWOW64\sspicli.dll
StaticCache.dat C:\Windows\Fonts\StaticCache.dat
urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation C:\Windows\SysWOW64\urlmon.dll
user32.dll Multi-User Windows USER API Client DLL Microsoft Corporation C:\Windows\SysWOW64\user32.dll
userenv.dll Userenv Microsoft Corporation C:\Windows\SysWOW64\userenv.dll
usp10.dll Uniscribe Unicode script processor Microsoft Corporation C:\Windows\SysWOW64\usp10.dll
uTorrent.exe µTorrent BitTorrent, Inc. C:\ProgramsInstalled\Utorrent\uTorrent.exe
uxtheme.dll Microsoft UxTheme Library Microsoft Corporation C:\Windows\SysWOW64\uxtheme.dll
version.dll Version Checking and File Installation Libraries Microsoft Corporation C:\Windows\SysWOW64\version.dll
WindowsCodecs.dll Microsoft Windows Codecs Library Microsoft Corporation C:\Windows\SysWOW64\WindowsCodecs.dll
wininet.dll Internet Extensions for Win32 Microsoft Corporation C:\Windows\SysWOW64\wininet.dll
winnsi.dll Network Store Information RPC interface Microsoft Corporation C:\Windows\SysWOW64\winnsi.dll
wintrust.dll Microsoft Trust Verification APIs Microsoft Corporation C:\Windows\SysWOW64\wintrust.dll
WLIDNSP.DLL Microsoft® Windows Live ID Namespace Provider Microsoft Corp. C:\Program Files (x86)\Common Files\microsoft shared\Windows Live\WLIDNSP.DLL
wow64.dll Win32 Emulation on NT64 Microsoft Corporation C:\Windows\System32\wow64.dll
wow64cpu.dll AMD64 Wow64 CPU Microsoft Corporation C:\Windows\System32\wow64cpu.dll
wow64win.dll Wow64 Console and Win32 API Logging Microsoft Corporation C:\Windows\System32\wow64win.dll
ws2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation C:\Windows\SysWOW64\ws2_32.dll
wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation C:\Windows\SysWOW64\wship6.dll
WSHTCPIP.DLL Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation C:\Windows\SysWOW64\WSHTCPIP.DLL

Link to comment
Share on other sites

McAfee SiteAdvisor fully removed - standing by for further development. So far so good, but that was the case after the restart yesterday as well.

On another note, why would McAfee start interfering now, after 6 months of staying idle and not making a beep?

Link to comment
Share on other sites

Due to the lack of proper internet connection, uTorrent will not be active in the next few days.

After the removal of McAfee site adviser, for the time being after the restart (~12-14GB download size) the CPU scored significantly lower usage. While one gadget still shows momentary peaks (refresh rate is set at 1 sec) which were not visible on the other gadget. The system has been stable, did not hang.

However, I would like to give it another try, this time leave it for longer period of time and greater torrent load (50+ GB)

Thank you for the quick answer, I think it really helped.

Link to comment
Share on other sites

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...