Miau Posted March 16, 2013 Report Share Posted March 16, 2013 This time i was able to rename appdata utorrent folder files and utorrent program folder name.meaning no files were in use with phantom utorrent process.I was able to kill all utorrents process handles other than in below: \Device\AfdA disk file, communications endpoint, or driver interfaceIs this virus in memory, if so, can i use memory editor to overwrite or empty it somehow, like i would edit game process with t-search? Link to comment Share on other sites More sharing options...
ciaobaby Posted March 16, 2013 Report Share Posted March 16, 2013 Ermmm??????It seems that a large part of the needed information is missing from your 'report' Link to comment Share on other sites More sharing options...
Miau Posted March 16, 2013 Author Report Share Posted March 16, 2013 uTorrent version 3.2.3.28705Vista 64bit SP2After downloads finished, i closed utorrent from file menu but it didn't close and now it wont start up for new download.Another weir thing was that when i wanted to look utorrent gui from system tray, nothing never opened.as usual in such case i click desktop shortcut. From there i went to file menu and closed utorrent and it turned into zombie process. Link to comment Share on other sites More sharing options...
DreadWingKnight Posted March 16, 2013 Report Share Posted March 16, 2013 Uninstall zonealarm. Link to comment Share on other sites More sharing options...
Miau Posted March 16, 2013 Author Report Share Posted March 16, 2013 I don't have any firewalls and antiviruses other than Windows Vista internal firewall. Link to comment Share on other sites More sharing options...
DreadWingKnight Posted March 16, 2013 Report Share Posted March 16, 2013 Then why did you only choose to disclose that information now? Link to comment Share on other sites More sharing options...
Miau Posted March 16, 2013 Author Report Share Posted March 16, 2013 Did find something from event viewer but nothing with that time stamp when zombie process started.Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 11 user registry handles leaked from \Registry\User\S-1-5-21-3900692805-459086625-2089198769-1000:Process 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000Process 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Microsoft\Windows\CurrentVersion\ExplorerProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Policies\Microsoft\Windows\CurrentVersion\Internet SettingsProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Microsoft\Windows\CurrentVersion\Internet SettingsProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\SoftwareProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\SoftwareProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExtsProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Microsoft\Internet Explorer\MainProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\PoliciesProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000\Software\Policies-------------Windows detected your registry file is still in use by other applications or services. The file will be unloaded now. The applications or services that hold your registry file may not function properly afterwards. DETAIL - 2 user registry handles leaked from \Registry\User\S-1-5-21-3900692805-459086625-2089198769-1000_Classes:Process 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000_CLASSES\Wow6432NodeProcess 2932 (\Device\HarddiskVolume4\Program Files (x86)\uTorrent\uTorrent.exe) has opened key \REGISTRY\USER\S-1-5-21-3900692805-459086625-2089198769-1000_CLASSES\Wow6432Node--------------\SystemRoot\SysWow64\Drivers\GEARAspiWDM.sys has been blocked from loading due to incompatibility with this system. Please contact your software vendor for a compatible version of the driver.--------------The COM+ Event System could not remove the EventSystem.EventSubscription object {24F07233-9005-4D33-AA40-3A2930E107F9}-{00000000-0000-0000-0000-000000000000}-{00000000-0000-0000-0000-000000000000}. The HRESULT was 80070005.-------------- Link to comment Share on other sites More sharing options...
Miau Posted March 17, 2013 Author Report Share Posted March 17, 2013 Today i got another uTorrent zombie process. Event viewer doesn't display any error messages.Yesterday when i had the zombie process my computer didn't enter in sleep mode.The key from my previews post points to \Device\HarddiskVolume4\Users\Human\NTUSER.DATWhat is it, is it like NTUSER.DAT gets locked by zombie processI will test the vuze torrent client, perhaps it's more stable, however no java fan. Link to comment Share on other sites More sharing options...
ciaobaby Posted March 17, 2013 Report Share Posted March 17, 2013 NTUSER.DAT is the file that is used by WINDOWS for your profile settings etc. otherwise known as the registry hives. It is ALWAYS in use when ever Windows is open, and ABSOLUTELY NOTHING AT ALL to do with uTorrent.DO NOT mess about with it, or try to delete it because you will irrevocably 'break' your computer. Link to comment Share on other sites More sharing options...
Miau Posted March 18, 2013 Author Report Share Posted March 18, 2013 Ok thx for warning.Yesterday my computer didn't go to sleep S3 either. It used to work always before i got the uTorrent zombie processes and i didn't have the uTorrent zombie processes atleast a month in a row after clean Vista install.Looks like something got corrupted but i haven't installed any new programs. I don't have any of that pirated software with shady cracks.Because i run resource intensive rendering in my machine CPU 100%, mem 5GB under rendering and it does this called tonemapping 1-2 min after every 25 min (in that time cpu doesn't divide resources that well for new tasks).Can it be like the gpu TDR timeout but only without restart and some files get corrupted or defined as harmful or infected by windows or something?I do the hibernation file cleaning but don't think it will help.Maybe problem is in free memory that i have only 2-3 GB, and uTorrent is set to download 256 MB to memory and not to write down unfinished pieces.But uTorrent never uses that much of a memory. Link to comment Share on other sites More sharing options...
Miau Posted March 18, 2013 Author Report Share Posted March 18, 2013 I have followed "Fix a corrupted user profile" tutorial http://windows.microsoft.com/en-us/windows-vista/fix-a-corrupted-user-profileNow my Computer can enter in hybrid sleep mode again Holy Moly this NTUSER files were huge and filled of garbage, µTorrent DOWNLOAD HISTORY INCLUDED (EVEN DELETED FILES AND ORIGINAL NAMES OF RENAMED FILES). Link to comment Share on other sites More sharing options...
Miau Posted March 21, 2013 Author Report Share Posted March 21, 2013 Little update as with uTorrent 3.3.0.29342,the zombie process bug is still present with Vista computer that is set to function only on ipv4.also in uTorrent disable _incoming _ipv6 is in effect.Only program running on background was Firefox. Link to comment Share on other sites More sharing options...
Miau Posted April 16, 2013 Author Report Share Posted April 16, 2013 HiIt's been a while.have been using Vuze now for some weeks and i have not had any zombie processes that won't allow to put PC in sleep at night.So problem lies in uTorrent core itself somewhere. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.