Spirotot Posted January 19, 2009 Report Share Posted January 19, 2009 I'm running Windows 7 Beta 1, and for anti-virus/firewall I'm using Kaspersky Internet Security 8.0 (Technical Preview for Windows 7).My problem is this: uTorrent seems to run just fine when I first start it. When I'm ready to close it, I click Exit, and it seems to close just fine. But, "uTorrent.exe" still shows up in the list of running processes in the Task Manager. When I try to end the process, it says it can't kill the process because "Access [is] denied." If I right-click on the process and click Properties, I get a window for the properties of the Windows system32 folder! Very strange. The only way I've found to get rid of the processes so far is to reboot my computer.So, since there's no beta version of uTorrent out, I upgraded to the alpha version. Same issue.If you need any extra info, just let me know.Any and all help is appreciated! Thanks. Link to comment Share on other sites More sharing options...
BikeHelmet Posted January 19, 2009 Report Share Posted January 19, 2009 Have you tried using Process Explorer to kill it?It ignores pesky access permissions, and kills it anyway. Link to comment Share on other sites More sharing options...
Spirotot Posted January 20, 2009 Author Report Share Posted January 20, 2009 I have, to no avail. I get the same (or at least similar) "Access Denied" message. Link to comment Share on other sites More sharing options...
BikeHelmet Posted January 20, 2009 Report Share Posted January 20, 2009 Are you logged in as an admin? Have you tried running Process Explorer as an admin? That right-click "Run-As" option can make all the difference.If it doesn't work then, then... no clue, and good luck. Link to comment Share on other sites More sharing options...
Spirotot Posted January 20, 2009 Author Report Share Posted January 20, 2009 I am logged in as an admin. And I have tried running the Task Manager, Process Explorer, and Hijackthis as an administrator (right-click -> Run as administrator), and none of them were able to kill the process. Link to comment Share on other sites More sharing options...
moogly Posted January 20, 2009 Report Share Posted January 20, 2009 Can you post here the Hijackthis and Process Explorer logs when uT is running. Link to comment Share on other sites More sharing options...
Spirotot Posted January 21, 2009 Author Report Share Posted January 21, 2009 Hijackthis log (with uTorrent still running normally):Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:10:20 PM, on 1/20/2009Platform: Unknown Windows (WinNT 6.01.2904)MSIE: Internet Explorer v8.00 (8.00.7000.0000)Boot mode: NormalRunning processes:C:\Windows\system32\taskhost.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Windows\system32\igfxsrvc.exeC:\Windows\RtHDVCpl.exeC:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exeC:\Program Files\Synaptics\SynTP\SynToshiba.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exeC:\Program Files\Zune\ZuneLauncher.exeC:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\avp.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Users\Aaron\AppData\Local\Apps\2.0\3EQ8M5C0.EEV\WOPRBQ5K.352\tray..tion_d00346c2ca499f4e_0001.0002_7d7e1ea01c37e8ce\trayay.exeC:\Program Files\RocketDock\RocketDock.exeC:\Program Files\NeoSmart Technologies\iReboot\iReboot.exeC:\Program Files\Windows Live\Contacts\wlcomm.exeC:\Program Files\uTorrent\uTorrent.exeC:\Windows\system32\msfeedssync.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\System32\taskmgr.exeC:\Program Files\Zune\Zune.exec:\Program Files\Zune\ZuneEnc.exeC:\Program Files\Windows Live\Mail\wlmail.exeC:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXEC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstartR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstartR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dllO2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dllO2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dllO2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dllO3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dllO4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exeO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exeO4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exeO4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\avp.exe"O4 - HKCU\..\Run: [A2Y] "C:\Users\Aaron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accountable2You\Accountable2You Product Suite.appref-ms"O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O4 - Global Startup: iReboot 1.1.0.lnk = C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exeO4 - Global Startup: Privoxy.lnk = C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exeO8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\ie_banner_deny.htmO8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dllO9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dllO9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\scieplgn.dllO9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLLO13 - Gopher Prefix: O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cabO16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cabO16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CABO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15102/CTPID.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cabO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0FO\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0FO\kloehk.dllO20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exeO23 - Service: Kaspersky Anti-Virus 8.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\avp.exeO23 - Service: Blue Coat K9 Web Protection (bckwfs) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exeO23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: iReboot Background Service (iReboot) - Unknown owner - C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exeO23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exeO23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe--End of file - 10917 bytesProject Explorer log (with uTorrent still running normally):Process PID CPU Description Company NameSystem Idle Process 0 2.94 Interrupts n/a 11.77 Hardware Interrupts DPCs n/a Deferred Procedure Calls System 4 11.77 smss.exe 388 Windows Session Manager Microsoft Corporationcsrss.exe 584 Client Server Runtime Process Microsoft Corporationwininit.exe 636 Windows Start-Up Application Microsoft Corporation services.exe 728 Services and Controller app Microsoft Corporation svchost.exe 872 Host Process for Windows Services Microsoft Corporation igfxsrvc.exe 3780 igfxsrvc Module Intel Corporation wlcomm.exe 4268 Windows Live Communications Platform Microsoft Corporation ZuneEnc.exe 5752 Zune Encoder Helper Microsoft Corporation svchost.exe 932 1.47 Host Process for Windows Services Microsoft Corporation svchost.exe 980 Host Process for Windows Services Microsoft Corporation audiodg.exe 5804 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1100 Host Process for Windows Services Microsoft Corporation dwm.exe 3360 10.29 Desktop Window Manager Microsoft Corporation WUDFHost.exe 3344 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation svchost.exe 1156 Host Process for Windows Services Microsoft Corporation svchost.exe 1288 Host Process for Windows Services Microsoft Corporation spoolsv.exe 1536 Spooler SubSystem App Microsoft Corporation svchost.exe 1572 Host Process for Windows Services Microsoft Corporation svchost.exe 1640 Host Process for Windows Services Microsoft Corporation avp.exe 1736 10.30 k9filter.exe 1760 mDNSResponder.exe 1792 Bonjour Service Apple Computer, Inc. svchost.exe 1856 Host Process for Windows Services Microsoft Corporation GoogleUpdaterService.exe 1916 gusvc Google iRebootd.exe 1940 iReboot Service pinger.exe 2032 Ivpsvmgr.exe 2604 IVP Service Manager Application TOSHIBA Corporation swupdtmr.exe 436 TosCoSrv.exe 1608 TOSHIBA Power Saver TOSHIBA Corporation svchost.exe 2788 23.52 Host Process for Windows Services Microsoft Corporation svchost.exe 2836 Host Process for Windows Services Microsoft Corporation wmpnetwk.exe 3624 Windows Media Player Network Sharing Service Microsoft Corporation SearchIndexer.exe 3904 Microsoft Windows Search Indexer Microsoft Corporation ZuneNss.exe 420 Zune Network Sharing Service Microsoft Corporation taskhost.exe 2888 Host Process for Windows Tasks Microsoft Corporation taskhost.exe 2944 Host Process for Windows Tasks Microsoft Corporation msfeedssync.exe 4512 Microsoft Feeds Synchronization Microsoft Corporation lsass.exe 736 Local Security Authority Process Microsoft Corporation lsm.exe 744 Local Session Manager Service Microsoft Corporationcsrss.exe 648 Client Server Runtime Process Microsoft Corporationwinlogon.exe 704 Windows Logon Application Microsoft Corporationexplorer.exe 3508 Windows Explorer Microsoft Corporation hkcmd.exe 1588 hkcmd Module Intel Corporation igfxpers.exe 3720 persistence Module Intel Corporation SynTPEnh.exe 3732 2.94 Synaptics TouchPad Enhancements Synaptics, Inc. SynToshiba.exe 2996 Toshiba Custom PlugIn Application Synaptics, Inc. SynTPHelper.exe 3616 Synaptics Pointing Device Helper Synaptics, Inc. RtHDVCpl.exe 4044 HD Audio Control Panel Realtek Semiconductor schedhlp.exe 3712 Acronis Scheduler Helper Acronis jusched.exe 444 Java(TM) Platform SE binary Sun Microsystems, Inc. realsched.exe 2272 RealNetworks Scheduler RealNetworks, Inc. TrueImageMonitor.exe 3668 Acronis True Image Monitor Acronis ZuneLauncher.exe 3456 Zune Auto-Launcher Microsoft Corporation avp.exe 928 Kaspersky Anti-Virus Kaspersky Lab msnmsgr.exe 3956 1.47 Windows Live Messenger Microsoft Corporation RocketDock.exe 1420 iReboot.exe 2876 iReboot NeoSmart Technologies uTorrent.exe 4952 µTorrent BitTorrent, Inc. firefox.exe 5840 4.41 Firefox Mozilla Corporation taskmgr.exe 5692 1.47 Windows Task Manager Microsoft Corporation Zune.exe 5884 7.35 Microsoft Zune Microsoft Corporation wlmail.exe 3924 Windows Live Mail Microsoft Corporation WINWORD.EXE 4956 Microsoft Office Word Microsoft Corporation procexp.exe 2720 4.41 Sysinternals Process Explorer Sysinternals - www.sysinternals.comtrayay.exe 428 Accountable2You Product Suite Accountable2Youoctoshape.exe 5768 Octoshape add-in for Adobe Flash Player Octoshape ApS octoshape.exe 2956 Octoshape add-in for Adobe Flash Player Octoshape ApSoctoshape.exe 5936 Octoshape add-in for Adobe Flash Player Octoshape ApS octoshape.exe 3368 Octoshape add-in for Adobe Flash Player Octoshape ApSProcess: uTorrent.exe Pid: 4952Name Description Company Name Version{6AF0698E-D558-4F6E-9B3C-3716689AF493}.2.ver0x0000000000000001.db {AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x000000000000000d.db {DDF571F2-BE98-426D-8288-1A9A39C3FDA2}.2.ver0x0000000000000001.db actxprxy.dll ActiveX Interface Marshaling Library Microsoft Corporation 6.01.7000.0000adialhk.dll kldialhk Kaspersky Lab 8.00.0000.1015ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.01.7000.0000ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000AUTHZ.dll Authorization Framework Microsoft Corporation 6.01.7000.0000CFGMGR32.dll Configuration Manager DLL Microsoft Corporation 6.01.7000.0000CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.7930.0000COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7000.0000comctl32.dll.mui User Experience Controls Library Microsoft Corporation 6.10.7000.0000comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.01.7000.0000credssp.dll Credential Delegation Security Package Microsoft Corporation 6.01.7000.0000CRYPT32.dll Crypto API32 Microsoft Corporation 6.01.7000.0000CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.01.7000.0000CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.01.7000.0000cversions.2.db cversions.2.db cversions.2.db DEVOBJ.dll Device Information Set DLL Microsoft Corporation 6.01.7000.0000dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.01.7000.0000dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.01.7000.0000DnsApi.dll DNS Client API DLL Microsoft Corporation 6.01.7000.0000DUI70.dll Windows DirectUI Engine Microsoft Corporation 6.01.7000.0000DUser.dll Windows DirectUser Engine Microsoft Corporation 6.01.7000.0000duser.dll.mui Windows DirectUser Engine Microsoft Corporation 6.01.7000.0000dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation 6.01.7000.0000FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.01.7000.0000fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.01.7000.0000GDI32.dll GDI Client DLL Microsoft Corporation 6.01.7000.0000GPAPI.dll Group Policy Client API Microsoft Corporation 6.01.7000.0000hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.01.7000.0000iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.00.7000.0000IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.01.7000.0000Iphlpapi.dll IP Helper API Microsoft Corporation 6.01.7000.0000kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.01.7000.0000KERNELBASE.dll Windows NT BASE API Mini Client DLL Microsoft Corporation 6.01.7000.0000KernelBase.dll.mui Windows NT BASE API Mini Client DLL Microsoft Corporation 6.01.7000.0000kloehk.dll Kaspersky OE plugin loader Kaspersky Lab 8.00.0000.1015locale.nls LPK.dll Language Pack Microsoft Corporation 6.01.7000.0000mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.01.7000.0000MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.01.7000.0000msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.7000.0000mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.01.7000.0000msxml3.dll MSXML 3.0 SP11 Microsoft Corporation 8.110.1041.0000msxml3r.dll XML Resources Microsoft Corporation 8.20.8730.0001netshell.dll Network Connections Shell Microsoft Corporation 6.01.7000.0000netutils.dll Net Win32 API Helpers DLL Microsoft Corporation 6.01.7000.0000nlaapi.dll Network Location Awareness 2 Microsoft Corporation 6.01.7000.0000normnfd.nls npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.01.7000.0000NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.01.7000.0000ntdll.dll NT Layer DLL Microsoft Corporation 6.01.7000.0000ntmarta.dll Windows NT MARTA provider Microsoft Corporation 6.01.7000.0000ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.01.7000.0000oleaut32.dll Microsoft Corporation 6.01.7000.0000peerdist.dll BranchCache Client Library Microsoft Corporation 6.01.7000.0000profapi.dll User Profile Basic API Microsoft Corporation 6.01.7000.0000propsys.dll Microsoft Property System Microsoft Corporation 7.00.7000.0000PSAPI.DLL Process Status Helper Microsoft Corporation 6.01.7000.0000R00000000000d.clb rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.01.7000.0000RocketDock.dll RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.01.7000.0000RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.01.7000.0000rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.01.7000.0000sechost.dll SCM/SDDL/LSA Lookup APIs DLL for minwin Microsoft Corporation 6.01.7000.0000SETUPAPI.dll Windows Setup API Microsoft Corporation 6.01.7000.0000SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.01.7000.0000shfolder.dll Shell Folder Service Microsoft Corporation 6.01.7000.0000SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.01.7000.0000slc.dll Software Licensing Client Dll Microsoft Corporation 6.01.7000.0000SortDefault.nls SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.01.7000.0000SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.01.7000.0000StaticCache.dat StaticCache.dat SXS.DLL Fusion 2.5 Microsoft Corporation 6.01.7000.0000upnp.dll UPnP Control Point API Microsoft Corporation 6.01.7000.0000urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 8.00.7000.0000USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.01.7000.0000USERENV.dll Userenv Microsoft Corporation 6.01.7000.0000USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7000.0000uTorrent.exe µTorrent BitTorrent, Inc. 1.09.0000.13910uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.01.7000.0000VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.01.7000.0000webio.dll Web Transfer Protocols API Microsoft Corporation 6.01.7000.0000WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.01.7000.0000WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.01.7000.0000wkscli.dll Workstation Service Client DLL Microsoft Corporation 6.01.7000.0000WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.01.7000.0000WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.01.7000.0000wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.01.7000.0000wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.01.7000.0000Hijackthis log (after trying to exit uTorrent):Logfile of Trend Micro HijackThis v2.0.2Scan saved at 6:20:01 PM, on 1/20/2009Platform: Unknown Windows (WinNT 6.01.2904)MSIE: Internet Explorer v8.00 (8.00.7000.0000)Boot mode: NormalRunning processes:C:\Windows\system32\taskhost.exeC:\Windows\system32\Dwm.exeC:\Windows\Explorer.EXEC:\Windows\System32\hkcmd.exeC:\Windows\System32\igfxpers.exeC:\Program Files\Synaptics\SynTP\SynTPEnh.exeC:\Windows\system32\igfxsrvc.exeC:\Windows\RtHDVCpl.exeC:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exeC:\Program Files\Synaptics\SynTP\SynToshiba.exeC:\Program Files\Java\jre6\bin\jusched.exeC:\Program Files\Common Files\Real\Update_OB\realsched.exeC:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exeC:\Program Files\Zune\ZuneLauncher.exeC:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\avp.exeC:\Program Files\Synaptics\SynTP\SynTPHelper.exeC:\Program Files\Windows Live\Messenger\msnmsgr.exeC:\Users\Aaron\AppData\Local\Apps\2.0\3EQ8M5C0.EEV\WOPRBQ5K.352\tray..tion_d00346c2ca499f4e_0001.0002_7d7e1ea01c37e8ce\trayay.exeC:\Program Files\RocketDock\RocketDock.exeC:\Program Files\NeoSmart Technologies\iReboot\iReboot.exeC:\Program Files\Windows Live\Contacts\wlcomm.exeC:\Windows\system32\msfeedssync.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Users\Aaron\AppData\Roaming\Macromedia\Flash Player\www.macromedia.com\bin\octoshape\octoshape.exeC:\Program Files\Mozilla Firefox\firefox.exeC:\Windows\System32\taskmgr.exeC:\Program Files\Zune\Zune.exec:\Program Files\Zune\ZuneEnc.exeC:\Program Files\Windows Live\Mail\wlmail.exeC:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXEC:\Users\Aaron\Desktop\Installers\ProcessExplorer\procexp.exeC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\Trend Micro\HijackThis\HijackThis.exeR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstartR1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://www.toshibadirect.com/dpdstartR1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.toshibadirect.com/dpdstartR0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant = R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch = R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = localR0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = O1 - Hosts: ::1 localhostO2 - BHO: IE7Pro BHO - {00011268-E188-40DF-A514-835FCD78B1BF} - C:\Program Files\IEPro\iepro.dllO2 - BHO: btorbit.com - {000123B4-9B42-4900-B3F7-F4B073EFC214} - C:\Program Files\Orbitdownloader\orbitcth.dllO2 - BHO: Adobe PDF Reader Link Helper - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dllO2 - BHO: Click-to-Call BHO - {5C255C8A-E604-49b4-9D64-90988571CECB} - C:\Program Files\Windows Live\Messenger\wlchtc.dllO2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dllO2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dllO2 - BHO: Google Toolbar Notifier BHO - {AF69DE43-7D58-4638-B6FA-CE66B5AD205D} - C:\Program Files\Google\GoogleToolbarNotifier\4.1.805.4472\swg.dllO2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dllO3 - Toolbar: (no name) - {0BF43445-2F28-4351-9252-17FE6E806AA0} - (no file)O3 - Toolbar: Grab Pro - {C55BBCD6-41AD-48AD-9953-3609C48EACC7} - C:\Program Files\Orbitdownloader\GrabPro.dllO3 - Toolbar: TextAloud - {F053C368-5458-45B2-9B4D-D8914BDDDBFF} - C:\PROGRA~1\TEXTAL~1\TAForIE.dllO4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exeO4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exeO4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exeO4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exeO4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exeO4 - HKLM\..\Run: [Acronis Scheduler2 Service] "C:\Program Files\Common Files\Acronis\Schedule2\schedhlp.exe"O4 - HKLM\..\Run: [AcronisTimounterMonitor] C:\Program Files\Acronis\TrueImageHome\TimounterMonitor.exeO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKLM\..\Run: [QuickTime Task] "C:\Program Files\QuickTime Alternative\QTTask.exe" -atboottimeO4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"O4 - HKLM\..\Run: [TkBellExe] "C:\Program Files\Common Files\Real\Update_OB\realsched.exe" -osbootO4 - HKLM\..\Run: [TrueImageMonitor.exe] C:\Program Files\Acronis\TrueImageHome\TrueImageMonitor.exeO4 - HKLM\..\Run: [Zune Launcher] "c:\Program Files\Zune\ZuneLauncher.exe"O4 - HKLM\..\Run: [AVP] "C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\avp.exe"O4 - HKCU\..\Run: [A2Y] "C:\Users\Aaron\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accountable2You\Accountable2You Product Suite.appref-ms"O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exeO4 - HKCU\..\Run: [MsnMsgr] "C:\Program Files\Windows Live\Messenger\MsnMsgr.Exe" /backgroundO4 - HKCU\..\Run: [RocketDock] "C:\Program Files\RocketDock\RocketDock.exe"O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exeO4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-19\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'LOCAL SERVICE')O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /autoRun (User 'NETWORK SERVICE')O4 - HKUS\S-1-5-20\..\RunOnce: [mctadmin] C:\Windows\System32\mctadmin.exe (User 'NETWORK SERVICE')O4 - Global Startup: iReboot 1.1.0.lnk = C:\Program Files\NeoSmart Technologies\iReboot\iReboot.exeO4 - Global Startup: Privoxy.lnk = C:\Program Files\Vidalia Bundle\Privoxy\privoxy.exeO8 - Extra context menu item: &Download by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/201O8 - Extra context menu item: &Grab video by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/204O8 - Extra context menu item: Add to Anti-Banner - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\ie_banner_deny.htmO8 - Extra context menu item: Do&wnload selected by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/203O8 - Extra context menu item: Down&load all by Orbit - res://C:\Program Files\Orbitdownloader\orbitmxt.dll/202O9 - Extra button: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dllO9 - Extra 'Tools' menuitem: IE7Pro Preferences - {0026439F-A980-4f18-8C95-4F1CBBF9C1D8} - C:\Program Files\IEPro\iepro.dllO9 - Extra button: Web Anti-Virus statistics - {1F460357-8A94-4D71-9CA3-AA4ACF32ED8E} - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\scieplgn.dllO9 - Extra button: Blog This - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra 'Tools' menuitem: &Blog This in Windows Live Writer - {219C3416-8CB2-491a-A3C7-D9FCDDC9D600} - C:\Program Files\Windows Live\Writer\WriterBrowserExtension.dllO9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~4\OFFICE11\REFIEBAR.DLLO13 - Gopher Prefix: O16 - DPF: {0A5FD7C5-A45C-49FC-ADB5-9952547D5715} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15031/CTSUEng.cabO16 - DPF: {67A5F8DC-1A4B-4D66-9F24-A704AD929EEE} (System Requirements Lab) - http://www.systemrequirementslab.com/sysreqlab2.cabO16 - DPF: {6C269571-C6D7-4818-BCA4-32A035E8C884} (Creative Software AutoUpdate) - http://www.creative.com/softwareupdate/su/ocx/15101/CTSUEng.cabO16 - DPF: {8BC53B30-32E4-4ED3-BEF9-DB761DB77453} (CInstallLPCtrl Object) - http://u3.sandisk.com/download/apps/LPInstaller.CABO16 - DPF: {F6ACF75C-C32C-447B-9BEF-46B766368D29} (Creative Software AutoUpdate Support Package) - http://www.creative.com/softwareupdate/su/ocx/15102/CTPID.cabO16 - DPF: {FD0B6769-6490-4A91-AA0A-B5AE0DC75AC9} (Performance Viewer Activex Control) - https://secure.logmein.com/activex/RACtrl.cabO20 - AppInit_DLLs: C:\PROGRA~1\KASPER~1\KASPER~1.0FO\adialhk.dll,C:\PROGRA~1\KASPER~1\KASPER~1.0FO\kloehk.dllO20 - Winlogon Notify: DfLogon - LogonDll.dll (file missing)O23 - Service: Acronis Scheduler2 Service (AcrSch2Svc) - Acronis - C:\Program Files\Common Files\Acronis\Schedule2\schedul2.exeO23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exeO23 - Service: Agere Modem Call Progress Audio (AgereModemAudio) - Agere Systems - C:\Windows\system32\agrsmsvc.exeO23 - Service: Kaspersky Anti-Virus 8.0 (AVP) - Kaspersky Lab - C:\Program Files\Kaspersky Lab\Kaspersky Anti-Virus 8.0 for Windows Workstations\avp.exeO23 - Service: Blue Coat K9 Web Protection (bckwfs) - Unknown owner - C:\Program Files\Blue Coat K9 Web Protection\k9filter.exeO23 - Service: Bonjour Service - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: Google Updater Service (gusvc) - Google - C:\Program Files\Google\Common\Google Updater\GoogleUpdaterService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\1150\Intel 32\IDriverT.exeO23 - Service: iReboot Background Service (iReboot) - Unknown owner - C:\Program Files\NeoSmart Technologies\iReboot\iRebootd.exeO23 - Service: pinger - Unknown owner - C:\TOSHIBA\IVP\ISM\pinger.exeO23 - Service: Remote Packet Capture Protocol v.0 (experimental) (rpcapd) - CACE Technologies - C:\Program Files\WinPcap\rpcapd.exeO23 - Service: Swupdtmr - Unknown owner - c:\TOSHIBA\IVP\swupdate\swupdtmr.exeO23 - Service: TOSHIBA Power Saver (TosCoSrv) - TOSHIBA Corporation - C:\Program Files\Toshiba\Power Saver\TosCoSrv.exe--End of file - 10980 bytesProcess Explorer log (after trying to exit uTorrent):Process PID CPU Description Company NameSystem Idle Process 0 61.20 Interrupts n/a 2.99 Hardware Interrupts DPCs n/a 1.49 Deferred Procedure Calls System 4 5.97 smss.exe 388 Windows Session Manager Microsoft Corporationcsrss.exe 584 Client Server Runtime Process Microsoft Corporationwininit.exe 636 Windows Start-Up Application Microsoft Corporation services.exe 728 Services and Controller app Microsoft Corporation svchost.exe 872 Host Process for Windows Services Microsoft Corporation igfxsrvc.exe 3780 igfxsrvc Module Intel Corporation wlcomm.exe 4268 Windows Live Communications Platform Microsoft Corporation ZuneEnc.exe 5752 Zune Encoder Helper Microsoft Corporation WmiPrvSE.exe 4780 WMI Provider Host Microsoft Corporation svchost.exe 932 Host Process for Windows Services Microsoft Corporation svchost.exe 980 Host Process for Windows Services Microsoft Corporation audiodg.exe 5804 Windows Audio Device Graph Isolation Microsoft Corporation svchost.exe 1100 Host Process for Windows Services Microsoft Corporation dwm.exe 3360 13.41 Desktop Window Manager Microsoft Corporation WUDFHost.exe 3344 Windows Driver Foundation - User-mode Driver Framework Host Process Microsoft Corporation svchost.exe 1156 Host Process for Windows Services Microsoft Corporation svchost.exe 1288 Host Process for Windows Services Microsoft Corporation spoolsv.exe 1536 Spooler SubSystem App Microsoft Corporation svchost.exe 1572 Host Process for Windows Services Microsoft Corporation svchost.exe 1640 Host Process for Windows Services Microsoft Corporation avp.exe 1736 1.49 k9filter.exe 1760 mDNSResponder.exe 1792 Bonjour Service Apple Computer, Inc. svchost.exe 1856 Host Process for Windows Services Microsoft Corporation GoogleUpdaterService.exe 1916 gusvc Google iRebootd.exe 1940 iReboot Service pinger.exe 2032 Ivpsvmgr.exe 2604 IVP Service Manager Application TOSHIBA Corporation swupdtmr.exe 436 TosCoSrv.exe 1608 TOSHIBA Power Saver TOSHIBA Corporation svchost.exe 2788 Host Process for Windows Services Microsoft Corporation svchost.exe 2836 Host Process for Windows Services Microsoft Corporation wmpnetwk.exe 3624 Windows Media Player Network Sharing Service Microsoft Corporation SearchIndexer.exe 3904 Microsoft Windows Search Indexer Microsoft Corporation ZuneNss.exe 420 Zune Network Sharing Service Microsoft Corporation taskhost.exe 2888 Host Process for Windows Tasks Microsoft Corporation taskhost.exe 2944 Host Process for Windows Tasks Microsoft Corporation msfeedssync.exe 4512 Microsoft Feeds Synchronization Microsoft Corporation lsass.exe 736 Local Security Authority Process Microsoft Corporation lsm.exe 744 Local Session Manager Service Microsoft Corporationcsrss.exe 648 Client Server Runtime Process Microsoft Corporationwinlogon.exe 704 Windows Logon Application Microsoft Corporationexplorer.exe 3508 1.49 Windows Explorer Microsoft Corporation hkcmd.exe 1588 hkcmd Module Intel Corporation igfxpers.exe 3720 persistence Module Intel Corporation SynTPEnh.exe 3732 Synaptics TouchPad Enhancements Synaptics, Inc. SynToshiba.exe 2996 Toshiba Custom PlugIn Application Synaptics, Inc. SynTPHelper.exe 3616 Synaptics Pointing Device Helper Synaptics, Inc. RtHDVCpl.exe 4044 HD Audio Control Panel Realtek Semiconductor schedhlp.exe 3712 Acronis Scheduler Helper Acronis jusched.exe 444 Java(TM) Platform SE binary Sun Microsystems, Inc. realsched.exe 2272 RealNetworks Scheduler RealNetworks, Inc. TrueImageMonitor.exe 3668 Acronis True Image Monitor Acronis ZuneLauncher.exe 3456 Zune Auto-Launcher Microsoft Corporation avp.exe 928 Kaspersky Anti-Virus Kaspersky Lab msnmsgr.exe 3956 1.49 Windows Live Messenger Microsoft Corporation RocketDock.exe 1420 iReboot.exe 2876 iReboot NeoSmart Technologies firefox.exe 5840 2.98 Firefox Mozilla Corporation taskmgr.exe 5692 1.49 Windows Task Manager Microsoft Corporation Zune.exe 5884 4.47 Microsoft Zune Microsoft Corporation wlmail.exe 3924 Windows Live Mail Microsoft Corporation WINWORD.EXE 4956 Microsoft Office Word Microsoft Corporation procexp.exe 2720 5.96 Sysinternals Process Explorer Sysinternals - www.sysinternals.com uTorrent.exe 5304 µTorrent BitTorrent, Inc. HijackThis.exe 2080 HijackThis Trend Micro Inc. notepad.exe 4656 Notepad Microsoft Corporationtrayay.exe 428 Accountable2You Product Suite Accountable2Youoctoshape.exe 5768 Octoshape add-in for Adobe Flash Player Octoshape ApS octoshape.exe 2956 Octoshape add-in for Adobe Flash Player Octoshape ApSoctoshape.exe 5936 Octoshape add-in for Adobe Flash Player Octoshape ApS octoshape.exe 3368 Octoshape add-in for Adobe Flash Player Octoshape ApSProcess: uTorrent.exe Pid: 5304Name Description Company Name Versionadialhk.dll kldialhk Kaspersky Lab 8.00.0000.1015ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 6.01.7000.0000ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000AUTHZ.dll Authorization Framework Microsoft Corporation 6.01.7000.0000CLBCatQ.DLL COM+ Configuration Catalog Microsoft Corporation 2001.12.7930.0000COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.10.7000.0000comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.01.7000.0000credssp.dll Credential Delegation Security Package Microsoft Corporation 6.01.7000.0000CRYPT32.dll Crypto API32 Microsoft Corporation 6.01.7000.0000CRYPTBASE.dll Base cryptographic API DLL Microsoft Corporation 6.01.7000.0000CRYPTSP.dll Cryptographic Service Provider API Microsoft Corporation 6.01.7000.0000dhcpcsvc.DLL DHCP Client Service Microsoft Corporation 6.01.7000.0000dhcpcsvc6.DLL DHCPv6 Client Microsoft Corporation 6.01.7000.0000DnsApi.dll DNS Client API DLL Microsoft Corporation 6.01.7000.0000DUI70.dll Windows DirectUI Engine Microsoft Corporation 6.01.7000.0000dwmapi.dll Microsoft Desktop Window Manager API Microsoft Corporation 6.01.7000.0000FirewallAPI.dll Windows Firewall API Microsoft Corporation 6.01.7000.0000fwpuclnt.dll FWP/IPsec User-Mode API Microsoft Corporation 6.01.7000.0000GDI32.dll GDI Client DLL Microsoft Corporation 6.01.7000.0000GPAPI.dll Group Policy Client API Microsoft Corporation 6.01.7000.0000hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 6.01.7000.0000iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 8.00.7000.0000IMM32.DLL Multi-User Windows IMM32 API Client DLL Microsoft Corporation 6.01.7000.0000Iphlpapi.dll IP Helper API Microsoft Corporation 6.01.7000.0000kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 6.01.7000.0000KERNELBASE.dll Windows NT BASE API Mini Client DLL Microsoft Corporation 6.01.7000.0000KernelBase.dll.mui Windows NT BASE API Mini Client DLL Microsoft Corporation 6.01.7000.0000kloehk.dll Kaspersky OE plugin loader Kaspersky Lab 8.00.0000.1015locale.nls LPK.dll Language Pack Microsoft Corporation 6.01.7000.0000mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 6.01.7000.0000MSCTF.dll MSCTF Server DLL Microsoft Corporation 6.01.7000.0000msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.7000.0000mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 6.01.7000.0000msxml3.dll MSXML 3.0 SP11 Microsoft Corporation 8.110.1041.0000netshell.dll Network Connections Shell Microsoft Corporation 6.01.7000.0000netutils.dll Net Win32 API Helpers DLL Microsoft Corporation 6.01.7000.0000nlaapi.dll Network Location Awareness 2 Microsoft Corporation 6.01.7000.0000normnfd.nls npmproxy.dll Network List Manager Proxy Microsoft Corporation 6.01.7000.0000NSI.dll NSI User-mode interface DLL Microsoft Corporation 6.01.7000.0000ntdll.dll NT Layer DLL Microsoft Corporation 6.01.7000.0000ntmarta.dll Windows NT MARTA provider Microsoft Corporation 6.01.7000.0000ole32.dll Microsoft OLE for Windows Microsoft Corporation 6.01.7000.0000oleaut32.dll Microsoft Corporation 6.01.7000.0000peerdist.dll BranchCache Client Library Microsoft Corporation 6.01.7000.0000profapi.dll User Profile Basic API Microsoft Corporation 6.01.7000.0000PSAPI.DLL Process Status Helper Microsoft Corporation 6.01.7000.0000rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 6.01.7000.0000RocketDock.dll RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 6.01.7000.0000RpcRtRemote.dll Remote RPC Extension Microsoft Corporation 6.01.7000.0000rsaenh.dll Microsoft Enhanced Cryptographic Provider Microsoft Corporation 6.01.7000.0000sechost.dll SCM/SDDL/LSA Lookup APIs DLL for minwin Microsoft Corporation 6.01.7000.0000SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.01.7000.0000shfolder.dll Shell Folder Service Microsoft Corporation 6.01.7000.0000SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.01.7000.0000slc.dll Software Licensing Client Dll Microsoft Corporation 6.01.7000.0000SortDefault.nls SSDPAPI.dll SSDP Client API DLL Microsoft Corporation 6.01.7000.0000SspiCli.dll Security Support Provider Interface Microsoft Corporation 6.01.7000.0000StaticCache.dat StaticCache.dat SXS.DLL Fusion 2.5 Microsoft Corporation 6.01.7000.0000upnp.dll UPnP Control Point API Microsoft Corporation 6.01.7000.0000urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 8.00.7000.0000USER32.dll Multi-User Windows USER API Client DLL Microsoft Corporation 6.01.7000.0000USERENV.dll Userenv Microsoft Corporation 6.01.7000.0000USP10.dll Uniscribe Unicode script processor Microsoft Corporation 1.626.7000.0000uTorrent.exe µTorrent BitTorrent, Inc. 1.09.0000.13910uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.01.7000.0000VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 6.01.7000.0000webio.dll Web Transfer Protocols API Microsoft Corporation 6.01.7000.0000WINHTTP.dll Windows HTTP Services Microsoft Corporation 6.01.7000.0000WINNSI.DLL Network Store Information RPC interface Microsoft Corporation 6.01.7000.0000wkscli.dll Workstation Service Client DLL Microsoft Corporation 6.01.7000.0000WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 6.01.7000.0000WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 6.01.7000.0000wship6.dll Winsock2 Helper DLL (TL/IPv6) Microsoft Corporation 6.01.7000.0000wshtcpip.dll Winsock2 Helper DLL (TL/IPv4) Microsoft Corporation 6.01.7000.0000 Link to comment Share on other sites More sharing options...
skimmy_jimmy Posted January 21, 2009 Report Share Posted January 21, 2009 i had the same problem. my problem was that all of the data was still being written onto my hard drive and it has to completely write everything before it exits out. i hope that makes sense! have you noticed it saying 100% disk overload at the bottom left hand corner? Link to comment Share on other sites More sharing options...
Spirotot Posted January 21, 2009 Author Report Share Posted January 21, 2009 Well, how long does it take for it to write the data? Hours? Also, about the 100% disk overload, where do I see that? The Task Manager? Or uTorrent? Link to comment Share on other sites More sharing options...
skimmy_jimmy Posted January 21, 2009 Report Share Posted January 21, 2009 its on utorrent at the bottom left hand corner by where it says DHT: xxx nodes, it is to the left of that IF it that is what it is doing. in my situation, it just depended on how big the file(s) was/were. i basically would bring up the task manager and see how much cpu utorrent was using after exiting utorrent. for me, it wouldnt exit until it got under 5000K. Link to comment Share on other sites More sharing options...
moogly Posted January 21, 2009 Report Share Posted January 21, 2009 RocketDock.dll adialhk.dll kldialhk Kaspersky Lab 8.00.0000.1015kloehk.dll Kaspersky OE plugin loader Kaspersky Lab 8.00.0000.1015These dll are potential issues, especially these ones of Kaspersky. I think it's the culprit when you try to exit uT, Kaspersky may block uT.Did you set correctly Kaspersky ? You can try to disable temporarily these modules and look at if the issue is fixed.In addition you are running Win 7 beta so uT is not still compliant with it... :/ Link to comment Share on other sites More sharing options...
Spirotot Posted January 23, 2009 Author Report Share Posted January 23, 2009 Well, I think you can mark this as solved, because uTorrent seems to be closing down correct now. I didn't even change anything, or at least nothing that I'm aware of. Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.