June 6th, 2006
 | Kontoro-ra-Shouten | | Join Date: June 6th, 2006 Location: Indiana
Posts: 2
| |
Bearshare automatically closes... The title says my problem. Generally happens during transfer. I can't leave it for a half an hour... I mean, it'll happen if I leave my computer and it is the only main drain on my system. Here's what the BearDiag program said: Code:
BEARDIAG ISSUES - brief summary: (Extracted on 2006/06/06 15:14:32)
Windows XP may need updating to Service Pack 2.
BearShare configured TCP port 6348 appears to be firewalled.
BearShare configured UDP port 0 appears to be firewalled.
BearShare currently shows port 6348 for TCP and port 0 for UDP that need to match with your firewall/router configuration
BearShare configured "UDP port" setting should be altered to reflect a non-zero value - suggest 6348
You are behind a NAT firewall and/or router.
Refer to the following guidelines to rectify firewall issues at:
- the Firewall FAQ at the official BearShare Help site www.bearshare.com/help/firewalls/index.htm,
- the definitive guide to port forwarding and setting up a static IP address at http://www.portforward.com/english/applications/port_forwarding/BearS/BearSindex.htm
Could not communicate with http://www3.limewire.com:6348/ - possible firewall configuration error
More technical diagnostic troubleshooting information follows: Code:
BEARDIAG: Bearcare for BearShare.
Details collected on 2006/06/06 15:12:59, BEARDIAG Version beta, expires 2006/11/15 (162 days), running from C:\Documents and Settings\AlGhoul\My Documents\
System Hardware Information
CPU Type is: Intel(R) Pentium(R) 4 CPU 2.80GHz, CPU speed is approx: 2793Mhz, System BIOS date is: 2004/03/02
OS Version is: WIN_XP, Service pack: Service Pack 1, OS Build: 2600, Computer Name: EOD-ALGHOUL
Browser name: C:\Program Files\Internet Explorer\iexplore.exe, version: 6.0.2800.1106, Admin user? YES
System Memory Parameters: Memory in use: 51%
Total Physical RAM: 446.8Mb Available Physical RAM: 217.3Mb
Total Pagefile: 1.0Gb Available Pagefile: 787.2Mb
Process info for BearShare
Pagefile peak usage: 46.6Mb, Number of threads: 25, Number of handles: 975, Virtual memory usage: 134.5Mb
Internet IP Address 24.145.xxx.xxx Private IP Address You are behind a NAT firewall and/or router.
File Locations
Program files are at: C:\Program Files, System Temporary files are at: C:\DOCUME~1\AlGhoul\LOCALS~1\Temp, Common desktop is at:C:\Documents and Settings\All Users\Desktop
BearShare version installed is:, Gnutella servent BearShare full path is: C:\Program Files\BearShare\
Temporary downloads at: D:\BearShare\Temp\, Completed downloads at: D:\BearShare\Media\
Disk statistics
Drive C: Total space: 74.52Gb Free: 67.61Gb Full: 9.3% Vol type: NTFS
Drive D: Total space: 189.92Gb Free: 63.46Gb Full: 66.6% Vol type: NTFS
Folder Statistics
Temporary downloads folder: Space used: 15.1Gb, File count: 150, Write access allowed? YES
Completed downloads folder: Space used: 3.3Gb, File count: 15, Write access allowed? YES
BearShare library file 'library.db' size is 338.0Kb, '/db' library folder size is 1.4Mb, console log size is 149.5Kb
FreePeers.ini settings
The freepeers.ini file is found at C:\Program Files\BearShare\FreePeers.ini. The extracted settings are as follows:
Yes : bAlwaysUpdate; Always Download and announce latest signaled BearShare program updates from FreePeers.inc
1 : connectionType; Network connection type
(0=Modem/AOL/ISDN, 1=Broadband/Cable/DSL/Wireless, 2=Satellite, 3=T1/T3/LAN/OC3/Microwave, 4=Custom values)
6348 : listenPort; TCP/IP port number to listen on
No : bNeverBecomeUltrapeer; Disable UltraPeer mode
No bAuthenticateHosts; Authenticate host connections
No bAuthenticateDownloads; Authenticate search results and downloads
Yes : bSymmetric; Is Internet connection symmetric
1024 : totalKbps; Maximum bandwidth for symmetric connections
256 : sendKbps; Maximum outbound bandwidth for asymmetric connections
1024 : recvKbps; Maximum inbound bandwidth for asymmetric connections
No : bMaxHostsKbps; Limit host bandwidth
0 : maxHostsKbps; Kbps of send/receive bandwidth to limit hosts
No : bMaxUploadsKbps; Limit upload bandwidth
0 : maxUploadsKbps; Kbps of send bandwidth to limit uploads
No : bMaxDownloadsKbps; Limit download bandwidth
0 : maxDownloadsKbps; Kbps of receive bandwidth to limit downloads
No : m_bEverUltrapeerCapable; Has client ever been an UltraPeer?
No : bTcpNFW; yes if TCP is not firewalled
No : bUdpNFW; yes if UDP is not firewalled
0 : UDP Port; UDP port
D:\BearShare\Media : szDownloadsDir; Directory where completed and hashed downloads are moved to
D:\BearShare\Temp : szTempDir; Directory where partial downloads are kept
10 : dlMaxFiles; Maximum files to download at once
500 : dlMaxStreams; Maximum connections total
100 : dlMaxStreamsFile; Maximum connections per file
No : bDelCompletedDownloads; ; Automatically remove completed downloads
Yes : bEnableSparseFiles; Enable Sparse files for temporary files
No : bDisablePushSources; Never send Push messages
No : bDisablePushProxySources; Never send Push Proxy requests
8 : maxTotUploads; Maximum files to upload at once
0 : lastSendBpsMaxAvg; last session average outgoing bandwidth
Firewall testing
Could not communicate with http://www3.limewire.com:6348/ - possible firewall configuration error
Testing on UDP port: 0 worked - http://www3.limewire.com:0/ is accessible.
C:\Program Files\BearShare\db\BearShareHostiles.zip: 1361560 bytes transferred over 4.08 seconds. Download speed is 2672Kbps. Unzip and install in C:\Program Files\BearShare\db\ folder
BearShare anti-Hostiles List, last updated 2006/06/01 18:05:35 on the local computer is 3768 bytes long, and 10384336 bytes on the internet - check if needs updating
LSPFix: 186368 bytes transferred over 1.43 seconds. Download speed is 1041Kbps.
StartupList report, 6/6/2006, 3:13:13 PM
StartupList version: 1.52
Started from : C:\Documents and Settings\AlGhoul\My Documents\StartupList.EXE
Detected: Windows XP SP1 (WinNT 5.01.2600)
Detected: Internet Explorer v6.00 SP1 (6.00.2800.1106)
* Using default options
Running processes:
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\AlGhoul\My Documents\BearDiag.exe
C:\Documents and Settings\AlGhoul\My Documents\StartupList.exe
Checking Windows NT UserInit:
[HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon]
UserInit = C:\WINDOWS\system32\userinit.exe,
Autorun entries from Registry:
ATIModeChange = Ati2mdxx.exe
ATIPTA = C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
ShStatEXE = "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
Zone Labs Client = C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
MSConfig = C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
Shell & screensaver key from C:\WINDOWS\SYSTEM.INI:
Shell=*INI section not found*
SCRNSAVE.EXE=*INI section not found*
drivers=*INI section not found*
Shell & screensaver key from Registry:
SCRNSAVE.EXE=*Registry value not found*
drivers=*Registry value not found*
Policies Shell key:
HKCU\..\Policies: Shell=*Registry value not found*
HKLM\..\Policies: Shell=*Registry value not found*
Enumerating Browser Helper Objects:
(no name) - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}
(no name) - C:\PROGRA~1\SPYBOT~1\SDHelper.dll - {53707962-6F74-2D53-2644-206D7942484F}
(no name) - c:\program files\google\googletoolbar1.dll - {AA58ED58-01DD-4d91-8333-CF10577473F7}
(no name) - C:\Program Files\Advanced System Optimizer\IEHelper.dll - {CF7C3CF0-4B15-11D1-ABED-709549C10000}
Enumerating Download Program Files:
[QuickTime Object]
InProcServer32 = C:\Program Files\QuickTime\QTPlugin.ocx
CODEBASE = http://www.apple.com/qtactivex/qtplugin.cab
[Windows Genuine Advantage Validation Tool]
InProcServer32 = C:\WINDOWS\System32\LegitCheckControl.DLL
CODEBASE = http://go.microsoft.com/fwlink/?linkid=39204
[Office Update Installation Engine]
InProcServer32 = C:\WINDOWS\opuc.dll
CODEBASE = http://office.microsoft.com/officeupdate/content/opuc3.cab
[Housecall ActiveX 6.5]
InProcServer32 = C:\WINDOWS\Downloaded Program Files\Housecall_ActiveX.dll
CODEBASE = http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
[Shockwave Flash Object]
InProcServer32 = C:\WINDOWS\System32\Macromed\Flash\Flash8b.ocx
CODEBASE = http://download.macromedia.com/pub/shockwave/cabs/flash/swflash.cab
Enumerating Winsock LSP files:
Protocol #1: C:\WINDOWS\System32\imslsp.dll
Protocol #2: C:\WINDOWS\System32\imslsp.dll
Protocol #3: C:\WINDOWS\System32\imslsp.dll
Protocol #4: C:\WINDOWS\System32\imslsp.dll
Protocol #5: C:\WINDOWS\System32\imslsp.dll
Protocol #6: C:\WINDOWS\System32\imslsp.dll
Protocol #7: C:\WINDOWS\System32\ZoneLabs\vetredir.dll
Protocol #8: C:\WINDOWS\System32\ZoneLabs\vetredir.dll
Protocol #9: C:\WINDOWS\System32\ZoneLabs\vetredir.dll
Protocol #33: C:\WINDOWS\System32\ZoneLabs\vetredir.dll
Protocol #34: C:\WINDOWS\System32\imslsp.dll
Enumerating Windows NT logon/logoff scripts:
*No scripts set to run*
Windows NT checkdisk command:
BootExecute = autocheck autochk *
Windows NT 'Wininit.ini':
PendingFileRenameOperations: C:\DOCUME~1\AlGhoul\LOCALS~1\Temp\GLB1A2B.EXE||c:\documents and settings\alghoul\local settings\temp\cookies\alghoul@02.presence.userplane[1].txt||c:\documents and settings\alghoul\local settings\temp\cookies\alghoul@trafficmp[1].txt|||@
Enumerating ShellServiceObjectDelayLoad items:
PostBootReminder: C:\WINDOWS\system32\SHELL32.dll
CDBurn: C:\WINDOWS\system32\SHELL32.dll
WebCheck: C:\WINDOWS\System32\webcheck.dll
SysTray: C:\WINDOWS\System32\stobject.dll
End of report, 6,071 bytes
Report generated in 0.125 seconds
Command line options:
/verbose - to add additional info on each section
/complete - to include empty sections and unsuspicious data
/full - to include several rarely-important sections
/force9x - to include Win9x-only startups even if running on WinNT
/forcent - to include WinNT-only startups even if running on Win9x
/forceall - to include all Win9x and WinNT startups, regardless of platform
/history - to list version history only
Current task list information for EOD-ALGHOUL, running WIN_XP, Service Pack 1, build 2600
Details collected on 2006/06/06 15:13:08
Process Name PID File Version Command line Peak Memory Usage (Kb) PageFaults VM Page File Usage (Kb) Handles Threads ReadOperations WriteOperations ReadTransferCount WriteTransferCount
System Idle Process 0 >0< 20Kb 1 0Kb 0 2 0 0 0 0
System 4 >0< 1984Kb 5254 0Kb 476 79 547 6544 12443813 23210361
smss.exe 428 5.1.2600.1106 >\SystemRoot\System32\smss.exe< 648Kb 276 172Kb 21 3 10 5 4146 516
csrss.exe 608 >0< 3268Kb 5469 1492Kb 516 11 81193 0 2834139 0
winlogon.exe 632 5.1.2600.1106 >winlogon.exe< 10204Kb 8266 7104Kb 566 19 9994 3194 2365737 370269
services.exe 676 5.1.2600.0 >C:\WINDOWS\system32\services.exe< 2992Kb 1590 1368Kb 309 16 37872 37809 3971182 2945897
lsass.exe 688 5.1.2600.1106 >C:\WINDOWS\system32\lsass.exe< 8060Kb 6268 6164Kb 375 25 248784 216279 15783558 18152860
ati2evxx.exe 860 >C:\WINDOWS\System32\Ati2evxx.exe< 1824Kb 595 296Kb 37 3 8 8 500 188
svchost.exe 888 5.1.2600.0 >C:\WINDOWS\system32\svchost -k rpcss< 6188Kb 2205 3984Kb 302 14 11 21 19812 704
svchost.exe 956 5.1.2600.0 >C:\WINDOWS\System32\svchost.exe -k netsvcs< 23380Kb 18390 14424Kb 1370 87 5831 9523 18246783 41321436
svchost.exe 1108 >0< 5212Kb 1998 3676Kb 130 11 20 26 34102 550
svchost.exe 1136 >0< 7104Kb 2544 4348Kb 210 20 34 30 38547 1082
spoolsv.exe 1188 5.1.2600.0 >C:\WINDOWS\system32\spoolsv.exe< 4072Kb 1432 2700Kb 122 10 13 13 776 804
FrameworkService.exe 1440 >"C:\Program Files\Network Associates\Common Framework\FrameworkService.exe" /ServiceStart< 5100Kb 4673 2696Kb 160 8 176 52 108117 61820
mcshield.exe 1456 >"C:\Program Files\Network Associates\VirusScan\mcshield.exe"< 82652Kb 581908 21348Kb 227 26 257650 713 1170785772 125260
vstskmgr.exe 1480 >"C:\Program Files\Network Associates\VirusScan\vstskmgr.exe"< 4468Kb 2629 2080Kb 101 10 704 5 124768 228
naPrdMgr.exe 1596 >0< 3912Kb 1921 1960Kb 78 4 33 2 730 144
SMAgent.exe 1608 >"C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe"< 1660Kb 429 448Kb 32 2 3 3 158 84
wdfmgr.exe 1712 >0< 1568Kb 512 404Kb 60 4 10 10 516 332
vsmon.exe 1748 6.1.744.1 >C:\WINDOWS\system32\ZoneLabs\vsmon.exe -service< 35024Kb 1002498 23748Kb 431 27 52127 5642 276422506 11914462
atiptaxx.exe 2060 >"C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe" < 4320Kb 1760 1560Kb 82 2 9 11 9062 388546
shstat.exe 2108 >"C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE< 4180Kb 4128 1548Kb 56 6 1 1 68 72
zlclient.exe 2116 6.1.744.1 >"C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe" < 11320Kb 8894 9248Kb 187 12 6951 175 6465919 21649
explorer.exe 3932 6.0.2800.1106 >C:\WINDOWS\explorer.exe< 45372Kb 1859813 24364Kb 523 14 409343 4919 133523234 14227914
BearShare.exe 3444 >"C:\Program Files\BearShare\BearShare.exe" < 36920Kb 18397 43332Kb 970 25 3911 3737 39431862 4836301
iexplore.exe 3224 6.0.2800.1106 >"C:\Program Files\Internet Explorer\iexplore.exe" < 34972Kb 18860 27832Kb 670 30 1201 1595 2397172 2123382
BearDiag.exe 3748 >"C:\Documents and Settings\AlGhoul\My Documents\BearDiag.exe" < 10584Kb 3063 6704Kb 219 10 306 62 2605819 626878
wmiprvse.exe 3828 >0< 4952Kb 1464 1832Kb 126 7 16 15 54694 1096
BearShare library folder information for EOD-ALGHOUL, running WIN_XP, Service Pack 1, build 2600
Details collected on 2006/06/06 15:14:32
Volume in drive C has no label.
Volume Serial Number is 60CB-19F4
Directory of C:\Program Files\BearShare\db
06/06/2006 03:14 PM <DIR> .
06/06/2006 03:14 PM <DIR> ..
06/06/2006 03:14 PM 1,361,560 BearShareHostiles.zip
06/01/2006 05:30 PM 2,974 config.bin
06/06/2006 01:19 PM 109,586 connect.txt
06/06/2006 10:01 AM 1,710 gwebcache.dat
06/01/2006 06:05 PM 3,768 Hostiles.old
04/30/2006 08:37 PM 10,384,336 Hostiles.txt
06/06/2006 10:01 AM 0 Hostiles-Chat.txt
06/06/2006 03:08 PM 346,112 library.2.db
06/06/2006 03:08 PM 346,112 library.2.db.lastgoodload.bak
06/06/2006 03:08 PM 346,112 library.db
06/06/2006 03:08 PM 346,112 library.db.lastgoodload.bak
06/06/2006 03:10 PM 19 searches.ini
12 File(s) 13,248,401 bytes
2 Dir(s) 72,583,331,840 bytes free
Logfile of HijackThis v1.99.1
Scan saved at 3:13:25 PM, on 6/6/2006
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)
Running processes:
C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
C:\Program Files\Network Associates\VirusScan\mcshield.exe
C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE
C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
C:\Program Files\BearShare\BearShare.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Documents and Settings\AlGhoul\My Documents\BearDiag.exe
C:\Documents and Settings\AlGhoul\My Documents\HijackThis.exe
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride =
O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Adobe\Acrobat 6.0\Reader\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\SPYBOT~1\SDHelper.dll
O2 - BHO: Google Toolbar Helper - {AA58ED58-01DD-4d91-8333-CF10577473F7} - c:\program files\google\googletoolbar1.dll
O2 - BHO: IEPlugin Class - {CF7C3CF0-4B15-11D1-ABED-709549C10000} - C:\Program Files\Advanced System Optimizer\IEHelper.dll
O3 - Toolbar: &Google - {2318C2B1-4965-11d4-9B18-009027A5CD4F} - c:\program files\google\googletoolbar1.dll
O3 - Toolbar: &Radio - {8E718888-423F-11D2-876E-00A0C9082467} - C:\WINDOWS\System32\msdxm.ocx
O4 - HKLM\..\Run: [ATIModeChange] Ati2mdxx.exe
O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
O4 - HKLM\..\Run: [ShStatEXE] "C:\Program Files\Network Associates\VirusScan\SHSTAT.EXE" /STANDALONE
O4 - HKLM\..\Run: [Zone Labs Client] C:\Program Files\Zone Labs\ZoneAlarm\zlclient.exe
O4 - HKLM\..\Run: [MSConfig] C:\WINDOWS\PCHealth\HelpCtr\Binaries\MSConfig.exe /auto
O8 - Extra context menu item: &Google Search - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsearch.html
O8 - Extra context menu item: &Translate English Word - res://C:\Program Files\Google\GoogleToolbar1.dll/cmwordtrans.html
O8 - Extra context menu item: Backward Links - res://C:\Program Files\Google\GoogleToolbar1.dll/cmbacklinks.html
O8 - Extra context menu item: Cached Snapshot of Page - res://C:\Program Files\Google\GoogleToolbar1.dll/cmcache.html
O8 - Extra context menu item: E&xport to Microsoft Excel - res://C:\PROGRA~1\MICROS~3\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: Similar Pages - res://C:\Program Files\Google\GoogleToolbar1.dll/cmsimilar.html
O8 - Extra context menu item: Translate Page into English - res://C:\Program Files\Google\GoogleToolbar1.dll/cmtrans.html
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\OFFICE11\REFIEBAR.DLL
O9 - Extra button: AIM - {AC9E2541-2814-11d5-BC6D-00B0D0A1DE45} - C:\Program Files\AIM\aim.exe
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {6E5A37BF-FD42-463A-877C-4EB7002E68AE} (Housecall ActiveX 6.5) - http://housecall65.trendmicro.com/housecall/applet/html/native/x86/win32/activex/hcImpl.cab
O16 - DPF: {BDEE1959-AB6B-4745-A29B-F492861102CC} -
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - "C:\PROGRA~1\MSNMES~1\msgrapp.dll" (file missing)
O20 - Winlogon Notify: RegCompact - C:\WINDOWS\SYSTEM32\RegCompact.dll
O23 - Service: Ati HotKey Poller - Unknown owner - C:\WINDOWS\System32\Ati2evxx.exe
O23 - Service: CA ISafe (CAISafe) - Computer Associates International, Inc. - C:\WINDOWS\System32\ZoneLabs\isafe.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: McAfee Framework Service (McAfeeFramework) - Network Associates, Inc. - C:\Program Files\Network Associates\Common Framework\FrameworkService.exe
O23 - Service: Network Associates McShield (McShield) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\mcshield.exe
O23 - Service: Network Associates Task Manager (McTaskManager) - Network Associates, Inc. - C:\Program Files\Network Associates\VirusScan\vstskmgr.exe
O23 - Service: SoundMAX Agent Service (SoundMAX Agent Service (default)) - Analog Devices, Inc. - C:\Program Files\Analog Devices\SoundMAX\SMAgent.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe
. Thanks in advance... |