resplence Posted April 28, 2008 Report Share Posted April 28, 2008 A few days ago uTorrent just started giving me access denied errors in everything I tried to download. I didn't catch any connection with this issue and my computer behavior or installed softwares.I do not use any of the softwares listed in the "incompatible software" section. I do use Windows Desktop Search, but I've always had, along with uTorrent. In any case, I disabled it, and still got the error. I thought Launchy could be the culprit, because of its indexing engine, but I disabled it and still got the error.Slackware, OpenOffice and single file torrents are also denied.I am saving the files to a directory with writing privileges.Searching for the handles in Process Explorer never returned anything, so I copied the DLL info.----------------------------------------------------------------------------------HiJackThis Log:================================================================Logfile of HijackThis v1.99.1Scan saved at 10:07:49, on 28/4/2008Platform: Windows XP SP2 (WinNT 5.01.2600)MSIE: Internet Explorer v7.00 (7.00.6000.16640)Running processes:C:\WINDOWS\System32\smss.exeC:\WINDOWS\system32\winlogon.exeC:\WINDOWS\system32\services.exeC:\WINDOWS\system32\lsass.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\System32\svchost.exeC:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeC:\WINDOWS\system32\spoolsv.exeC:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeC:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeC:\PROGRA~1\Grisoft\AVG7\avgemc.exeC:\Program Files\Bonjour\mDNSResponder.exeC:\WINDOWS\eHome\ehRecvr.exeC:\WINDOWS\eHome\ehSched.exeC:\WINDOWS\system32\svchost.exeC:\WINDOWS\system32\SearchIndexer.exeC:\Program Files\Unlocker\UnlockerAssistant.exeC:\Program Files\Taskbar Shuffle\taskbarshuffle.exeC:\Program Files\Volumouse\volumouse.exeC:\WINDOWS\system32\ctfmon.exeC:\WINDOWS\system32\dllhost.exeC:\Program Files\MSN Messenger\msnmsgr.exeC:\Program Files\MSN Messenger\usnsvc.exeC:\WINDOWS\explorer.exeC:\Program Files\eMule\emule.exeC:\WINDOWS\system32\wisptis.exeC:\Program Files\Timer\yTimer.exeC:\PROGRA~1\MOZILL~1\FIREFOX.EXEC:\Program Files\uTorrent\uTorrent.exeC:\Program Files\7-Zip\7zFM.exeD:\Users\Rafael\LOCALS~1\Temp\7zO2DC.tmp\procexp.exeC:\Program Files\Launchy\Launchy.exeG:\backup\install\hijackthis\HijackThis.exeC:\WINDOWS\system32\SearchProtocolHost.exeO2 - BHO: ContributeBHO Class - {074C1DC5-9320-4A9A-947D-C042949C6216} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dllO2 - BHO: dsWebAllowBHO Class - {2F85D76C-0569-466F-A488-493E6BD0E955} - C:\Program Files\Windows Desktop Search\dsWebAllow.dllO2 - BHO: BitComet ClickCapture - {39F7E362-828A-4B5A-BCAF-5B79BFDFEA60} - C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dllO2 - BHO: Spybot-S&D IE Protection - {53707962-6F74-2D53-2644-206D7942484F} - C:\PROGRA~1\Spybot\SDHelper.dllO2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO2 - BHO: (no name) - {7E853D72-626A-48EC-A868-BA8D5E23E045} - (no file)O3 - Toolbar: Contribute Toolbar - {517BDDE4-E3A7-4570-B21E-2B52B6139FC7} - C:\Program Files\Adobe\/Adobe Contribute CS3/contributeieplugin.dllO4 - HKLM\..\Run: [unlockerAssistant] "C:\Program Files\Unlocker\UnlockerAssistant.exe" -HO4 - HKLM\..\Run: [AVG7_CC] C:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUPO4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"O4 - HKCU\..\Run: [Taskbar Shuffle] C:\Program Files\Taskbar Shuffle\taskbarshuffle.exeO4 - HKCU\..\Run: [$Volumouse$] "C:\Program Files\Volumouse\volumouse.exe" /nodlgO4 - HKCU\..\Run: [ctfmon.exe] C:\WINDOWS\system32\ctfmon.exeO4 - Startup: Velox.lnk = ?O4 - Global Startup: Launchy.lnk = C:\Program Files\Launchy\Launchy.exeO8 - Extra context menu item: &D&ownload &with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddLink.htmO8 - Extra context menu item: &D&ownload all video with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddVideo.htmO8 - Extra context menu item: &D&ownload all with BitComet - res://C:\Program Files\BitComet\BitComet.exe/AddAllLink.htmO9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Program Files\Java\jre1.6.0_02\bin\ssv.dllO9 - Extra button: BitComet - {D18A0B52-D63C-4ed0-AFC6-C1E3DC1AF43A} - res://C:\Program Files\BitComet\tools\BitCometBHO_1.2.2.28.dll/206 (file missing)O9 - Extra button: (no name) - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dllO9 - Extra 'Tools' menuitem: Spybot - Search & Destroy Configuration - {DFB852A3-47F8-48C4-A200-58CAB36FD2A2} - C:\PROGRA~1\Spybot\SDHelper.dllO9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - %windir%\Network Diagnostic\xpnetdiag.exe (file missing)O10 - Unknown file in Winsock LSP: c:\program files\bonjour\mdnsnsp.dllO11 - Options group: [iNTERNATIONAL] International*O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/PT-BR/a-UNO1/GAME_UNO1.cabO16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1154385976359O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/SharedContent/common/bin/cabsa.cabO16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsClient.cab31267.cabO16 - DPF: {97E71027-0BA2-44F2-97DB-F84D808ED0B6} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab55762.cabO16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab55579.cabO16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cabO16 - DPF: {DCEA263C-75E9-4029-F6AA-37F011CC4EF1} (IM2Webconference) - http://dialcom.com/spontania/download/SpontaniaVideoCollaboration.cabO17 - HKLM\System\CCS\Services\Tcpip\..\{B31E86BB-F81F-4CA3-A664-292BBB3ED631}: NameServer = 200.149.55.142 200.165.132.154O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLLO18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\COMMON~1\Skype\SKYPE4~1.DLLO20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dllO23 - Service: Ad-Aware 2007 Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware 2007\aawservice.exeO23 - Service: AVG7 Alert Manager Server (Avg7Alrt) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgamsvr.exeO23 - Service: AVG7 Update Service (Avg7UpdSvc) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgupsvc.exeO23 - Service: AVG E-mail Scanner (AVGEMS) - GRISOFT, s.r.o. - C:\PROGRA~1\Grisoft\AVG7\avgemc.exeO23 - Service: ##Id_String1.6844F930_1628_4223_B5CC_5BB94B879762## (Bonjour Service) - Apple Computer, Inc. - C:\Program Files\Bonjour\mDNSResponder.exeO23 - Service: FLEXnet Licensing Service - Macrovision Europe Ltd. - C:\Program Files\Common Files\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exeO23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exeO23 - Service: ServiceLayer - Nokia. - C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe----------------------------------------------------------------------------------Process Explorer Log:================================================================Process PID CPU Description Company Name Working Setfirefox.exe 440 Firefox Mozilla Corporation 68.572 Kmsnmsgr.exe 2200 Messenger Microsoft Corporation 23.792 Kprocexp.exe 3940 Sysinternals Process Explorer Sysinternals - www.sysinternals.com 20.868 Kemule.exe 1956 eMule http://www.emule-project.net 19.736 Kexplorer.exe 2712 Windows Explorer Microsoft Corporation 19.716 Ksearchindexer.exe 648 Microsoft Windows Search Indexer Microsoft Corporation 13.916 KLaunchy.exe 2260 13.856 Ksvchost.exe 1148 Generic Host Process for Win32 Services Microsoft Corporation 13.712 KyTimer.exe 3100 Multiple countdown timer Spacejock Software 7.420 KuTorrent.exe 384 0.76 7.308 K7zFM.exe 3104 6.468 Kctfmon.exe 2232 CTF Loader Microsoft Corporation 2.392 Ksvchost.exe 1232 Generic Host Process for Win32 Services Microsoft Corporation 2.252 Kcsrss.exe 744 Client Server Runtime Process Microsoft Corporation 2.196 Ksvchost.exe 1312 Generic Host Process for Win32 Services Microsoft Corporation 2.096 Kservices.exe 812 0.76 Services and Controller app Microsoft Corporation 1.932 Ksvchost.exe 332 Generic Host Process for Win32 Services Microsoft Corporation 1.628 Ksvchost.exe 1052 Generic Host Process for Win32 Services Microsoft Corporation 1.600 Ksvchost.exe 1004 Generic Host Process for Win32 Services Microsoft Corporation 1.580 Kavgemc.exe 1868 AVG E-Mail Scanner GRISOFT, s.r.o. 1.572 Ktaskbarshuffle.exe 2156 Taskbar Shuffle Jay Elaraj 1.280 Klsass.exe 824 LSA Shell (Export Version) Microsoft Corporation 1.036 Kwinlogon.exe 768 Windows NT Logon Application Microsoft Corporation 1.020 Kusnsvc.exe 3680 Messenger Sharing USN Journal Reader Service Microsoft Corporation 1.020 Kvolumouse.exe 2224 Volumouse Utility NirSoft 1.008 Kwisptis.exe 4000 Microsoft Tablet PC Component Microsoft Corporation 936 KmDNSResponder.exe 1884 Bonjour Service Apple Computer, Inc. 904 Kdllhost.exe 3184 COM Surrogate Microsoft Corporation 884 Kspoolsv.exe 1728 Spooler SubSystem App Microsoft Corporation 856 KPresentationFontCache.exe 1372 Windows Presentation Foundation Font Cache Service Microsoft Corporation 848 Kalg.exe 3432 Application Layer Gateway Service Microsoft Corporation 672 Kavgamsvr.exe 1812 AVG Alert Manager GRISOFT, s.r.o. 452 KUnlockerAssistant.exe 2100 372 Kaawservice.exe 1492 Ad-Aware 2007 Service Lavasoft 332 KehSched.exe 2004 Media Center Scheduler Service Microsoft Corporation 308 KehRecvr.exe 1992 Media Center Receiver Service Microsoft Corporation 148 Kavgupsvc.exe 1844 AVG Update Service GRISOFT, s.r.o. 132 Kwdfmgr.exe 532 Windows User Mode Driver Manager Microsoft Corporation 88 Ksmss.exe 688 Windows NT Session Manager Microsoft Corporation 56 KSystem 4 44 KSystem Idle Process 0 97.73 16 KInterrupts n/a Hardware Interrupts 0 KDPCs n/a 0.76 Deferred Procedure Calls 0 KProcess: uTorrent.exe Pid: 384Name Description Company Name VersionACTIVEDS.dll ADs Router Layer DLL Microsoft Corporation 5.01.2600.2180adsldpc.dll ADs LDAP Provider C DLL Microsoft Corporation 5.01.2600.2180ADVAPI32.dll Advanced Windows 32 Base API Microsoft Corporation 5.01.2600.2180apphelp.dll Application Compatibility Client Library Microsoft Corporation 5.01.2600.2180ATL.DLL ATL Module for Windows XP (Unicode) Microsoft Corporation 3.05.2284.0000browseui.dll Shell Browser UI Library Microsoft Corporation 6.00.2900.3157CLBCATQ.DLL Microsoft Corporation 2001.12.4414.0308COMCTL32.dll User Experience Controls Library Microsoft Corporation 6.00.2900.2982comdlg32.dll Common Dialogs DLL Microsoft Corporation 6.00.2900.2180COMRes.dll Microsoft Corporation 2001.12.4414.0258CRYPT32.dll Crypto API32 Microsoft Corporation 5.131.2600.2180CRYPTUI.dll Microsoft Trust UI Provider Microsoft Corporation 5.131.2600.2180ctype.nls DNSAPI.dll DNS Client API DLL Microsoft Corporation 5.01.2600.3316GDI32.dll GDI Client DLL Microsoft Corporation 5.01.2600.3316hnetcfg.dll Home Networking Configuration Manager Microsoft Corporation 5.01.2600.2180ieframe.dll Internet Explorer Microsoft Corporation 7.00.6000.16640iertutil.dll Run time utility for Internet Explorer Microsoft Corporation 7.00.6000.16640IMAGEHLP.dll Windows NT Image Helper Microsoft Corporation 5.01.2600.2180IMM32.DLL Windows XP IMM32 API Client DLL Microsoft Corporation 5.01.2600.2180Iphlpapi.dll IP Helper API Microsoft Corporation 5.01.2600.2912kernel32.dll Windows NT BASE API Client DLL Microsoft Corporation 5.01.2600.3119locale.nls mdnsNSP.dll Bonjour Namespace Provider Apple Computer, Inc. 1.00.0003.0001MPRAPI.dll Windows NT MP Router Administration DLL Microsoft Corporation 5.01.2600.2180MSASN1.dll ASN.1 Runtime APIs Microsoft Corporation 5.01.2600.2180MSCTF.dll MSCTF Server DLL Microsoft Corporation 5.01.2600.2180msctfime.ime Microsoft Text Frame Work Service IME Microsoft Corporation 5.01.2600.2180MSNLNamespaceMgr.dll Windows Desktop Search Namespace Manager Microsoft Corporation 6.00.6000.16431msvcrt.dll Windows NT CRT DLL Microsoft Corporation 7.00.2600.2180mswsock.dll Microsoft Windows Sockets 2.0 Service Provider Microsoft Corporation 5.01.2600.2180NETAPI32.dll Net Win32 API DLL Microsoft Corporation 5.01.2600.2976Normaliz.dll Unicode Normalization DLL Microsoft Corporation 6.00.5441.0000ntdll.dll NT Layer DLL Microsoft Corporation 5.01.2600.2180ole32.dll Microsoft OLE for Windows Microsoft Corporation 5.01.2600.2726oleaut32.dll Microsoft Corporation 5.01.2600.3266PSAPI.DLL Process Status Helper Microsoft Corporation 5.01.2600.2180rasadhlp.dll Remote Access AutoDial Helper Microsoft Corporation 5.01.2600.2938RPCRT4.dll Remote Procedure Call Runtime Microsoft Corporation 5.01.2600.3173rtutils.dll Routing Utilities Microsoft Corporation 5.01.2600.2180SAMLIB.dll SAM Library DLL Microsoft Corporation 5.01.2600.2180Secur32.dll Security Support Provider Interface Microsoft Corporation 5.01.2600.2180SETUPAPI.dll Windows Setup API Microsoft Corporation 5.01.2600.2180SHDOCVW.dll Shell Doc Object and Control Library Microsoft Corporation 6.00.2900.3157SHELL32.dll Windows Shell Common Dll Microsoft Corporation 6.00.2900.3241SHLWAPI.dll Shell Light-weight Utility Library Microsoft Corporation 6.00.2900.3157sortkey.nls sorttbls.nls unicode.nls UnlockerHook.dll urlmon.dll OLE32 Extensions for Win32 Microsoft Corporation 7.00.6000.16640USER32.dll Windows XP USER API Client DLL Microsoft Corporation 5.01.2600.3099uTorrent.exe uxtheme.dll Microsoft UxTheme Library Microsoft Corporation 6.00.2900.2180VERSION.dll Version Checking and File Installation Libraries Microsoft Corporation 5.01.2600.2180vlmshlp.dll Volumouse Helper DLL NirSoft 1.05.0001.0000WININET.dll Internet Extensions for Win32 Microsoft Corporation 7.00.6000.16640winrnr.dll LDAP RnR Provider DLL Microsoft Corporation 5.01.2600.2180WINTRUST.dll Microsoft Trust Verification APIs Microsoft Corporation 5.131.2600.2180WLDAP32.dll Win32 LDAP API DLL Microsoft Corporation 5.01.2600.2180WS2_32.dll Windows Socket 2.0 32-Bit DLL Microsoft Corporation 5.01.2600.2180WS2HELP.dll Windows Socket 2.0 Helper for Windows NT Microsoft Corporation 5.01.2600.2180wshtcpip.dll Windows Sockets Helper DLL Microsoft Corporation 5.01.2600.2180----------------------------------------------------------------------------------PS: I only installed BitComet after uTorrent stopped working.Any ideas? Link to comment Share on other sites More sharing options...
Switeck Posted April 28, 2008 Report Share Posted April 28, 2008 Search indexers have a nasty habit of locking files they're indexing so other programs cannot edit them:C:\WINDOWS\system32\SearchIndexer.exesearchindexer.exe 648 Microsoft Windows Search Indexer Microsoft Corporation 13.916 KYou'll need to edit Microsoft Windows Search Indexer settings or disable it. Link to comment Share on other sites More sharing options...
jewelisheaven Posted April 29, 2008 Report Share Posted April 29, 2008 Get rid of injected DLLs and try again :/vlmshlp.dll Volumouse Helper DLL NirSoft 1.05.0001.0000Have you tried it with Emule closed? It's possible that emule is holding open your directory if you also share it on that network. How about with that ytimer or taskbar shuffle closed?If you're getting access denied on Openoffice there has to be a handle call made to openoffice. Nothing can't show up. It would at least show the handle in utorrent.exe. Are you sure you checked it before/during the error message? Another way would be to get Process Monitor from http://sysinternals.com (yes same people)... use Ctrl-L to filter for the end of the filename that you're looking for, select include say OK then Ctrl-E to log as you start OOo. How long does it normally take to manifest?? This may be a rpobem with starting at the beginning because the logfiles on my system use 5MB of RAM + pagefile a minute, soooooo, you'll need to clear (Ctrl-X) a few times if you're waiting for a bit. After you get access denied Ctrl-E again to stop logging..... (only ideas atm, bit frazzled tbh, power outages.... dying infrastructure <grumble>) Link to comment Share on other sites More sharing options...
Recommended Posts
Archived
This topic is now archived and is closed to further replies.