Jump to content

2.2.1.25113 running as non-admin user doesn't start + dll hijacking


Rassilon

Recommended Posts

Posted

2.2.1.25113:when starting utorrent from an administrative command prompt the interface loads ok but when starting it directly from the normal user account, without ANY administrative rights, this build doesn't start at all.

it pegs one of the cpu cores at 100% and it freezes there without showing any interface elements and i have to kill it via the task manager.

When i revert to v2.2.0.24683 uTorrent works normally under the user account.

os: win7 sp1 ultimate x86,

hw: intel E5200, 3gb ddr2 ram in dual channel, 2 x wd caviar black 640gb, raid 0.

Software restriction policies are enabled for all files, including DLLs that are run by a non-admin user (admin is not restricted) and set to deny execution of anything that is not under c:\program files, c:\windows and c:\users (this last one is to cover for temporary files, files on desktop and so on)

Any idea what's happening with build 2.2.1.25113 that turns it into an inert cpu hog when started by a non-admin user?

P.S.

at http://dl.transfer.ro/Logfile-transfer_RO-16mar-708178.7z i have uploaded a CSV file from a diagnostic trace created with Sysinternals ProcMon.

I see a few buffer overflows there. :(

ProcMon filters are set to only log uTorrent.exe and only show events with a result different from "success"

P.S. #2.. oh, and wasn't the dll hijacking security bug supposed to be already resolved?

why is utorrent looking in the current directory for standard system dll files before trying the system folders?:

C:\Program Files\uTorrent\MSIMG32.dll

C:\Program Files\uTorrent\SspiCli.dll

C:\Program Files\uTorrent\USERENV.dll

C:\Program Files\uTorrent\WINSPOOL.DRV

and so on..a lot of these

PS #3 - originally this thread was about 2.2.1.25110, but i downloaded 2.2.1.25113 today and it behaves the same.

P.S (final). i decided to let it run a bit at 100% cpu, and it finally showed the user interface.

AFTER 3 MINUTES !

Archived

This topic is now archived and is closed to further replies.

×
×
  • Create New...