Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

problema di ri-connessione Opzioni
barbone
Inviato: Thursday, February 15, 2007 4:59:12 PM

Rank: AiutAmico

Iscritto dal : 11/29/2006
Posts: 1,014
..no molti valori non sono impostati...ma come ti ripeto bisognerebbe conoscere cos'è che provoca il problema...quelle voci che ti ho postato mi sembra di capire che non sei riuscito ad eliminarle o sbaglio? ..
musatti
Inviato: Thursday, February 15, 2007 11:29:49 PM
Rank: AiutAmico

Iscritto dal : 1/31/2005
Posts: 314
infatti non ci sono riuscito, l'unica cosa che se n'è andata è il (BHO.My IEHelper.A) che virit, a forza di girare è riuscito a rimuovere, o, almeno, non lo trova più e poi FASTTRACK che, tramite regseeker, ho cancellato. però gli antirrotkit non funzionano ancora e nemmeno HT. Ti terrò informato dell'evoluzione. Comunque virit quando arriva a system32 si blocca e c'è la schermata blu. Idem per Spybot S&D e per l'antivirus.
barbone
Inviato: Friday, February 16, 2007 1:09:10 AM

Rank: AiutAmico

Iscritto dal : 11/29/2006
Posts: 1,014
leggiti questa discussione... A. spiega come eliminare
O4 - HKLM\..\Run: [gwiz] C:\WINDOWS\System32\ntsystem.exe
musatti
Inviato: Friday, February 16, 2007 9:15:43 AM
Rank: AiutAmico

Iscritto dal : 1/31/2005
Posts: 314

In attesa di leggere ti mando questo log dello strumento di antispy
Microsoft, sperando che possa servire a qualcosa, ciao
[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:916 SetupUtil::SwitchLoggingLocation()] Trying to start logging under WOC\Logs

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:965 SetupUtil::SwitchLoggingLocation()] Changing Log output to WOC\Logs 00000000

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:978 SetupUtil::SwitchLoggingLocation()] Moving log from [ C:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\WinSSTemp\Logs\Logs.log ] to [ C:\Programmi\Microsoft Windows OneCare Live\Logs\Logs.log ] 0x80070003

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetup.cpp:36 wWinMain()] Enter: OCSetup. 1890.18

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [omnitureutil.cpp:51 WinSSPlatform::COmnitureUtil::ReportEventW()] Page: InstallAppStarted , Value: event11

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetup.cpp:45 wWinMain()] Host: XXX-NBRNCGW61T7

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetup.cpp:46 wWinMain()] Environment: Production

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetup.cpp:47 wWinMain()] Command line: ' '

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [cmdlineanalyzer.cpp:32 CCmdLineAnalyzer::GetSetupType()] No command line arguments. Starting default OCSetup Install mode.

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:318 CApplicationQue::SetUICallBack()] Entering

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:0 CApplicationQue::SetUICallBack()] Exiting

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:19 COCSetupConfigSettings::GetClientConfigItem()] Entering

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:67 COCSetupConfigSettings::EnsureClientConfigSettingsInitialized()] Entering

[2007-02-15 23:55:28 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:87 COCSetupConfigSettings::EnsureClientConfigSettingsInitialized()] Reading service.xml from: e:\33f03635a035e32ac9621d55\service.xml

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:0 COCSetupConfigSettings::EnsureClientConfigSettingsInitialized()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:0 COCSetupConfigSettings::GetClientConfigItem()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [resourceshelper.cpp:72 CResourcesHelper::FillResourcesIDToLanguageDataMap()] !Warning! Language 1041 is not installed.

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [resourceshelper.cpp:277 CResourcesHelper::LoadResourceDLL()] Resource DLL (LCID = 1040 ) e:\33f03635a035e32ac9621d55\it-it\OCSetupRO.dll is loaded.

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [dialogeula.cpp:137 CDialogEULA::Create()] !Warning! 0x80070490 Can not turn on Auto URL detection on 'EULA' dialog window.

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:19 COCSetupConfigSettings::GetClientConfigItem()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:67 COCSetupConfigSettings::EnsureClientConfigSettingsInitialized()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:87 COCSetupConfigSettings::EnsureClientConfigSettingsInitialized()] Reading service.xml from: e:\33f03635a035e32ac9621d55\service.xml

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:0 COCSetupConfigSettings::EnsureClientConfigSettingsInitialized()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupconfigsettings.cpp:0 COCSetupConfigSettings::GetClientConfigItem()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [driveruiinstall.cpp:337 CDriverUIInstall::Initialize()] Brand from local service.xml (no command line brand provided): Default

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:166 CApplicationQue::OnMessage()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:465 CApplicationQue::OnRunPrePrequalMessage()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:382 SetupUtil::PrequalReboot()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:0 SetupUtil::PrequalReboot()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:401 SetupUtil::PrequalAdminUser()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:0 SetupUtil::PrequalAdminUser()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:304 SetupUtil::PrequalOS()] Entering

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [utilities.cpp:3967 WinSSPlatform::Utilities::IsOSSupportedEx()] !Error! Unsupported OS, Version: 5 . 1 . 2600 SP: 1

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:315 SetupUtil::PrequalOS()] !Error! OS is not supported

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:0 SetupUtil::PrequalOS()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:0 CApplicationQue::OnRunPrePrequalMessage()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:0 CApplicationQue::OnMessage()] Exiting

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [driverui.cpp:260 CDriverUI::HandleApplicationError()] !Error! Failed sending a message to AppQue, hr: 0x80004005 , message: 1

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [driverui.cpp:296 CDriverUI::ShowError()] !Error! ShowError() called with hr: 0x80004005

[2007-02-15 23:55:29 +01:00] [1348-1352] [UNK] [dialoginstallerror.cpp:224 CDialogInstallError::SetErrorStrings()] !Error! Error context & code: ID errore: 0003-80004005

[2007-02-15 23:55:30 +01:00] [1348-1352] [UNK] [driverui.cpp:383 CDriverUI::ShowError()] !Error! 0x80070002 Attempt to create an install failure watson report failed

[2007-02-15 23:55:30 +01:00] [1348-1352] [UNK] [omnitureutil.cpp:29 WinSSPlatform::COmnitureUtil::ReportPageVisit()] InstallShowErrorDialog

[2007-02-15 23:55:30 +01:00] [1348-1360] [UNK] [analyticsuploadq.cpp:58 WinSSPlatform::CAnalyticsUploadQ::OnMessage()] !Warning! 0x80072ee7 dwCommand 2

[2007-02-15 23:55:30 +01:00] [1348-1360] [UNK] [analyticsuploadq.cpp:58 WinSSPlatform::CAnalyticsUploadQ::OnMessage()] !Warning! 0x80072ee7 dwCommand 3

[2007-02-15 23:55:30 +01:00] [1348-1360] [UNK] [analyticsuploadq.cpp:58 WinSSPlatform::CAnalyticsUploadQ::OnMessage()] !Warning! 0x80072ee7 dwCommand 3

[2007-02-15 23:55:30 +01:00] [1348-1360] [UNK] [analyticsuploadq.cpp:58 WinSSPlatform::CAnalyticsUploadQ::OnMessage()] !Warning! 0x80072ee7 dwCommand 1

[2007-02-15 23:55:43 +01:00] [1348-1352] [UNK] [dialoginstallerror.cpp:141 CDialogInstallError::OnCommand()] Help button pressed

[2007-02-15 23:55:43 +01:00] [1348-1352] [UNK] [omnitureutil.cpp:29 WinSSPlatform::COmnitureUtil::ReportPageVisit()] InstallOnErrorHelpMessage

[2007-02-15 23:55:43 +01:00] [1348-1360] [UNK] [analyticsuploadq.cpp:58 WinSSPlatform::CAnalyticsUploadQ::OnMessage()] !Warning! 0x80072ee7 dwCommand 1

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [dialoginstallerror.cpp:164 CDialogInstallError::OnCommand()] Cancel button pressed

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [omnitureutil.cpp:29 WinSSPlatform::COmnitureUtil::ReportPageVisit()] OnInstallErrorCancelMessage

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [driveruiinstall.cpp:621 CDriverUIInstall::OnErrorCancelMessage()] User closed error dialog, no cleanup needed, exiting.

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [driverui.cpp:152 CDriverUI::OnCloseAllWindows()] Entering

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [driverui.cpp:0 CDriverUI::OnCloseAllWindows()] Exiting

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [ocsetuputil.cpp:1133 SetupUtil::ReleaseSetupMutex()] !Warning! Mutex handle is already NULL - Cannot release

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [ocsetupappque.cpp:154 CApplicationQue::~CApplicationQue()] !Warning! 0x80070057 Failed to release setup mutex

[2007-02-15 23:55:57 +01:00] [1348-1352] [UNK] [ocsetup.cpp:116 wWinMain()] 00000000 Quitting app. Pausing for 9 seconds.

[2007-02-15 23:55:57 +01:00] [1348-1360] [UNK] [analyticsuploadq.cpp:58 WinSSPlatform::CAnalyticsUploadQ::OnMessage()] !Warning! 0x80072ee7 dwCommand 1

[2007-02-15 23:56:06 +01:00] [1348-1352] [UNK] [ocsetup.cpp:143 wWinMain()] 00000000 Exit: OCSetup.
barbone
Inviato: Friday, February 16, 2007 2:33:24 PM

Rank: AiutAmico

Iscritto dal : 11/29/2006
Posts: 1,014
<b><font color=red>...devi aggiornare a SP2...</font id=red></b>
musatti
Inviato: Sunday, February 18, 2007 11:30:47 AM
Rank: AiutAmico

Iscritto dal : 1/31/2005
Posts: 314
Ora mi attivo per SP2, comunque jt ha ripèreso a funzionare, ti mando l'ultimo log.
Logfile of HijackThis v1.99.0
Scan saved at 10:33:36, on 18/02/2007
Platform: Windows XP SP1 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP1 (6.00.2800.1106)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\Canon\MultiPASS4\MPSERVIC.EXE
C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
C:\WINDOWS\System32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\Program Files\Libero\Adsl\dslstat.exe
C:\Program Files\Libero\Adsl\dslagent.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = Dial-Up PPP Connection
R3 - Default URLSearchHook is missing
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Libero\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Libero\Adsl\dslagent.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe /waitservice
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\Plugins\BrowserBar\ie_bar.dll
O23 - Service: AntiVir Scheduler - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service - AVIRA GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: MpService - Canon Inc. - C:\Programmi\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: Outpost Firewall Service - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
O23 - Service: Virit eXplorer Lite - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe
Non so come è successo, ho pasticciato un po' con Reanimator. Comunque l'antivirus rebotta sempre su \System32\Isass
dove la I di Isass non è proprio una I, ma mi sembra un segno
Non riuscivo a concellare quello che volevo perché avevo il teatimer di Spybot S&D che bloccava le impostazioni
a rileggerci
musatti
Inviato: Sunday, February 18, 2007 5:05:17 PM
Rank: AiutAmico

Iscritto dal : 1/31/2005
Posts: 314
dunque: sono passato a SP2, accludo il log di HjT. Va tutto bene?
Logfile of HijackThis v1.99.0
Scan saved at 16:18:08, on 18/02/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
C:\Programmi\Canon\MultiPASS4\MPSERVIC.EXE
C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
C:\WINDOWS\System32\svchost.exe
C:\VEXPLITE\viritsvc.exe
C:\WINDOWS\system32\wscntfy.exe
C:\WINDOWS\Explorer.EXE
C:\Program Files\Libero\Adsl\dslstat.exe
C:\Program Files\Libero\Adsl\dslagent.exe
C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe
C:\unzipped\hijackthis\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = www.libero.it
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Libero\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Libero\Adsl\dslagent.exe
O4 - HKLM\..\Run: [avgnt] "C:\Programmi\AntiVir PersonalEdition Classic\avgnt.exe" /min
O4 - HKLM\..\Run: [AVGCtrl] "C:\Programmi\AVPersonal\AVGNT.EXE" /min
O4 - HKLM\..\Run: [Outpost Firewall] C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe /waitservice
O9 - Extra button: Outpost Firewall Pro Quick Tune - {44627E97-789B-40d4-B5C2-58BD171129A1} - C:\PROGRA~1\Agnitum\OUTPOS~1.0\Plugins\BrowserBar\ie_bar.dll
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O23 - Service: AntiVir Scheduler - Avira GmbH - C:\Programmi\AntiVir PersonalEdition Classic\sched.exe
O23 - Service: AntiVir PersonalEdition Classic Service - AVIRA GmbH - C:\Programmi\AntiVir PersonalEdition Classic\avguard.exe
O23 - Service: MpService - Canon Inc. - C:\Programmi\Canon\MultiPASS4\MPSERVIC.EXE
O23 - Service: Outpost Firewall Service - Agnitum Ltd. - C:\PROGRA~1\Agnitum\OUTPOS~1.0\outpost.exe
O23 - Service: Virit eXplorer Lite - TG Soft Sas www.tgsoft.it - C:\VEXPLITE\viritsvc.exe

Ho un problema DI MANTENIMENTO (AMMESSO CHE ORA VAdA BENE)il firewall. Attualmente ho outpost, a parte che è eccessivaemte petulante, è un trial di 30 gg. (ormai meno) cosa posso installare di gratuito? (che rimanga gratuito e non divenga a pagamento al primo aggiornamento come outpost?
Ma il firewall di default è collegato a microsoft, si deve scaricare da loro? io non vorrei (ehm, ehm)
grazie, ciao


barbone
Inviato: Sunday, February 18, 2007 9:04:48 PM

Rank: AiutAmico

Iscritto dal : 11/29/2006
Posts: 1,014
..il log è pulito..per il firewall c'è zone alarm...cmq se fai una piccola ricerca su google penso ne troverai altri...se installi un'altro firewall quello della microsoft lo devi disattivare
musatti
Inviato: Monday, February 19, 2007 11:38:16 AM
Rank: AiutAmico

Iscritto dal : 1/31/2005
Posts: 314
Caro Barbone, grazie tantissime per la tua assistenza, senza di te e i tuoi link non avrei combinato niente. Renato
musatti
Inviato: Sunday, April 15, 2007 11:36:52 PM
Rank: AiutAmico

Iscritto dal : 1/31/2005
Posts: 314
salve, il problema di prima è superato, però mi sono trovato infettato da alcuni trojan e blackdoor (credo sia questo il nome) che funzionavano da dialer r mi cambiavano indirizzo e connessione e password dentro il modem adsl; naturalmente la connessione si chiudeva immediatamente o non si apriva, ma ho dovuto fare una bella fatica a debellarli, tra l'altro ho fatto una scansione completa con l'antivirus che ho scelto ora, avast, e non ha rilevato niente, mentre in modalità provvisoria sia Doctor Web (anche se vecchio) e poi lo stesso avast hanno scovato e debellato le minacce (almeno così sembra. Ma non esiste un sistema per difendersi dai dialer meno macchinoso che disinstallare gli activeX o il download oppure usare Stopdialers (che mi pare macchinoso anche lui?)i nuovi rilasci diMicrosoft fanno qualcosa anche per questo?
grazie
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.