Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

non riesco più ad installare aggiornamenti da Windows Update Opzioni
fardito
Inviato: Tuesday, June 29, 2010 9:14:33 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 21.09.35, on 29/06/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\taskeng.exe
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\system32\igfxsrvc.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Users\Francesco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\1SQNSZXV\HiJackThis[1].exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Windows\system32\SearchProtocolHost.exe
C:\Users\Francesco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\FLPT1Y38\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/it-IT/wlscctrl2.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7485 bytes

Ho fatto scansione antivirus Norton e malware ma non si risolve. Grazie per l'aiuto
Sponsor
Inviato: Tuesday, June 29, 2010 9:14:33 PM

 
r16
Inviato: Tuesday, June 29, 2010 9:26:49 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
fardito
Inviato: Tuesday, June 29, 2010 10:30:38 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Grazie ci provo poi ti dico
fardito
Inviato: Wednesday, June 30, 2010 10:20:10 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Niente non me lo lascia installare. Nel frattempo avevo scritto anche a Microsoft che dopo alcuni consigli mi ha scritto:
_________________
Gentile sig. Ardito

la presente in relazione al suo caso aperto presso il nostro centro di supporto con il numero di pratica

[1133253403]



Nel suo caso devo ritenere che il worm rilevato ha danneggiato irrimediabilmente le librerie di sistema onde impedire di essere rilevato in seguito ad un aggiornamento del sistema.

La rimozione del Worm ovviamente non ripara le librarie ormai danneggiate,


Questo tipo di infezione worm, comporta l'inserimento del pc infetto in una BOTNET ( http://it.wikipedia.org/wiki/Botnet); il gestore della BOTNET utilizza poi il pc infetto per compiere attività illegali (p.e. truffe informatiche, navigazione in siti pedo-pornografici ecc..) che sembreranno effettuate dall'utente del pc infetto.

Una volta che un malintenzionato ha il controllo del pc infetto, solitamente provvede all'installazione di ROOTKIT ( http://it.wikipedia.org/wiki/Rootkit), ovvero una serie di accorgimenti che permettono di nascondere diversi malaware, rendendoli non più identificabili dall'antivirus, se non smontando il disco fisso per collegarlo ad un apposito computer.

Il nostro consiglio è di procedere ad un salvataggio dei dati, eliminazione delle partizioni, formattazione e re installazione del sistema operativo, quindi alla modifica di tutte le password utilizzate nel sistema e nelle utenze in rete in quanto il worm potrebbe averle rilevate e trasmesse ai malintenzionati.
Cordiali saluti
Gabriele Ramacciani
Microsoft Customer Service Representative
( PER QUALUNQUE CONTATTO O INFORMAZIONE CONTATTARE TRAMITE MAIL E NON RICONTATTARE IL CENTRALINO)

EMEA Global Technical Support Center
Microsoft Product Support Services
Tel: +39 02 70 398 398
E-Mail: v-42gara@mssupport.microsoft.com
Supporto OnLine: <http://www.microsoft.com/italy/support>
Sicurezza & Privacy: <http://www.microsoft.com/italy/protect>
r16
Inviato: Wednesday, June 30, 2010 11:10:52 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ciao.
Commenta:
Nel suo caso devo ritenere che il worm rilevato ha danneggiato irrimediabilmente le librerie di sistema onde impedire di essere rilevato in seguito ad un aggiornamento del sistema.

Vorrei capire su quali basi dicono che il pc è infetto da worm .
E su quale base asseriscono, che fai parte di una BOTNET.
O tirano a indovinare.....
Oppure, tu gli hai spedito qualche log.... (che in questo caso, vorrei vedere)

Vediamo:
Scarica ed installa MalwareBytes:
clicca qui per il download : http://www.aiutamici.com/software?id=80346
Prima di fare la scansione AGGIORNALO. (è molto importante)
Esegui una scansione completa del sistema.
Elimina gli eventuali file infetti trovati.
Posta il log.

fardito
Inviato: Wednesday, June 30, 2010 11:42:16 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Si mi hanno fatto fare un log? lo allego.
____
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 18.02.41, on 23/06/2010
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v7.00 (7.00.6001.18000)
Boot mode: Normal

Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Windows\system32\taskeng.exe
C:\Program Files\Apoint2K\Apoint.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Windows\System32\hkcmd.exe
C:\Windows\System32\igfxpers.exe
C:\Program Files\Hp\HP Software Update\hpwuSchd2.exe
C:\Program Files\Common Files\Java\Java Update\jusched.exe
C:\Windows\ehome\ehtray.exe
C:\Program Files\Windows Media Player\wmpnscfg.exe
C:\Windows\ehome\ehmsas.exe
C:\Windows\system32\igfxsrvc.exe
C:\Program Files\Hewlett-Packard\HP wireless Assistant\WiFiMsg.EXE
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Hewlett-Packard\Shared\HpqToaster.exe
C:\Program Files\Apoint2K\Apntex.exe
C:\Windows\system32\conime.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\ieuser.exe
C:\Windows\system32\SearchProtocolHost.exe
C:\Program Files\Microsoft Office\Office12\OUTLOOK.EXE
C:\Users\Francesco\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LWV631U1\HiJackThis[1].exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60347
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Canon Easy-WebPrint EX BHO - {3785D0AD-BFFF-47F6-BF5B-A587C162FED9} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexbho.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Symantec NCO BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O2 - BHO: Symantec Intrusion Prevention - {6D53EC84-6AAE-4787-AEEE-F4628F01010C} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\IPSBHO.DLL
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live ID - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Canon Easy-WebPrint EX - {759D9886-0C6F-4498-BAB6-4A5F47C6C72F} - C:\Program Files\Canon\Easy-WebPrint EX\ewpexhlp.dll
O3 - Toolbar: Norton Toolbar - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\coIEPlg.dll
O4 - HKLM\..\Run: [Apoint] C:\Program Files\Apoint2K\Apoint.exe
O4 - HKLM\..\Run: [IAAnotif] "C:\Program Files\Intel\Intel Matrix Storage Manager\Iaanotif.exe"
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [IgfxTray] C:\Windows\system32\igfxtray.exe
O4 - HKLM\..\Run: [HotKeysCmds] C:\Windows\system32\hkcmd.exe
O4 - HKLM\..\Run: [Persistence] C:\Windows\system32\igfxpers.exe
O4 - HKLM\..\Run: [HP Software Update] C:\Program Files\Hp\HP Software Update\HPWuSchd2.exe
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Common Files\Java\Java Update\jusched.exe"
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKCU\..\Run: [WMPNSCFG] C:\Program Files\Windows Media Player\WMPNSCFG.exe
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~3\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {3860DD98-0549-4D50-AA72-5D17D200EE10} (Windows Live OneCare safety scanner control) - http://cdn.scan.onecare.live.com/resource/download/scanner/it-IT/wlscctrl2.cab
O16 - DPF: {9191F686-7F0A-441D-8A98-2FE3AC1BD913} (ActiveScan 2.0 Installer Class) - http://acs.pandasoftware.com/activescan/cabs/as2stubie.cab
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: GameConsoleService - WildTangent, Inc. - C:\Program Files\HP Games\My HP Game Console\GameConsoleService.exe
O23 - Service: Servizio di Google Update (gupdate) (gupdate) - Google Inc. - C:\Program Files\Google\Update\GoogleUpdate.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\Iaantmon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: Norton Internet Security (NIS) - Symantec Corporation - C:\Program Files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
O23 - Service: XAudioService - Conexant Systems, Inc. - C:\Windows\system32\DRIVERS\xaudio.exe

--
End of file - 7352 bytes
____
Grazie
r16
Inviato: Thursday, July 01, 2010 12:03:36 AM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Sinceramente, a parte l'installazione di HijackThis, che è sbagliata, (si trova in una cartella temporanea), e neanche se ne sono accorti, e un'altra voce che si riferisce a Spyware Terminator:
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Bar = http://www.crawler.com/search/dispatcher.aspx?tp=aus&qkw=%s&tbid=60347
ma che non è di sicuro, un worm, e il Java da aggiornare, non c'è nient'altro sul log.
Secondo quell'analizzatore della Microsoft, potresti avere il "Conficker", in quanto questa infezione, fra le tante cose, impedisce gli aggiornamenti, da Microsoft.
Ma se fosse tale virus, dovresti avere anche altre grosse anomalie.
Senza contare, che Vista, dovrebbe essere immune da tale infezione.

Segui l'indicazione che ho postato sopra, e vediamo cosa rileva Malwarebytes.
fardito
Inviato: Thursday, July 01, 2010 8:13:15 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Ciao
fatto scansione completa con Malwarebytes aggiornato ma non ha trovato nulla.
io ho Vista con SP1.
Boh?
grazie
r16
Inviato: Thursday, July 01, 2010 9:06:08 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Ultimo controllo:
Scarica Combofix (usa Internet Explorer)

http://download.bleepingcomputer.com/sUBs/ComboFix.exe

Salvalo sul desktop. (è obligatorio)

Importante: Disabilita il tuo antivirus e chiudi TUTTI i programmi aperti,(Firewall compreso) e dopo aver scaricato COMBOFIX, chiudi la connessione.

Doppio click su combofix.exe (se usi Vista: tasto destro su Combofix.exe e clicca su: "Esegui come Amministratore" )


E' probabile che ti siano inviati messaggi dall'antivirus,(o dallo stesso Combofix) tu ignorali.

Se ti verrà chiesto se vuoi Installare LA CONSOLE DI RIPRISTINO DI EMERGENZA, clicca NO.

Durante l'operazione di scansione è importante non usare il PC (neanche il mouse) e attendere pazientemente la fine delle operazioni.
Al termine, verrà creato un file log sul Desktop, chiamato C:\ComboFix.txt. Postalo qui.
fardito
Inviato: Friday, July 02, 2010 11:05:00 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Ecco il file combofix
_____
ComboFix 10-07-01.02 - Francesco 02/07/2010 22.00.17.1.2 - x86
Microsoft® Windows Vistaâ„¢ Home Premium 6.0.6001.1.1252.39.1040.18.3061.1694 [GMT 2:00]
Eseguito da: c:\users\Francesco\Desktop\ComboFix.exe
SP: Spybot - Search and Destroy *disabled* (Updated) {ED588FAF-1B8F-43B4-ACA8-8E3C85DADBE9}
SP: Windows Defender *enabled* (Updated) {D68DDC3A-831F-4FAE-9E44-DA132C1ACF46}
.

((((((((((((((((((((((((( Files Creati Da 2010-06-02 al 2010-07-02 )))))))))))))))))))))))))))))))))))
.

2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\Vivi\AppData\Local\temp
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\Sara\AppData\Local\temp
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\manu\AppData\Local\temp
2010-07-02 20:11 . 2010-07-02 20:11 -------- d-----w- c:\users\Default\AppData\Local\temp
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_E8107429428345802769A1.exe
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_D707CE1C009F1381803C2C.exe
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_21F3885A18D238E15AAE81.exe
2010-07-02 15:58 . 2010-07-02 15:58 43646 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_01A0E73821A82CA3751F06.exe
2010-07-02 15:58 . 2010-07-02 15:58 29926 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_7D9DC4673740B3F1827A58.exe
2010-07-02 15:58 . 2010-07-02 15:58 109534 ----a-r- c:\users\Francesco\AppData\Roaming\Microsoft\Installer\{08B14AF7-8C27-4D4F-A40A-1384B9E636A1}\_6FEFF9B68218417F98F549.exe
2010-07-02 15:58 . 2010-07-02 15:58 -------- d-----w- c:\program files\Macrium
2010-07-02 15:54 . 2010-07-02 15:55 -------- d-----w- c:\program files\IZArc
2010-07-02 15:02 . 2010-07-02 15:02 -------- d-----w- c:\users\Francesco\AppData\Roaming\Uniblue
2010-06-30 21:46 . 2010-06-30 21:46 -------- dc----w- C:\353a499f9f114ea0c67a9d3ce63e
2010-06-30 21:09 . 2010-06-30 21:09 -------- dc----w- C:\Temp
2010-06-30 21:06 . 2010-06-30 21:06 -------- d-----w- c:\users\Francesco\AppData\Local\IsolatedStorage
2010-06-30 20:06 . 2010-06-30 19:50 15880 ----a-w- c:\windows\system32\lsdelete.exe
2010-06-30 19:50 . 2010-06-30 19:49 64288 ----a-w- c:\windows\system32\drivers\Lbd.sys
2010-06-30 19:50 . 2010-06-30 19:50 95024 ----a-w- c:\windows\system32\drivers\SBREDrv.sys
2010-06-30 19:43 . 2010-06-30 19:43 -------- dc-h--w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}
2010-06-30 19:43 . 2010-02-04 15:53 2954656 -c--a-w- c:\programdata\{74D08EB8-01D1-4BAE-91E3-F30C1B031AC6}\Ad-AwareInstaller.exe
2010-06-29 21:05 . 2010-06-29 21:05 -------- d-----w- c:\windows\CheckSur
2010-06-29 20:51 . 2010-06-29 20:51 -------- d-----w- c:\windows\system32\EventProviders
2010-06-29 20:29 . 2010-04-29 13:39 38224 ----a-w- c:\windows\system32\drivers\mbamswissarmy.sys
2010-06-29 20:29 . 2010-04-29 13:39 20952 ----a-w- c:\windows\system32\drivers\mbam.sys
2010-06-21 09:58 . 2010-06-21 09:58 15328 ----a-w- c:\windows\system32\drivers\pssnap.sys
2010-06-21 09:57 . 2010-06-21 09:57 44512 ----a-w- c:\windows\system32\drivers\psmounter.sys
2010-06-19 21:34 . 2010-07-02 14:42 -------- d-----w- c:\program files\Panda Security
2010-06-19 21:24 . 2010-06-20 13:16 -------- d-----w- c:\program files\Fortinet
2010-06-19 21:22 . 2010-06-19 21:22 -------- d-----w- c:\programdata\Applications
2010-06-18 21:20 . 2010-05-06 04:01 44080 ----a-r- c:\windows\system32\drivers\SymIMV.sys
2010-06-17 17:37 . 2010-06-17 17:37 -------- d-----w- c:\users\Francesco\AppData\Roaming\Malwarebytes
2010-06-17 17:36 . 2010-06-17 17:36 -------- d-----w- c:\programdata\Malwarebytes
2010-06-17 17:36 . 2010-06-29 20:29 -------- d-----w- c:\program files\Malwarebytes' Anti-Malware
2010-06-15 17:31 . 2010-06-29 20:25 -------- d-----w- c:\program files\Windows Live Safety Center
2010-06-10 21:50 . 2010-06-10 21:51 -------- dc----w- C:\WUA

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-06-30 22:18 . 2008-08-19 21:56 -------- d-----w- c:\programdata\Spybot - Search & Destroy
2010-06-30 20:13 . 2008-08-19 21:56 -------- d-----w- c:\program files\Spybot - Search & Destroy
2010-06-30 19:46 . 2009-03-20 18:31 -------- d-----w- c:\program files\Lavasoft
2010-06-30 19:43 . 2009-03-20 18:31 -------- d-----w- c:\programdata\Lavasoft
2010-06-30 17:26 . 2007-11-30 03:30 662846 ----a-w- c:\windows\system32\perfh010.dat
2010-06-30 17:26 . 2007-11-30 03:30 120326 ----a-w- c:\windows\system32\perfc010.dat
2010-06-19 15:54 . 2010-04-12 19:43 -------- d-----w- c:\program files\7-Zip
2010-06-10 21:08 . 2007-11-29 20:29 -------- d-----w- c:\programdata\Microsoft Help
2010-06-07 18:38 . 2008-08-07 21:23 -------- d-----w- c:\users\Francesco\AppData\Roaming\U3
2010-06-05 08:41 . 2008-08-21 20:40 -------- d-----w- c:\program files\Microsoft Silverlight
2010-06-03 21:39 . 2010-05-30 13:07 -------- d-----w- c:\program files\Common Files\Nero
2010-06-03 21:38 . 2010-05-30 13:07 -------- d-----w- c:\programdata\Nero
2010-05-30 13:22 . 2010-05-30 13:22 -------- d-----w- c:\users\Francesco\AppData\Roaming\Nero
2010-05-30 10:16 . 2009-01-26 22:20 -------- d-----w- c:\program files\Microsoft
2010-05-26 15:24 . 2010-01-28 21:15 -------- d-----w- c:\program files\CCleaner
2010-05-22 18:33 . 2007-11-29 21:00 -------- d-----w- c:\program files\Common Files\Java
2010-05-22 18:14 . 2007-11-29 21:00 -------- d-----w- c:\program files\Java
2010-05-14 20:07 . 2009-12-13 09:54 -------- d-----w- c:\users\Francesco\AppData\Roaming\SATURN_Gadgets
2010-05-10 19:37 . 2010-05-10 19:37 -------- d-----w- c:\users\Francesco\AppData\Roaming\KoshyJohn.com
2010-05-10 19:37 . 2010-05-10 19:37 913446 ----a-w- c:\users\Francesco\AppData\Roaming\KoshyJohn.com\DiskMax\DiskMax.exe
2010-05-07 15:29 . 2010-05-04 16:49 -------- d-----w- c:\program files\Google
2010-05-03 12:47 . 2008-09-08 21:40 568 ----a-w- c:\users\Francesco\AppData\Roaming\wklnhst.dat
2010-04-12 15:29 . 2010-05-22 18:14 411368 ----a-w- c:\windows\system32\deployJava1.dll
2008-08-18 20:49 . 2008-08-18 20:49 22 --sha-w- c:\windows\SMINST\HPCD.sys
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ehTray.exe"="c:\windows\ehome\ehTray.exe" [2008-01-19 125952]
"WMPNSCFG"="c:\program files\Windows Media Player\WMPNSCFG.exe" [2008-01-19 202240]
"SpybotSD TeaTimer"="c:\program files\Spybot - Search & Destroy\TeaTimer.exe" [2009-03-05 2260480]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"Apoint"="c:\program files\Apoint2K\Apoint.exe" [2007-10-25 212992]
"IAAnotif"="c:\program files\Intel\Intel Matrix Storage Manager\Iaanotif.exe" [2007-10-03 178712]
"QPService"="c:\program files\HP\QuickPlay\QPService.exe" [2007-09-30 181544]
"QlbCtrl"="c:\program files\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe" [2007-09-27 202032]
"UCam_Menu"="c:\program files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" [2007-09-13 222504]
"Windows Defender"="c:\program files\Windows Defender\MSASCui.exe" [2008-01-19 1008184]
"hpWirelessAssistant"="c:\program files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe" [2007-10-03 480560]
"IgfxTray"="c:\windows\system32\igfxtray.exe" [2008-02-11 141848]
"HotKeysCmds"="c:\windows\system32\hkcmd.exe" [2008-02-11 166424]
"Persistence"="c:\windows\system32\igfxpers.exe" [2008-02-11 133656]
"HP Software Update"="c:\program files\Hp\HP Software Update\HPWuSchd2.exe" [2007-05-08 54840]
"SunJavaUpdateSched"="c:\program files\Common Files\Java\Java Update\jusched.exe" [2010-02-18 248040]

[HKEY_LOCAL_MACHINE\software\microsoft\windows\currentversion\policies\system]
"EnableUIADesktopToggle"= 0 (0x0)

[HKEY_LOCAL_MACHINE\software\microsoft\windows nt\currentversion\drivers32]
"aux"=wdmaud.drv

[HKEY_LOCAL_MACHINE\system\currentcontrolset\control\session manager]
BootExecute REG_MULTI_SZ autocheck autochk *\0\0lsdelete

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\Lavasoft Ad-Aware Service]
@="Service"

[HKEY_LOCAL_MACHINE\SYSTEM\CurrentControlSet\Control\SafeBoot\Minimal\WinDefend]
@="Service"

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonMyPrinter]
2009-03-23 17:00 1983816 ----a-w- c:\program files\Canon\MyPrinter\BJMYPRT.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\CanonSolutionMenu]
2009-03-17 16:40 767312 ----a-w- c:\program files\Canon\SolutionMenu\CNSLMAIN.EXE

[HKEY_LOCAL_MACHINE\software\microsoft\shared tools\msconfig\startupreg\HPAdvisor]
2007-10-01 15:10 1783136 ----a-w- c:\program files\Hewlett-Packard\HP Advisor\HPAdvisor.exe

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecAntiVirus]
"DisableMonitoring"=dword:00000001

[HKEY_LOCAL_MACHINE\software\microsoft\security center\Monitoring\SymantecFirewall]
"DisableMonitoring"=dword:00000001

R2 gupdate;Servizio di Google Update (gupdate);c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 136176]
R2 Lavasoft Ad-Aware Service;Lavasoft Ad-Aware Service;c:\program files\Lavasoft\Ad-Aware\AAWService.exe [2010-06-30 1352832]
R3 cpuz131;cpuz131;c:\users\FRANCE~1\AppData\Local\Temp\cpuz131\cpuz_x32.sys [x]
S0 Lbd;Lbd;c:\windows\system32\DRIVERS\Lbd.sys [2010-06-30 64288]
S0 pssnap;Paramount Software Snapshot Filter;c:\windows\system32\DRIVERS\pssnap.sys [2010-06-21 15328]
S0 SymDS;Symantec Data Store;c:\windows\system32\drivers\NIS\1107000.00C\SYMDS.SYS [2009-10-15 328752]
S0 SymEFA;Symantec Extended File Attributes;c:\windows\system32\drivers\NIS\1107000.00C\SYMEFA.SYS [2010-04-22 173104]
S1 BHDrvx86;BHDrvx86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\BASHDefs\20100619.001\BHDrvx86.sys [2010-05-22 691248]
S1 ccHP;Symantec Hash Provider;c:\windows\system32\drivers\NIS\1107000.00C\ccHPx86.sys [2010-02-26 501888]
S1 IDSVix86;IDSVix86;c:\programdata\Norton\{0C55C096-0F1D-4F28-AAA2-85EF591126E7}\NIS_17.5.0.127\Definitions\IPSDefs\20100701.001\IDSvix86.sys [2010-05-28 344112]
S1 SymIRON;Symantec Iron Driver;c:\windows\system32\drivers\NIS\1107000.00C\Ironx86.SYS [2010-04-29 116784]
S1 SYMTDIv;Symantec Vista Network Dispatch Driver;c:\windows\System32\Drivers\NIS\1107000.00C\SYMTDIV.SYS [2010-05-06 339504]
S2 NIS;Norton Internet Security;c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe [2010-02-26 126392]
S2 ReflectService;Macrium Reflect Image Mounting Service;c:\program files\Macrium\Reflect\ReflectService.exe [2010-06-21 220128]
S2 SBSDWSCService;SBSD Security Center Service;c:\program files\Spybot - Search & Destroy\SDWinSec.exe [2009-01-26 1153368]
S3 EraserUtilRebootDrv;EraserUtilRebootDrv;c:\program files\Common Files\Symantec Shared\EENGINE\EraserUtilRebootDrv.sys [2010-05-27 102448]

.
Contenuto della cartella 'Scheduled Tasks'

2010-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineCore.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 16:49]

2010-07-02 c:\windows\Tasks\GoogleUpdateTaskMachineUA.job
- c:\program files\Google\Update\GoogleUpdate.exe [2010-05-04 16:49]

2010-05-26 c:\windows\Tasks\Norton Internet Security - Francesco - Scansione completa.job
- c:\program files\Norton Internet Security\Engine\17.7.0.12\navw32.exe [2010-05-26 05:34]

2010-06-13 c:\windows\Tasks\SmartDefrag.job
- c:\program files\IObit\IObit SmartDefrag\IObit SmartDefrag.exe [2009-12-16 14:48]

2010-07-02 c:\windows\Tasks\User_Feed_Synchronization-{AA888B5A-860D-408D-8F93-87CBFFC56934}.job
- c:\windows\system32\msfeedssync.exe [2008-08-24 07:33]

2010-07-02 c:\windows\Tasks\User_Feed_Synchronization-{B5A88B38-907E-4947-856F-6499D7DB775F}.job
- c:\windows\system32\msfeedssync.exe [2008-08-24 07:33]

2010-07-02 c:\windows\Tasks\User_Feed_Synchronization-{CBBAAE3C-B911-4739-A239-97EC70E4B7EC}.job
- c:\windows\system32\msfeedssync.exe [2008-08-24 07:33]
.
.
------- Scansione supplementare -------
.
uStart Page = hxxp://www.libero.it/
mStart Page = hxxp://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Presario&pf=laptop
.

**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-07-02 22:11
Windows 6.0.6001 Service Pack 1 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************

[HKEY_LOCAL_MACHINE\system\ControlSet001\Services\NIS]
"ImagePath"="\"c:\program files\Norton Internet Security\Engine\17.7.0.12\ccSvcHst.exe\" /s \"NIS\" /m \"c:\program files\Norton Internet Security\Engine\17.7.0.12\diMaster.dll\" /prefetch:1"
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_LOCAL_MACHINE\system\ControlSet001\Control\Class\{4D36E96D-E325-11CE-BFC1-08002BE10318}\0000\AllUserSettings]
@Denied: (A) (Users)
@Denied: (A) (Everyone)
@Allowed: (B 1 2 3 4 5) (S-1-5-20)
"BlindDial"=dword:00000000
.
Ora fine scansione: 2010-07-02 22:18:16
ComboFix-quarantined-files.txt 2010-07-02 20:18

Pre-Run: 103.459.774.464 byte disponibili
Post-Run: 103.415.496.704 byte disponibili

- - End Of File - - B7E75F516F8A0F35300248FE016CBC12
r16
Inviato: Friday, July 02, 2010 11:19:54 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
Il pc non ha infezioni.
Disattiva il Tea Timer di SpyBot:

Apri SpyBot in modalità avanzata (menù modalità - avanzata) poi vai in utilità - resident e togli la spunta a TeaTimer, e riavvia il pc.

Non vorrei, che fosse perchè Microsoft, non rilascia più aggiornamenti per SP1 di Vista.
Mi sembra di avere sentito qualcosa del genere.
Sei sicuro di avere l'SP1 vero?
Perchè, per scaricare l'SP2, è indispensabile avere installato, l'SP1.

P.S:
http://support.microsoft.com/kb/929427/it
paolopa
Inviato: Saturday, July 03, 2010 6:30:28 AM

Rank: AiutAmico

Iscritto dal : 10/14/2008
Posts: 2,777
ciao R16:provare magari a scaricare l' sp2 da un altra parte?questa è la prima pagina che mi è capitata:
http://windows-vista-service-pack-2.softonic.it/
r16
Inviato: Saturday, July 03, 2010 12:06:14 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
@paolopa :
Può provare, ma non credo che ci riesca.

@fardito :

Leggi bene questo articolo della Microfoft:

http://support.microsoft.com/kb/836941
fardito
Inviato: Saturday, July 03, 2010 3:28:19 PM
Rank: Member

Iscritto dal : 10/8/2003
Posts: 11
Ciao
ho Disattivato il Tea Timer di SpyBot...riavviato mA NULLA-

Sono sicuro di avere SP1
ma non mi fa installare SP2
maopapof
Inviato: Saturday, July 03, 2010 3:45:00 PM

Rank: AiutAmico

Iscritto dal : 10/31/2004
Posts: 7,185
C:\Program Files\Hewlett-Packard\...... HP Wireless Assistant ...... \HPWAMain.exe
C:\Windows\System32\hkcmd.exe

sei amministratore vero ?

prova .... pulisci tutto e

scarica cleanup su questo sito ... ultima versione e senza toccare nulla ... fregatene se ti dice solo per xp .... e fallo girare ...spegni e riaccendi ... e prova :O)

Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.