Aiutamici Forum
Benvenuto Ospite Cerca | Topic Attivi | Utenti | | Log In | Registra

cavallo di troia Opzioni
giorgia87
Inviato: Saturday, October 02, 2010 8:53:36 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ciao! è da un paio di settimane che l'antivirus Avira mi segnala la presenza di un cavallo di troia, esattamente TR/Downloader.Gen
ho scritto oggi stesso qui su aiutamici ma in un'altra sezione e mi è stato consigliato di scrivere qui, questo è il link dei suggerimenti che mi sn stati dati! http://forum.aiutamici.com/yaf_postsm360383_virus.aspx#360383

grazie mille!
Sponsor
Inviato: Saturday, October 02, 2010 8:53:36 PM

 
shapiro
Inviato: Saturday, October 02, 2010 8:54:48 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

ciao giorgia


scarica hijackthis da qui
lancia il programma cliccando l’eseguibile e avvia la scansione, scegliendo la voce "Do a system scan and save a logfile"

Ricordati di mettere HIJACKTHIS in una cartella a lui dedicata (in Programmi o Documenti), l'importante è che non si trovi sul desktop o in cartelle temporanee è importante se vuoi salvare i backup

Posta il log che rilascia
panchoz
Inviato: Saturday, October 02, 2010 8:58:57 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
Shapiro, amichevolmente ti dico ATTENTO!

Credo avrai notato che le è stato consigliato di formattare nell'altro thread!!


L'intrepida Giorgia che vuol risolvere il problema è ammirevole Applause , in pratica ha snobbato il WebMaster Drool
giorgia87
Inviato: Saturday, October 02, 2010 9:05:22 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ecco qui!

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 21.04.27, on 02/10/2010
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v8.00 (8.00.6001.18702)
Boot mode: Normal

Running processes:
D:\WINDOWS\System32\smss.exe
D:\WINDOWS\system32\winlogon.exe
D:\WINDOWS\system32\services.exe
D:\WINDOWS\system32\lsass.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\System32\svchost.exe
D:\WINDOWS\system32\spoolsv.exe
D:\Programmi\Avira\AntiVir Desktop\sched.exe
D:\Programmi\Avira\AntiVir Desktop\avguard.exe
D:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
D:\Programmi\Bonjour\mDNSResponder.exe
D:\WINDOWS\system32\svchost.exe
D:\WINDOWS\Explorer.EXE
D:\WINDOWS\system32\RUNDLL32.EXE
D:\WINDOWS\RTHDCPL.EXE
D:\Programmi\Avira\AntiVir Desktop\avgnt.exe
D:\WINDOWS\cisvc.exe
D:\Programmi\File comuni\Adobe\OOBE\PDApp\UWA\AAM Updates Notifier.exe
E:\Programmi\iTunesHelper.exe
D:\WINDOWS\system32\ctfmon.exe
D:\Programmi\Windows Live\Messenger\msnmsgr.exe
D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE
D:\Programmi\REALTEK RTL8185 Wireless LAN Driver and Utility\RtWLan.exe
D:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\RtkBtMnt.exe
D:\Programmi\iPod\bin\iPodService.exe
D:\WINDOWS\system32\wuauclt.exe
E:\Programmi\AutoCAD 2008\acad.exe
D:\DOCUME~1\ADMINI~1\IMPOST~1\Temp\AdskCleanup.0001
D:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
E:\Programmi\Microsoft Office\OFFICE11\WINWORD.EXE
D:\Programmi\Internet Explorer\IEXPLORE.EXE
D:\Programmi\Internet Explorer\IEXPLORE.EXE
D:\Programmi\Internet Explorer\IEXPLORE.EXE
D:\WINDOWS\system32\msiexec.exe
D:\Programmi\Trend Micro\HiJackThis\HiJackThis.exe

R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = *.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
F3 - REG:win.ini: load=D:\WINDOWS\cisvc.exe
O2 - BHO: AcroIEHelperStub - {18DF081C-E8AD-4283-A596-FA578C2EBDC3} - D:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelperShim.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - D:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE D:\WINDOWS\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [nwiz] nwiz.exe /install
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE D:\WINDOWS\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [RTHDCPL] RTHDCPL.EXE
O4 - HKLM\..\Run: [Alcmtr] ALCMTR.EXE
O4 - HKLM\..\Run: [avgnt] "D:\Programmi\Avira\AntiVir Desktop\avgnt.exe" /min
O4 - HKLM\..\Run: [AdobeAAMUpdater-1.0] "D:\Programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe"
O4 - HKLM\..\Run: [SwitchBoard] D:\Programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe
O4 - HKLM\..\Run: [AdobeCS5ServiceManager] "D:\Programmi\File comuni\Adobe\CS5ServiceManager\CS5ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "E:\Programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [Adobe ARM] "D:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [AdobeCS4ServiceManager] "D:\Programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe" -launchedbylogin
O4 - HKLM\..\Run: [QuickTime Task] "D:\Programmi\QuickTime\qttask.exe" -atboottime
O4 - HKLM\..\Run: [iTunesHelper] "E:\Programmi\iTunesHelper.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [msnmsgr] "D:\Programmi\Windows Live\Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [EPSON Stylus DX4400 Series] D:\WINDOWS\System32\spool\DRIVERS\W32X86\3\E_FATICAE.EXE /FU "D:\WINDOWS\TEMP\E_SD6.tmp" /EF "HKCU"
O4 - HKLM\..\Policies\Explorer\Run: [Mstsc] D:\DOCUME~1\ADMINI~1\DATIAP~1\mstsc.exe /waitservice
O4 - HKCU\..\Policies\Explorer\Run: [Cisvc] D:\DOCUME~1\ADMINI~1\DATIAP~1\cisvc.exe /waitservice
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Policies\Explorer\Run: [SessMgr] D:\WINDOWS\sessmgr.exe /waitservice (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] D:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - HKUS\.DEFAULT\..\Policies\Explorer\Run: [SessMgr] D:\WINDOWS\sessmgr.exe /waitservice (User 'Default user')
O4 - Global Startup: REALTEK RTL8185 Wireless LAN Utility.lnk = ?
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://E:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - E:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - D:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {05CA9FB0-3E3E-4b36-BF41-0E3A5CAA8CD8} (Office Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=58813
O16 - DPF: {17492023-C23A-453E-A040-C7C580BBF700} (Windows Genuine Advantage Validation Tool) - http://go.microsoft.com/fwlink/?linkid=39204
O16 - DPF: {5AE58FCF-6F6A-49B2-B064-02492C66E3F4} (MUCatalogWebControl Class) - http://catalog.update.microsoft.com/v7/site/ClientControl/en/x86/MuCatalogWebControl.cab?1191420098671
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupdate/v6/V5Controls/en/x86/client/wuweb_site.cab?1123705518796
O16 - DPF: {6e32070a-766d-4ee6-879c-dc1fa91d2fc3} (MUWebControl Class) - http://update.microsoft.com/microsoftupdate/v6/V5Controls/en/x86/client/muweb_site.cab?1139406804265
O16 - DPF: {E2883E8F-472F-4FB0-9522-AC9BF37916A7} - http://platformdl.adobe.com/NOS/getPlusPlus/1.6/gp.cab
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - D:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - D:\WINDOWS\system32\browseui.dll
O23 - Service: Avira AntiVir Scheduler (AntiVirScheduler) - Avira GmbH - D:\Programmi\Avira\AntiVir Desktop\sched.exe
O23 - Service: Avira AntiVir Guard (AntiVirService) - Avira GmbH - D:\Programmi\Avira\AntiVir Desktop\avguard.exe
O23 - Service: Apple Mobile Device - Apple Inc. - D:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Autodesk Licensing Service - Autodesk - D:\Programmi\File comuni\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: Servizio Bonjour (Bonjour Service) - Apple Inc. - D:\Programmi\Bonjour\mDNSResponder.exe
O23 - Service: FLEXnet Licensing Service - Acresso Software Inc. - D:\Programmi\File comuni\Macrovision Shared\FLEXnet Publisher\FNPLicensingService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - D:\Programmi\iPod\bin\iPodService.exe
O23 - Service: NVIDIA Display Driver Service (NVSvc) - Unknown owner - D:\WINDOWS\system32\nvsvc32.exe (file missing)
O23 - Service: SwitchBoard - Adobe Systems Incorporated - D:\Programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe

--
End of file - 8296 bytes
shapiro
Inviato: Saturday, October 02, 2010 9:12:45 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
nel log ci sono delle voci che non mi convincono, come questa per esempio e' nel percorso sbagliato

D:\WINDOWS\cisvc.exe


scarica combofix sul desktop
non dar retta agli avvisi dell'antivirus e procedi tranquilla

alla richiesta se vuoi installare la recovery console clicca su NO

esegui ComboFix.exe

segui le instruzioni

finita la scansione portati in C:\ e copia/incolla, nella tua prossima risposta, il contenuto del file di testo Combofix.txt
giorgia87
Inviato: Saturday, October 02, 2010 9:31:36 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ComboFix 10-10-01.07 - Administrator 02/10/2010 21.22.43.1.2 - x86
Microsoft Windows XP Professional 5.1.2600.3.1252.39.1040.18.2046.1594 [GMT 2:00]
Eseguito da: d:\documents and settings\Administrator\Desktop\ComboFix.exe
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-6C25-9E7C08000A00}
AV: AntiVir Desktop *On-access scanning enabled* (Updated) {00000002-0002-0000-7C25-9E7C08000A00}
.

((((((((((((((((((((((((((((((((((((( Altre eliminazioni )))))))))))))))))))))))))))))))))))))))))))))))))))
.

d:\documents and settings\Administrator\Dati applicazioni\cisvc.exe
d:\documents and settings\Administrator\Dati applicazioni\mstsc.exe
d:\windows\CISVC.exe
d:\windows\logman.exe
d:\windows\sessmgr.exe
d:\windows\system\dllhst3g.exe
d:\windows\system\WINSPOOL.DRV
d:\windows\system32\keystone.exe
d:\windows\system32\nvappbar.exe
d:\windows\system32\nvcolor.exe
d:\windows\system32\nvcplui.exe
d:\windows\system32\nvcpluir.dll
d:\windows\system32\nvdspsch.exe
d:\windows\system32\nvexpbar.dll
d:\windows\system32\nvmccsrs.dll

d:\windows\system32\msgsvc.dll . . . è infetto!!

.
((((((((((((((((((((((((( Files Creati Da 2010-09-02 al 2010-10-02 )))))))))))))))))))))))))))))))))))
.

2010-10-02 19:27 . 2010-10-02 19:27 -------- d-----w- d:\windows\system32\xircom
2010-10-02 19:27 . 2010-10-02 19:27 -------- d-----w- d:\windows\system32\wbem\snmp
2010-10-02 19:01 . 2010-10-02 19:01 388096 ----a-r- d:\documents and settings\Administrator\Dati applicazioni\Microsoft\Installer\{45A66726-69BC-466B-A7A4-12FCBA4883D7}\HiJackThis.exe
2010-10-02 19:01 . 2010-10-02 19:01 -------- d-----w- d:\programmi\Trend Micro
2010-10-02 13:22 . 2010-10-02 13:22 -------- d-----w- d:\documents and settings\Administrator\Dati applicazioni\Malwarebytes
2010-10-02 13:22 . 2010-04-29 13:39 38224 ----a-w- d:\windows\system32\drivers\mbamswissarmy.sys
2010-10-02 13:22 . 2010-10-02 13:22 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Malwarebytes
2010-10-02 13:22 . 2010-04-29 13:39 20952 ----a-w- d:\windows\system32\drivers\mbam.sys
2010-10-02 13:22 . 2010-10-02 13:22 -------- d-----w- d:\programmi\Malwarebytes' Anti-Malware
2010-10-01 12:07 . 2010-10-01 12:07 -------- d-----w- d:\documents and settings\Administrator\Dati applicazioni\chc.4875E02D9FB21EE389F73B8D1702B320485DF8CE.1
2010-09-19 23:11 . 2010-09-19 23:11 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Apple
2010-09-19 23:10 . 2010-09-19 23:13 -------- d-----w- d:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Apple Computer
2010-09-19 22:11 . 2010-09-19 22:11 -------- d-----w- d:\documents and settings\Administrator\Dati applicazioni\DivX
2010-09-19 22:10 . 2010-09-19 22:10 -------- d-----w- d:\windows\system32\custom matrices
2010-09-19 22:10 . 2010-09-19 22:10 -------- d-----w- d:\windows\system32\C2MP
2010-09-19 22:10 . 2010-09-19 22:10 -------- d-----w- d:\windows\system32\QuickTime
2010-09-19 16:27 . 2010-09-19 16:27 -------- d-----w- d:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\Identities
2010-09-19 11:34 . 2010-09-19 11:34 -------- d-----r- d:\documents and settings\LocalService\Preferiti
2010-09-19 11:34 . 2010-09-19 11:34 -------- d-sh--w- d:\documents and settings\LocalService\IETldCache
2010-09-17 14:28 . 2007-01-11 04:02 113664 ----a-w- d:\documents and settings\All Users\Dati applicazioni\EPSON\EPW!3 SSRP\E_S40RP7.EXE
2010-09-17 14:28 . 2010-09-17 14:28 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\EPSON
2010-09-17 14:28 . 2004-09-10 20:12 49152 ----a-w- d:\windows\system32\E_DCINST.DLL
2010-09-17 14:28 . 2006-12-08 02:04 76800 ----a-w- d:\windows\system32\E_FLBCAE.DLL
2010-09-17 14:28 . 2006-04-19 02:00 62976 ----a-w- d:\windows\system32\E_FD4BCAE.DLL
2010-09-17 14:28 . 2008-04-13 09:45 15104 ----a-w- d:\windows\system32\drivers\usbscan.sys
2010-09-17 14:26 . 2010-09-17 14:27 -------- d-----w- d:\programmi\epson
2010-09-17 14:26 . 2006-12-27 22:00 66560 ----a-w- d:\windows\system32\eswia7e.dll
2010-09-17 14:26 . 2006-12-27 22:00 208896 ----a-w- d:\windows\system32\esint7e.dll
2010-09-17 14:26 . 2006-03-09 22:00 3584 ----a-w- d:\windows\system32\eswiaml.dll
2010-09-17 14:25 . 2008-04-13 09:47 25856 ----a-w- d:\windows\system32\drivers\usbprint.sys
2010-09-16 15:49 . 2010-08-17 13:17 58880 ------w- d:\windows\system32\dllcache\spoolsv.exe
2010-09-16 15:49 . 2010-06-18 17:43 293888 ------w- d:\windows\system32\dllcache\winsrv.dll
2010-09-16 15:48 . 2010-04-16 15:37 406016 ------w- d:\windows\system32\dllcache\usp10.dll
2010-09-04 20:07 . 2010-09-04 20:07 -------- d-----w- d:\programmi\File comuni\Macrovision Shared
2010-09-04 18:06 . 2002-12-31 12:00 26624 ----a-w- d:\documents and settings\LocalService\Dati applicazioni\Microsoft\UPnP Device Host\upnphost\udhisapi.dll

.
(((((((((((((((((((((((((((((((((((((((( Find3M Report )))))))))))))))))))))))))))))))))))))))))))))))))))
.
2010-10-02 19:27 . 2010-10-02 19:27 -------- d-----w- d:\programmi\microsoft frontpage
2010-10-02 19:02 . 2010-09-01 12:29 -------- d-----w- d:\programmi\Windows Media Connect 2
2010-10-02 14:14 . 2002-12-31 12:00 85330 ----a-w- d:\windows\system32\perfc010.dat
2010-10-02 14:14 . 2002-12-31 12:00 492504 ----a-w- d:\windows\system32\perfh010.dat
2010-09-19 23:13 . 2010-09-19 23:13 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\{429CAD59-35B1-4DBC-BB6D-1DB246563521}
2010-09-19 23:13 . 2010-09-19 23:13 -------- d-----w- d:\programmi\iPod
2010-09-19 23:13 . 2010-09-19 23:11 -------- d-----w- d:\programmi\File comuni\Apple
2010-09-19 23:13 . 2010-09-19 23:12 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Apple Computer
2010-09-19 23:12 . 2010-09-19 23:12 -------- d-----w- d:\programmi\QuickTime
2010-09-19 23:12 . 2010-09-19 23:12 -------- d-----w- d:\programmi\Apple Software Update
2010-09-19 23:11 . 2010-09-19 23:11 -------- d-----w- d:\programmi\Bonjour
2010-09-19 21:54 . 2010-09-19 23:13 -------- d-----w- d:\documents and settings\Administrator\Dati applicazioni\Apple Computer
2010-09-18 22:43 . 2010-09-01 18:19 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Autodesk
2010-09-18 22:43 . 2010-09-01 18:19 -------- d-----w- d:\documents and settings\Administrator\Dati applicazioni\Autodesk
2010-09-17 14:16 . 2010-09-01 18:02 -------- d-----w- d:\programmi\File comuni\Adobe
2010-09-16 16:32 . 2010-09-01 16:59 74776 ----a-w- d:\documents and settings\Administrator\Impostazioni locali\Dati applicazioni\GDIPFONTCACHEV1.DAT
2010-09-13 09:42 . 2010-09-01 18:12 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\regid.1986-12.com.adobe
2010-09-01 18:58 . 2010-09-01 18:47 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\FLEXnet
2010-09-01 18:22 . 2010-09-01 18:18 -------- d-----w- d:\programmi\File comuni\Autodesk Shared
2010-09-01 18:19 . 2010-09-01 18:19 -------- d-----w- d:\programmi\File comuni\InstallShield
2010-09-01 18:18 . 2010-09-01 18:18 -------- d-----w- d:\programmi\Autodesk
2010-09-01 18:05 . 2010-09-01 18:05 -------- d-----w- d:\programmi\File comuni\Adobe AIR
2010-09-01 18:05 . 2010-09-01 18:06 38784 ----a-w- d:\documents and settings\Default User\Dati applicazioni\Macromedia\Flash Player\www.macromedia.com\bin\airappinstaller\airappinstaller.exe
2010-09-01 17:52 . 2010-09-01 12:26 -------- d-----w- d:\programmi\Microsoft Silverlight
2010-09-01 17:09 . 2010-09-01 17:07 -------- d-----w- d:\programmi\Windows Live
2010-09-01 17:08 . 2010-09-01 17:08 -------- d-----w- d:\programmi\Microsoft
2010-09-01 17:08 . 2010-09-01 17:08 -------- d-----w- d:\programmi\Windows Live SkyDrive
2010-09-01 17:00 . 2010-09-01 17:00 -------- d-----w- d:\programmi\File comuni\Windows Live
2010-09-01 16:43 . 2010-09-01 16:43 -------- d-----w- d:\programmi\MSXML 4.0
2010-09-01 16:34 . 2010-09-01 16:34 -------- d-----w- d:\programmi\Microsoft.NET
2010-09-01 16:32 . 2010-09-01 16:32 0 ---ha-w- d:\windows\system32\drivers\Msft_Kernel_winbondhidcir_01005.Wdf
2010-09-01 16:32 . 2010-09-01 16:32 0 ---ha-w- d:\windows\system32\drivers\MsftWdf_Kernel_01005_Coinstaller_Critical.Wdf
2010-09-01 15:51 . 2010-09-01 15:51 -------- d-----w- d:\programmi\Avira
2010-09-01 15:51 . 2010-09-01 15:51 -------- d-----w- d:\documents and settings\All Users\Dati applicazioni\Avira
2010-09-01 15:18 . 2010-09-01 15:18 -------- d-----w- d:\programmi\CONEXANT
2010-09-01 15:04 . 2010-09-01 15:04 69632 ----a-r- d:\documents and settings\Administrator\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\NewShortcut2_B358DA4D0918436EA0E64813B1E5965A.exe
2010-09-01 15:04 . 2010-09-01 15:04 69632 ----a-r- d:\documents and settings\Administrator\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\NewShortcut1_B358DA4D0918436EA0E64813B1E5965A.exe
2010-09-01 15:04 . 2010-09-01 15:04 10134 ----a-r- d:\documents and settings\Administrator\Dati applicazioni\Microsoft\Installer\{B358DA4D-0918-436E-A0E6-4813B1E5965A}\ARPPRODUCTICON.exe
2010-09-01 13:54 . 2010-09-01 13:54 -------- d-----w- d:\programmi\REALTEK RTL8185 Wireless LAN Driver and Utility
2010-09-01 13:54 . 2010-09-01 13:54 21035 ----a-w- d:\windows\system32\drivers\AegisP.sys
2010-09-01 13:54 . 2010-09-01 13:54 -------- d--h--w- d:\programmi\InstallShield Installation Information
2010-09-01 13:54 . 2010-09-01 13:54 -------- d-----w- d:\documents and settings\Administrator\Dati applicazioni\InstallShield
2010-09-01 13:26 . 2010-09-01 12:30 86327 ----a-w- d:\windows\pchealth\helpctr\OfflineCache\index.dat
2010-09-01 12:45 . 2010-09-01 12:45 -------- d-----w- d:\programmi\MSBuild
2010-09-01 12:45 . 2010-09-01 12:45 -------- d-----w- d:\programmi\Reference Assemblies
2010-09-01 12:44 . 2010-09-01 12:44 -------- d-----w- d:\programmi\MSXML 6.0
2010-09-01 12:30 . 2010-09-01 12:30 -------- d-----w- d:\programmi\Servizi in linea
2010-09-01 12:27 . 2010-09-01 12:27 21840 ----a-w- d:\windows\system32\emptyregdb.dat
2010-09-01 07:12 . 2010-09-01 07:12 73000 ----a-w- d:\documents and settings\All Users\Dati applicazioni\Apple Computer\Installer Cache\iTunes 10.0.0.68\SetupAdmin.exe
2010-08-17 13:17 . 2002-12-31 12:00 58880 ----a-w- d:\windows\system32\spoolsv.exe
2010-07-27 16:44 . 2010-07-27 16:44 91424 ----a-w- d:\windows\system32\dnssd.dll
2010-07-27 16:44 . 2010-07-27 16:44 75040 ----a-w- d:\windows\system32\jdns_sd.dll
2010-07-27 16:44 . 2010-07-27 16:44 197920 ----a-w- d:\windows\system32\dnssdX.dll
2010-07-27 16:44 . 2010-07-27 16:44 107808 ----a-w- d:\windows\system32\dns-sd.exe
2010-07-22 15:48 . 2002-12-31 12:00 590848 ----a-w- d:\windows\system32\rpcrt4.dll
2010-07-22 09:49 . 2008-05-05 05:25 5632 ----a-w- d:\windows\system32\xpsp4res.dll
.

((((((((((((((((((((((((((((((((((((( Punti Reg Caricati ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Nota* i valori vuoti & legittimi/default non sono visualizzati.
REGEDIT4

[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"msnmsgr"="d:\programmi\Windows Live\Messenger\msnmsgr.exe" [2010-04-16 3872080]

[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"NvCplDaemon"="d:\windows\system32\NvCpl.dll" [2007-06-06 8433664]
"NvMediaCenter"="d:\windows\system32\NvMcTray.dll" [2007-06-06 81920]
"RTHDCPL"="RTHDCPL.EXE" [2007-05-28 16132608]
"avgnt"="d:\programmi\Avira\AntiVir Desktop\avgnt.exe" [2009-03-02 209153]
"AdobeAAMUpdater-1.0"="d:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\UpdaterStartupUtility.exe" [2010-03-06 500208]
"SwitchBoard"="d:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe" [2010-02-19 517096]
"AdobeCS5ServiceManager"="d:\programmi\File comuni\Adobe\CS5ServiceManager\CS5ServiceManager.exe" [2010-02-22 406992]
"Adobe Reader Speed Launcher"="e:\programmi\Adobe\Reader 9.0\Reader\Reader_sl.exe" [2010-06-20 35760]
"Adobe ARM"="d:\programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe" [2010-06-09 976832]
"AdobeCS4ServiceManager"="d:\programmi\File comuni\Adobe\CS4ServiceManager\CS4ServiceManager.exe" [2008-08-14 611712]
"QuickTime Task"="d:\programmi\QuickTime\qttask.exe" [2010-08-10 421888]
"iTunesHelper"="e:\programmi\iTunesHelper.exe" [2010-09-01 421160]

[HKEY_USERS\.DEFAULT\Software\Microsoft\Windows\CurrentVersion\Run]
"CTFMON.EXE"="d:\windows\system32\CTFMON.EXE" [2002-12-31 15360]

d:\documents and settings\All Users\Menu Avvio\Programmi\Esecuzione automatica\
REALTEK RTL8185 Wireless LAN Utility.lnk - d:\programmi\REALTEK RTL8185 Wireless LAN Driver and Utility\RtWLan.exe [2010-9-1 770048]

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\AuthorizedApplications\List]
"%windir%\\Network Diagnostic\\xpnetdiag.exe"=
"%windir%\\system32\\sessmgr.exe"=
"d:\\Programmi\\Windows Live\\Messenger\\wlcsdk.exe"=
"d:\\Programmi\\Windows Live\\Messenger\\msnmsgr.exe"=
"e:\\Programmi\\eMule AdunanzA\\eMule_AdnzA.exe"=
"d:\\Programmi\\File comuni\\Adobe\\CS4ServiceManager\\CS4ServiceManager.exe"=
"d:\\Programmi\\Bonjour\\mDNSResponder.exe"=
"e:\\Programmi\\iTunes.exe"=

[HKLM\~\services\sharedaccess\parameters\firewallpolicy\standardprofile\GloballyOpenPorts\List]
"5353:TCP"= 5353:TCP:Adobe CSI CS4

R2 EAPPkt;Realtek EAPPkt Protocol;d:\windows\system32\drivers\EAPPkt.sys [01/09/2010 15.54.24 38144]
R3 hidshim;Service for HID-KMDF Shim layer;d:\windows\system32\drivers\hidshim.sys [03/06/2008 13.37.04 5632]
R3 winbondhidcir;Winbond HID CIR Receiver;d:\windows\system32\drivers\winbondhidcir.sys [03/06/2008 13.37.00 23040]
S3 SwitchBoard;SwitchBoard;d:\programmi\File comuni\Adobe\SwitchBoard\SwitchBoard.exe [19/02/2010 13.37.14 517096]
.
Contenuto della cartella 'Scheduled Tasks'

2010-09-23 d:\windows\Tasks\AdobeAAMUpdater-1.0-GIORGIA-Administrator.job
- d:\programmi\File comuni\Adobe\OOBE\PDApp\UWA\updaterstartuputility.exe [2010-09-01 01:44]

2010-09-19 d:\windows\Tasks\AppleSoftwareUpdate.job
- d:\programmi\Apple Software Update\SoftwareUpdate.exe [2009-10-22 09:50]
.
.
------- Scansione supplementare -------
.
uInternet Settings,ProxyOverride = *.local
IE: E&sporta in Microsoft Excel - e:\progra~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
.
.
------- Associazioni dei file -------
.
.scr=AutoCADScriptFile
.
- - - - CHIAVI ORFANE RIMOSSE - - - -

HKLM-Run-nwiz - nwiz.exe
HKLM-Explorer_Run-Mstsc - d:\docume~1\ADMINI~1\DATIAP~1\mstsc.exe
HKU-Default-Explorer_Run-SessMgr - d:\windows\sessmgr.exe



**************************************************************************

catchme 0.3.1398 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2010-10-02 21:27
Windows 5.1.2600 Service Pack 3 NTFS

scansione processi nascosti ...

scansione entrate autostart nascoste ...

Scansione files nascosti ...

Scansione completata con successo
Files nascosti: 0

**************************************************************************
.
--------------------- CHIAVI DI REGISTRO BLOCCATE ---------------------

[HKEY_USERS\S-1-5-21-1547161642-1958367476-1417001333-500\Software\Microsoft\Internet Explorer\User Preferences]
@Denied: (2) (Administrator)
"88D7D0879DAB32E14DE5B3A805A34F98AFF34F5977"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,fe,d9,3f,48,83,5a,4f,88,3d,22,\
"2D53CFFC5C1A3DD2E97B7979AC2A92BD59BC839E81"=hex:01,00,00,00,d0,8c,9d,df,01,15,
d1,11,8c,7a,00,c0,4f,c2,97,eb,01,00,00,00,85,fe,d9,3f,48,83,5a,4f,88,3d,22,\

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}]
@Denied: (A 2) (Everyone)
@="FlashBroker"
"LocalizedString"="@d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe,-101"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\Elevation]
"Enabled"=dword:00000001

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\LocalServer32]
@="d:\\WINDOWS\\system32\\Macromed\\Flash\\FlashUtil10k_ActiveX.exe"

[HKEY_LOCAL_MACHINE\software\Classes\CLSID\{A483C63A-CDBC-426E-BF93-872502E8144E}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}]
@Denied: (A 2) (Everyone)
@="IFlashBroker4"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\ProxyStubClsid32]
@="{00020424-0000-0000-C000-000000000046}"

[HKEY_LOCAL_MACHINE\software\Classes\Interface\{E3F2C3CB-5EB8-4A04-B22C-7E3B4B6AF30F}\TypeLib]
@="{FAB3E735-69C7-453B-A446-B6823C6DF1C9}"
"Version"="1.0"

[HKEY_LOCAL_MACHINE\software\Microsoft\Windows\CurrentVersion\Installer\UserData\LocalSystem\Components\€–€|ÿÿÿÿÀ•€|ù•9~*]
"01403E1900063D11C8EF10054038389C"="D?\\WINDOWS\\system32\\FM20ENU.DLL"
.
--------------------- Dlls caricate dai processi in esecuzione ---------------------

- - - - - - - > 'explorer.exe'(3500)
d:\windows\system32\WININET.dll
d:\windows\system32\msi.dll
d:\windows\system32\webcheck.dll
d:\windows\system32\WPDShServiceObj.dll
d:\windows\system32\PortableDeviceTypes.dll
d:\windows\system32\PortableDeviceApi.dll
e:\programmi\Microsoft Office\OFFICE11\msohev.dll
d:\windows\system32\mmfinfo.dll
d:\windows\system32\mkunicode.dll
d:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.dll
d:\programmi\File comuni\Adobe\Acrobat\ActiveX\PDFShell.ITA
.
------------------------ Altri processi in esecuzione ------------------------
.
d:\programmi\Avira\AntiVir Desktop\sched.exe
d:\programmi\Avira\AntiVir Desktop\avguard.exe
d:\programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
d:\programmi\Bonjour\mDNSResponder.exe
d:\windows\system32\RUNDLL32.EXE
d:\windows\RTHDCPL.EXE
d:\docume~1\ADMINI~1\IMPOST~1\Temp\RtkBtMnt.exe
d:\programmi\iPod\bin\iPodService.exe
.
**************************************************************************
.
Ora fine scansione: 2010-10-02 21:30:38 - Il pc è stato riavviato
ComboFix-quarantined-files.txt 2010-10-02 19:30

Pre-Run: 13.379.846.144 byte disponibili
Post-Run: 13.510.238.208 byte disponibili

- - End Of File - - F79C967CAA77B689297880F8AF1B3559
shapiro
Inviato: Saturday, October 02, 2010 9:46:57 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
Giorgia mentre finisco di controllare puoi dirmi al momento cosa riscontri
giorgia87
Inviato: Saturday, October 02, 2010 10:05:02 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
eh...mi è apparsa ancora la notifica di avira....
shapiro
Inviato: Saturday, October 02, 2010 10:40:16 PM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164


collegati QUI usado il browser I.E. e fai una scansione completa del sistema

posta il rapporto

giorgia87
Inviato: Sunday, October 03, 2010 12:30:14 AM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ho provato...ma si blocca!
hai qualche altro consiglio da darmi?
...grazie per il disturbo!
shapiro
Inviato: Sunday, October 03, 2010 1:01:13 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164
scarica Kaspersky Virus Removal Tool

1> al termine della installazione verrà mostrata la schermata principale del tool
2> verrà creata una cartella sul Desktop dal nome Virus Removal Tool
3> seleziona la partizione da scansionare e clicca su Scan per avviare la scansione
4> terminata la scansione, in caso di rilevazione di infezioni, clicca su Neutralize all
5> si apriranno dei popup dove potrai scegliere se Cancellare o Disinfettare l'oggetto
6> metti la spunta su Apply to all e clicca su Quarantine
7> per salvare il Report che verrà rilasciato, clicca sul tasto Reports: salvalo sul Desktop poi allegalo sul forum.
giorgia87
Inviato: Sunday, October 03, 2010 2:37:18 AM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ecco qui:

Autoscan: stopped 1 hour ago (events: 2, objects: 203, time: 00.00.25)
Autoscan: completed 6 minutes ago (events: 22, objects: 347645, time: 01.12.26)
03/10/2010 1.17.34 Task started
03/10/2010 1.24.42 Detected: HEUR:Trojan.Win32.Generic D:\Qoobox\Quarantine\D\WINDOWS\cisvc.exe.vir
03/10/2010 1.24.42 Detected: HEUR:Trojan.Win32.Generic D:\Qoobox\Quarantine\D\Documents and Settings\Administrator\Dati applicazioni\mstsc.exe.vir
03/10/2010 1.24.42 Detected: HEUR:Trojan.Win32.Generic D:\Qoobox\Quarantine\D\Documents and Settings\Administrator\Dati applicazioni\cisvc.exe.vir
03/10/2010 1.26.45 Detected: HEUR:Trojan.Win32.Generic D:\Qoobox\Quarantine\D\WINDOWS\logman.exe.vir
03/10/2010 1.26.55 Detected: HEUR:Trojan.Win32.Generic D:\Qoobox\Quarantine\D\WINDOWS\sessmgr.exe.vir
03/10/2010 1.26.56 Detected: HEUR:Trojan.Win32.Generic D:\Qoobox\Quarantine\D\WINDOWS\system\dllhst3g.exe.vir
03/10/2010 1.28.45 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP15\A0008357.exe
03/10/2010 1.29.12 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP21\A0011676.exe
03/10/2010 1.29.13 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP21\A0012669.exe
03/10/2010 1.29.13 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP21\A0012670.exe
03/10/2010 1.29.18 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP21\A0012671.exe
03/10/2010 1.29.34 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP26\A0013841.exe
03/10/2010 1.29.34 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP26\A0013924.exe
03/10/2010 1.29.34 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP26\A0013928.exe
03/10/2010 1.31.36 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP27\A0015537.exe
03/10/2010 1.31.36 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP27\A0015536.exe
03/10/2010 1.31.36 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP27\A0015538.exe
03/10/2010 1.31.42 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP27\A0015539.exe
03/10/2010 1.31.44 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP27\A0015540.exe
03/10/2010 1.31.47 Detected: HEUR:Trojan.Win32.Generic D:\System Volume Information\_restore{2BE86A07-D189-4482-A3B3-D644014D5950}\RP27\A0015541.exe
03/10/2010 2.30.00 Task completed
shapiro
Inviato: Sunday, October 03, 2010 11:36:02 AM

Rank: AiutAmico

Iscritto dal : 8/24/2008
Posts: 4,164

hai usato l'opzione ''scansione completa''? se la risposta e' no rieseguilo con la completa

rimuovi combofix con OTC by OldTimer

eseguilo
Clicca su CleanUp.
Alla richiesta di riavvio clicca SI


disattiva il ripristino

Code:
Start --> programmi --> accessori --> utilita' di sistema --> ripristino configurazioni di sistema --> impostazioni ripristino configurazioni di sistema --> Disattiva ripristino!



riavvia il pc

riattivalo e crea un nuovo punto

esegui una nuova scansione completa con malwarebytes dopo averlo aggirnato


edit

quando hai finito dobbiamo sostituire questo file, combofix lo segnala infetto

d:\windows\system32\msgsvc.dll

hai il cd di windows?
giorgia87
Inviato: Sunday, October 03, 2010 1:34:13 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ascolta non c'è scritto scansione completa...ho solo spuntato tutto e avviato la scansione...va bene comunque?
e durante la scansione mi si aprono di nuovo gli avvisi di avira...ora non è ancora conclusa!

ecco mi sono dimenticata di dirti che dall'email di hotmail mi partono delle email a contatti sconosciuti, tipo 1 ogni minuto!

ho il cd di windows!
panchoz
Inviato: Sunday, October 03, 2010 1:51:56 PM

Rank: AiutAmico

Iscritto dal : 11/6/2008
Posts: 2,452
"ecco mi sono dimenticata di dirti che dall'email di hotmail mi partono delle email a contatti sconosciuti, tipo 1 ogni minuto!"

Gli account Hotmail sono fra i più facili ad essere "bucati". Spero tu non abbia dati sensibili nella tua corrispondenza elettronica, vedi C/C bancario o password di altro tipo.




"Quando un virus prende possesso di una macchina, oltre a disattivare tutti i sistemi di sicurezza della macchina stessa, invia in automatico a tutti gli indirizzi della rubrica una email, sperando che qualcun’altro, amico dell’infettato, ci caschi aprendo ingenuamente l’email ."

http://www.informattico.net/peteivanhotmailcom-bufala-virus-email/



giorgia87
Inviato: Sunday, October 03, 2010 2:08:34 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
tranquillo!...non ho nulla di importante!non possiedo ancora dati importanti!!!
giorgia87
Inviato: Sunday, October 03, 2010 2:21:28 PM

Rank: Member

Iscritto dal : 10/2/2010
Posts: 20
ascolta non so come fare a "creare un nuovo punto"...me lo riesci a spiegare?
grazie!
francesco240194
Inviato: Sunday, October 03, 2010 2:26:50 PM

Rank: AiutAmico

Iscritto dal : 7/13/2010
Posts: 150
Epic Fail
r16
Inviato: Sunday, October 03, 2010 2:33:48 PM
Rank: AiutAmico

Iscritto dal : 8/7/2007
Posts: 11,016
@francesco240194 :
La richiesta era un'altra.Eh?

*********************************************************************************

@giorgia87 :

Fai così:

Start

Programmi

Accessori

Utilità di sistema

Ripristino configurazione di sistema

Crea un punto di ripristino

Clicca Avanti

Inserisci una descrizione (quello che vuoi)

Clicca Crea e attendi pazientemente la fine delle operazioni
Utenti presenti in questo topic
Guest


Salta al Forum
Aggiunta nuovi Topic disabilitata in questo forum.
Risposte disabilitate in questo forum.
Eliminazione tuoi Post disabilitata in questo forum.
Modifica dei tuoi post disabilitata in questo forum.
Creazione Sondaggi disabilitata in questo forum.
Voto ai sondaggi disabilitato in questo forum.

Main Forum RSS : RSS

Aiutamici Theme
Powered by Yet Another Forum.net versione 1.9.1.8 (NET v2.0) - 3/29/2008
Copyright © 2003-2008 Yet Another Forum.net. All rights reserved.