Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

script per bagle

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

script per bagle

Messaggioda Gattos » mer feb 14, 2007 7:38 pm

ciao ho copiato lo script da un post ma mi ha dato alcuni errori chi si offre per farmene uno ad hock in caso non avesse elimitato il virus?

posto lo script di Gmer

GMER 1.0.12.12027 - http://www.gmer.net
Autostart scan 2007-02-14 18:10:35
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = PDBoot.exe autocheck autochk *

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = H:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
WgaLogon@DLLName = WgaLogon.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AcrSch2Svc /*Acronis Scheduler2 Service*/@ = "H:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe" /*file not found*/
ATI Smart /*ATI Smart*/@ = H:\WINDOWS\system32\ati2sgag.exe
Avg7Alrt /*AVG7 Alert Manager Server*/@ = H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
Avg7UpdSvc /*AVG7 Update Service*/@ = H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
btwdins /*Bluetooth Service*/@ = H:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
GEARSecurity@ = %SystemRoot%\System32\GEARSec.exe
LEC TranslateDotNet Server /*LEC TranslateDotNet Server*/@ = "H:\Programmi\Power Translator 10\LogoMedia TranslateDotNet Server.exe"
PDAgent /*PDAgent*/@ = H:\Programmi\Raxco\PerfectDisk\PDAgent.exe
RichVideo /*Cyberlink RichVideo Service(CRVS)*/@ = "H:\Programmi\CyberLink\Shared files\RichVideo.exe" ??????????????????????????????????????????????????
SecurityConsole /*SecurityConsole*/@ = H:\WINDOWS\AppPatch\Patches32\svchost.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UserAccess7 /*SecuROM User Access Service (V7)*/@ = H:\WINDOWS\system32\UAService7.exe
V2i Protector /*V2i Protector*/@ = H:\Programmi\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
wwSecSvc /*Washer AutoComplete*/@ = H:\WINDOWS\system32\wwSecure.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@BluetoothAuthenticationAgentrundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent = rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
@AVG7_CCH:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP = H:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Cartella compressa*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/H:\Programmi\WinRAR\rarext.dll = H:\Programmi\WinRAR\rarext.dll
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll = H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll = H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/H:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = H:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/H:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = H:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/H:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = H:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/H:\Programmi\Microsoft Office\OFFICE11\msohev.dll = H:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@(null) =
@{6af09ec9-b429-11d4-a1fb-0090960218cb} /*My Bluetooth Places*/H:\WINDOWS\system32\btneighborhood.dll = H:\WINDOWS\system32\btneighborhood.dll
@{41154927-7C82-457D-8692-A561C6EB80D4} /*FolderContextMenu*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{7A51BD61-1591-4160-9693-97D8A66363A3} /*ExtractIcon*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{1240F6A4-42B6-4FA9-9494-544DE7CE3800} /*ShellPropSheet*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{3DE31A9C-C186-424C-8F30-8AA9AC77BFEC} /*Mobile Devices*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/H:\WINDOWS\system32\dfshim.dll = H:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/H:\WINDOWS\system32\dfshim.dll = H:\WINDOWS\system32\dfshim.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{52B87208-9CCF-42C9-B88E-069281105805} /*Trojan Remover Shell Extension*/(null) =
@{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} /*PhoneBrowser*/H:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll = H:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
@{C0C4375A-5B72-4efe-929D-3B848C3A1E91} /*Message View*/H:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll = H:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll
@{46E22146-59C0-4136-9233-52E412E2B428} /*EzCddax extension*/H:\Programmi\Easy CD-DA Extractor 8\ezcddax8.dll = H:\Programmi\Easy CD-DA Extractor 8\ezcddax8.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/(null) =
@{FED7043D-346A-414D-ACD7-550D052499A7} /*dBpowerAMP Music Converter 1*/H:\Programmi\Illustrate\dBpowerAMP\dBShell.dll = H:\Programmi\Illustrate\dBpowerAMP\dBShell.dll
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpowerAMP Music Converter*/H:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll = H:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll
@{6EE51AA0-77A0-11D7-B4E1-000347126E46} /*Window Washer Shredding Utility*/H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL = H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/H:\Programmi\iTunes\iTunesMiniPlayer.dll = H:\Programmi\iTunes\iTunesMiniPlayer.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/H:\Programmi\MSN Messenger\fsshext.8.1.0178.00.dll = H:\Programmi\MSN Messenger\fsshext.8.1.0178.00.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{49BF5420-FA7F-11cf-8011-00A0C90A8F78} /*Mobile Device*/H:\PROGRA~1\MI3AA1~1\Wcesview.dll = H:\PROGRA~1\MI3AA1~1\Wcesview.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/H:\Programmi\Real\RealPlayer\rpshell.dll = H:\Programmi\Real\RealPlayer\rpshell.dll
@{5E2121EE-0300-11D4-8D3B-444553540000} /*Catalyst Context Menu extension*/H:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll = H:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/H:\Programmi\Grisoft\AVG7\avgse.dll = H:\Programmi\Grisoft\AVG7\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/H:\Programmi\Grisoft\AVG7\avgse.dll = H:\Programmi\Grisoft\AVG7\avgse.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = H:\Programmi\Grisoft\AVG7\avgse.dll
EzCddax@{46E22146-59C0-4136-9233-52E412E2B428} = H:\Programmi\Easy CD-DA Extractor 8\ezcddax8.dll
Washer@{6EE51AA0-77A0-11D7-B4E1-000347126E46} = H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = H:\Programmi\WinRAR\rarext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = H:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
Washer@{6EE51AA0-77A0-11D7-B4E1-000347126E46} = H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = H:\Programmi\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = H:\Programmi\Grisoft\AVG7\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = H:\Programmi\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = H:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}H:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = H:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{4E9CAE1A-545D-48EA-8EEF-4D1DB6695AD3}H:\Programmi\Sytexis Software\Web Stream Recorder\wsr_ieplug.dll = H:\Programmi\Sytexis Software\Web Stream Recorder\wsr_ieplug.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}H:\Programmi\Java\jre1.5.0_06\bin\ssv.dll = H:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}H:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = H:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

HKCU\Control Panel\Desktop@SCRNSAVE.EXE = H:\WINDOWS\WATER_~1.SCR

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageH:\WINDOWS\system32\blank.htm = H:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = H:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = H:\WINDOWS\system32\msvidctl.dll
its@CLSID = H:\WINDOWS\system32\itss.dll
livecall@CLSID = H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = H:\WINDOWS\system32\itss.dll
ms-itss@CLSID = H:\Programmi\File comuni\Microsoft Shared\Information Retrieval\msitss.dll
msnim@CLSID = H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = H:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = H:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
talkto@CLSID = H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
tv@CLSID = H:\WINDOWS\system32\msvidctl.dll
wia@CLSID = H:\WINDOWS\system32\wiascr.dll
widimg@CLSID = H:\WINDOWS\system32\btxppanel.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{283D737C-7AA5-44BF-9824-1CD5DE389577} /*LAN WIFI*/ >>>
@IPAddress192.168.0.1 = 192.168.0.1
@NameServer192.168.0.1 = 192.168.0.1
@DefaultGateway =
@Domain =

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004@LibraryPath = %SystemRoot%\system32\wshbth.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = xfire_lsp.dll
000000000002@PackedCatalogItem = xfire_lsp.dll
000000000003@PackedCatalogItem = xfire_lsp.dll
000000000004@PackedCatalogItem = xfire_lsp.dll
000000000005@PackedCatalogItem = xfire_lsp.dll
000000000006@PackedCatalogItem = xfire_lsp.dll
000000000007@PackedCatalogItem = xfire_lsp.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015@PackedCatalogItem = xfire_lsp.dll

---- EOF - GMER 1.0.12 ----
Grazie a tutti siete fantastici [rotolo]
Avatar utente
Gattos
Neo Iscritto
Neo Iscritto
 
Messaggi: 5
Iscritto il: mer feb 14, 2007 7:22 pm

Messaggioda Amantide » mer feb 14, 2007 8:08 pm

Putroppo in questo log mancano i valori Run in HKEY_Current_USER
HKLM\Software\Microsoft\Windows\CurrentVersion\Run
e quindi non ti so dire se è stato eliminato tutto. [uhm]

Prova a rifare la scansione spuntando tutte le voci a destra, compreso Show all e riposta sia il log di Autorun che Rootkit.


Ah! Ciao e benvenuto [:)]
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Messaggioda Gattos » mer feb 14, 2007 10:38 pm

GMER 1.0.12.12027 - http://www.gmer.net
Autostart scan 2007-02-14 21:34:56
Windows 5.1.2600 Service Pack 2


HKLM\SYSTEM\CurrentControlSet\Control\Session Manager@BootExecute = PDBoot.exe autocheck autochk *

HKLM\SYSTEM\CurrentControlSet\Control\Session Manager\SubSystems@Windows = %SystemRoot%\system32\csrss.exe ObjectDirectory=\Windows SharedSection=1024,3072,512 Windows=On SubSystemType=Windows ServerDll=basesrv,1 ServerDll=winsrv:UserServerDllInitialization,3 ServerDll=winsrv:ConServerDllInitialization,2 ProfileControl=Off MaxRequestThreads=16

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon@Userinit = H:\WINDOWS\system32\userinit.exe,

HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\ >>>
AtiExtEvent@DLLName = Ati2evxx.dll
WgaLogon@DLLName = WgaLogon.dll

HKLM\SYSTEM\CurrentControlSet\Services\ >>>
AcrSch2Svc /*Acronis Scheduler2 Service*/@ = "H:\Programmi\File comuni\Acronis\Schedule2\schedul2.exe" /*file not found*/
ATI Smart /*ATI Smart*/@ = H:\WINDOWS\system32\ati2sgag.exe
Avg7Alrt /*AVG7 Alert Manager Server*/@ = H:\PROGRA~1\Grisoft\AVG7\avgamsvr.exe
Avg7UpdSvc /*AVG7 Update Service*/@ = H:\PROGRA~1\Grisoft\AVG7\avgupsvc.exe
btwdins /*Bluetooth Service*/@ = H:\Programmi\WIDCOMM\Software Bluetooth\bin\btwdins.exe
GEARSecurity@ = %SystemRoot%\System32\GEARSec.exe
LEC TranslateDotNet Server /*LEC TranslateDotNet Server*/@ = "H:\Programmi\Power Translator 10\LogoMedia TranslateDotNet Server.exe"
PDAgent /*PDAgent*/@ = H:\Programmi\Raxco\PerfectDisk\PDAgent.exe
RichVideo /*Cyberlink RichVideo Service(CRVS)*/@ = "H:\Programmi\CyberLink\Shared files\RichVideo.exe" ??????????????????????????????????????????????????
SecurityConsole /*SecurityConsole*/@ = H:\WINDOWS\AppPatch\Patches32\svchost.exe
Spooler /*Spooler di stampa*/@ = %SystemRoot%\system32\spoolsv.exe
UserAccess7 /*SecuROM User Access Service (V7)*/@ = H:\WINDOWS\system32\UAService7.exe
V2i Protector /*V2i Protector*/@ = H:\Programmi\PowerQuest\Drive Image 7.0\Agent\PQV2iSvc.exe
wwSecSvc /*Washer AutoComplete*/@ = H:\WINDOWS\system32\wwSecure.exe

HKLM\Software\Microsoft\Windows\CurrentVersion\Run >>>
@BluetoothAuthenticationAgentrundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent = rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
@AVG7_CCH:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP = H:\PROGRA~1\Grisoft\AVG7\avgcc.exe /STARTUP
@KernelFaultCheck%systemroot%\system32\dumprep 0 -k = %systemroot%\system32\dumprep 0 -k

HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved >>>
@{42071714-76d4-11d1-8b24-00a0c9068ff3} /*Estensione panoramica video del Pannello di controllo*/deskpan.dll /*file not found*/ = deskpan.dll /*file not found*/
@{596AB062-B4D2-4215-9F74-E9109B0A8153} /*Pagina proprietà versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{9DB7A13C-F208-4981-8353-73CC61AE2783} /*Versioni precedenti*/%SystemRoot%\system32\twext.dll = %SystemRoot%\system32\twext.dll
@{E88DCCE0-B7B3-11d1-A9F0-00AA0060FA31} /*Cartella compressa*/(null) =
@{692F0339-CBAA-47e6-B5B5-3B84DB604E87} /*Extensions Manager Folder*/%SystemRoot%\system32\extmgr.dll = %SystemRoot%\system32\extmgr.dll
@{B41DB860-8EE4-11D2-9906-E49FADC173CA} /*WinRAR shell extension*/H:\Programmi\WinRAR\rarext.dll = H:\Programmi\WinRAR\rarext.dll
@{B327765E-D724-4347-8B16-78AE18552FC3} /*NeroDigitalIconHandler*/H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll = H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll
@{7F1CF152-04F8-453A-B34C-E609530A9DC8} /*NeroDigitalPropSheetHandler*/H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll = H:\Programmi\File comuni\Ahead\lib\NeroDigitalExt.dll
@{BDEADF00-C265-11D0-BCED-00A0C90AB50F} /*Cartelle Web*/H:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL = H:\PROGRA~1\FILECO~1\MICROS~1\WEBFOL~1\MSONSEXT.DLL
@{00020D75-0000-0000-C000-000000000046} /*Microsoft Office Outlook Desktop Icon Handler*/H:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL = H:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL
@{0006F045-0000-0000-C000-000000000046} /*Microsoft Office Outlook Custom Icon Handler*/H:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL = H:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL
@{42042206-2D85-11D3-8CFF-005004838597} /*Microsoft Office HTML Icon Handler*/H:\Programmi\Microsoft Office\OFFICE11\msohev.dll = H:\Programmi\Microsoft Office\OFFICE11\msohev.dll
@(null) =
@{6af09ec9-b429-11d4-a1fb-0090960218cb} /*My Bluetooth Places*/H:\WINDOWS\system32\btneighborhood.dll = H:\WINDOWS\system32\btneighborhood.dll
@{41154927-7C82-457D-8692-A561C6EB80D4} /*FolderContextMenu*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{7A51BD61-1591-4160-9693-97D8A66363A3} /*ExtractIcon*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{1240F6A4-42B6-4FA9-9494-544DE7CE3800} /*ShellPropSheet*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{3DE31A9C-C186-424C-8F30-8AA9AC77BFEC} /*Mobile Devices*/H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL = H:\PROGRA~1\NOVA-E~1\PCMOBI~1\MOBILE~1.DLL
@{e82a2d71-5b2f-43a0-97b8-81be15854de8} /*ShellLink for Application References*/H:\WINDOWS\system32\dfshim.dll = H:\WINDOWS\system32\dfshim.dll
@{E37E2028-CE1A-4f42-AF05-6CEABC4E5D75} /*Shell Icon Handler for Application References*/H:\WINDOWS\system32\dfshim.dll = H:\WINDOWS\system32\dfshim.dll
@{00E7B358-F65B-4dcf-83DF-CD026B94BFD4} /*Autoplay for SlideShow*/(null) =
@{52B87208-9CCF-42C9-B88E-069281105805} /*Trojan Remover Shell Extension*/(null) =
@{416651E4-9C3C-11D9-8BDE-F66BAD1E3F3A} /*PhoneBrowser*/H:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll = H:\Programmi\Nokia\Nokia PC Suite 6\PhoneBrowser.dll
@{C0C4375A-5B72-4efe-929D-3B848C3A1E91} /*Message View*/H:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll = H:\Programmi\Nokia\Nokia PC Suite 6\MessageView.dll
@{46E22146-59C0-4136-9233-52E412E2B428} /*EzCddax extension*/H:\Programmi\Easy CD-DA Extractor 8\ezcddax8.dll = H:\Programmi\Easy CD-DA Extractor 8\ezcddax8.dll
@{32020A01-506E-484D-A2A8-BE3CF17601C3} /*AlcoholShellEx*/(null) =
@{FED7043D-346A-414D-ACD7-550D052499A7} /*dBpowerAMP Music Converter 1*/H:\Programmi\Illustrate\dBpowerAMP\dBShell.dll = H:\Programmi\Illustrate\dBpowerAMP\dBShell.dll
@{2C49B5D0-ACE7-4D17-9DF0-A254A6C5A0C5} /*dBpowerAMP Music Converter*/H:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll = H:\Programmi\Illustrate\dBpowerAMP\dMCShell.dll
@{6EE51AA0-77A0-11D7-B4E1-000347126E46} /*Window Washer Shredding Utility*/H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL = H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
@{B9E1D2CB-CCFF-4AA6-9579-D7A4754030EF} /*iTunes*/H:\Programmi\iTunes\iTunesMiniPlayer.dll = H:\Programmi\iTunes\iTunesMiniPlayer.dll
@{FC9FB64A-1EB2-4CCF-AF5E-1A497A9B5C2D} /*Messenger Sharing Folders*/H:\Programmi\MSN Messenger\fsshext.8.1.0178.00.dll = H:\Programmi\MSN Messenger\fsshext.8.1.0178.00.dll
@{35786D3C-B075-49b9-88DD-029876E11C01} /*Portable Devices*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{D6791A63-E7E2-4fee-BF52-5DED8E86E9B8} /*Portable Devices Menu*/%SystemRoot%\system32\wpdshext.dll = %SystemRoot%\system32\wpdshext.dll
@{49BF5420-FA7F-11cf-8011-00A0C90A8F78} /*Mobile Device*/H:\PROGRA~1\MI3AA1~1\Wcesview.dll = H:\PROGRA~1\MI3AA1~1\Wcesview.dll
@{F0CB00CD-5A07-4D91-97F5-A8C92CDA93E4} /*Shell Extensions for RealOne Player*/H:\Programmi\Real\RealPlayer\rpshell.dll = H:\Programmi\Real\RealPlayer\rpshell.dll
@{5E2121EE-0300-11D4-8D3B-444553540000} /*Catalyst Context Menu extension*/H:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll = H:\Programmi\ATI Technologies\ATI.ACE\atiacmxx.dll
@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} /*AVG7 Shell Extension*/H:\Programmi\Grisoft\AVG7\avgse.dll = H:\Programmi\Grisoft\AVG7\avgse.dll
@{9F97547E-460A-42C5-AE0C-81C61FFAEBC3} /*AVG7 Find Extension*/H:\Programmi\Grisoft\AVG7\avgse.dll = H:\Programmi\Grisoft\AVG7\avgse.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = H:\Programmi\Grisoft\AVG7\avgse.dll
EzCddax@{46E22146-59C0-4136-9233-52E412E2B428} = H:\Programmi\Easy CD-DA Extractor 8\ezcddax8.dll
Washer@{6EE51AA0-77A0-11D7-B4E1-000347126E46} = H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = H:\Programmi\WinRAR\rarext.dll

HKLM\Software\Classes\*\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = H:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\ >>>
Washer@{6EE51AA0-77A0-11D7-B4E1-000347126E46} = H:\PROGRA~1\FILECO~1\WEBROO~1\SHELLW~1.DLL
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = H:\Programmi\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\ >>>
AVG7 Shell Extension@{9F97547E-4609-42C5-AE0C-81C61FFAEBC3} = H:\Programmi\Grisoft\AVG7\avgse.dll
WinRAR@{B41DB860-8EE4-11D2-9906-E49FADC173CA} = H:\Programmi\WinRAR\rarext.dll

HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers@{EB4D3CFE-E2AA-4C6E-B2FE-2A749F95D208} = H:\Programmi\Nero\Nero 7\Nero BackItUp\NBShell.dll

HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects >>>
@{06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}H:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll = H:\Programmi\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
@{4E9CAE1A-545D-48EA-8EEF-4D1DB6695AD3}H:\Programmi\Sytexis Software\Web Stream Recorder\wsr_ieplug.dll = H:\Programmi\Sytexis Software\Web Stream Recorder\wsr_ieplug.dll
@{761497BB-D6F0-462C-B6EB-D4DAF1D92D43}H:\Programmi\Java\jre1.5.0_06\bin\ssv.dll = H:\Programmi\Java\jre1.5.0_06\bin\ssv.dll
@{9030D464-4C02-4ABF-8ECC-5164760863C6}H:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll = H:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll

HKCU\Control Panel\Desktop@SCRNSAVE.EXE = H:\WINDOWS\WATER_~1.SCR

HKLM\Software\Microsoft\Internet Explorer\Main >>>
@Default_Page_URLhttp://www.microsoft.com/isapi/redir.dll?prd=ie&pver=6&ar=msnhome = http://www.microsoft.com/isapi/redir.dl ... ar=msnhome
@Start Pagehttp://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home = http://www.microsoft.com/isapi/redir.dll?prd={SUB_PRD}&clcid={SUB_CLSID}&pver={SUB_PVER}&ar=home
@Local Page%SystemRoot%\system32\blank.htm = %SystemRoot%\system32\blank.htm

HKCU\Software\Microsoft\Internet Explorer\Main >>>
@Start Pagehttp://www.google.it/ = http://www.google.it/
@Local PageH:\WINDOWS\system32\blank.htm = H:\WINDOWS\system32\blank.htm

HKLM\Software\Classes\PROTOCOLS\Filter\text/xml@CLSID = H:\Programmi\File comuni\Microsoft Shared\OFFICE11\MSOXMLMF.DLL

HKLM\Software\Classes\PROTOCOLS\Handler\ >>>
dvd@CLSID = H:\WINDOWS\system32\msvidctl.dll
its@CLSID = H:\WINDOWS\system32\itss.dll
livecall@CLSID = H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mhtml@CLSID = %SystemRoot%\system32\inetcomm.dll
ms-its@CLSID = H:\WINDOWS\system32\itss.dll
ms-itss@CLSID = H:\Programmi\File comuni\Microsoft Shared\Information Retrieval\msitss.dll
msnim@CLSID = H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
mso-offdap@CLSID = H:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\10\OWC10.DLL
mso-offdap11@CLSID = H:\PROGRA~1\FILECO~1\MICROS~1\WEBCOM~1\11\OWC11.DLL
talkto@CLSID = H:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
tv@CLSID = H:\WINDOWS\system32\msvidctl.dll
wia@CLSID = H:\WINDOWS\system32\wiascr.dll
widimg@CLSID = H:\WINDOWS\system32\btxppanel.dll

HKLM\SYSTEM\CurrentControlSet\Services\Tcpip\Parameters\Interfaces\{283D737C-7AA5-44BF-9824-1CD5DE389577} /*LAN WIFI*/ >>>
@IPAddress192.168.0.1 = 192.168.0.1
@NameServer192.168.0.1 = 192.168.0.1
@DefaultGateway =
@Domain =

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\NameSpace_Catalog5\Catalog_Entries\000000000004@LibraryPath = %SystemRoot%\system32\wshbth.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\ >>>
000000000001@PackedCatalogItem = xfire_lsp.dll
000000000002@PackedCatalogItem = xfire_lsp.dll
000000000003@PackedCatalogItem = xfire_lsp.dll
000000000004@PackedCatalogItem = xfire_lsp.dll
000000000005@PackedCatalogItem = xfire_lsp.dll
000000000006@PackedCatalogItem = xfire_lsp.dll
000000000007@PackedCatalogItem = xfire_lsp.dll

HKLM\SYSTEM\CurrentControlSet\Services\WinSock2\Parameters\Protocol_Catalog9\Catalog_Entries\000000000015@PackedCatalogItem = xfire_lsp.dll

---- EOF - GMER 1.0.12 ----
Avatar utente
Gattos
Neo Iscritto
Neo Iscritto
 
Messaggi: 5
Iscritto il: mer feb 14, 2007 7:22 pm


Messaggioda Amantide » mer feb 14, 2007 10:53 pm

Niente da fare, questo è uguale al primo [boh]
Mi sa che fai prima a postarmi i log con l'esito di Avenger, cerca il file avenger.txt in C:\ oppure in C:\Avenger\

Dai un occhiatina a questo articolo, soprattutto all'ultima pagina, troverai delle cose interessanti. [;)]
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Messaggioda Gattos » mer feb 14, 2007 11:09 pm

a lo letto se non lo trovavo grazie a google non sarei qui..su altri forum ecc ho trovato altre soluzioni ecc ma nessuno sapeva veramente il da farsi [^]

comunque questo è il log da quel momento le cose vano molto meglio

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\gfhonlag

*******************

Script file located at: \??\H:\myjkukoc.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at H:\Avenger

*******************

Beginning to process script file:



Could not open file H::\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys for deletion
Deletion of file H::\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys failed!

Could not process line:
H::\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys
Status: 0xc000003a



Could not open file H::\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe for deletion
Deletion of file H::\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe failed!

Could not process line:
H::\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe
Status: 0xc000003a



Could not open file H::\WINDOWS\system32\wintems.exe for deletion
Deletion of file H::\WINDOWS\system32\wintems.exe failed!

Could not process line:
H::\WINDOWS\system32\wintems.exe
Status: 0xc000003a



Could not open file H::\WINDOWS\system32\hldrrr.exe for deletion
Deletion of file H::\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
H::\WINDOWS\system32\hldrrr.exe
Status: 0xc000003a



Could not open folder H::\Documents and Settings\Mirko\Dati applicazioni\hidires for deletion
Deletion of folder H::\Documents and Settings\Mirko\Dati applicazioni\hidires failed!

Could not process line:
H::\Documents and Settings\Mirko\Dati applicazioni\hidires
Status: 0xc000003a



Could not open folder H::\WINDOWS\exefld for deletion
Deletion of folder H::\WINDOWS\exefld failed!

Could not process line:
H::\WINDOWS\exefld
Status: 0xc000003a

Registry key HKLM\SYSTEM\CurrentControlSet\Services\m_hook deleted successfully.
Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK deleted successfully.
Registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hldrrr deleted successfully.

Completed script processing.

*******************

Finished! Terminate.
Avatar utente
Gattos
Neo Iscritto
Neo Iscritto
 
Messaggi: 5
Iscritto il: mer feb 14, 2007 7:22 pm

Messaggioda Amantide » mer feb 14, 2007 11:18 pm

Va meglio, ripeto meglio... non bene... perché con questo script sei riuscito eliminare alcune chiavi di registro, ma... hai commesso un'errore nella compilazione dello script.
Dopo la H doppi punti andavano solo una volta, non due [;)]

Prova con questo:

Files to delete:
H:\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys
H:\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe
H:\WINDOWS\system32\wintems.exe
H:\WINDOWS\system32\hldrrr.exe

folders to delete:
H:\Documents and Settings\Mirko\Dati applicazioni\hidires
H:\WINDOWS\exefld

registry keys to delete:
HKLM\SYSTEM\CurrentControlSet\Services\m_hook
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK

registry values to delete:
HKLM\Software\Microsoft\Windows\CurrentVersion\Run | hldrrr
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Messaggioda Gattos » mer feb 14, 2007 11:39 pm

Logfile of The Avenger version 1, by Swandog46
Running from registry key:
\Registry\Machine\System\CurrentControlSet\Services\eixnyoou

*******************

Script file located at: \??\H:\WINDOWS\system32\ygmflpdi.txt
Script file opened successfully.

Script file read successfully

Backups directory opened successfully at H:\Avenger

*******************

Beginning to process script file:



Could not open file H:\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys for deletion
Deletion of file H:\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys failed!

Could not process line:
H:\Documents and Settings\Mirko\Dati applicazioni\hidires\m_hook.sys
Status: 0xc000003a



Could not open file H:\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe for deletion
Deletion of file H:\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe failed!

Could not process line:
H:\Documents and Settings\Mirko\Dati applicazioni\hidires\hidr.exe
Status: 0xc000003a



File H:\WINDOWS\system32\wintems.exe not found!
Deletion of file H:\WINDOWS\system32\wintems.exe failed!

Could not process line:
H:\WINDOWS\system32\wintems.exe
Status: 0xc0000034



File H:\WINDOWS\system32\hldrrr.exe not found!
Deletion of file H:\WINDOWS\system32\hldrrr.exe failed!

Could not process line:
H:\WINDOWS\system32\hldrrr.exe
Status: 0xc0000034



Folder H:\Documents and Settings\Mirko\Dati applicazioni\hidires not found!
Deletion of folder H:\Documents and Settings\Mirko\Dati applicazioni\hidires failed!

Could not process line:
H:\Documents and Settings\Mirko\Dati applicazioni\hidires
Status: 0xc0000034



Folder H:\WINDOWS\exefld not found!
Deletion of folder H:\WINDOWS\exefld failed!

Could not process line:
H:\WINDOWS\exefld
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Services\m_hook not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Services\m_hook failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Services\m_hook
Status: 0xc0000034



Registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK not found!
Deletion of registry key HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK failed!

Could not process line:
HKLM\SYSTEM\CurrentControlSet\Enum\Root\LEGACY_M_HOOK
Status: 0xc0000034



Could not delete registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hldrrr
Deletion of registry value HKLM\Software\Microsoft\Windows\CurrentVersion\Run|hldrrr failed!
Status: 0xc0000034


Completed script processing.

*******************

Finished! Terminate.


molte cose le ho eliminate manualmente prima vorrei essere solo sicuro [std]
Avatar utente
Gattos
Neo Iscritto
Neo Iscritto
 
Messaggi: 5
Iscritto il: mer feb 14, 2007 7:22 pm

Messaggioda Amantide » gio feb 15, 2007 12:59 pm

Direi che sei riuscito ad eliminare tutto [;)] l'esito di Avenger è negativo.
...per volare alto, bisogna saper cadere...
Avatar utente
Amantide
Membro Ufficiale (Gold)
Membro Ufficiale (Gold)
 
Messaggi: 8126
Iscritto il: lun feb 06, 2006 4:13 pm
Località: Abruzzo

Messaggioda Gattos » gio feb 15, 2007 7:32 pm

io ringrazio tutti [^] [applauso+] senza di voi non sarei mai riuscito nell opera Speriamo di risentirci magari non x un altro rootkit ciao
Avatar utente
Gattos
Neo Iscritto
Neo Iscritto
 
Messaggi: 5
Iscritto il: mer feb 14, 2007 7:22 pm


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 12 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising