Punto informatico Network
Login Esegui login | Non sei registrato? Iscriviti ora (è gratuito!)
Username: Password:
  • Annuncio Pubblicitario

CONESSIONE PREDEFINITA

Un virus si è intromesso nel tuo computer? Vuoi navigare in tutta sicurezza? Sono sicure le transazione online? Come impedire a malintenzionati di intromettersi nel tuo pc? Come proteggere i tuoi dati? Qui trovi le risposte a queste ed altre domande

CONESSIONE PREDEFINITA

Messaggioda SILVELLO10 » lun lug 09, 2007 5:27 pm

Salve! mi sono trovato una CONESSIONE PREDEFINITA IN RISORSE DEL COMPUTER non so cosa sia ,ho provato ad eliminarla da PROPRIETA' DI INTERNET in OPZIONI INTERNET( nel PANNELLO DI CONTROLLO)Ma li' c'e' solo la conessione normale mia altre voci non c'e' ne sono dubito un dialer ,ho provato col tasto detro del mouse e mi esce"OPEN MY MENU' oppure sotto "CREA COLLEGAMENTO" che fare? grazie mille. [uhm]
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

Messaggioda BilloKenobi » lun lug 09, 2007 7:28 pm

è una richiesta anomala, ma oltre al log di hijackthis (mi pare di ricordare che tu l'abbia già usato) vorrei una volta tanto anche uno screenshot del problema [rolleyes]

probabile però che dovremo andare più a fondo [;)]
Begun the Clone War has
Avatar utente
BilloKenobi
Senior Member
Senior Member
 
Messaggi: 453
Iscritto il: gio ago 10, 2006 11:06 am

log

Messaggioda SILVELLO10 » lun lug 09, 2007 8:58 pm

Logfile of HijackThis v1.99.1
Scan saved at 19.59.07, on 09/07/2007
Platform: Windows XP SP2 (WinNT 5.01.2600)
MSIE: Internet Explorer v7.00 (7.00.6000.16473)

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\system32\ZoneLabs\vsmon.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\a-squared Free\a2service.exe
C:\Programmi\AOL\Active Virus Shield\avp.exe
C:\Programmi\ProcessGuard\dcsuserprot.exe
C:\Programmi\SiteAdvisor\6066\SAService.exe
C:\Programmi\Spyware Terminator\sp_rsser.exe
C:\WINDOWS\System32\svchost.exe
C:\Program Files\Libero\Adsl\dslstat.exe
C:\Program Files\Libero\Adsl\dslagent.exe
C:\Programmi\SiteAdvisor\6066\SiteAdv.exe
C:\WINDOWS\SOUNDMAN.EXE
C:\Programmi\File comuni\Real\Update_OB\realsched.exe
C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe
C:\Programmi\ProcessGuard\pgaccount.exe
D:\Programmi\Winamp\winampa.exe
C:\WINDOWS\system32\rundll32.exe
C:\Programmi\AOL\Active Virus Shield\avp.exe
C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe
C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe
C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe
C:\WINDOWS\system32\ctfmon.exe
C:\Programmi\ProcessGuard\procguard.exe
C:\Programmi\MSN Messenger\msnmsgr.exe
C:\Programmi\Spamihilator\spamihilator.exe
C:\Digital Imaging\bin\hpotdd01.exe
C:\Programmi\WinZip\WZQKPICK.EXE
C:\PROGRA~1\INCRED~1\bin\IMApp.exe
C:\Programmi\Mozilla Firefox\firefox.exe
C:\Documents and Settings\jhwh\Desktop\HijackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.libero.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
R3 - URLSearchHook: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
R3 - URLSearchHook: Coolstreaming_Tool-Bar_v1.0 toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCoo0.dll
O2 - BHO: Yahoo! Toolbar Helper - {02478D38-C3F9-4EFB-9B51-7695ECA05670} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Programmi\File comuni\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {089FD14D-132B-48FC-8861-0048AE113215} - C:\Programmi\SiteAdvisor\6066\SiteAdv.dll
O2 - BHO: Canon Easy Web Print Helper - {68F9551E-0411-48E4-9AAF-4BC42A6A46BE} - C:\Programmi\Canon\Easy-WebPrint\EWPBrowseLoader.dll
O2 - BHO: SSVHelper Class - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
O2 - BHO: Windows Live Sign-in Helper - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Coolstreaming_Tool-Bar_v1.0 toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCoo0.dll
O3 - Toolbar: McAfee SiteAdvisor - {0BF43445-2F28-4351-9252-17FE6E806AA0} - C:\Programmi\SiteAdvisor\6066\SiteAdv.dll
O3 - Toolbar: Yahoo! Toolbar con blocco Pop-Up - {EF99BD32-C1FB-11D2-892F-0090271D4F88} - C:\Programmi\Yahoo!\Companion\Installs\cpn\yt.dll
O3 - Toolbar: Coolstreaming_Tool-Bar_v1.0 toolbar - {bd0e4d83-654e-4213-965b-fcbe887061f4} - C:\Programmi\Coolstreaming_Tool-Bar_v1.0\tbCoo0.dll
O3 - Toolbar: Easy-WebPrint - {327C2873-E90D-4c37-AA9D-10AC9BABA46C} - C:\Programmi\Canon\Easy-WebPrint\Toolband.dll
O4 - HKLM\..\Run: [DSLSTATEXE] C:\Program Files\Libero\Adsl\dslstat.exe icon
O4 - HKLM\..\Run: [DSLAGENTEXE] C:\Program Files\Libero\Adsl\dslagent.exe
O4 - HKLM\..\Run: [SiteAdvisor] C:\Programmi\SiteAdvisor\6066\SiteAdv.exe
O4 - HKLM\..\Run: [SoundMan] SOUNDMAN.EXE
O4 - HKLM\..\Run: [TkBellExe] "C:\Programmi\File comuni\Real\Update_OB\realsched.exe" -osboot
O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
O4 - HKLM\..\Run: [SpywareTerminator] "C:\Programmi\Spyware Terminator\SpywareTerminatorShield.exe"
O4 - HKLM\..\Run: [!1_pgaccount] "C:\Programmi\ProcessGuard\pgaccount.exe"
O4 - HKLM\..\Run: [WinampAgent] D:\Programmi\Winamp\winampa.exe
O4 - HKLM\..\Run: [BluetoothAuthenticationAgent] rundll32.exe bthprops.cpl,,BluetoothAuthenticationAgent
O4 - HKLM\..\Run: [aol] "C:\Programmi\AOL\Active Virus Shield\avp.exe"
O4 - HKLM\..\Run: [ZoneAlarm Client] "C:\Programmi\Zone Labs\ZoneAlarm\zlclient.exe"
O4 - HKLM\..\Run: [SSBkgdUpdate] "C:\Programmi\File comuni\Scansoft Shared\SSBkgdUpdate\SSBkgdupdate.exe" -Embedding -boot
O4 - HKLM\..\Run: [OpwareSE4] "C:\Programmi\ScanSoft\OmniPageSE4.0\OpwareSE4.exe"
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Programmi\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\Java\jre1.6.0_01\bin\jusched.exe"
O4 - HKCU\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\ctfmon.exe
O4 - HKCU\..\Run: [!1_ProcessGuard_Startup] "C:\Programmi\ProcessGuard\procguard.exe" -minimize
O4 - HKCU\..\Run: [IncrediMail] C:\PROGRA~1\INCRED~1\bin\IncMail.exe /c
O4 - HKCU\..\Run: [msnmsgr] "C:\Programmi\MSN Messenger\msnmsgr.exe" /background
O4 - HKCU\..\Run: [Spamihilator] "C:\Programmi\Spamihilator\spamihilator.exe"
O4 - Startup: Microsoft Office OneNote 2003 Quick Launch.lnk = D:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: Avvio veloce di Microsoft Office OneNote 2003.lnk = D:\Programmi\Microsoft Office\OFFICE11\ONENOTEM.EXE
O4 - Global Startup: hpoddt01.exe.lnk = ?
O4 - Global Startup: WinZip Quick Pick.lnk = C:\Programmi\WinZip\WZQKPICK.EXE
O8 - Extra context menu item: Aggiungi all'elenco di stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_AddToList.html
O8 - Extra context menu item: Anteprima Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Preview.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://D:\PROGRA~1\MICROS~1\OFFICE11\EXCEL.EXE/3000
O8 - Extra context menu item: E&xport to Microsoft Excel - res://D:\PROGRA~1\MICROS~1\Office10\EXCEL.EXE/3000
O8 - Extra context menu item: Stampa ad alta velocità Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_HSPrint.html
O8 - Extra context menu item: Stampa Easy-WebPrint - res://C:\Programmi\Canon\Easy-WebPrint\Toolband.dll/RC_Print.html
O9 - Extra button: (no name) - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra 'Tools' menuitem: Sun Java Console - {08B0E5C0-4FCB-11CF-AAA5-00401C608501} - C:\Programmi\Java\jre1.6.0_01\bin\ssv.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - D:\PROGRA~1\MICROS~1\OFFICE11\REFIEBAR.DLL
O9 - Extra button: Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O9 - Extra 'Tools' menuitem: Windows Messenger - {FB5F1910-F110-11d2-BB9E-00C04F795683} - C:\Programmi\Messenger\msmsgs.exe
O16 - DPF: {2917297F-F02B-4B9D-81DF-494B6333150B} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b31267.cab
O16 - DPF: {2BC66F54-93A8-11D3-BEB6-00105AA9B6AE} (Symantec AntiVirus scanner) - http://security.symantec.com/sscv6/Shar ... vSniff.cab
O16 - DPF: {5CD4310E-88FB-43C1-BE24-5F3FA9C5C9D1} (KooPlayer Control) - http://www.coolstreaming.us/consolle/we ... Player.ocx
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/IT-IT/a-U ... E_UNO1.cab
O16 - DPF: {6414512B-B978-451D-A0D8-FCFDF33E833C} (WUWebControl Class) - http://update.microsoft.com/windowsupda ... 0496384734
O16 - DPF: {644E432F-49D3-41A1-8DD5-E099162EEEC5} (Symantec RuFSI Utility Class) - http://security.symantec.com/sscv6/Shar ... /cabsa.cab
O16 - DPF: {8E0D4DE5-3180-4024-A327-4DFAD1796A8D} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b31267.cab
O16 - DPF: {9A9307A0-7DA4-4DAF-B042-5009F29E09E1} (ActiveScan Installer Class) - http://acs.pandasoftware.com/activescan ... asinst.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/Me ... b56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/Mi ... b56986.cab
O16 - DPF: {FE0BD779-44EE-4A4B-AA2E-743C63F2E5E6} (IWinAmpActiveX Class) - http://pdl.stream.aol.com/downloads/aol ... _en_dl.cab
O17 - HKLM\System\CCS\Services\Tcpip\..\{510B5161-C208-4627-8DE7-26B5641C3B97}: NameServer = 193.70.152.15 193.70.152.25
O18 - Protocol: livecall - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: msnim - {828030A1-22C1-4009-854F-8E305202313F} - C:\PROGRA~1\MSNMES~1\MSGRAP~1.DLL
O18 - Protocol: siteadvisor - {3A5DC592-7723-4EAA-9EE6-AF4222BCF879} - C:\Programmi\SiteAdvisor\6066\SiteAdv.dll
O20 - Winlogon Notify: klogon - C:\WINDOWS\system32\klogon.dll
O20 - Winlogon Notify: WgaLogon - C:\WINDOWS\SYSTEM32\WgaLogon.dll
O21 - SSODL: WPDShServiceObj - {AAA288BA-9A4C-45B0-95D7-94D524869DB5} - C:\WINDOWS\system32\WPDShServiceObj.dll
O23 - Service: a-squared Free Service (a2free) - Emsi Software GmbH - C:\Programmi\a-squared Free\a2service.exe
O23 - Service: Active Virus Shield (AVP) - Unknown owner - C:\Programmi\AOL\Active Virus Shield\avp.exe" -r (file missing)
O23 - Service: DiamondCS ProcessGuard Service v3.200 (DCSPGSRV) - DiamondCS - C:\Programmi\ProcessGuard\dcsuserprot.exe
O23 - Service: RGMGGXZWRMDV - Sysinternals - www.sysinternals.com - C:\DOCUME~1\jhwh\IMPOST~1\Temp\RGMGGXZWRMDV.exe
O23 - Service: SiteAdvisor Service - McAfee, Inc. - C:\Programmi\SiteAdvisor\6066\SAService.exe
O23 - Service: Spyware Terminator Clam Service (sp_clamsrv) - Crawler.com - C:\Programmi\WinClamAVShield\sp_clamsrv.exe
O23 - Service: Spyware Terminator Realtime Shield Service (sp_rssrv) - Crawler.com - C:\Programmi\Spyware Terminator\sp_rsser.exe
O23 - Service: TrueVector Internet Monitor (vsmon) - Zone Labs, LLC - C:\WINDOWS\system32\ZoneLabs\vsmon.exe

questo e' il mio log
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA


mistero

Messaggioda SILVELLO10 » lun lug 09, 2007 9:18 pm

mistero!!! non si trova in nessuna voce ,ne cartelle ,ne alcunche' da nessuna parte fatto scansione on line antivirus PANDA , SIMANTEC NIENTE!!! HO provato con SPYBOT non rivela NIENTE !!! eppure quella CONNESSIONE PREDEFINITA rimane nelle RISORSE DEL COMPUTER [boh] ORA la cosa diventa seria eppure non c'e' l'ho messa io .
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

CRAZY CAT

Messaggioda SILVELLO10 » lun lug 09, 2007 10:17 pm

CRAZY CAT AIUTAMI !!!!
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

Messaggioda BilloKenobi » mar lug 10, 2007 2:01 am

eh ehi, aspetta... tutto va fatto con la dovuta calma... senza nulla togliere a crazy.cat, mi sento capace e in pieno diritto di provare da solo a risolvere questo problema [bleh]

comunque, dato che con hijackthis non traspare nulla, scarica systemscan, estrailo, avvialo, metti la spunta a tutte le voci e premi "Scan". poi vai su www.easy-share.com e metti lì il suo log (che trovi in C:\suspectfile\report.txt). poi dacci il link per scaricarlo (solo quello per scaricarlo, non quello per eliminarlo dal sito di hosting)

Oppure puoi direttamente metterlo qui sul forum, ma come allegato!!!
Begun the Clone War has
Avatar utente
BilloKenobi
Senior Member
Senior Member
 
Messaggi: 453
Iscritto il: gio ago 10, 2006 11:06 am

Messaggioda crazy.cat » mar lug 10, 2007 9:22 am

Che è sta roba??????
O23 - Service: RGMGGXZWRMDV - Sysinternals - www.sysinternals.com - C:\DOCUME~1\jhwh\IMPOST~1\Temp\RGMGGXZWRMDV.exe

Carica il file RGMGGXZWRMDV.exe sul sito www.virustotal.com e vediamo di cosa si tratta.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda BilloKenobi » mar lug 10, 2007 12:55 pm

non dovrebbe essere relativo a qualche tool della sysinternals.com? non è la prima volta che lo vedo... magari l'ho sottovalutato [uhm]
Begun the Clone War has
Avatar utente
BilloKenobi
Senior Member
Senior Member
 
Messaggi: 453
Iscritto il: gio ago 10, 2006 11:06 am

Messaggioda crazy.cat » mar lug 10, 2007 1:07 pm

BilloKenobi ha scritto:non dovrebbe essere relativo a qualche tool della sysinternals.com? non è la prima volta che lo vedo... magari l'ho sottovalutato [uhm]

Con un nome del genere e nella cartella temp??
Tutto può essere, virustotal e togliamo il dubbio.
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

Messaggioda BilloKenobi » mar lug 10, 2007 1:28 pm

crazy.cat ha scritto:Con un nome del genere e nella cartella temp??


mi pareva di ricordare che fosse simile nello "stile", ossia in Temp e con nome random. comunque sia, hai ragione, meglio vedere con virustotal (sempre se il file esiste ancora) [:)]
Begun the Clone War has
Avatar utente
BilloKenobi
Senior Member
Senior Member
 
Messaggi: 453
Iscritto il: gio ago 10, 2006 11:06 am

rootkit

Messaggioda SILVELLO10 » mar lug 10, 2007 3:10 pm

sorpresa! dopo vari tentativi andati a vuoto l'icona della connessione predefinita su risorse di RISORSE DEL COMPUTER non c'e' piu' pero' l'antivirus mi segnala un "ROOTKIT WIN 32 AGENT.GO " per cui AVS NON LO ELIMINA cosa fare? [uhm]
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

tipo

Messaggioda SILVELLO10 » mar lug 10, 2007 3:21 pm

ecco il rootkit :WIN 32 AGENT.GO-- FILE C:\WINDOWS\SYSTEM32\DRIVERS\MCHINJDRV.SYS HO provato ad analizzare sul disco C .windows -system32 drivers ma......il resto non ho trovato "mchinjdrv.sys questa voce niente.
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

Messaggioda SILVELLO10 » mar lug 10, 2007 5:19 pm

GMER 1.0.13.12551 - http://www.gmer.net
Rootkit scan 2007-07-10 16:18:00
Windows 5.1.2600 Service Pack 2


---- System - GMER 1.0.13 ----

SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwClose
SSDT \SystemRoot\System32\vsdatant.sys ZwConnectPort
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateFile
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateKey
SSDT \SystemRoot\System32\vsdatant.sys ZwCreatePort
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcess
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateProcessEx
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwCreateSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwCreateSymbolicLinkObject
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwCreateThread
SSDT \SystemRoot\System32\vsdatant.sys ZwCreateWaitablePort
SSDT \SystemRoot\System32\vsdatant.sys ZwDeleteFile
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteKey
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwDeleteValueKey
SSDT \SystemRoot\System32\vsdatant.sys ZwDuplicateObject
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwEnumerateValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwFlushKey
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwFsControlFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwInitializeRegistry
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwLoadDriver
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwLoadKey2
SSDT \SystemRoot\System32\vsdatant.sys ZwMapViewOfSection
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwNotifyChangeKey
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwOpenFile
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwOpenKey
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenProcess
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwOpenSection
SSDT \SystemRoot\System32\vsdatant.sys ZwOpenThread
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwProtectVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryMultipleValueKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQuerySystemInformation
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwQueryValueKey
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwReadVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwReplaceKey
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwRequestWaitReplyPort
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwRestoreKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwResumeThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSaveKey
SSDT \SystemRoot\System32\vsdatant.sys ZwSecureConnectPort
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwSetContextThread
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationFile
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationKey
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetInformationProcess
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwSetSecurityObject
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwSetSystemInformation
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwSetValueKey
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwSuspendProcess
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwSuspendThread
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwTerminateProcess
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwTerminateThread
SSDT \SystemRoot\System32\vsdatant.sys ZwUnloadDriver
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys ZwUnloadKey
SSDT \??\C:\WINDOWS\system32\drivers\sp_rsdrv2.sys ZwWriteFile
SSDT \??\C:\WINDOWS\system32\drivers\procguard.sys ZwWriteVirtualMemory
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[284]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[285]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[286]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[287]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[288]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[289]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[290]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[291]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[292]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[293]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[294]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[295]
SSDT \??\C:\WINDOWS\system32\drivers\klif.sys SSDT[296]

INT 0x20 srescan.sys F838EA00

Code \??\C:\WINDOWS\system32\drivers\klif.sys FsRtlCheckLockForReadAccess
Code \??\C:\WINDOWS\system32\drivers\klif.sys IoIsOperationSynchronous

---- Kernel code sections - GMER 1.0.13 ----

.text ntoskrnl.exe!KiDispatchInterrupt + 100 804DC962 7 Bytes JMP F60C7D70 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntoskrnl.exe!IoIsOperationSynchronous 804EAF7E 5 Bytes JMP F60C5000 \??\C:\WINDOWS\system32\drivers\klif.sys
.text ntoskrnl.exe!FsRtlCheckLockForReadAccess 804F3BF9 5 Bytes JMP F60C4B70 \??\C:\WINDOWS\system32\drivers\klif.sys
? srescan.sys Impossibile trovare il file specificato.
? C:\WINDOWS\system32\drivers\procguard.sys Accesso negato.

---- User code sections - GMER 1.0.13 ----

.text C:\WINDOWS\system32\ZoneLabs\vsmon.exe[1028] ntdll.dll!KiFastSystemCall + 2 7C91EB8D 2 Bytes [ CD, 20 ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ntdll.dll!NtSetValueKey 7C91E7BC 3 Bytes [ FF, 25, 1E ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ntdll.dll!NtSetValueKey + 4 7C91E7C0 2 Bytes [ 20, 5F ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ntdll.dll!NtWriteFile 7C91E9F3 3 Bytes [ FF, 25, 1E ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ntdll.dll!NtWriteFile + 4 7C91E9F7 2 Bytes [ 1D, 5F ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] kernel32.dll!LoadLibraryExW 7C801AF1 6 Bytes JMP 5F040F5A
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] kernel32.dll!WriteProcessMemory 7C80220F 6 Bytes JMP 5F0D0F5A
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] kernel32.dll!OpenProcess 7C8309E1 6 Bytes JMP 5F100F5A
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ADVAPI32.dll!CreateServiceA 77FA7071 6 Bytes JMP 5F130F5A
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ADVAPI32.dll!CreateServiceW 77FA7209 3 Bytes [ FF, 25, 1E ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] ADVAPI32.dll!CreateServiceW + 4 77FA720D 2 Bytes [ 17, 5F ]
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] WS2_32.dll!connect 71A3406A 6 Bytes JMP 5F070F5A
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] WS2_32.dll!listen 71A388D3 6 Bytes JMP 5F0A0F5A
.text C:\Programmi\SiteAdvisor\6066\SiteAdv.exe[2328] SHELL32.dll!Shell_NotifyIconW 7CA31B6A 6 Bytes JMP 5F190F5A
.text C:\Programmi\MSN Messenger\msnmsgr.exe[2644] kernel32.dll!SetUnhandledExceptionFilter 7C84467D 5 Bytes JMP 004DE392 C:\Programmi\MSN Messenger\msnmsgr.exe
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!DialogBoxParamW 7E3A555F 5 Bytes JMP 435FF2A1 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!DialogBoxIndirectParamW 7E3B2032 5 Bytes JMP 43790277 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!MessageBoxIndirectA 7E3BA04A 5 Bytes JMP 437901F8 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!DialogBoxParamA 7E3BB10C 5 Bytes JMP 4379023C C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!MessageBoxExW 7E3D05D8 5 Bytes JMP 43790184 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!MessageBoxExA 7E3D05FC 5 Bytes JMP 437901BE C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!DialogBoxIndirectParamA 7E3D6B50 5 Bytes JMP 437902B2 C:\WINDOWS\system32\IEFRAME.dll
.text C:\Programmi\Internet Explorer\IEXPLORE.EXE[3996] USER32.dll!MessageBoxIndirectW 7E3E62AB 5 Bytes JMP 4362164E C:\WINDOWS\system32\IEFRAME.dll

---- Kernel IAT/EAT - GMER 1.0.13 ----

IAT \SystemRoot\System32\DRIVERS\intelppm.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\VIDEOPRT.SYS[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\USBPORT.SYS[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\ks.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\Drivers\Modem.SYS[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\system32\drivers\STREAM.SYS[NTOSKRNL.EXE!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\fdc.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\serial.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\serenum.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\parport.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\imapi.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\redbook.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\system32\drivers\portcls.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\audstub.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\ndistapi.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisCloseAdapter] 821E4710
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisOpenAdapter] 821E4660
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisDeregisterProtocol] 821E4722
IAT \SystemRoot\System32\DRIVERS\ndiswan.sys[NDIS.SYS!NdisRegisterProtocol] 821E4646
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisRegisterProtocol] [F6297950] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisOpenAdapter] [F6297E70] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisCloseAdapter] [F6297FD0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\raspppoe.sys[NDIS.SYS!NdisDeregisterProtocol] [F6297AC0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisDeregisterProtocol] [F6297AC0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisRegisterProtocol] [F6297950] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisOpenAdapter] [F6297E70] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\psched.sys[NDIS.SYS!NdisCloseAdapter] [F6297FD0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\msgpc.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\termdd.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\kbdclass.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\mouclass.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\swenum.sys[NTOSKRNL.EXE!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\mssmbios.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisRegisterProtocol] [F6297950] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisCloseAdapter] [F6297FD0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisOpenAdapter] [F6297E70] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\Drivers\NDProxy.SYS[NDIS.SYS!NdisDeregisterProtocol] [F6297AC0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\usbhub.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\flpydisk.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\Drivers\Beep.SYS[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\Drivers\Npfs.SYS[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\rasacd.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\ipsec.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisCloseAdapter] [F6297FD0] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisOpenAdapter] [F6297E70] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[NDIS.SYS!NdisRegisterProtocol] [F6297950] \SystemRoot\System32\vsdatant.sys
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\tcpip.sys[TDI.SYS!TdiRegisterDeviceObject] 82201AB2
IAT \SystemRoot\System32\DRIVERS\netbt.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\netbt.sys[TDI.SYS!TdiRegisterDeviceObject] 82201AB2
IAT \SystemRoot\System32\DRIVERS\ipnat.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisDeregisterProtocol] 821E4722
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisRegisterProtocol] 821E4646
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisOpenAdapter] 821E4660
IAT \SystemRoot\System32\DRIVERS\wanarp.sys[NDIS.SYS!NdisCloseAdapter] 821E4710
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[ntoskrnl.exe!IoCreateDevice] 82201A02
IAT \SystemRoot\System32\DRIVERS\arp1394.sys[NDIS.SYS!NdisCloseAda
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

Messaggioda crazy.cat » mar lug 10, 2007 7:00 pm

Usa uno dei programmi antirootkit, panda o il mcafee
http://www.MegaLab.it/2714/2

Fai analizzare quel file che ti ho detto.....
Quando i molti governano, pensano solo a contentar sé stessi, si ha allora la tirannia più balorda e più odiosa: la tirannia mascherata da libertà.
Avatar utente
crazy.cat
MLI Hero
MLI Hero
 
Messaggi: 30959
Iscritto il: lun gen 12, 2004 1:38 pm
Località: Mestre

ANALISI VIRUSTOTAL

Messaggioda SILVELLO10 » mar lug 10, 2007 7:13 pm

MI E' pervenuto questo da virustotal:Complete scanning result of "4.jpg", processed in VirusTotal at 07/10/2007 14:01:38 (CET).

[ file data ]
* name: 4.jpg
* size: 15451
* md5.: 730a9c53a53993dee1e9e406be2a22aa
* sha1: 40b7477adb5ecee48342e1d3f385f6d4c68fe1de

[ scan result ]
AhnLab-V3 2007.7.7.0/20070710 found nothing
AntiVir 7.4.0.39/20070710 found nothing
Authentium 4.93.8/20070709 found nothing
Avast 4.7.997.0/20070709 found nothing
AVG 7.5.0.476/20070709 found nothing
BitDefender 7.2/20070710 found nothing
CAT-QuickHeal 9.00/20070709 found nothing
ClamAV devel-20070416/20070710 found nothing
DrWeb 4.33/20070710 found nothing
eSafe 7.0.15.0/20070708 found nothing
eTrust-Vet 30.8.3777/20070710 found nothing
Ewido 4.0/20070710 found nothing
F-Prot 4.3.2.48/20070709 found nothing
FileAdvisor 1/20070710 found nothing
Fortinet 2.91.0.0/20070710 found nothing
Ikarus T3.1.1.8/20070710 found nothing
Kaspersky 4.0.2.24/20070710 found nothing
McAfee 5070/20070709 found nothing
Microsoft 1.2704/20070710 found nothing
NOD32v2 2389/20070710 found nothing
Norman 5.80.02/20070710 found nothing
Panda 9.0.0.4/20070710 found nothing
Sophos 4.19.0/20070706 found nothing
Sunbelt 2.2.907.0/20070707 found nothing
Symantec 10/20070710 found nothing
TheHacker 6.1.6.144/20070709 found nothing
VBA32 3.12.0.2/20070709 found nothing
VirusBuster 4.3.23:9/20070709 found nothing
Webwasher-Gateway 6.0.1/20070710 found nothing

__________________________________________________
VirusTotal is a free service offered by Hispasec Sistemas. There are no guarantees about the availability and continuity of this service. Do not reply to this message. It has been generated by an automatic address that will not handle any reply. Although the detection rate afforded by the use of multiple antivirus engines is far superior to that offered by just one product, these results DO NOT guarantee the harmlessness of a file. Currently, there is not any solution that offers a 100% effectiveness rate for detecting viruses and malware.
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

scomparso

Messaggioda SILVELLO10 » mar lug 10, 2007 8:00 pm

non c'e' piu' questa voce.C:\DOCUME~1\jhwh\IMPOST~1\Temp\RGMGGXZWRMDV.exe
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

SENZA RISPOSTE

Messaggioda SILVELLO10 » gio lug 12, 2007 1:28 pm

senza risposte me la sono cavata lo stesso !!!! saluti. [grazie]
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA

Messaggioda GIANLUCA.GIUSTO » dom lug 15, 2007 2:17 pm

IO ho il tuo stesso problema. Ti sto rincorrendo su tutti i forum, mi dici come hai fatto a cancellare quell' icona? CHI puo' aiutarmi?
Avatar utente
GIANLUCA.GIUSTO
Neo Iscritto
Neo Iscritto
 
Messaggi: 19
Iscritto il: dom lug 15, 2007 11:12 am

gmer

Messaggioda SILVELLO10 » lun lug 23, 2007 8:22 pm

con gmer e poi riavvii.
Avatar utente
SILVELLO10
Senior Member
Senior Member
 
Messaggi: 452
Iscritto il: mer lug 13, 2005 12:05 am
Località: CITTADELLA


Torna a Sicurezza

Chi c’è in linea

Visitano il forum: Nessuno e 15 ospiti

Powered by phpBB © 2002, 2005, 2007, 2008 phpBB Group
Traduzione Italiana phpBB.it

megalab.it: testata telematica quotidiana registrata al Tribunale di Cosenza n. 22/09 del 13.08.2009, editore Master New Media S.r.l.; © Copyright 2008 Master New Media S.r.l. a socio unico - P.I. 02947530784. GRUPPO EDIZIONI MASTER Spa Tutti i diritti sono riservati. Per la pubblicità: Master Advertising