Condividi:        

Trojan individuato ma con problemi di rimozione.

Come rimuovere virus e spyware? Le carte di credito sono davvero sicure in rete? È possibile navigare anonimi? Con quali programmi tutelare la propria privacy? Come proteggere i file importanti? Se volete una risposta a queste e altre domande questo è il luogo giusto!

Moderatori: m.paolo, kadosh, Luke57

Trojan individuato ma con problemi di rimozione.

Postdi eddiguff » 17/08/13 11:04

Buongiorno. L'antivirus VIPRE ha individuato nel mio pc questa infezione:
Nome: Trojan.Boot.Sinowal.Gen / Categoria: Rootkit / Percorso: PhysicalDrive0
Mi dice però che non riesce a rimuoverlo.
Ho quindi fatto una scansione con KASPERSKY TDSSKiller che ha rilevato lo stesso problema. Scelgo quindi
l'opzione "cure" e a quel punto mi dice:
"Can't cure MBR. Write standard boot code? If you have installed custom bootloader (eg Acronis, Grub, Lilo),
you will need to reinstall them after the treatment."
Devo scegliere YER or NO.
Che faccio? Sapete aiutarmi? Grazie.
eddiguff
Utente Junior
 
Post: 11
Iscritto il: 15/11/10 22:17

Sponsor
 

Re: Trojan individuato ma con problemi di rimozione.

Postdi quizface » 17/08/13 12:16

Fai un check del MBR con MBRCheck 1.2.3 se e' infetto ovviamente dovrai dire si a KASPERSKY TDSSKiller
oppure segui questo video
http://www.youtube.com/watch?v=7c9djogpad0
Se non siete sicuri di quello che scrivete, non scrivete niente, nessuno vi obbliga ed eviterete di confondere chi gia' e' confuso. Ciao..ciao
Avatar utente
quizface
Utente Senior
 
Post: 15071
Iscritto il: 03/10/04 00:36

Re: Trojan individuato ma con problemi di rimozione.

Postdi eddiguff » 17/08/13 13:59

Ecco il risultato del check. Vedete qualcosa che non va? E se dico YES a KASPERSKY TDSSKiller, non è che poi
mi trovo ad avere problemi con l'avvio del pc?


MBRCheck, version 1.2.3
(c) 2010, AD

Command-line:
Windows Version: Windows XP Home Edition
Windows Information: Service Pack 3 (build 2600)
Logical Drives Mask: 0x0000001d

Kernel Drivers (total 116):
0x804D7000 \WINDOWS\system32\ntkrnlpa.exe
0x806D2000 \WINDOWS\system32\hal.dll
0xF7987000 \WINDOWS\system32\KDCOM.DLL
0xF7897000 \WINDOWS\system32\BOOTVID.dll
0xF7358000 ACPI.sys
0xF7989000 \WINDOWS\system32\DRIVERS\WMILIB.SYS
0xF7347000 pci.sys
0xF7487000 isapnp.sys
0xF7A4F000 pciide.sys
0xF7707000 \WINDOWS\system32\DRIVERS\PCIIDEX.SYS
0xF7497000 MountMgr.sys
0xF7328000 ftdisk.sys
0xF770F000 PartMgr.sys
0xF74A7000 VolSnap.sys
0xF7310000 atapi.sys
0xF72F6000 nvata.sys
0xF74B7000 disk.sys
0xF74C7000 \WINDOWS\system32\DRIVERS\CLASSPNP.SYS
0xF72D6000 fltmgr.sys
0xF72C4000 sr.sys
0xF74D7000 PxHelp20.sys
0xF72AD000 KSecDD.sys
0xF7220000 Ntfs.sys
0xF71F3000 NDIS.sys
0xF71D9000 Mup.sys
0xF7627000 \SystemRoot\system32\DRIVERS\AmdK8.sys
0xF7887000 \SystemRoot\system32\DRIVERS\fdc.sys
0xF681E000 \SystemRoot\system32\DRIVERS\parport.sys
0xF7953000 \SystemRoot\system32\DRIVERS\gameenum.sys
0xF7637000 \SystemRoot\system32\DRIVERS\i8042prt.sys
0xF788F000 \SystemRoot\system32\DRIVERS\kbdclass.sys
0xF771F000 \SystemRoot\system32\DRIVERS\mouclass.sys
0xF680D000 \SystemRoot\system32\DRIVERS\serial.sys
0xF7957000 \SystemRoot\system32\DRIVERS\serenum.sys
0xF7727000 \SystemRoot\system32\DRIVERS\usbohci.sys
0xF67E9000 \SystemRoot\system32\DRIVERS\USBPORT.SYS
0xF772F000 \SystemRoot\system32\DRIVERS\usbehci.sys
0xF67C1000 \SystemRoot\system32\DRIVERS\HDAudBus.sys
0xF7657000 \SystemRoot\system32\DRIVERS\nvnetbus.sys
0xF66A5000 \SystemRoot\system32\DRIVERS\NVNRM.SYS
0xF68C2000 \SystemRoot\system32\DRIVERS\imapi.sys
0xF68B2000 \SystemRoot\system32\DRIVERS\cdrom.sys
0xF68A2000 \SystemRoot\system32\DRIVERS\redbook.sys
0xF6682000 \SystemRoot\system32\DRIVERS\ks.sys
0xF5A31000 \SystemRoot\system32\DRIVERS\nv4_mini.sys
0xF5A1D000 \SystemRoot\system32\DRIVERS\VIDEOPRT.SYS
0xF7A63000 \SystemRoot\system32\DRIVERS\audstub.sys
0xF6872000 \SystemRoot\system32\DRIVERS\rasl2tp.sys
0xF7963000 \SystemRoot\system32\DRIVERS\ndistapi.sys
0xF5A06000 \SystemRoot\system32\DRIVERS\ndiswan.sys
0xF6862000 \SystemRoot\system32\DRIVERS\raspppoe.sys
0xF6852000 \SystemRoot\system32\DRIVERS\raspptp.sys
0xF7737000 \SystemRoot\system32\DRIVERS\TDI.SYS
0xF59F5000 \SystemRoot\system32\DRIVERS\psched.sys
0xF6842000 \SystemRoot\system32\DRIVERS\msgpc.sys
0xF773F000 \SystemRoot\system32\DRIVERS\ptilink.sys
0xF7747000 \SystemRoot\system32\DRIVERS\raspti.sys
0xF6832000 \SystemRoot\system32\DRIVERS\termdd.sys
0xF59DF000 \SystemRoot\system32\DRIVERS\SBFWIM.sys
0xF79B9000 \SystemRoot\system32\DRIVERS\swenum.sys
0xF5981000 \SystemRoot\system32\DRIVERS\update.sys
0xF796B000 \SystemRoot\system32\DRIVERS\mssmbios.sys
0xF7667000 \SystemRoot\System32\Drivers\NDProxy.SYS
0xF7677000 \SystemRoot\system32\DRIVERS\usbhub.sys
0xF79C1000 \SystemRoot\system32\DRIVERS\USBD.SYS
0xF7687000 \SystemRoot\system32\DRIVERS\NVENETFD.sys
0xF290F000 \SystemRoot\system32\drivers\RtkHDAud.sys
0xF28EB000 \SystemRoot\system32\drivers\portcls.sys
0xF76A7000 \SystemRoot\system32\drivers\drmk.sys
0xF775F000 \SystemRoot\system32\DRIVERS\flpydisk.sys
0xF79C5000 \SystemRoot\System32\Drivers\Fs_Rec.SYS
0xF7A7F000 \SystemRoot\System32\Drivers\Null.SYS
0xF79C7000 \SystemRoot\System32\Drivers\Beep.SYS
0xF2883000 \??\C:\WINDOWS\system32\drivers\SBREdrv.sys
0xF776F000 \SystemRoot\System32\drivers\vga.sys
0xF79C9000 \SystemRoot\System32\Drivers\mnmdd.SYS
0xF79CB000 \SystemRoot\System32\DRIVERS\RDPCDD.sys
0xF7777000 \SystemRoot\System32\Drivers\Msfs.SYS
0xF777F000 \SystemRoot\System32\Drivers\Npfs.SYS
0xF7947000 \SystemRoot\system32\DRIVERS\rasacd.sys
0xF2850000 \SystemRoot\system32\DRIVERS\ipsec.sys
0xF27F7000 \SystemRoot\system32\DRIVERS\tcpip.sys
0xF27A6000 \SystemRoot\system32\drivers\SbFw.sys
0xF2772000 \SystemRoot\system32\drivers\sbtis.sys
0xF274A000 \SystemRoot\system32\DRIVERS\netbt.sys
0xF2728000 \SystemRoot\System32\drivers\afd.sys
0xF76C7000 \SystemRoot\system32\DRIVERS\netbios.sys
0xF794F000 \SystemRoot\system32\drivers\sbaphd.sys
0xF26FD000 \SystemRoot\system32\DRIVERS\rdbss.sys
0xF268D000 \SystemRoot\system32\DRIVERS\mrxsmb.sys
0xF76E7000 \SystemRoot\System32\Drivers\Fips.SYS
0xF2667000 \SystemRoot\system32\DRIVERS\ipnat.sys
0xF76F7000 \SystemRoot\system32\DRIVERS\wanarp.sys
0xF7547000 \SystemRoot\System32\Drivers\Cdfs.SYS
0xF2625000 \SystemRoot\System32\Drivers\dump_nvata.sys
0xF79E7000 \SystemRoot\System32\Drivers\dump_WMILIB.SYS
0xBF800000 \SystemRoot\System32\win32k.sys
0xF28BF000 \SystemRoot\System32\drivers\Dxapi.sys
0xF778F000 \SystemRoot\System32\watchdog.sys
0xBD000000 \SystemRoot\System32\drivers\dxg.sys
0xF7A6C000 \SystemRoot\System32\drivers\dxgthk.sys
0xBD012000 \SystemRoot\System32\nv4_disp.dll
0xBD45C000 \SystemRoot\System32\ATMFD.DLL
0xB7E94000 \SystemRoot\system32\drivers\sbapifs.sys
0xB7EC2000 \SystemRoot\system32\DRIVERS\ndisuio.sys
0xB7C27000 \SystemRoot\system32\drivers\wdmaud.sys
0xB7D9C000 \SystemRoot\system32\drivers\sysaudio.sys
0xB7902000 \SystemRoot\system32\DRIVERS\mrxdav.sys
0xF7995000 \SystemRoot\System32\Drivers\ParVdm.SYS
0xF7997000 \SystemRoot\System32\Drivers\StarOpen.SYS
0xF76D7000 \SystemRoot\System32\Drivers\DgiVecp.sys
0xB7792000 \SystemRoot\system32\DRIVERS\srv.sys
0xB7319000 \SystemRoot\System32\Drivers\HTTP.sys
0xB7109000 \SystemRoot\System32\Drivers\Fastfat.SYS
0xB703E000 \SystemRoot\system32\drivers\kmixer.sys
0x7C910000 \WINDOWS\system32\ntdll.dll

Processes (total 31):
0 System Idle Process
4 System
900 C:\WINDOWS\system32\smss.exe
948 csrss.exe
972 C:\WINDOWS\system32\winlogon.exe
1028 C:\WINDOWS\system32\services.exe
1040 C:\WINDOWS\system32\lsass.exe
1196 C:\WINDOWS\system32\svchost.exe
1260 svchost.exe
1468 C:\WINDOWS\system32\svchost.exe
1536 svchost.exe
1612 svchost.exe
1960 C:\WINDOWS\explorer.exe
2020 C:\WINDOWS\system32\spoolsv.exe
360 C:\Programmi\GFI Software\VIPRE\SBAMTray.exe
400 D:\Programmi\itunes\iTunesHelper.exe
412 C:\Programmi\File comuni\Java\Java Update\jusched.exe
452 C:\Programmi\OpenOffice.org 3\program\soffice.exe
480 C:\Programmi\OpenOffice.org 3\program\soffice.bin
736 svchost.exe
768 C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
804 C:\Programmi\Java\jre7\bin\jqs.exe
868 C:\Programmi\GFI Software\VIPRE\SBAMSvc.exe
1900 C:\Programmi\GFI Software\VIPRE\SBPIMSvc.exe
1928 C:\WINDOWS\system32\svchost.exe
2160 C:\Programmi\iPod\bin\iPodService.exe
2604 C:\WINDOWS\system32\wbem\wmiapsrv.exe
2736 alg.exe
328 C:\WINDOWS\system32\wuauclt.exe
464 C:\Programmi\Opera\opera.exe
4076 C:\Documents and Settings\eXPerience\Desktop\MBRCheck.exe

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000039`38a06c00 (NTFS)

PhysicalDrive0 Model Number: ST500DM002-1BD142, Rev: KC45

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0
eddiguff
Utente Junior
 
Post: 11
Iscritto il: 15/11/10 22:17

Re: Trojan individuato ma con problemi di rimozione.

Postdi quizface » 17/08/13 14:31

Ma hai avuto il risultato verde?

Immagine
Se non siete sicuri di quello che scrivete, non scrivete niente, nessuno vi obbliga ed eviterete di confondere chi gia' e' confuso. Ciao..ciao
Avatar utente
quizface
Utente Senior
 
Post: 15071
Iscritto il: 03/10/04 00:36

Re: Trojan individuato ma con problemi di rimozione.

Postdi eddiguff » 17/08/13 15:55

Nessun risultato verde. Il check si blocca subito a questo punto:

\\.\C: --> \\.\PhysicalDrive0 at offset 0x00000000`00007e00 (NTFS)
\\.\D: --> \\.\PhysicalDrive0 at offset 0x00000039`38a06c00 (NTFS)

PhysicalDrive0 Model Number: ST500DM002-1BD142, Rev: KC45

Size Device Name MBR Status
--------------------------------------------
465 GB \\.\PhysicalDrive0

e non va più avanti, creando il log che ho sopra postato.
Durante il check si blocca addirittura il pc e devo riavviare.
Intanto posto il log di HijackThis... se può servire...
Grazie comunque a quizface.

Logfile of Trend Micro HijackThis v2.0.4
Scan saved at 15.08.47, on 17/08/2013
Platform: Windows XP SP3 (WinNT 5.01.2600)
MSIE: Internet Explorer v6.00 SP3 (6.00.2900.5512)
Boot mode: Normal

Running processes:
C:\WINDOWS\System32\smss.exe
C:\WINDOWS\system32\winlogon.exe
C:\WINDOWS\system32\services.exe
C:\WINDOWS\system32\lsass.exe
C:\WINDOWS\system32\svchost.exe
C:\WINDOWS\System32\svchost.exe
C:\WINDOWS\Explorer.EXE
C:\WINDOWS\system32\spoolsv.exe
C:\Programmi\GFI Software\VIPRE\SBAMTray.exe
D:\Programmi\itunes\iTunesHelper.exe
C:\Programmi\File comuni\Java\Java Update\jusched.exe
C:\Programmi\OpenOffice.org 3\program\soffice.exe
C:\Programmi\OpenOffice.org 3\program\soffice.bin
C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
C:\Programmi\Java\jre7\bin\jqs.exe
C:\Programmi\GFI Software\VIPRE\SBAMSvc.exe
C:\Programmi\GFI Software\VIPRE\SBPIMSvc.exe
C:\WINDOWS\system32\svchost.exe
C:\Programmi\iPod\bin\iPodService.exe
C:\WINDOWS\system32\wbem\wmiapsrv.exe
C:\WINDOWS\system32\wuauclt.exe
C:\Programmi\Opera\opera.exe
C:\Programmi\hijackthis\HiJackThis.exe

R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.iol.it/
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://go.microsoft.com/fwlink/?LinkId=69157
R1 - HKCU\Software\Microsoft\Windows\CurrentVersion\Internet Settings,ProxyOverride = local;*.local
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Collegamenti
O2 - BHO: Skype add-on (mastermind) - {22BF413B-C6D2-4d91-82A9-A0F997BA588C} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O2 - BHO: RealPlayer Download and Record Plugin for Internet Explorer - {3049C3E9-B461-4BC5-8870-4C09146192CA} - C:\Documents and Settings\All Users\Dati applicazioni\Real\RealPlayer\BrowserRecordPlugin\IE\rpbrowserrecordplugin.dll
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Programmi\Java\jre7\bin\ssv.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Programmi\File comuni\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: Vuze Remote - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programmi\Vuze_Remote\prxtbVuz0.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Programmi\Java\jre7\bin\jp2ssv.dll
O3 - Toolbar: Vuze Remote Toolbar - {ba14329e-9550-4989-b3f2-9732e92d17cc} - C:\Programmi\Vuze_Remote\prxtbVuz0.dll
O3 - Toolbar: (no name) - {10EDB994-47F8-43F7-AE96-F2EA63E9F90F} - (no file)
O4 - HKLM\..\Run: [SBAMTray] "C:\Programmi\GFI Software\VIPRE\SBAMTray.exe"
O4 - HKLM\..\Run: [Adobe ARM] "C:\Programmi\File comuni\Adobe\ARM\1.0\AdobeARM.exe"
O4 - HKLM\..\Run: [APSDaemon] "C:\Programmi\File comuni\Apple\Apple Application Support\APSDaemon.exe"
O4 - HKLM\..\Run: [iTunesHelper] "D:\Programmi\itunes\iTunesHelper.exe"
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Programmi\File comuni\Java\Java Update\jusched.exe"
O4 - HKUS\S-1-5-19\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [CTFMON.EXE] C:\WINDOWS\system32\CTFMON.EXE (User 'Default user')
O4 - Startup: OpenOffice.org 3.4.1.lnk = C:\Programmi\OpenOffice.org 3\program\quickstart.exe
O8 - Extra context menu item: Add to Google Photos Screensa&ver - res://C:\WINDOWS\system32\GPhotos.scr/200
O9 - Extra button: (no name) - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra 'Tools' menuitem: Skype add-on for Internet Explorer - {5067A26B-1337-4436-8AFE-EE169C2DA79F} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Skype - {77BF5300-1474-4EC7-9980-D32B190E9B07} - C:\Programmi\Skype\Toolbars\Internet Explorer\SkypeIEPlugin.dll
O9 - Extra button: Ricerche - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
O9 - Extra button: (no name) - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O9 - Extra 'Tools' menuitem: @xpsp3res.dll,-20001 - {e2e2dd38-d088-4134-82b7-f2ba38496583} - C:\WINDOWS\Network Diagnostic\xpnetdiag.exe
O16 - DPF: {3EA4FA88-E0BE-419A-A732-9B79B87A6ED0} (CTVUAxCtrl Object) - http://dl.tvunetworks.com/TVUAx.cab
O18 - Protocol: skype4com - {FFC8B962-9B40-4DFF-9458-1830C7DD7F5D} - C:\PROGRA~1\FILECO~1\Skype\SKYPE4~1.DLL
O20 - AppInit_DLLs: C:\Documents and Settings\All Users\Application Data\1191\mscc.dll
O21 - SSODL: WindowsCopy - {312BED3C-A901-4203-B4F2-ADCB957D1887} - (no file)
O22 - SharedTaskScheduler: Precaricatore Browseui - {438755C2-A8BA-11D1-B96B-00A0C90312E1} - C:\WINDOWS\system32\browseui.dll
O22 - SharedTaskScheduler: Daemon di cache delle categorie di componenti - {8C7461EF-2B13-11d2-BE35-3078302C2030} - C:\WINDOWS\system32\browseui.dll
O23 - Service: Apple Mobile Device - Apple Inc. - C:\Programmi\File comuni\Apple\Mobile Device Support\AppleMobileDeviceService.exe
O23 - Service: Google Updater Service (gusvc) - Google - C:\Programmi\Google\Common\Google Updater\GoogleUpdaterService.exe
O23 - Service: Servizio iPod (iPod Service) - Apple Inc. - C:\Programmi\iPod\bin\iPodService.exe
O23 - Service: Java Quick Starter (JavaQuickStarterService) - Oracle Corporation - C:\Programmi\Java\jre7\bin\jqs.exe
O23 - Service: NMIndexingService - Unknown owner - C:\Programmi\File comuni\Ahead\Lib\NMIndexingService.exe (file missing)
O23 - Service: VIPRE Internet Security (SBAMSvc) - GFI Software - C:\Programmi\GFI Software\VIPRE\SBAMSvc.exe
O23 - Service: SB Recovery Service (SBPIMSvc) - GFI Software - C:\Programmi\GFI Software\VIPRE\SBPIMSvc.exe

--
End of file - 5944 bytes
eddiguff
Utente Junior
 
Post: 11
Iscritto il: 15/11/10 22:17

Re: Trojan individuato ma con problemi di rimozione.

Postdi Luke57 » 18/08/13 09:15

Ciao, vai avanti con Tdss killer scegliendo Sì.
Luke57
Moderatore
 
Post: 6413
Iscritto il: 11/08/05 19:10

Re: Trojan individuato ma con problemi di rimozione.

Postdi eddiguff » 18/08/13 10:06

Ok, Luke57. Mi puoi confermare che poi non avrò problemi di avvio?
Perchè Tdss killer con l'opzione "SI" mi dice "If you have installed custom bootloader (eg Acronis, Grub, Lilo),
you will need to reinstall them after the treatment." E io non capisco a cosa si riferisce.
eddiguff
Utente Junior
 
Post: 11
Iscritto il: 15/11/10 22:17

Re: Trojan individuato ma con problemi di rimozione.

Postdi quizface » 18/08/13 10:31

Si riferisce a:
se tu hai cambiato deliberatamente il bootloader con uno diverso dall'originale, per fare il dual boot con un altro sistema operativo (per esempio XP e Linux) dovrai reinstallarlo altrimenti partira' solo XP
Se non siete sicuri di quello che scrivete, non scrivete niente, nessuno vi obbliga ed eviterete di confondere chi gia' e' confuso. Ciao..ciao
Avatar utente
quizface
Utente Senior
 
Post: 15071
Iscritto il: 03/10/04 00:36

Re: Trojan individuato ma con problemi di rimozione.

Postdi eddiguff » 18/08/13 13:30

Bene. Ho seguito le vostre istruzioni e con Tdss Killer IL PROBLEMA E' RISOLTO!! Grazie davvero. Ciao.
eddiguff
Utente Junior
 
Post: 11
Iscritto il: 15/11/10 22:17


Torna a Sicurezza e Privacy


Topic correlati a "Trojan individuato ma con problemi di rimozione.":


Chi c’è in linea

Visitano il forum: Nessuno e 18 ospiti