HELP!! forse un virus

Aperto da Ark_roma, 28 Ottobre 2009, 17:43:22

Discussione precedente - Discussione successiva

0 Utenti e 1 Visitatore stanno visualizzando questa discussione.

Ark_roma

Ciao a tutti! sono nuovo del forum. Magari c'è una sezione specifica per presentarsi, forse non c'è bisogno, non so...cmq per stare tranquilli...io sono Sabatino! e ringrazio già da ora tutti quelli che vorranno darmi una mano!
 
Allora - il mio sistema operativo è Windosw Vista Home
il mio antivurus Avast Home
 
Problema - Da un po' di tempo, mi ritrovo cliccando sul tasto "passa da una finestra all'altra" [fig.1] (quello sulla barra di windows) mi compaio otto finestre (che in realtà io non ho mai aperto e che non vedo) col nome "FORM 1" l'unico modo per chiuderle è tramite il task manager.
A queste finistre fanno riferimento processi tipo "cchihg.xyz.exe"! [fig.2 - fig.3]
 
Allego le immagini per farvi capire...non so se ho spiegato bene!
 
Suluzioni provate - Ho fatto più scansioni antivirus sia normalmente che all'avvio (con avast antivirus). Ho controllato se c'erano errori usando ccleaner. Ho fatto una scansione anti-spyware con Ad-Aware 2008.
 
Ma non ho risolto il problema. Questo FORM1 non vuole lasciare il mio pc! si sarà affezionato!
 
Domande: 1. ma cos'è, un virus???
2. come lo elimino, qualunque cosa sia??
 
Help me... :que: ...grazie a tutti

dasoca

Ciao e benvenuto su Forumzone!!! ;):okduo:
Mi dispiace dirtelo, ma sei pieno di trojan:(:blade:
Posta un log di HijackThis, intanto vediamo quello.
Poi prova una scansione in modalita provvisoria con l'antivirus....
Ascolta la donna quando ti guarda, non quando ti parla......

Ark_roma

D'oh...quindi ho beccato un po' di virus!!! :(:( che fanno comunella sul mio pc :beerbeer:.....
 
"Posta un log di HijackThis"     --- cioè???? me lo spieghi in stampatello?!! sorry!  :que::que:

grazie...

dasoca

Scarica HijackThis da QUI
Installalo e avvialo (se usi win Vista devi avviarlo come amministratore).
Clicca su "Do a system scan only" al termine clicca su "Save log" e salva dove ti pare il file di testo creato.
A questo punto posta il file txt sul forum che ci diamo un'occhiata.;)
Ascolta la donna quando ti guarda, non quando ti parla......

Ark_roma

Spero sia giusto!  :)
 
 
 
Logfile of Trend Micro HijackThis v2.0.2
Scan saved at 17.41.22, on 31/10/2009
Platform: Windows Vista SP1 (WinNT 6.00.1905)
MSIE: Internet Explorer v8.00 (8.00.6001.18813)
Boot mode: Normal
Running processes:
C:\Windows\system32\Dwm.exe
C:\Windows\Explorer.EXE
C:\Program Files\Synaptics\SynTP\SynTPStart.exe
C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
C:\Windows\RtHDVCpl.exe
C:\Program Files\Intel\Intel Matrix Storage Manager\IAAnotif.exe
C:\Program Files\Hp\QuickPlay\QPService.exe
C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\QLBCTRL.exe
C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
C:\Program Files\Windows Defender\MSASCui.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
C:\Program Files\Alwil Software\Avast4\ashDisp.exe
C:\Windows\System32\rundll32.exe
C:\Program Files\Java\jre6\bin\jusched.exe
C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe
C:\PerfLogs\cchihg.xyz.exe
C:\boot\cbbbbg.xyz.exe
C:\boot\bdhfbb.xyz.exe
C:\Program Files\bbcbbb.xyz.exe
C:\PerfLogs\bcbicb.xyz.exe
C:\Program Files\chdcbl.xyz.exe
C:\CVS\bidccg.xyz.exe
C:\Media\bbbbeb.xyz.exe
C:\Windows\ehome\ehtray.exe
C:\Windows\ehome\ehmsas.exe
C:\Program Files\Common Files\PCSuite\Services\ServiceLayer.exe
C:\Windows\System32\rundll32.exe
C:\Windows\system32\taskeng.exe
C:\Windows\System32\mobsync.exe
C:\Windows\system32\wbem\unsecapp.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\wuauclt.exe
C:\Program Files\Internet Explorer\iexplore.exe
C:\Windows\system32\SearchFilterHost.exe
C:\Windows\Explorer.exe
C:\Programmi\Trend Micro\HijackThis\HijackThis.exe
R1 - HKCU\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page = http://www.google.it/
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Page_URL = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Pavilion&pf=laptop
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Default_Search_URL = http://go.microsoft.com/fwlink/?LinkId=54896
R1 - HKLM\Software\Microsoft\Internet Explorer\Main,Search Page = http://go.microsoft.com/fwlink/?LinkId=54896
R0 - HKLM\Software\Microsoft\Internet Explorer\Main,Start Page = http://ie.redirect.hp.com/svs/rdr?TYPE=3&tp=iehome&locale=it_it&c=81&bd=Pavilion&pf=laptop
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,SearchAssistant =
R0 - HKLM\Software\Microsoft\Internet Explorer\Search,CustomizeSearch =
R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName =
O1 - Hosts: ::1 localhost
O2 - BHO: Supporto di collegamento per Adobe PDF Reader - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} - C:\Program Files\Common Files\Adobe\Acrobat\ActiveX\AcroIEHelper.dll
O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
O2 - BHO: Java(tm) Plug-In SSV Helper - {761497BB-D6F0-462C-B6EB-D4DAF1D92D43} - C:\Program Files\Java\jre6\bin\ssv.dll
O2 - BHO: AOL Toolbar Launcher - {7C554162-8CB7-45A4-B8F4-8EA1C75885F9} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O2 - BHO: Guida per l'accesso a Windows Live - {9030D464-4C02-4ABF-8ECC-5164760863C6} - C:\Program Files\Common Files\Microsoft Shared\Windows Live\WindowsLiveLogin.dll
O2 - BHO: AcroIEToolbarHelper Class - {AE7CD045-E861-484f-8273-0445EE161910} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O2 - BHO: Java(tm) Plug-In 2 SSV Helper - {DBC80044-A445-435b-BC74-9C25C1C588A9} - C:\Program Files\Java\jre6\bin\jp2ssv.dll
O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O3 - Toolbar: AOL Toolbar - {DE9C389F-3316-41A7-809B-AA305ED9D922} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O3 - Toolbar: Adobe PDF - {47833539-D0C5-4125-9FA8-0819E2EAAC93} - C:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll
O4 - HKLM\..\Run: [SynTPStart] C:\Program Files\Synaptics\SynTP\SynTPStart.exe
O4 - HKLM\..\Run: [SMSERIAL] C:\Program Files\Motorola\SMSERIAL\sm56hlpr.exe
O4 - HKLM\..\Run: [RtHDVCpl] RtHDVCpl.exe
O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
O4 - HKLM\..\Run: [QPService] "C:\Program Files\HP\QuickPlay\QPService.exe"
O4 - HKLM\..\Run: [QlbCtrl] %ProgramFiles%\Hewlett-Packard\HP Quick Launch Buttons\QlbCtrl.exe /Start
O4 - HKLM\..\Run: [OnScreenDisplay] C:\Program Files\Hewlett-Packard\HP QuickTouch\HPKBDAPP.exe
O4 - HKLM\..\Run: [UCam_Menu] "C:\Program Files\CyberLink\YouCam\MUITransfer\MUIStartMenu.exe" "C:\Program Files\CyberLink\YouCam" update "Software\CyberLink\YouCam\1.0"
O4 - HKLM\..\Run: [Windows Defender] %ProgramFiles%\Windows Defender\MSASCui.exe -hide
O4 - HKLM\..\Run: [HP Health Check Scheduler] [ProgramFilesFolder]Hewlett-Packard\HP Health Check\HPHC_Scheduler.exe
O4 - HKLM\..\Run: [hpWirelessAssistant] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\HPWAMain.exe
O4 - HKLM\..\Run: [WAWifiMessage] C:\Program Files\Hewlett-Packard\HP Wireless Assistant\WiFiMsg.exe
O4 - HKLM\..\Run: [avast!] C:\PROGRA~1\ALWILS~1\Avast4\ashDisp.exe
O4 - HKLM\..\Run: [NvSvc] RUNDLL32.EXE C:\Windows\system32\nvsvc.dll,nvsvcStart
O4 - HKLM\..\Run: [NvCplDaemon] RUNDLL32.EXE C:\Windows\system32\NvCpl.dll,NvStartup
O4 - HKLM\..\Run: [NvMediaCenter] RUNDLL32.EXE C:\Windows\system32\NvMcTray.dll,NvTaskbarInit
O4 - HKLM\..\Run: [SunJavaUpdateSched] "C:\Program Files\Java\jre6\bin\jusched.exe"
O4 - HKLM\..\Run: [DataLayer] C:\Program Files\Common Files\PCSuite\DataLayer\DataLayer.exe
O4 - HKLM\..\Run: [PCSuiteTrayApplication] C:\Program Files\Nokia\Nokia PC Suite 6\LaunchApplication.exe -onlytray
O4 - HKLM\..\Run: [Adobe Reader Speed Launcher] "C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe"
O4 - HKLM\..\Run: [cchihg.xyz.exe] C:\PerfLogs\cchihg.xyz.exe
O4 - HKLM\..\Run: [cbbbbg.xyz.exe] C:\boot\cbbbbg.xyz.exe
O4 - HKLM\..\Run: [bdhfbb.xyz.exe] C:\boot\bdhfbb.xyz.exe
O4 - HKLM\..\Run: [bbcbbb.xyz.exe] C:\Program Files\bbcbbb.xyz.exe
O4 - HKLM\..\Run: [bcbicb.xyz.exe] C:\PerfLogs\bcbicb.xyz.exe
O4 - HKLM\..\Run: [chdcbl.xyz.exe] C:\Program Files\chdcbl.xyz.exe
O4 - HKLM\..\Run: [bidccg.xyz.exe] C:\CVS\bidccg.xyz.exe
O4 - HKLM\..\Run: [bbbbeb.xyz.exe] C:\Media\bbbbeb.xyz.exe
O4 - HKCU\..\Run: [ehTray.exe] C:\Windows\ehome\ehTray.exe
O4 - HKUS\S-1-5-19\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-19\..\Run: [WindowsWelcomeCenter] rundll32.exe oobefldr.dll,ShowWelcomeCenter (User 'SERVIZIO LOCALE')
O4 - HKUS\S-1-5-20\..\Run: [Sidebar] %ProgramFiles%\Windows Sidebar\Sidebar.exe /detectMem (User 'SERVIZIO DI RETE')
O4 - HKUS\S-1-5-18\..\Run: [cchihg.xyz.exe] C:\PerfLogs\cchihg.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bcbicb.xyz.exe] C:\PerfLogs\bcbicb.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [chdcbl.xyz.exe] C:\Program Files\chdcbl.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bidccg.xyz.exe] C:\CVS\bidccg.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bbbbeb.xyz.exe] C:\Media\bbbbeb.xyz.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [cchihg.xyz.exe] C:\PerfLogs\cchihg.xyz.exe (User 'Default user')
O8 - Extra context menu item: &AOL Toolbar Cerca - c:\program files\aol\aol toolbar 5.0\resources\it-it\local\search.html
O8 - Extra context menu item: Converti destinazione link in Adobe PDF - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti destinazione link in file PDF esistente - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti i link selezionati in Adobe PDF - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECaptureSelLinks.html
O8 - Extra context menu item: Converti i link selezionati in file PDF esistente - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppendSelLinks.html
O8 - Extra context menu item: Converti in Adobe PDF - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti nel file PDF esistente - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: Converti selezione in Adobe PDF - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIECapture.html
O8 - Extra context menu item: Converti selezione in file PDF esistente - res://c:\Program Files\Adobe\Adobe Acrobat 7.0\Acrobat\AcroIEFavClient.dll/AcroIEAppend.html
O8 - Extra context menu item: E&sporta in Microsoft Excel - res://c:\PROGRA~1\MICROS~3\Office12\EXCEL.EXE/3000
O9 - Extra button: AOL Toolbar - {3369AF0D-62E9-4bda-8103-B4C75499B578} - C:\Program Files\AOL\AOL Toolbar 5.0\aoltb.dll
O9 - Extra button: Research - {92780B25-18CC-41C8-B9BE-3C9C571A8263} - C:\PROGRA~1\MI1933~1\Office12\REFIEBAR.DLL
O13 - Gopher Prefix:
O16 - DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} (GameDesire Roulette) - http://cached.gamedesire.com/g_bin/eng/roulette_2_0_0_27.cab
O16 - DPF: {20A60F0D-9AFA-4515-A0FD-83BD84642501} (Checkers Class) - http://messenger.zone.msn.com/binary/msgrchkr.cab56986.cab
O16 - DPF: {4F1E5B1A-2A80-42CA-8532-2D05CB959537} (MSN Photo Upload Tool) - http://gfx2.hotmail.com/mail/w3/resources/VistaMSNPUpldit-it.cab
O16 - DPF: {5D6F45B3-9043-443D-A792-115447494D24} (UnoCtrl Class) - http://messenger.zone.msn.com/MessengerGamesContent/GameContent/it/uno1/GAME_UNO1.cab
O16 - DPF: {B8BE5E93-A60C-4D26-A2DC-220313175592} (MSN Games - Installer) - http://messenger.zone.msn.com/binary/ZIntro.cab56649.cab
O16 - DPF: {BFA1F11D-3121-AFE1-4112-894323212DAC} (GameDesire Word Games) - http://download.gamedesire.com/g_bin/eng/words_2_0_0_51.cab
O16 - DPF: {C3F79A2B-B9B4-4A66-B012-3EE46475B072} (MessengerStatsClient Class) - http://messenger.zone.msn.com/binary/MessengerStatsPAClient.cab56907.cab
O16 - DPF: {F5A7706B-B9C0-4C89-A715-7A0C6B05DD48} (Minesweeper Flags Class) - http://messenger.zone.msn.com/binary/MineSweeper.cab56986.cab
O16 - DPF: {FDDBE2B8-6602-4AD8-946D-94C5A32FA6C1} (GameDesire Pool 8) - http://194.244.16.123/g_bin/eng/billard8_2_0_0_35.cab
O23 - Service: Lavasoft Ad-Aware Service (aawservice) - Lavasoft - C:\Program Files\Lavasoft\Ad-Aware\aawservice.exe
O23 - Service: Adobe LM Service - Adobe Systems - C:\Program Files\Common Files\Adobe Systems Shared\Service\Adobelmsvc.exe
O23 - Service: Adobe Version Cue CS2 - Adobe Systems Incorporated - C:\Program Files\Adobe\Adobe Version Cue CS2\bin\VersionCueCS2.exe
O23 - Service: avast! iAVS4 Control Service (aswUpdSv) - ALWIL Software - C:\Program Files\Alwil Software\Avast4\aswUpdSv.exe
O23 - Service: Autodesk Licensing Service - Autodesk - C:\Program Files\Common Files\Autodesk Shared\Service\AdskScSrv.exe
O23 - Service: avast! Antivirus - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashServ.exe
O23 - Service: avast! Mail Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashMaiSv.exe
O23 - Service: avast! Web Scanner - ALWIL Software - C:\Program Files\Alwil Software\Avast4\ashWebSv.exe
O23 - Service: Com4Qlb - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\HP Quick Launch Buttons\Com4Qlb.exe
O23 - Service: HP Health Check Service - Hewlett-Packard - c:\Program Files\Hewlett-Packard\HP Health Check\hphc_service.exe
O23 - Service: hpqwmiex - Hewlett-Packard Development Company, L.P. - C:\Program Files\Hewlett-Packard\Shared\hpqwmiex.exe
O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMON) - Intel Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\IAANTMon.exe
O23 - Service: InstallDriver Table Manager (IDriverT) - Macrovision Corporation - C:\Program Files\Common Files\InstallShield\Driver\11\Intel 32\IDriverT.exe
O23 - Service: LightScribeService Direct Disc Labeling Service (LightScribeService) - Hewlett-Packard Company - C:\Program Files\Common Files\LightScribe\LSSrvc.exe
O23 - Service: QuickPlay Background Capture Service (QBCS) (QPCapSvc) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPCapSvc.exe
O23 - Service: QuickPlay Task Scheduler (QTS) (QPSched) - Unknown owner - C:\Program Files\HP\QuickPlay\Kernel\TV\QPSched.exe
O23 - Service: Cyberlink RichVideo Service(CRVS) (RichVideo) - Unknown owner - C:\Program Files\CyberLink\Shared Files\RichVideo.exe
--
End of file - 12964 bytes

dasoca

Ok!:okduo:

Fixa le seguenti voci:
        O2 - BHO: (no name) - {5C255C8A-E604-49b4-9D64-90988571CECB} - (no file)
O2 - BHO: NCO 2.0 IE BHO - {602ADB0E-4AFF-4217-8AA1-95DAC4DFA408} - (no file)
        O3 - Toolbar: (no name) - {7FEBEFE3-6B19-4349-98D2-FFB09D4B49CA} - (no file)
O4 - HKLM\..\Run: [cbbbbg.xyz.exe] C:\boot\cbbbbg.xyz.exe
O4 - HKLM\..\Run: [bdhfbb.xyz.exe] C:\boot\bdhfbb.xyz.exe
O4 - HKLM\..\Run: [bbcbbb.xyz.exe] C:\Program Files\bbcbbb.xyz.exe
O4 - HKLM\..\Run: [bbcbbb.xyz.exe] C:\Program Files\bbcbbb.xyz.exe
O4 - HKLM\..\Run: [bcbicb.xyz.exe] C:\PerfLogs\bcbicb.xyz.exe
O4 - HKLM\..\Run: [chdcbl.xyz.exe] C:\Program Files\chdcbl.xyz.exe
O4 - HKLM\..\Run: [bidccg.xyz.exe] C:\CVS\bidccg.xyz.exe
        O4 - HKLM\..\Run: [bbbbeb.xyz.exe] C:\Media\bbbbeb.xyz.exe
O4 - HKUS\S-1-5-18\..\Run: [cchihg.xyz.exe] C:\PerfLogs\cchihg.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bcbicb.xyz.exe] C:\PerfLogs\bcbicb.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [chdcbl.xyz.exe] C:\Program Files\chdcbl.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bidccg.xyz.exe] C:\CVS\bidccg.xyz.exe (User 'SYSTEM')
O4 - HKUS\S-1-5-18\..\Run: [bbbbeb.xyz.exe] C:\Media\bbbbeb.xyz.exe (User 'SYSTEM')
O4 - HKUS\.DEFAULT\..\Run: [cchihg.xyz.exe] C:\PerfLogs\cchihg.xyz.exe (User 'Default user')
O16 - DPF: {18506D80-9B80-11D4-82C2-0080C8D7ED4A} (GameDesire Roulette) - http://cached.gamedesire.com/g_bin/eng/roulette_2_0_0_27.cab
Ascolta la donna quando ti guarda, non quando ti parla......

Ark_roma

ho fixato le voci che mi avevi indicato...ed era rimasto uno di quei "FORM 1"...
 
..quindi ho guardato un po' in giro e...ho beccato anke l'ultimo!
Ora sembra tutto ok!!!
Grazie mille!!!  :okduo::beerbeer::circle:

dasoca

Ottimo!!!:okduo:
Eventualmente puoi fare anche una scansione con l'antivirus in modalità provvisoria....
Ascolta la donna quando ti guarda, non quando ti parla......

Ark_roma

Sono riapparsi!!!! come mai???
 
:(

dasoca

Strano....:(
Rifai un log di HijakThis e vediamo, poi una scansione con l'antivirus in modalità provvisoria....:blade:
Ascolta la donna quando ti guarda, non quando ti parla......