08.01.07, 14:16
na pewnym komputerze wyskakuje od paru dni alarm ze NOD 32 wykryl wirusa
plik sie nazywa tt.exe
sprawdzilem to na stronce
virusscan.jotti.org
i wyskoczyla nastepujaca lista:
AntiVir Found HEUR/Malware
ArcaVir Found nothing
Avast Found Win32:Agent-DHX
BitDefender Found Trojan.Agent.AET
Dr.Web Found MULDROP.Trojan (probable variant)
NOD32 Found a variant of Win32/PSW.Agent.NBN

wystepuje pod adresem
www.pptp.cn/tt.exe
a na dysku jest pod adresem
C:\Program Files\tt.exe
za kazdym razem jest kasowany ale jakos powraca.
co z tym mozna zrobic, ktos sie z czyms takim spotkal?
Obserwuj wątek
      • darekkr1 Re: wirus? 09.01.07, 09:34
        Log z hijacka:

        Logfile of HijackThis v1.99.1
        Scan saved at 09:31:39, on 2007-01-09
        Platform: Windows XP Dodatek SP2 (WinNT 5.01.2600)
        MSIE: Internet Explorer v6.00 SP2 (6.00.2900.2180)

        Running processes:
        C:\WINDOWS\System32\smss.exe
        C:\WINDOWS\system32\csrss.exe
        C:\WINDOWS\system32\winlogon.exe
        C:\WINDOWS\system32\services.exe
        C:\WINDOWS\system32\lsass.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\System32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\WINDOWS\system32\svchost.exe
        C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens
        Computers\odClientService.exe
        C:\WINDOWS\system32\spoolsv.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
        C:\Program Files\Eset\nod32krn.exe
        C:\WINDOWS\System32\alg.exe
        C:\WINDOWS\system32\Ati2evxx.exe
        C:\WINDOWS\Explorer.EXE
        C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe
        C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe
        C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens
        Computers\OdTray.exe
        C:\WINDOWS\sm56hlpr.exe
        C:\Program Files\Eset\nod32kui.exe
        C:\Program Files\Alcatel\SpeedTouch USB\Dragdiag.exe
        C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
        C:\Program Files\Outlook Express\msimn.exe
        C:\Program Files\Microsoft Office\OFFICE11\WINWORD.EXE
        C:\temp\hijack\HijackThis.exe

        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Start Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Main,Local Page =
        R0 - HKCU\Software\Microsoft\Internet Explorer\Toolbar,LinksFolderName = Łącza
        O2 - BHO: AcroIEHlprObj Class - {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3} -
        C:\Program Files\Adobe\Acrobat 7.0\ActiveX\AcroIEHelper.dll
        O4 - HKLM\..\Run: [ATIPTA] C:\Program Files\ATI Technologies\ATI Control
        Panel\atiptaxx.exe
        O4 - HKLM\..\Run: [SynTPLpr] C:\Program Files\Synaptics\SynTP\SynTPLpr.exe
        O4 - HKLM\..\Run: [SynTPEnh] C:\Program Files\Synaptics\SynTP\SynTPEnh.exe
        O4 - HKLM\..\Run: [IAAnotif] C:\Program Files\Intel\Intel Matrix Storage
        Manager\iaanotif.exe
        O4 - HKLM\..\Run: [OdTray.exe] "C:\Program Files\Fujitsu Siemens
        Computers\Odyssey Client for Fujitsu Siemens Computers\OdTray.exe"
        O4 - HKLM\..\Run: [NeroFilterCheck] C:\WINDOWS\system32\NeroCheck.exe
        O4 - HKLM\..\Run: [Skrót do strony właściwości High Definition Audio] HDAShCut.exe
        O4 - HKLM\..\Run: [SMSERIAL] sm56hlpr.exe
        O4 - HKLM\..\Run: [nod32kui] "C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE
        O4 - HKLM\..\Run: [SpeedTouch USB Diagnostics] "C:\Program
        Files\Alcatel\SpeedTouch USB\Dragdiag.exe" /icon
        O4 - HKLM\..\Run: [WOOWATCH] C:\PROGRA~1\Wanadoo\Watch.exe
        O4 - HKLM\..\Run: [WOOTASKBARICON] C:\PROGRA~1\Wanadoo\TaskbarIcon.exe
        O4 - HKCU\..\Run: [updateMgr] C:\Program Files\Adobe\Acrobat
        7.0\Reader\AdobeUpdateManager.exe AcRdB7_0_5 -reboot 1
        O4 - Startup: Skrót do EasySearch_3.0.0.0.lnk = C:\temp\EasySearch_3.0.0.0.exe
        O4 - Global Startup: Adobe Reader Speed Launch.lnk = C:\Program
        Files\Adobe\Acrobat 7.0\Reader\reader_sl.exe
        O4 - Global Startup: DSLMON.lnk = C:\Program Files\SAGEM\SAGEM F@st
        800-840\dslmon.exe
        O8 - Extra context menu item: E&ksport do programu Microsoft Excel -
        res://C:\PROGRA~1\MICROS~2\OFFICE11\EXCEL.EXE/3000
        O9 - Extra button: Badanie - {92780B25-18CC-41C8-B9BE-3C9C571A8263} -
        C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL
        O20 - Winlogon Notify: OdysseyClient - C:\WINDOWS\SYSTEM32\odyEvent.dll
        O23 - Service: Ati HotKey Poller - ATI Technologies Inc. -
        C:\WINDOWS\system32\Ati2evxx.exe
        O23 - Service: Intel(R) Matrix Storage Event Monitor (IAANTMon) - Intel
        Corporation - C:\Program Files\Intel\Intel Matrix Storage Manager\iaantmon.exe
        O23 - Service: NOD32 Kernel Service (NOD32krn) - Eset - C:\Program
        Files\Eset\nod32krn.exe
        O23 - Service: Odyssey Client for Fujitsu Siemens Computers (odClientService) -
        Funk Software, Inc. - C:\Program Files\Fujitsu Siemens Computers\Odyssey Client
        for Fujitsu Siemens Computers\odClientService.exe
          • darekkr1 Re: wirus? 09.01.07, 13:57
            log z Silent runers:
            "Silent Runners.vbs", revision 49, www.silentrunners.org/
            Operating System: Windows XP SP2
            Output limited to non-default values, except where indicated by "{++}"


            Startup items buried in registry:
            ---------------------------------

            HKCU\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
            "updateMgr" = "C:\Program Files\Adobe\Acrobat 7.0\Reader\AdobeUpdateManager.exe
            AcRdB7_0_5 -reboot 1" ["Adobe Systems Incorporated"]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Run\ {++}
            "ATIPTA" = "C:\Program Files\ATI Technologies\ATI Control Panel\atiptaxx.exe"
            ["ATI Technologies, Inc."]
            "SynTPLpr" = "C:\Program Files\Synaptics\SynTP\SynTPLpr.exe" ["Synaptics, Inc."]
            "SynTPEnh" = "C:\Program Files\Synaptics\SynTP\SynTPEnh.exe" ["Synaptics, Inc."]
            "IAAnotif" = "C:\Program Files\Intel\Intel Matrix Storage Manager\iaanotif.exe"
            ["Intel Corporation"]
            "OdTray.exe" = ""C:\Program Files\Fujitsu Siemens Computers\Odyssey Client for
            Fujitsu Siemens Computers\OdTray.exe"" ["Funk Software, Inc."]
            "NeroFilterCheck" = "C:\WINDOWS\system32\NeroCheck.exe" ["Ahead Software Gmbh"]
            "Skrót do strony właściwości High Definition Audio" = "HDAShCut.exe" ["Windows
            (R) Server 2003 DDK provider"]
            "SMSERIAL" = "sm56hlpr.exe" ["Motorola Inc."]
            "nod32kui" = ""C:\Program Files\Eset\nod32kui.exe" /WAITSERVICE" ["Eset "]
            "SpeedTouch USB Diagnostics" = ""C:\Program Files\Alcatel\SpeedTouch
            USB\Dragdiag.exe" /icon" ["THOMSON multimedia"]
            "WOOWATCH" = "C:\PROGRA~1\Wanadoo\Watch.exe" ["France Télécom R&D"]
            "WOOTASKBARICON" = "C:\PROGRA~1\Wanadoo\TaskbarIcon.exe" ["France Télécom R&D"]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\Browser Helper Objects\
            {06849E9F-C8D7-4D59-B87D-784B7D6BE0B3}\(Default) = (no title provided)
            -> {HKLM...CLSID} = "AcroIEHlprObj Class"
            \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat
            7.0\ActiveX\AcroIEHelper.dll" ["Adobe Systems Incorporated"]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved\
            "{42071714-76d4-11d1-8b24-00a0c9068ff3}" = "Rozszerzenie CPL kadrowania
            wyświetlania"
            -> {HKLM...CLSID} = "Rozszerzenie CPL kadrowania wyświetlania"
            \InProcServer32\(Default) = "deskpan.dll" [file not found]
            "{88895560-9AA2-1069-930E-00AA0030EBC8}" = "Rozszerzenie ikony HyperTerminalu"
            -> {HKLM...CLSID} = "HyperTerminal Icon Ext"
            \InProcServer32\(Default) = "C:\WINDOWS\system32\hticons.dll"
            ["Hilgraeve, Inc."]
            "{2F603045-309F-11CF-9774-0020AFD0CFF6}" = "Synaptics Control Panel"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program
            Files\Synaptics\SynTP\SynTPCpl.dll" ["Synaptics, Inc."]
            "{E0D79304-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
            ["WinZip Computing, Inc."]
            "{E0D79305-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
            ["WinZip Computing, Inc."]
            "{E0D79306-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
            ["WinZip Computing, Inc."]
            "{E0D79307-84BE-11CE-9641-444553540000}" = "WinZip"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
            ["WinZip Computing, Inc."]
            "{B327765E-D724-4347-8B16-78AE18552FC3}" = "NeroDigitalIconHandler"
            -> {HKLM...CLSID} = "NeroDigitalIconHandler Class"
            \InProcServer32\(Default) = "C:\Program Files\Common
            Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
            "{7F1CF152-04F8-453A-B34C-E609530A9DC8}" = "NeroDigitalPropSheetHandler"
            -> {HKLM...CLSID} = "NeroDigitalPropSheetHandler Class"
            \InProcServer32\(Default) = "C:\Program Files\Common
            Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
            "{00020D75-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Desktop
            Icon Handler"
            -> {HKLM...CLSID} = "Microsoft Office Outlook"
            \InProcServer32\(Default) =
            "C:\PROGRA~1\MICROS~2\OFFICE11\MLSHEXT.DLL" [MS]
            "{0006F045-0000-0000-C000-000000000046}" = "Microsoft Office Outlook Custom Icon
            Handler"
            -> {HKLM...CLSID} = "Rozszerzenie ikon plików programu Outlook"
            \InProcServer32\(Default) =
            "C:\PROGRA~1\MICROS~2\OFFICE11\OLKFSTUB.DLL" [MS]
            "{42042206-2D85-11D3-8CFF-005004838597}" = "Microsoft Office HTML Icon Handler"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program Files\Microsoft
            Office\OFFICE11\msohev.dll" [MS]
            "{23170F69-40C1-278A-1000-000100020000}" = "7-Zip Shell Extension"
            -> {HKLM...CLSID} = "7-Zip Shell Extension"
            \InProcServer32\(Default) = "C:\Program
            Files\7-Zip\7-zip.dll" ["Igor Pavlov"]
            "{7CDDBD23-1B50-47b2-B28D-1B84D9A40ED1}" = "Sony Digital Voice File Shell
            Extention Module"
            -> {HKLM...CLSID} = "Sony Digital Voice File Shell Extention Module"
            \InProcServer32\(Default) = "IcdShlex.dll" ["Sony Corporation"]
            "{B089FE88-FB52-11d3-BDF1-0050DA34150D}" = "NOD32 Context Menu Shell Extension"
            -> {HKLM...CLSID} = "NOD32 Context Menu Shell Extension"
            \InProcServer32\(Default) = "C:\Program
            Files\Eset\nodshex.dll" ["Eset "]

            HKLM\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks\
            <<!>> "{1A404685-7563-4d02-B0F6-58B308A406A9}" = (no title provided)
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "c:\program files\ati
            technologies\ati control panel\ackoxkfq.dll" [empty string]

            HKLM\Software\Microsoft\Windows NT\CurrentVersion\Winlogon\Notify\
            <<!>> AtiExtEvent\DLLName = "Ati2evxx.dll" ["ATI Technologies Inc."]
            <<!>> OdysseyClient\DLLName = "odyEvent.dll" ["Funk Software, Inc."]

            HKLM\Software\Classes\PROTOCOLS\Filter\
            <<!>> text/xml\CLSID = "{807553E5-5146-11D5-A672-00B0D022E945}"
            -> {HKLM...CLSID} = (no title provided)
            \InProcServer32\(Default) = "C:\Program Files\Common
            Files\Microsoft Shared\OFFICE11\MSOXMLMF.DLL" [MS]

            HKLM\Software\Classes\Folder\shellex\ColumnHandlers\
            {7D4D6379-F301-4311-BEBA-E26EB0561882}\(Default) =
            "NeroDigitalExt.NeroDigitalColumnHandler"
            -> {HKLM...CLSID} = "NeroDigitalColumnHandler Class"
            \InProcServer32\(Default) = "C:\Program Files\Common
            Files\Ahead\Lib\NeroDigitalExt.dll" ["Nero AG"]
            {F9DB5320-233E-11D1-9F84-707F02C10627}\(Default) = "PDF Column Info"
            -> {HKLM...CLSID} = "PDF Shell Extension"
            \InProcServer32\(Default) = "C:\Program Files\Adobe\Acrobat
            7.0\ActiveX\PDFShell.dll" ["Adobe Systems, Inc."]

            HKLM\Software\Classes\*\shellex\ContextMenuHandlers\
            7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
            -> {HKLM...CLSID} = "7-Zip Shell Extension"
            \InProcServer32\(Default) = "C:\Program
            Files\7-Zip\7-zip.dll" ["Igor Pavlov"]
            NOD32 Context Menu Shell Extension\(Default) =
            "{B089FE88-FB52-11d3-BDF1-0050DA34150D}"
            -> {HKLM...CLSID} = "NOD32 Context Menu Shell Extension"
            \InProcServer32\(Default) = "C:\Program
            Files\Eset\nodshex.dll" ["Eset "]
            WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
            -> {HKLM...CLSID} = "WinZip"
            \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
            ["WinZip Computing, Inc."]

            HKLM\Software\Classes\Directory\shellex\ContextMenuHandlers\
            7-Zip\(Default) = "{23170F69-40C1-278A-1000-000100020000}"
            -> {HKLM...CLSID} = "7-Zip Shell Extension"
            \InProcServer32\(Default) = "C:\Program
            Files\7-
            • darekkr1 Re: wirus? 10.01.07, 09:00
              Postaram sie dorwać później ten komputer i go tym ewido przeskanować
              Dalsza część loga:
              -Zip\7-zip.dll" ["Igor Pavlov"]
              WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
              -> {HKLM...CLSID} = "WinZip"
              \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
              ["WinZip Computing, Inc."]

              HKLM\Software\Classes\Folder\shellex\ContextMenuHandlers\
              NOD32 Context Menu Shell Extension\(Default) =
              "{B089FE88-FB52-11d3-BDF1-0050DA34150D}"
              -> {HKLM...CLSID} = "NOD32 Context Menu Shell Extension"
              \InProcServer32\(Default) = "C:\Program
              Files\Eset\nodshex.dll" ["Eset "]
              WinZip\(Default) = "{E0D79304-84BE-11CE-9641-444553540000}"
              -> {HKLM...CLSID} = "WinZip"
              \InProcServer32\(Default) = "C:\PROGRA~1\WINZIP\WZSHLSTB.DLL"
              ["WinZip Computing, Inc."]


              Group Policies {policy setting}:
              --------------------------------

              Note: detected settings may not have any effect.

              HKLM\Software\Microsoft\Windows\CurrentVersion\Policies\System\

              "shutdownwithoutlogon" = (REG_DWORD) hex:0x00000001
              {Shutdown: Allow system to be shut down without having to log on}

              "undockwithoutlogon" = (REG_DWORD) hex:0x00000001
              {Devices: Allow undock without having to log on}


              Active Desktop and Wallpaper:
              -----------------------------

              Active Desktop may be disabled at this entry:
              HKCU\Software\Microsoft\Windows\CurrentVersion\Explorer\ShellState

              Displayed if Active Desktop enabled and wallpaper not set by Group Policy:
              HKCU\Software\Microsoft\Internet Explorer\Desktop\General\
              "Wallpaper" = "C:\WINDOWS\system32\config\systemprofile\Ustawienia lokalne\Dane
              aplikacji\Microsoft\Wallpaper1.bmp"

              Displayed if Active Desktop disabled and wallpaper not set by Group Policy:
              HKCU\Control Panel\Desktop\
              "Wallpaper" = "C:\Documents and Settings\AMILO\Ustawienia lokalne\Dane
              aplikacji\Microsoft\Wallpaper1.bmp"


              Enabled Screen Saver:
              ---------------------

              HKCU\Control Panel\Desktop\
              "SCRNSAVE.EXE" = "C:\WINDOWS\system32\logon.scr" [MS]


              Startup items in "AMILO" & "All Users" startup folders:
              -------------------------------------------------------

              C:\Documents and Settings\AMILO\Menu Start\Programy\Autostart
              "Skrót do EasySearch_3.0.0.0" -> shortcut to: "C:\temp\EasySearch_3.0.0.0.exe"
              ["D-Link"]

              C:\Documents and Settings\All Users\Menu Start\Programy\Autostart
              "Adobe Reader Speed Launch" -> shortcut to: "C:\Program Files\Adobe\Acrobat
              7.0\Reader\reader_sl.exe" ["Adobe Systems Incorporated"]
              "DSLMON" -> shortcut to: "C:\Program Files\SAGEM\SAGEM F@st 800-840\dslmon.exe
              /W" [empty string]


              Winsock2 Service Provider DLLs:
              -------------------------------

              Namespace Service Providers

              HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\NameSpace_Catalog5\Catalog_Entries\
              {++}
              000000000001\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]
              000000000002\LibraryPath = "%SystemRoot%\System32\winrnr.dll" [MS]
              000000000003\LibraryPath = "%SystemRoot%\System32\mswsock.dll" [MS]

              Transport Service Providers

              HKLM\System\CurrentControlSet\Services\Winsock2\Parameters\Protocol_Catalog9\Catalog_Entries\
              {++}
              0000000000##\PackedCatalogItem (contains) DLL [Company Name], (at) ## range:
              imon.dll ["Eset "], 01 - 05, 11
              %SystemRoot%\system32\mswsock.dll [MS], 06 - 08, 12 - 25
              %SystemRoot%\system32\rsvpsp.dll [MS], 09 - 10


              Toolbars, Explorer Bars, Extensions:
              ------------------------------------

              Explorer Bars

              HKLM\Software\Microsoft\Internet Explorer\Explorer Bars\

              HKLM\Software\Classes\CLSID\{FF059E31-CC5A-4E2E-BF3B-96E929D65503}\(Default) =
              "&Badanie"
              Implemented Categories\{00021493-0000-0000-C000-000000000046}\ [vertical bar]
              InProcServer32\(Default) = "C:\PROGRA~1\MICROS~2\OFFICE11\REFIEBAR.DLL" [MS]

              Extensions (Tools menu items, main toolbar menu buttons)

              HKLM\Software\Microsoft\Internet Explorer\Extensions\
              {92780B25-18CC-41C8-B9BE-3C9C571A8263}\
              "ButtonText" = "Badanie"


              Running Services (Display Name, Service Name, Path {Service DLL}):
              ------------------------------------------------------------------

              Ati HotKey Poller, Ati HotKey Poller, "C:\WINDOWS\system32\Ati2evxx.exe" ["ATI
              Technologies Inc."]
              Intel(R) Matrix Storage Event Monitor, IAANTMon, "C:\Program Files\Intel\Intel
              Matrix Storage Manager\iaantmon.exe" ["Intel Corporation"]
              NOD32 Kernel Service, NOD32krn, "C:\Program Files\Eset\nod32krn.exe" ["Eset "]
              Odyssey Client for Fujitsu Siemens Computers, odClientService, ""C:\Program
              Files\Fujitsu Siemens Computers\Odyssey Client for Fujitsu Siemens
              Computers\odClientService.exe"" ["Funk Software, Inc."]


              Print Monitors:
              ---------------

              HKLM\System\CurrentControlSet\Control\Print\Monitors\
              Microsoft Document Imaging Writer Monitor\Driver = "mdimon.dll" [MS]
              OKI HiperC Language Monitor2\Driver = "OPDMN014.DLL" ["Okidata Corporation"]
              PDFCreator\Driver = "pdfcmnnt.dll" [null data]
              RICOH Language Monitor2\Driver = "rc4mon.dll" ["RICOH CO.,Ltd."]


              ----------
              <<!>>: Suspicious data at a malware launch point.

              + This report excludes default entries except where indicated.
              + To see *everywhere* the script checks and *everything* it finds,
              launch it from a command prompt or a shortcut with the -all parameter.
              + To search all directories of local fixed drives for DESKTOP.INI
              DLL launch points, use the -supp parameter or answer "No" at the
              first message box and "Yes" at the second message box.
              --------

Nie pamiętasz hasła

lub ?

 

Nie masz jeszcze konta? Zarejestruj się

Nakarm Pajacyka